Privacy Policy
KATO INFORMATION TECHNOLOGY CO., LTD. (Business Registration Number 60707143, "we") handles personal data in AIITO as set out below, in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong.
1. What we collect
Name, email address, telephone number, billing details, login credentials, service usage logs, IP addresses processed in short-lived rate-limiting records and, where applicable, operational mail or server logs, and content you store or send through the service — including email messages and their recipients, website content, enquiries, and what you enter into AI features.
Credit card details are collected and processed by our payment processor (Stripe). We do not hold your card number.
2. Why we use it
To provide the service; to verify your identity; to bill you; to provide support; to prevent misuse; to monitor and improve the reliability, security and performance of the service using usage data and, where practicable, aggregated data; and to send you important notices.
When investigating a fault you have reported, our staff may need to look at the affected email or website content. We do this only so far as necessary to resolve the fault, and access is limited to staff who need it.
The information needed to register an account, verify your identity and take payment is necessary in order to use the service. If you do not provide it, we may be unable to open an account or provide the service.
Your telephone number, the content of your website and email, what you enter into the AI features and other content are provided according to the features you use and the support you ask for. If you do not use the AI features, you do not need to provide anything to them.
3. AI processing and overseas transfer
To provide the AI features, prompts, instructions and related data you enter are sent to an AI provider for processing. As at the date of this policy we use Anthropic, PBC (United States).
Under the commercial API we use, inputs and outputs are not used to train AI models. We do not opt in to training, and we do not send feedback that would lead to training use.
Not used for training is not the same as not retained. The provider states that, under its standard commercial terms, inputs and outputs are automatically deleted from its systems within about 30 days, subject to exceptions such as legal obligations and its own abuse monitoring. We use its prompt caching feature, which holds part of the request briefly so that it does not have to be sent again. We have not arranged zero data retention, and we do not use its batch or file upload features.
Rights in the data you input and the output you receive are governed by our Terms of Service.
4. Disclosure and transfer to others
- Stripe and its group companies, for payment processing.
- Server providers, to whom we entrust the operation of the hosting platform.
- The AI provider described in section 3.
- Kato Tech LLC (Japan), our affiliated company, which provides technical operations and support services and may access personal data where necessary to perform those services.
- A purchaser, successor or proposed purchaser of all or part of our business, where the disclosure is reasonably necessary for the proposed or completed transaction and is subject to appropriate confidentiality and data protection safeguards.
- These include transfers outside Hong Kong, including to the United States and Japan. Where we transfer your data outside Hong Kong we take steps to ensure it is handled with a level of protection comparable to that required under the Ordinance.
- Apart from the recipients described above, and except where required or permitted by law, we do not disclose your personal data to others without your consent.
5. Direct marketing
We do not use your personal data for direct marketing without your consent, and we do not provide it to others for their marketing. Where we wish to do so we will seek your consent first, and you may withdraw it at any time at no cost by writing to aiito@kato-tech.com.hk.
Service notices — billing, faults, changes to terms — are not direct marketing and are sent as part of providing the service.
6. Cookies
We place one cookie, which remembers the language you chose. It contains no personal data and expires after one year.
We do not use cookies for analytics or advertising, and we do not use any third-party analytics service. Signing in uses your browser's local storage rather than a cookie.
Where you pay by card, the payment pages are operated by Stripe on their own site and any cookies there are theirs, not ours.
You can refuse or delete cookies in your browser settings. If you do, the site will simply not remember your language choice.
7. Security
We apply the following measures to protect personal data against unauthorised access, loss or damage:
- Encryption in transit. Connections to the service are encrypted (TLS).
- Passwords are not stored in a readable form. They are stored as a cryptographic hash.
- Certain stored credentials are encrypted, including mailbox passwords.
- We do not hold card numbers. These are handled by our payment processor.
- Access controls, log auditing, and supervision of the parties we engage.
Stored service content — email, website files and database records — is not encrypted at rest. It is protected by the access controls and operational measures described above.
8. How long we keep it
Hosted email, website content, files and other service content are deleted 30 days after access ends. Our application keeps one line of record for each request it handles — the time, the operation requested, the result, and which account made it. These lines do not contain the content of your data, what you typed, or your IP address. We have not yet set a retention period for them. Mail and other operational server logs are kept only for as long as the relevant server software retains them — in practice about one month — and are then overwritten. We do not archive the server logs. Billing, transaction and legal records may be retained for longer where required by law or reasonably necessary for legal or accounting purposes.
9. Your rights
Under the Ordinance you may ask us whether we hold your personal data, request a copy of it, and request correction of any inaccuracy. We will respond in accordance with the Ordinance, after verifying your identity. We may charge a fee for complying with a data access request. Any such fee is limited to costs directly related to and necessary for complying with the request, and will not be excessive.
Please write to aiito@kato-tech.com.hk.
10. Changes
We may revise this policy. We will publish the revised version on this page.
11. Who to contact
Requests to access or correct your personal data, and any question about this policy, should be addressed to our Privacy Officer:
Privacy Officer
KATO INFORMATION TECHNOLOGY CO., LTD.
Flat/Rm A8, 17/F, Sunrise Industrial Centre
10 Hong Man Street, Chai Wan, Hong Kong
Email: aiito@kato-tech.com.hk
Issued: 10 August 2026 / KATO INFORMATION TECHNOLOGY CO., LTD.