Buzzably
Privacy Framework

Privacy Policy

Version 1.2 | Effective June 5, 2026

1. Introduction & Data Controller

This Privacy Policy ("Policy") explains how Buzzably Limited, a company incorporated in Hong Kong SAR ("Buzzably", "we", "us", or "our"), collects, uses, stores, shares, and protects your personal data when you access or use the Buzzably platform, including any associated websites, applications, APIs, and services (collectively, the "Platform").

Buzzably Limited is the data controller responsible for the processing of your personal data under this Policy. We are committed to protecting your privacy and handling your personal data in accordance with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") and, where applicable, international data protection standards.

By accessing or using the Platform, you acknowledge that you have read, understood, and agree to the practices described in this Policy. If you do not agree with any part of this Policy, you must discontinue use of the Platform immediately.

2. Information We Collect

We collect and process the following categories of personal data, limited to what is strictly necessary to operate and improve the Platform:

Account Data. When you register for an account, we collect your display name, username, email address, profile biography, avatar image, and account preferences. If you choose to verify your identity via Stripe Identity, Stripe processes your identity documents directly — Buzzably does not receive or store copies of your identity documents.

Device & Browser Data. We automatically collect technical information when you access the Platform, including your IP address, browser type and version, operating system, device type, screen resolution, preferred language, and time zone. This data is used for security, fraud prevention, and to ensure the Platform functions correctly across devices.

Usage & Analytics Data. We collect pseudonymised analytics data about how you interact with the Platform, including pages visited, features used, session duration, and navigation paths. This data is aggregated and cannot be used to identify you personally. We do not engage in behavioural tracking, shadow profiling, or cross-site tracking.

Cookie Data. We use essential cookies to maintain your session and preferences. Analytics cookies are only placed with your explicit consent. We do not use third-party advertising cookies. Full details are provided in Section 10 below.

Content You Create. We store the content you create, publish, or upload to the Platform, including posts, articles, drafts, images, media files, Editorial Persona configurations, Voice DNA profiles, Pipeline Builder workflows, and autonomous agent definitions. This content is stored to provide the Platform's services and is subject to the content ownership terms set out in our Terms & Conditions.

Payment Data. All payment processing is handled exclusively by Stripe. Buzzably does not receive, process, or store credit card numbers, bank account details, or other sensitive financial credentials. We receive only transaction metadata from Stripe, such as subscription status, billing period, and payout amounts, which is necessary to manage your account and provide creator monetisation features.

3. How We Use Your Data

We process your personal data for the following purposes:

  • Service Delivery — To create and manage your account, authenticate your identity, process subscriptions, facilitate creator payouts via Stripe Connect, and deliver the core features of the Platform.
  • Personalisation — To remember your preferences, language settings, Editorial Persona configurations, and display options to provide a consistent and tailored user experience.
  • AI Model Training (Opt-In Only) — If you explicitly opt in, anonymised and aggregated usage patterns may be used to improve the quality of our AI Services, including Voice DNA accuracy and Draft Assistant relevance. Your individual content is never used for model training without your express written consent. You may withdraw this consent at any time through your account settings.
  • Analytics & Platform Improvement — To understand how the Platform is used in aggregate, identify technical issues, improve performance, and develop new features. All analytics data is pseudonymised before processing.
  • Fraud Prevention & Security — To detect and prevent fraudulent activity, enforce our Terms & Conditions, protect the security and integrity of the Platform, and comply with legal obligations.
  • Communications — To send you essential service notifications, security alerts, and billing confirmations. We will only send promotional or marketing communications with your explicit opt-in consent, and you may unsubscribe at any time.

4. Legal Basis for Processing

Our processing of your personal data is governed by the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") and its six Data Protection Principles. We process your data on the following legal bases:

  • Consent — Where you have given clear, informed, and voluntary consent for specific processing activities, such as opting in to AI model training, analytics cookies, or marketing communications. You may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
  • Contractual Necessity — Where processing is necessary for the performance of our contract with you (i.e., these Terms & Conditions), including account management, subscription billing, content hosting, and creator payout processing.
  • Legitimate Interests — Where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This includes fraud prevention, security monitoring, platform stability, and aggregate analytics. We conduct a balancing assessment for each legitimate interest purpose to ensure proportionality.
  • Legal Obligation — Where processing is necessary to comply with applicable laws, regulations, court orders, or government requests, including Hong Kong regulatory requirements and financial reporting obligations.

5. Data Sharing & Third Parties

Buzzably Limited does not sell, rent, trade, or otherwise commercially exploit your personal data to third parties. We share your data only with the following categories of service providers, each of whom is contractually bound to process your data solely for the purposes we specify and in compliance with applicable data protection laws:

  • Stripe — Payment processing, subscription billing, creator payouts (via Stripe Connect Express accounts), and optional identity verification (via Stripe Identity). Stripe processes payment data in accordance with PCI DSS standards. Buzzably does not receive or store raw credit card numbers.
  • Supabase — Database hosting, authentication services, real-time data synchronisation, and file storage. All data stored in Supabase is protected by Row Level Security (RLS) policies, ensuring users can only access their own data.
  • Vercel — Application hosting, edge network delivery, serverless function execution, and content delivery. Vercel processes request metadata (IP addresses, user agents) as part of standard web hosting operations.
  • AI Providers (including OpenAI) — AI model inference for the Draft Assistant, Voice DNA fingerprinting, Editorial Persona compilation, and autonomous agent workflows. Content submitted to AI providers for inference is processed transiently and is not retained by the provider for model training unless you have explicitly opted in. We use API-level data processing agreements with each provider.
  • Novu — Multi-channel notification delivery (email, in-app, and push notifications). Novu processes recipient email addresses and notification content solely for the purpose of delivering communications on our behalf.

We may also disclose your personal data where required by law, regulation, legal process, or enforceable governmental request, or where necessary to protect the rights, property, or safety of Buzzably Limited, our users, or the public.

6. International Data Transfers

As a Hong Kong-based company using global infrastructure providers, your personal data may be transferred to and processed in jurisdictions outside of Hong Kong SAR. Our primary database infrastructure is hosted in data centres located within the European Union, which provides a high standard of data protection.

Where personal data is transferred to jurisdictions that do not provide an equivalent level of data protection, we implement appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with all sub-processors.
  • Data Processing Agreements (DPAs) with all third-party service providers that specify security obligations, data handling requirements, and breach notification procedures.
  • Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256) for all cross-border data transfers.

We regularly review the data protection laws of each jurisdiction to which data is transferred and update our safeguards accordingly. You may request information about the specific safeguards applied to transfers of your data by contacting us at legal@buzzab.ly.

7. Data Retention & Deletion

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, as described in this Policy, or as required by applicable law. Our data retention schedule is as follows:

  • Account Data — Retained for the duration of your active account. Upon account closure or deactivation, your personal data is masked (pseudonymised) within a thirty (30) day soft deletion period, during which your account may be reactivated.
  • Content Data — Published content is retained while your account is active and transitions to "Removed" status upon account closure. Removed content is retained in an audit-accessible, non-public format as required for legal and integrity purposes.
  • Payment Records — Transaction metadata is retained for a minimum of seven (7) years to comply with Hong Kong financial record-keeping requirements and Stripe's data retention obligations.
  • Analytics Data — Pseudonymised analytics data is retained for a maximum of twenty-four (24) months, after which it is permanently deleted or further aggregated to the point of irreversible anonymisation.
  • Backup Copies — All backup copies containing your personal data are purged within ninety (90) days following account deletion. We use crypto-shredding (permanent destruction of encryption keys) to render backed-up data irrecoverable.

Upon receiving a valid erasure request, we will delete or irreversibly anonymise your personal data within thirty (30) days, except where retention is required by law. You will receive written confirmation when the deletion process is complete.

8. Your Rights Under PDPO

Under the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486), you have the following rights in relation to your personal data:

  • Right of Access — You have the right to request a copy of the personal data we hold about you. We will respond to your data access request within forty (40) days, as prescribed by the PDPO. A reasonable fee may be charged to cover administrative costs.
  • Right of Correction — You have the right to request the correction of any inaccurate or incomplete personal data we hold about you. We will make the requested corrections within forty (40) days of receiving your request.
  • Right of Erasure — You may request the deletion of your personal data. Upon receiving a valid erasure request, we will delete or irreversibly anonymise your data within thirty (30) days, subject to any legal retention obligations.
  • Right to Data Portability — You may request a copy of your personal data in a structured, commonly used, and machine-readable format (JSON or CSV). We will provide the export within forty (40) days of your request.
  • Right to Withdraw Consent — Where processing is based on your consent, you may withdraw that consent at any time through your account settings or by contacting us. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.

To exercise any of these rights, please submit your request to legal@buzzab.ly with the subject line "Data Rights Request". We may require verification of your identity before processing your request. If you are dissatisfied with our response, you have the right to lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong.

9. Children's Privacy

The Platform is not intended for use by individuals under the age of eighteen (18) years. We do not knowingly collect, solicit, or process personal data from anyone under 18 years of age. This age restriction is mandated by the nature of the Platform's services, which include financial market content, payment processing, and monetary transactions.

If we become aware that we have collected personal data from a person under 18, we will take immediate steps to delete that data and terminate the associated account. If you believe that a minor has provided us with personal data, please contact us immediately at legal@buzzab.ly.

10. Cookies & Tracking Technologies

The Platform uses cookies and similar technologies to enhance your experience. We categorise cookies into the following types:

  • Essential Cookies — Required for the Platform to function correctly. These cookies manage authentication sessions, security tokens, load balancing, and consent preferences. They cannot be disabled without impairing core Platform functionality.
  • Analytics Cookies — Used to collect pseudonymised usage data to help us understand how the Platform is used and identify areas for improvement. These cookies are only placed with your explicit consent via our Consent Management Platform (CMP).
  • Preference Cookies — Used to remember your settings such as language preference, theme selection (light/dark mode), and display density. These cookies enhance your experience but are not strictly necessary for Platform operation.

We do not use third-party advertising cookies, retargeting pixels, social media tracking scripts, or any form of cross-site tracking technology. You may manage your cookie preferences at any time through the cookie settings panel accessible from the Platform footer. Most browsers also allow you to control cookies through their settings; however, disabling essential cookies may prevent the Platform from functioning correctly.

11. AI-Specific Disclosures

The Platform incorporates several AI-powered features that process your data. We are committed to transparency about how these features work and how your data is used within them:

  • Voice DNA Fingerprinting — Analyses your existing published content to generate a statistical writing style profile (vocabulary patterns, sentence structure, tone markers). Your Voice DNA profile is stored within your account and is only used to guide AI-generated draft outputs. Voice DNA profiles are not shared with other users or third parties.
  • Draft Assistant Suggestions — Processes your prompts, selected parameters, and Editorial Persona settings to generate draft content. Prompts and generated outputs are transmitted to AI providers for inference only and are subject to our data processing agreements. Draft content is stored in your account until you choose to publish or delete it.
  • Editorial Persona Compilation — Creates configurable AI voice profiles based on your Voice DNA data and custom parameters you define. Persona configurations are stored within your account and are used to maintain consistent editorial identity across AI-assisted content.
  • Pipeline Builder & Autonomous Agents — Allows you to define scheduled or webhook-triggered content generation workflows that operate on your behalf according to predefined rules. Agent configurations, execution logs, and generated outputs are stored in your account. Autonomous agents operate within your Buzz Budget allocation and are subject to the same data processing safeguards as interactive AI features.

All AI-generated outputs on the Platform are clearly labelled as AI-assisted content. This labelling is automatic and cannot be removed by users, ensuring full transparency for readers and subscribers. AI Services are strictly assistive — all generated content requires human review and approval before publication.

12. Security Measures

We implement comprehensive technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption at Rest — All stored data, including database records, file uploads, and backup copies, is encrypted using AES-256 encryption.
  • Encryption in Transit — All data transmitted between your device and our servers, and between our servers and third-party services, is encrypted using TLS 1.2 or higher.
  • Row Level Security (RLS) — Our database implements Postgres Row Level Security policies to ensure that each user can only access their own data. RLS policies are enforced at the database level, providing defence-in-depth independent of application logic.
  • Audit Logging — All significant data access and modification events are recorded in tamper-evident audit logs. These logs are retained for a minimum of twelve (12) months and are used for security monitoring, incident investigation, and compliance verification.
  • Access Controls — Access to personal data within our organisation is restricted to authorised personnel on a need-to-know basis. All administrative access requires multi-factor authentication and is logged.
  • Incident Response — We maintain a documented data breach response plan. In the event of a personal data breach, we will notify affected individuals and the relevant authorities in accordance with our obligations under the PDPO and any other applicable data protection laws.

While we take extensive precautions to protect your data, no method of electronic storage or transmission is 100% secure. We encourage you to use strong, unique passwords and to enable any available account security features.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or Platform features. When we make material changes to this Policy, we will provide at least thirty (30) days' prior notice via:

  • Email notification to the address associated with your account.
  • A prominent notice displayed on the Platform.
  • An updated "Last Modified" date at the top of this Policy.

Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Policy. If you do not agree with the revised Policy, you must discontinue use of the Platform before the changes take effect and may request deletion of your account and personal data.

14. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

  • Email: legal@buzzab.ly
  • Entity: Buzzably Limited
  • Jurisdiction: Hong Kong Special Administrative Region

For data access, correction, or erasure requests, please include the subject line "Data Rights Request" in your email. We will acknowledge receipt of your request within five (5) business days and will respond substantively within the timeframes prescribed by the PDPO.

If you are not satisfied with our response to your data rights request, you have the right to lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD) at https://www.pcpd.org.hk.

15. Precedence of English Version

This Privacy Policy is originally drafted in the English language. In the event of any discrepancies or inconsistencies between the English version and any translated or localised versions, the English version shall prevail and take precedence.