KORA Privacy Policy

Version v1.1 — Authoritative English text

Effective Date: 1 August 2026 Last Updated: 12 August 2026

This English version is the authoritative text of this Policy. In the event of any discrepancy between the English and Chinese versions, the English version shall prevail.

1. Who We Are and How to Contact Us

1.1 This Privacy Policy is issued by We Aries Group Limited, a limited company incorporated in Hong Kong operating under the "KORA" brand (the "Company", "we" or "us"), and explains how we collect, use, disclose and safeguard personal data. KORA is a product under the AR Phoenix Technology Limited brand.

1.2 This Policy applies to: (a) visitors to the KORA website (kora.arphoenix.com); (b) customers who register to use the KORA service and their authorised users; and (c) end users who converse with the AI through the KORA chat window (the "Widget") on a customer's website (for the scope, see Clause 4).

1.3 If you have any enquiry or request concerning this Policy or our handling of personal data, please contact: aikora@arphoenix.com.

1.4 We comply with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (the "Ordinance"), including its six Data Protection Principles.

2. What Data We Collect

(a) Account and registration data — company name, contact name, job title, corporate email address, company size, industry, company website, password (stored after processing with a one-way cryptographic hash, which we cannot reverse to plain text) and registration source.

(b) Payment data — credit card details are collected and processed directly by the third-party payment service provider Stripe, Inc.; we do not store full card numbers and retain only the limited data required for billing records (such as the last four digits of the card, charge status and subscription identifiers).

(c) Content uploaded by customers — documents uploaded and content entered by customers in order to build their AI knowledge base. Where such content contains personal data, the customer must ensure that it is entitled to provide it.

(d) End user conversation records — messages entered by end users through the Widget and the AI's replies (see Clause 4).

(e) Technical and usage data — IP address, browser type, device information, page view and event records (including those collected by Google Analytics 4), source parameters (UTM) and cookies (see Clause 10).

Except for fields marked as mandatory, the provision of personal data is voluntary; however, if you are unable to provide the data required for registration, verification or payment, we may be unable to provide you with the service or some of its features.

3. Purposes of Collection and Use

3.1 We use the above data for the following purposes:

3.2 We do not use your data to train language models. We will not use customer content or end user conversation content to train, fine-tune or otherwise modify any large language model or general-purpose artificial intelligence model, whether that model is owned by us or by any third party. KORA uses retrieval-augmented generation (RAG) technology — the AI model retrieves relevant knowledge base content only at the point of generating a reply; your data does not become training data for any language model and is not incorporated into any model's parameters.

In the interest of transparency, we disclose the following: the service improvements described in Clause 3.5(b) may include building or tuning auxiliary classification models (for example, a router that determines the intent of a query, or a safety filter that detects inappropriate content). Such models are not language models; they do not generate reply content and do not store or reproduce the text of any conversation. They are built and tuned using only data that has been de-identified in accordance with Clause 3.5(b).

3.3 We will use personal data only for purposes directly related to the purpose of collection; where a new purpose arises, we will obtain prescribed consent in accordance with the Ordinance.

3.4 Direct marketing. We intend to use the names and email addresses of customer contacts to send them promotional information about KORA and our related services (such as feature updates, offers and events). We will not so use your personal data unless we have your consent (or an indication of no objection). Every marketing message will provide a free means of opting out; you may also email aikora@arphoenix.com at any time to ask us to stop, and we will comply without charge.

3.5 How we use conversation data to improve the service. Subject to the limits set out in Clause 3.2, we use conversation data to improve service quality in the following ways:

(a) For an individual customer (within that tenant) — we use a particular customer's conversation records to improve that customer's own AI customer service performance, for example by compiling a library of good reply examples specific to that customer, or refining that customer's intent routing and reply rules. Such uses do not cross over to other customers.

(b) For the service as a whole (after de-identification) — we use conversation data, after de-identification, to improve the overall quality of KORA, including refining system instructions and reply logic, improving the accuracy of intent routing, and building automated safety filtering mechanisms and quality test sets.

(c) No cross-customer use — no customer's knowledge base content and no identifiable conversation content will be used to generate replies displayed to any other customer or to that other customer's end users.

(d) Customer contact data excluded — the account and registration data described in paragraph 2(a) (including contact names, corporate email addresses and job titles) will not be used for any of the improvement purposes described above.

4. How End User Conversations Are Handled (Please Read If You Use the Widget)

4.1 Content entered by an end user through the Widget is transmitted to our systems in order to generate an AI reply, and is stored as a conversation record which the relevant customer (that is, the operator of the website) may review in its admin dashboard and use to improve its customer service configuration. Conversation records are retained for thirty (30) days only, after which they are automatically purged (see Clause 7.2).

4.2 In respect of personal data contained in end user conversations, the relevant customer is the data user and we process that data only on that customer's behalf. Save for the service improvement purposes set out in Clause 3.5, we do not use conversation content that identifies an individual for our own purposes; and improvement of the service as a whole across customers uses de-identified data only (see Clauses 3.5(b) and (c)). An end user who wishes to access or correct personal data contained in their conversation should first contact the operator of the website; they may also contact us at aikora@arphoenix.com, and we will refer the matter to the relevant customer for follow-up.

4.3 Please do not provide unnecessary sensitive personal data in a conversation (such as identity card numbers, full credit card numbers or medical records). AI replies are generated automatically and are for reference only.

4.4 Conversation content is processed through our cloud infrastructure (see Clauses 5 and 6), including the generation of replies by AI models on AWS Bedrock.

4.5 Notice before a conversation begins. The KORA Widget displays a notice to end users before a conversation begins, explaining that: (a) the conversation is supported by a third-party service provider, KORA (We Aries Group Limited); (b) the content of the conversation is recorded and stored, and is available to the operator of the website; and (c) the content may be used, after de-identification, to improve service quality (see Clause 3.5). An end user who does not accept these arrangements may choose not to use the chat window and may instead contact the website operator through the other channels it provides. We require our customers not to remove or conceal that notice.

5. To Whom We Disclose Data

5.1 We do not sell personal data. We disclose personal data only in the following circumstances:

(a) Service providers (sub-processors):

(b) Legal requirements — in response to a lawful requirement of law, a court order or a regulatory authority;

(c) Business transfer — disclosure to a transferee in a merger, acquisition or business reorganisation (the transferee being required to remain bound by equivalent privacy protections).

5.2 We have contractual arrangements with our service providers requiring them to process personal data only on our instructions and to apply adequate security measures.

6. Cross-Border Transfer of Data

6.1 Our servers and databases are located in the AWS Asia Pacific (Tokyo) region (ap-northeast-1). Your personal data will be transferred outside Hong Kong (principally to Japan) for storage and processing. In addition, our website analytics provider (Google LLC) and payment service provider (Stripe, Inc.) process the relevant technical, usage and payment data in the United States or other locations.

6.2 We take reasonable steps (including contractual and technical measures such as encryption and access controls) to ensure that personal data so transferred receives protection comparable to Hong Kong standards.

7. Data Retention Periods

7.1 Account data and content uploaded by customers. A customer's account and registration data, and the knowledge base content it uploads, are retained for the duration of the customer's subscription.

7.2 End user conversation records — thirty-day rolling retention. Conversation records (including end user messages and AI replies) are retained for no more than thirty (30) days from the end of the conversation concerned, after which they are automatically purged by the system, whether or not the subscription remains in force. This is a uniform platform-level setting, intended to control the volume of data held and to avoid retaining personal data unnecessarily.

A customer that needs to retain conversation records for a longer period should review and separately keep its own copies through the admin dashboard.

For the avoidance of doubt, aggregate statistics and quality scores derived from conversations that do not contain information identifying an individual (such as conversation scores), and de-identified datasets processed under Clause 3.5(b), are not subject to the thirty-day limit in this Clause.

7.3 After termination of a subscription. Following termination of a subscription (the Termination Effective Date being determined under Clause 11.4(a) of the Terms of Service), the account data and uploaded content described in Clause 7.1 will be retained for no more than ninety (90) days, and only for the following compliance purposes: (a) system backup and disaster recovery; (b) completing settlement, invoicing, tax and accounting records; (c) handling or defending unresolved disputes, claims or complaints; and (d) responding to a lawful requirement of law, a court order or a regulatory authority. During that period we will not use such data for any other purpose. Upon expiry it will be deleted or anonymised, save where a longer retention period is required by law (for example, tax and accounting records).

Conversation records are not covered by this ninety-day period. They are governed solely by the thirty-day rolling period in Clause 7.2, which is not extended by termination. Any conversation record still in existence when the subscription terminates is therefore purged no later than the thirtieth (30th) day after the Termination Effective Date, and in every case before the ninety-day period above expires. No conversation record is kept beyond that point for any purpose, including the compliance purposes listed above.

So, after a subscription ends, what we still hold consists only of: (a) account and registration data; (b) content uploaded by the customer — knowledge base documents, supplementary knowledge entries, brand materials, and rules-layer and skills-layer configuration; and (c) conversation records from at most the thirty days before termination, which are then purged as described.

7.4 Technical logs. Retained for no more than thirty (30) days, after which they are deleted or de-identified. Aggregate and de-identified analytics data is not subject to the thirty-day period above, to the extent that it is in fact no longer capable of identifying any individual.

8. Data Security

8.1 We take reasonably practicable measures to safeguard personal data, including: encryption in transit (HTTPS/TLS), access controls at the storage layer, multi-tenant data isolation (a separate data schema for each customer), tiered staff permissions and the principle of least privilege. We also take reasonably practicable steps to ensure that the personal data we hold is accurate and is not kept longer than is necessary.

8.2 However, transmission over the internet is not absolutely secure and we cannot guarantee absolute data security. In the event of a significant security incident involving personal data, we will notify affected persons and/or the Office of the Privacy Commissioner for Personal Data in accordance with applicable law and guidance.

9. Your Rights

9.1 Under the Ordinance, you have the right to: (a) ascertain whether we hold your personal data; (b) request access to that data; and (c) request correction of data that is inaccurate.

9.2 Access or correction requests should be sent to aikora@arphoenix.com. We will comply within the forty (40) days prescribed by the Ordinance; if we are unable to comply, we will notify you within those forty days and deal with the request as soon as practicable thereafter. A fee that is not excessive may be charged for complying with a data access request.

9.3 As regards the exercise of end users' rights in relation to Widget conversations, see Clause 4.2.

9.4 If you have any complaint about the way we handle personal data, please contact us first (aikora@arphoenix.com); you are also entitled to complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (www.pcpd.org.hk).

10. Cookies and Analytics

10.1 Our website uses cookies and similar technologies: (a) necessary cookies (login state, security); and (b) analytics cookies (Google Analytics 4, used to understand website usage and the effectiveness of marketing channels, including attribution by UTM parameters).

10.2 You may refuse or delete cookies through your browser settings; refusing necessary cookies may affect the functioning of the website.

11. Children

The service is directed at businesses and is not aimed at persons under 18. We do not knowingly collect the personal data of persons under 18. If we discover that data we have collected ourselves falls into this category, we will delete it as soon as possible; if we discover it within Widget conversation records, we will notify the relevant customer to follow up.

12. Updates to this Policy

12.1 We may revise this Policy from time to time. Material changes will be notified by website announcement or email at least thirty (30) days before they take effect. The "Last Updated" date at the top of this page indicates the date of the current version.

12.2 Continued use of the service after a change takes effect indicates that you are aware of the updated Policy.