Privacy Policy
Last updated: June 2026
This Privacy Policy explains how Warden9 Limited (“Warden9”, “we”, “us”, or “our”) collects, uses, discloses, and protects personal data when you access or use the Warden9 platform, websites, and related services (together, the “Service”). We are committed to handling personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of the laws of Hong Kong (the “PDPO”) and its six Data Protection Principles. By accessing or using the Service, you acknowledge that you have read and understood this policy.
1. Who We Are
The data user responsible for your personal data is Warden9 Limited, a company incorporated in Hong Kong, with its registered office at Room 2201, Wayson Commercial House, 68-70 Lockhart Road, Wanchai, Hong Kong. For all data-protection matters, including questions, requests, and complaints, you may contact us at [email protected] or by writing to us at the address above marked for the attention of the Privacy Officer.
2. Scope of This Policy
This policy applies to personal data we collect from and about visitors, account holders, and authorized users of the Service. Where our customers use the Service to authorize, run, and govern the actions of AI agents across their own connected systems, the customer is the data user in respect of the personal data contained in their content, and we act as a data processor handling that data on their behalf and on their instructions. In that role, the customer's own privacy notice governs how that personal data is collected and used, and this policy governs the personal data for which Warden9 is the data user.
3. Personal Data We Collect
We collect personal data directly from you, automatically through your use of the Service, and from third parties such as identity providers and integration partners. The categories of personal data we may collect include the following.
Account and identity data: your name, work email address, username, password credentials, job title, organization or employer, and the role and permissions assigned to you within the Service.
Usage and operational data: how you interact with the Service, features accessed, configuration and policy settings you create, connected integration metadata, authorization scopes, tool-call records, approval decisions, and the audit logs generated when agents act through the runtime.
Technical and device data: IP address, browser type and version, device identifiers, operating system, language settings, access times, referring URLs, and diagnostic or crash information.
Communications data: the content of enquiries, support requests, and correspondence you send to us, including via our contact form, together with your name and contact details.
You are not obliged to provide personal data to us. However, if you do not provide the data necessary to create and administer an account, we may be unable to provide the Service or parts of it to you.
4. How and Why We Use Personal Data
We use personal data only for the purposes for which it was collected, or a directly related purpose, and in accordance with the PDPO. Those purposes include the following.
To create and administer accounts, authenticate users, provide, operate, maintain, and improve the Service, and authorize and run agent tool calls for signed-in users in line with your policies.
To secure the Service, produce and retain audit trails, detect, investigate, and prevent fraud, abuse, security incidents, and breaches of our terms.
To respond to your enquiries and support requests, send service and administrative messages, and, where permitted, provide information about features and updates.
To comply with applicable laws, regulations, lawful requests from public authorities, and to establish, exercise, or defend legal claims.
We will not use your personal data for direct marketing without first obtaining your consent where such consent is required under the PDPO, and you may withdraw that consent at any time, free of charge, by contacting us.
We do not sell your personal data.
5. Disclosure and Transfer of Personal Data
We do not disclose your personal data except as described in this policy. We may disclose personal data to the following classes of recipients.
Service providers and sub-processors, such as cloud hosting, infrastructure, analytics, communications, and support providers who process personal data on our behalf under written obligations of confidentiality and data protection.
Regulators, law-enforcement agencies, courts, and other authorities where disclosure is required or permitted by law, or is necessary to protect the rights, property, or safety of Warden9, our users, or others.
Actual or prospective purchasers, investors, or successors in connection with a merger, acquisition, reorganization, financing, or sale of assets, subject to appropriate confidentiality protections.
6. Transfers Outside Hong Kong
We and our service providers may store and process personal data on servers located outside Hong Kong. Where we transfer personal data outside Hong Kong, we take reasonable steps to ensure that the data is handled in accordance with this policy and receives a level of protection consistent with the requirements of the PDPO, including through contractual safeguards with the recipients of the data.
7. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including to provide the Service, maintain audit records, resolve disputes, and comply with our legal, accounting, or reporting obligations. When personal data is no longer required, we take reasonable steps to erase it or render it anonymous, unless a longer retention period is required or permitted by law.
8. Data Security
We take practicable and appropriate technical and organizational measures to protect personal data against unauthorized or accidental access, processing, erasure, loss, or use. These measures include access controls, encryption in transit, logging, and internal policies restricting access to personal data on a need-to-know basis. No method of transmission or storage is completely secure, and while we strive to protect personal data, we cannot guarantee its absolute security.
9. Your Rights Under the PDPO
Subject to the PDPO, you have the following rights in relation to the personal data we hold about you.
The right to request access to your personal data and to be informed whether we hold personal data about you.
The right to request correction of your personal data where it is inaccurate.
The right to request that we cease to use your personal data for direct marketing.
To exercise these rights, please contact our Privacy Officer at [email protected]. We may require you to verify your identity before responding, and we may charge a reasonable fee for complying with a data-access request to the extent permitted by the PDPO. We will respond to your request within the time limits prescribed by law. If you are dissatisfied with how we handle your personal data, you may lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong.
10. Agent Processing and Automated Actions
Tool calls, inputs, and outputs routed through the Service are processed to authorize and run agent actions, apply the policies you configure, and produce the resulting audit record. Policy decisions and other outputs are generated from the information, integrations, and rules you provide, and may involve automated processing. These outputs support your work and are not a guarantee of any outcome; you remain responsible for reviewing approvals and checking results before relying on them.
11. Cookies and Analytics
The Service may use cookies and similar technologies to operate the site, remember your preferences, maintain your session, and understand how the Service is used. Some cookies are strictly necessary for the Service to function, while others are optional. You can control or delete cookies through your browser settings, though disabling certain cookies may affect how the Service works.
12. Children's Privacy
The Service is intended for business users and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so that we can take appropriate steps to delete it.
13. Third-Party Services and Links
The Service may integrate with, or contain links to, third-party systems, tools, and websites that are not operated by us. This policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy notices of any third-party service you connect to or visit.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. We will post the updated policy on this page and revise the “Last updated” date above. Where required by law, we will provide additional notice or seek your consent. If you continue to use the Service after an update takes effect, you accept the revised policy.
15. How to Contact Us
If you have questions, requests, or complaints about this Privacy Policy or how your personal data is handled, please contact the Privacy Officer at Warden9 Limited, Room 2201, Wayson Commercial House, 68-70 Lockhart Road, Wanchai, Hong Kong, or by email at [email protected].