This policy explains what personal data we handle when you use the Alpha AI Indoor Inspection mobile app (the “Service”), and the rights you have over it.
The Service is not open to the public. There is no sign-up. Accounts are created and issued by the organisation that engages us — a building owner, a property manager, an inspection consultancy or their contractor. If you are using the Service, someone at your organisation gave you the account.
1. Who we are
The Service is operated by Alpha AI Technology Limited (“Alpha AI”, “we”, “us”), a company registered in Hong Kong with its registered office at United Centre, 95 Queensway, Admiralty, Hong Kong.
For any question about this policy or about your personal data, contact privacy@alphaaivision.com. Section 11 explains what we will do.
2. Our role — and your employer’s
Two different kinds of data run through the Service, and we hold them in two different capacities. The distinction decides who you ask when you want something changed or removed.
Inspection content — we act for your organisation
Defect photos, repair photos, floor plans, notes and reports belong to the client organisation that commissioned the inspection. We process them under that organisation’s instructions, to deliver the Service to them. In data-protection terms they are the controller and we are the processor.
If you want inspection content corrected or deleted, the decision is your organisation’s to make, not ours. Ask them; we will act on their instruction.
Account data — we decide
Your name, work email address, role and account activity exist so that we can run the Service securely and support it. We are the controller for that data, and you can exercise the rights in section 10 with us directly.
3. What we collect
| Category | What it is | Where it comes from |
|---|---|---|
| Account | Name, work email address, password, role, and the projects and inspections you are permitted to see. | Created by your organisation’s administrator; you supply your password at sign-in. |
| Inspection content | Photographs of buildings and defects, repair photographs, floor plans, and the classifications, severities and locations recorded against them. | Captured or uploaded by you and your colleagues. |
| Free text | Defect remarks and repair notes. | Typed by you. |
| Activity | Who captured, edited, submitted, endorsed or deleted a record, and when. This is the audit trail the Service exists to produce. | Generated by the Service as you work. |
| Technical | Server logs of requests to our API, including IP address, timestamp and the app or browser version. | Generated automatically when your device talks to our servers. |
What we do not collect
- No advertising identifiers, and no tracking. The app contains no advertising SDK, no analytics SDK, no crash-reporting SDK and no attribution SDK. We do not track you across other companies’ apps or websites, and the app will never show you an App Tracking Transparency prompt because there is nothing to ask you about.
- No device location. Neither mobile app requests location permission or reads your device’s position. See section 5 for the one place location can still appear.
- No contacts, calendar, microphone, or health data.
- No payment data. The Service is sold to organisations under contract; nobody pays through the app.
4. Why we use it
| Purpose | Data used |
|---|---|
| Signing you in and keeping your session secure | Account |
| Showing you the projects and inspections you are entitled to see, and no others | Account |
| Recording defects, tracking repairs and producing inspection reports | Inspection content, free text, activity |
| Keeping an audit trail of who did what, which is the point of a compliance record | Activity |
| Automatically detecting and classifying defects in imagery | Inspection content (see section 6) |
| Keeping the Service available, diagnosing faults, and investigating abuse | Technical |
| Supporting you when you or your organisation raise an issue | Account, technical |
We do not sell personal data. We do not use your inspection content to advertise anything to you or to anyone else.
Legal basis
Where Hong Kong’s Personal Data (Privacy) Ordinance (Cap. 486) applies, we collect and use personal data for the purposes above, which are directly related to providing the Service, and we do not use it for a new purpose without consent. Where the EU or UK GDPR applies, our lawful bases are contract (running the Service for your organisation) and legitimate interests (securing the Service and preventing abuse). We do not rely on consent, so there is no consent for you to withdraw. As a Hong Kong company we are subject to the PDPO; the GDPR applies only where you are in the EEA or the UK.
5. Photographs, imagery, and location inside them
Photographs are the substance of the Service. The camera and photo library permissions exist for one reason: to attach evidence to a defect, a repair or an inspection. Nothing is uploaded that you did not take or choose.
Photographs can contain people. A defect photograph taken on an occupied site may catch a resident, a worker or the inside of someone’s home. Only people authorised on that inspection can see it. Ask your organisation about their own rules for photographing occupied premises.
Photographs can carry location even though the app never asks for it. A camera can embed coordinates in the file’s EXIF metadata. In this app, a photo taken or chosen on the phone is re-encoded to JPEG on the device before upload, which removes that metadata. We do not use it to locate you.
6. Automated processing
The Service uses automated analysis to detect and classify defects in imagery, and to help inspectors work through an inspection. It is a tool for the inspector, not a decision-maker.
- It runs on infrastructure we control. Your imagery and inspection content are not sent to any third-party analysis or model vendor.
- No decision about a person is made automatically. A detection is a suggestion an inspector confirms or discards. Nothing in the Service produces a legal or similarly significant effect on anyone without a human deciding it.
7. Who else sees it
We share personal data only as set out here.
- Your organisation. Colleagues, teams and contractors authorised on the same inspection see the content of that inspection, and the audit trail shows your name against what you did. That is the Service working as intended.
- Service providers we rely on, listed below, each bound to handle the data only for us.
- Where the law requires it — a valid legal demand, or to establish or defend a legal claim.
- A successor, if the business or the relevant part of it is transferred. We will say so before it takes effect.
Service providers
We use a small number of infrastructure providers to run the Service — to host the application and its database, and to store photographs, imagery and generated reports. They hold data only to provide that infrastructure to us, under contract, and are not permitted to use it for anything of their own.
We do not give any provider access to your inspection content for their own purposes, and we do not use any third-party advertising, analytics or model vendor. If you would like the current list of the providers we use, ask us at privacy@alphaaivision.com.
Transfers out of your jurisdiction
Our infrastructure is located in Singapore. If you are in a place whose law restricts sending personal data abroad, data may be transferred to and stored in those locations, under appropriate safeguards with each provider. Where the destination requires it, we use appropriate safeguards such as standard contractual clauses.
8. Security
- Traffic between the app and our servers is encrypted in transit over HTTPS.
- Your password is never stored or transmitted in the clear. It is encrypted on your device before it is sent, and held on our servers in hashed form.
- On mobile, your sign-in token is kept in the operating system’s secure storage — the iOS Keychain or the Android Keystore — not in ordinary app preferences.
- Access is scoped per inspection and per role. A contractor account can reach only the inspections it is assigned to, and can submit repair evidence without being able to reclassify or delete a defect.
- Photographs and reports are held in private object storage, not publicly listable, and served through links that expire.
No system is perfectly secure. If a breach affects your personal data and the law requires us to tell you, we will, without undue delay.
9. How long we keep it
| What | Kept for |
|---|---|
| Inspection content and audit trail | For as long as your organisation’s contract with us runs, then 7 years after it ends, unless they instruct us otherwise. An inspection record is a compliance document and organisations are often required to keep it. |
| Account data | Until the account is closed by your organisation or by us, then 30 days. |
| Server logs | 90 days. |
| Backups | Deleted data persists in backups for up to 90 days before being overwritten on the normal cycle. |
10. Your rights
You can ask us to:
- Tell you whether we hold personal data about you, and give you a copy.
- Correct anything inaccurate.
- Delete your account and the personal data tied to it — see section 11.
- Restrict or object to a particular use, where the law gives you that right.
- Receive your data in a portable format, where the law gives you that right.
One limit worth being straight about. Where we hold inspection content on behalf of a client organisation, we cannot delete or alter it on your request alone — it is their record, and it is often one they are legally required to keep. We will pass your request to them and act on their instruction. Your account, and the personal data we control, are a different matter and we can act on those directly.
Under Hong Kong’s PDPO you may also complain to the Office of the Privacy Commissioner for Personal Data. In the EEA or the UK, you may complain to your national supervisory authority. We would rather you came to us first.
11. Deleting your data
There is a dedicated page for this, reachable without installing the app or signing in: Request data deletion.
It sets out what gets deleted, what is kept and why, and how long it takes.
12. Children
The Service is a workplace tool for adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child’s personal data has reached us, contact us and we will remove it.
13. Changes to this policy
If we change this policy we will update the date at the top. For a change that materially affects how we handle your personal data, we will give notice in the app or by email before it takes effect.
14. Contact
Alpha AI Technology Limited
United Centre, 95 Queensway, Admiralty, Hong Kong
privacy@alphaaivision.com
We aim to acknowledge a request within 5 working days and to answer it in full within 30 days. We may need to verify who you are before we act, so that we do not hand your data to someone else.
