Ward-AI Log in

Privacy Policy

Last updated: April 14, 2026

This policy describes how KRP (hereinafter "we") processes personal data in connection with the Service ward-ai.io, in accordance with Regulation (EU) 2016/679 ("GDPR") and the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486, "PDPO").

1. Data Controller

KRP, Hong Kong, privacy@ward-ai.io.

For data processed on behalf of our enterprise clients (questions submitted by their users, documents analyzed), we act as a data processor within the meaning of Article 28 GDPR. A Data Processing Agreement (DPA) is available upon request.

2. Data Collected

CategoryDataLegal BasisRetention
User accountEmail, hashed password (Argon2id), encrypted 2FA secret, role, languagePerformance of contract (Art. 6.1.b)Duration of account + 1 year
AuthenticationIP, user agent, session timestamps, JTILegitimate interest — security (Art. 6.1.f)6 months
BillingCompany name, address, VAT number, payment transactionsLegal obligation (Art. 6.1.c)7 years (HK IRD accounting obligations)
UsageNumber of requests, tokens, cost, timestampsPerformance of contract (Art. 6.1.b)12 months
QueriesContent of messages sent to the AIPerformance of contract (Art. 6.1.b)Not stored permanently — technical log for 7 days
Uploaded documentsPDF/image files for analysisPerformance of contract (Art. 6.1.b)Configurable by the client — retained for the duration chosen in settings, then automatically deleted
Audit logAdministrative actions (HMAC-SHA256 chain)Legal obligation / legitimate interest2 years — accessible and exportable (CSV) by the client at any time
Contact formEmail, company, messagePre-contractual measures (Art. 6.1.b)12 months

3. Recipients and Sub-processors

We use the following sub-processors, all located within the EU:

All infrastructure and AI processing remain within the EU. The data controller (KRP) is established in Hong Kong. This international transfer from the EU to Hong Kong is governed by Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914). A copy is available on request.

4. International Data Transfers

Your data is processed and stored exclusively on servers located in the EU (Germany). The data controller operates from Hong Kong. To ensure adequate protection of personal data transferred outside the EU, we rely on:

5. Cookies

We only use strictly necessary cookies (authentication session, language preference). No advertising or third-party tracking cookies are used.

6. Your Rights

In accordance with Articles 15 to 22 of the GDPR and the PDPO, you have the following rights:

To exercise these rights: privacy@ward-ai.io. We will respond within one month.

7. Security

8. Data Breach Notification

In the event of a personal data breach likely to pose a risk to the rights and freedoms of data subjects, we will notify the supervisory authority within 72 hours (Art. 33 GDPR) and, where applicable, the affected data subjects (Art. 34 GDPR).

9. Service Discontinuation

In the event that the Service is discontinued ("wind-down"):

10. Changes

Any material change to this policy will be notified to registered users by email with 30 days' prior notice.