PRIVACY POLICY STATEMENT (PPS) OF PTI PROFESSIONAL DEVELOPMENT LIMITED (Version 4.9)
Updated: August 2026
PTI Professional Development Limited (“PTI”) fully complies with the six Data Protection Principles (DPPs) of the Personal Data (Privacy) Ordinance (Cap. 486). This policy integrates the six Data Protection Principles (DPPs) of the Personal Data (Privacy) Ordinance (Cap. 486), June 2024 Model AI Framework, the August 2026 Agentic AI Rules, the April 2021 Messaging Platforms Guidance, the February 2023 Data Security Measures, and the PCPD Code of Practice on the Identity Card Number and Other Personal Identifiers (First Revision, April 2016). As a data user, PTI remains strictly accountable for all personal data collected, held, processed, or deployed by our autonomous AI agents.
PART I: ORGANISATIONAL GOVERNANCE & ACCOUNTABILITY
Our internal AI Governance Committee maintains a comprehensive AI Agent Inventory. If necessary, we would consider commissioning an independent internal or external task force to evaluate policy compliance periodically. Where relevant, our Policy is to require our data scientists, developers, human reviewers, and legal staff undergo regular training covering encryption software, remote system access, data sanitisation, and data breach containment loops.
PART II: REGULATORY RESTRICTIONS ON PERSONAL IDENTIFIERS & HKID CARDS
- Non-Compulsory Collection Defenses: In strict alignment with the 2016 Code of Practice, PTI prohibits the compulsory requirement or collection of a learner’s Hong Kong Identity Card (HKID) number or card copy during user registration, unless expressly authorized by a statutory provision of Hong Kong law. Email addresses are legally deemed not to be personal identifiers under this framework.
- Less Privacy-Intrusive Registration Alternatives: Users signing up for online training portal access must be provided with clear, non-HKID alternatives to establish their identity. PTI explicitly permits and accepts alternative personal identifiers of the user’s choice, such as a passport number, or the physical production of a non-permanent identity document in lieu of an HKID record.
- Prohibition of Transient or Clerical Copy Collection: No physical or digital copies of an HKID card shall ever be collected merely to safeguard against clerical error or in anticipation of a prospective customer relationship. Copies of identification documents are strictly disallowed until a learneris officially registered, admitted, and confirmed into a multi-step accredited examination sequence that involves significant financial or corporate asset custody.
- Physical Production & Verification Defenses: Where the collection of an HKID number is legally justified to prevent impersonation fraud in high-risk transactions, accuracy must be established through the physical production of the card in person or via verified official mail channels. Staff members are forbidden from manually typing or recording numbers based on unverified representations.
- Mandatory Permanent Copy Watermarking: If an authenticated digital image or paper copy of an HKID card is legally collected, it must be immediately and permanently watermarked with the word ‘COPY’ or ‘副本’ in Chinese across the entire face of the image at the exact time of collection to prevent secondary misuse.
- Prohibition on Legible ID Display: PTI strictly prohibits displaying a user’s name and HKID number together publicly. No training credential, learnerportal card, or staff badge issued by PTI may bear the user’s HKID number in a legible form (including altered strings from which the original card number can be deduced).
- Section 26 Immediate Erasure Protocols: Pursuant to Section 26 of the Ordinance, HKID numbers and personal identifier records collected as a condition for granting access to premises or equipment must be completely erased from all system logs immediately upon the user leaving the premises or ceasing to use the equipment.
- Digital Identity Shielding: Separate-channel Multi-Factor Authentication (MFA) and distinct, non-overlapping passwords are mandatory across our technological ecosystem to insulate unique digital identities from credential fraud, ransomware, or phishing campaigns.
PART III: RISK-BASED SYSTEMS & LEAST-PRIVILEGE AGENT ISOLATION
We enforce rigid technical constraints that explicitly deny autonomous AI agents operating system administrator privileges, restricting visibility to the absolute minimum required to complete tasks. To prevent inaccurate data cascading across multi-agent training pipelines, we mandate Chain of Thought (CoT) path constraints and Retrieval-Augmented Generation (RAG) checkpoints. Maximum retention caps are enforced on memory logs, combined with regular, manual curation of long-term agent interaction registries.
To secure our network perimeters, PTI aim at maintaining multi-layered firewall infrastructure, database access locks, and active anti-malware tracing. Our Bring Your Own Device (BYOD) framework commands isolated remote wipe capabilities and endpoint block parameters. Furthermore, we strive to maintain a centralized hardware inventory and enforce zero-fill data sanitisation on all Portable Storage Devices (PSDs) directly after use. PTI completely blocks cross-platform tracking vectors by banning third-party social media log-ins and deploying anti-scraping filters.
PART IV: DATA PROCESSOR COMPLIANCE & INCIDENT DISCONNECTION
In accordance with DPP4(2), all third-party data processors and AI cloud vendors would be contractually bound via strict Data Processing Agreements (DPAs) mandating minimal data transfer protocols, regular compliance reliability audits, and immediate data security incident notifications. In the event of an anomaly alert, our objective is: Our active forensic blueprint would dictate immediate system disconnection, password token revocation, configuration remediation, network integrity scans, and rapid reporting loops to the PCPD and affected users within regulatory timeframes.
PART V: STAKEHOLDER RIGHTS & EXPLAINABLE PRINCIPLES
PTI operates under the core values of being respectful, beneficial, and fair. Despite the complex data routing which may be inherent to multi-agent architectures, our Policy is for our systemsto ensure that all personal profiles remain fully locatable, retrievable, and auditable. Users retain absolute statutory rights under DPP6 to access, review, and correct their information profile or challenge any automated grading output. All verified modification requests would be completed within 40 calendar days.
