Legal
Privacy Policy
What dejima live collects, why, how we protect it, who we share it with, and the rights you have over it.
1. Who we are
dejima live (“dejima”, “we”, “us”, “our”) is a design-led, AI-assisted, trilingual Hong Kong double-entry bookkeeping and accounting service for small businesses, studios and independent workers.
The Service is operated by Dejima Live Limited (出島數據有限公司), a company being incorporated in Hong Kong (Business Registration application in progress).
Registered office / correspondence address:
Unit 804A, 8/F, JCCAC, 30 Pak Tin Street, Shek Kip Mei, Kowloon, Hong Kong.
For any privacy question, or to exercise your rights (Section 12), contact us at studio@maryisgood.com.
For the purposes of the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (the “PDPO”), Dejima Live Limited (and, until its incorporation is complete, its founders operating the Service) is the data user responsible for the personal data described in this Policy.
2. Scope, and the current stage of the Service
This Policy explains what personal data we collect, why, how we use and protect it, who we share it with, and your rights.
Where we are today. dejima live is not yet open for general use. Security hardening is being completed first. Right now, signing up “for the beta” means joining our beta waitlist — you give us your contact details so we can invite you when the beta opens. Until you are invited and choose to start using the application, we do not collect or hold any of your books or financial records.
This Policy therefore covers two stages:
- Waitlist stage (now): we collect only the contact and profile details you submit to join the list (Section 3.1).
- Beta stage (once you are invited and start using the app): the rest of this Policy — about your books, AI processing, security and retention — applies.
It does not cover third-party websites we link to.
Two kinds of data are involved once you use the app:
- Your account and contact details — data about you.
- Your books (“Customer Content”) — the receipts, statements, invoices, ledgers, contacts and financial records you put into dejima. This may include personal data about other people (for example your clients or staff). You control this content; we process it on your instructions. You are responsible for having a lawful basis to put other people’s personal data into dejima (see also our Terms & Conditions).
3. The personal data we collect
3.1 Data you give us directly
- Waitlist / beta application data (collected now): your name, email address, business or studio name, business type or size, city or country, and anything you write in the form.
- Account data (once the beta opens): login email, a securely hashed password, display name, language preference, and settings.
- Customer Content (once you use the app): receipts and their images, bank and card statements, invoices and quotations, ledger entries, chart-of-accounts data, project and client records, contact details of your clients or suppliers, tax and MPF-related figures, and notes or attachments. This frequently contains financial information and may contain personal data about third parties.
- Communications: messages you send us, and responses to surveys or interviews.
The beta is free, so we do not collect payment card details. If paid plans launch later, payments will be handled by a third-party payment processor and card details would be collected and stored by that processor, not by us; we will update this Policy before that happens.
3.2 Data we collect automatically
- Technical and device data: IP address, browser type and version, device and operating system, language, and approximate location inferred from IP.
- Usage and diagnostic data: actions taken in the app, timestamps, and error logs.
- Cookies: see Section 5.
3.3 Data from other sources
If you reach us through a referral, event or partner (for example the design community or a bookkeeping/audit practice), we may receive your name and contact details from them, with your knowledge. We do not use third-party analytics or advertising services.
We do not intentionally collect special-category/sensitive personal data, and we ask that you do not upload it into dejima unless it is genuinely necessary for your bookkeeping.
4. How we use your data, and our basis for doing so
We use personal data to:
- Run the waitlist — hold your details and invite you when the beta opens. (Basis: the purpose for which you gave us the data.)
- Provide and operate the Service — create and secure your account, store and organise your books, run the bookkeeping features, and generate your documents. (Basis: operating the Service you asked for; performance of our Terms with you.)
- Enable the AI features — where you turn them on with your own AI key (Section 6).
- Communicate with you — service messages, support, onboarding, and beta surveys or interviews.
- Keep the Service safe and reliable — authentication, abuse prevention, debugging, and security monitoring.
- Improve the Service — using aggregated or de-identified data wherever practicable.
- Meet legal obligations — record-keeping, responding to lawful requests, and establishing or defending legal claims.
We only send marketing where you have opted in, and you can withdraw at any time (Section 12). We do not sell your personal data, and we will not use it for a new, incompatible purpose without telling you and, where required, obtaining consent.
5. Cookies
We keep this to an absolute minimum.
- We use no tracking, analytics or advertising cookies whatsoever.
- The waitlist website does not set cookies.
- When the beta application itself opens, it may use a single strictly-necessary cookie to keep you securely signed in during a session. Nothing more.
Because we set no non-essential cookies, there is no cookie-consent banner to manage. Blocking the strictly-necessary session cookie would stop you being able to stay logged in to the app.
6. AI features and how your content is processed
dejima’s AI features save you time — for example, reading a photographed receipt or a bank statement and turning it into a drafted accounting entry that you review and confirm.
Which arrangement applies depends on your plan. In both cases the content is sent to a third-party AI provider (currently Google’s Gemini API), processed there, and the draft is returned to you. What differs is whose agreement with that provider governs the processing.
- Paid plans (Freelance, Studio, Practice) and the public demo — processed under our agreement. AI is included in these plans, so the call is made using dejima’s own API credentials. For these calls Google acts as our sub-processor: we are responsible for that transfer, Google is listed in Section 7, and the processing is governed by our agreement with Google rather than yours. Google processes this content outside Hong Kong; see Section 9 on international transfers.
- Solo (free) plan — you bring your own key. The AI features work using your own API key with the provider. The content is sent under your own account and key; that processing is governed by your own agreement with the AI provider, and you are responsible for obtaining and maintaining your key, complying with the provider’s terms, and any usage costs it charges you. For these calls Google is not our sub-processor, because we are not the party sending the content.
How we hold a key you give us. If you are on the Solo plan and store your own API key with us, it is encrypted at rest using a secret held separately from the database, is never displayed back to you (we show only its last four characters so you can tell which key is stored), and is never written to our logs. You can remove it at any time from Settings, which deletes it.
What we record about AI use. For calls made on our credentials we keep a count of calls per day, so we can meter and budget the feature. We do not keep the document you submitted, the prompt, or the model’s response as part of that record.
AI output can be wrong. dejima’s AI drafts; you confirm. You are responsible for reviewing AI-suggested entries before relying on them. Please avoid submitting to AI features any personal data that is not necessary for the task.
Training. We do not use your Customer Content to train any dejima model. For calls made on our credentials, Google’s Gemini API terms state that prompts submitted via the paid API are not used to train Google’s models. For calls made on your own key, whether the provider uses that content is governed by that provider’s terms for your account, which you should review.
7. Who we share your data with
We do not sell your personal data. We share it only as follows:
- Service providers / sub-processors who help us run dejima, under contracts requiring them to protect the data and use it only to provide services to us. Currently these are Hostinger, which provides our website and application hosting and our email, and Google (Gemini API), which processes content you submit to the AI features on paid plans and in the public demo. A current list of sub-processors is available on request at studio@maryisgood.com.
- Your own AI provider account — on the Solo (free) plan, where you have supplied your own key, content is processed by the provider under your account rather than ours, as described in Section 6.
- Our team — access is limited to those who need it to operate and support the Service (Section 10).
- Professional advisers — such as our auditors, lawyers and insurers, where reasonably necessary and under confidentiality.
- Legal and safety — where required by law, court order, or lawful request from a competent authority, or to protect our rights, users or the public.
- Business transfers — if dejima is involved in a merger, acquisition, financing or sale of assets, personal data may transfer as part of it; we will require the recipient to honour this Policy or notify you of any material change.
8. Transfers outside Hong Kong
Some of our providers and team are located outside Hong Kong. For example, our hosting/email provider (Hostinger) may store or process data in data centres outside Hong Kong; a member of our team is located in the United Kingdom; and, if you use the AI features, your chosen AI provider may process content outside Hong Kong under your key. This means your personal data may be transferred to, stored in, or accessed from outside Hong Kong.
Where we transfer personal data outside Hong Kong, we take reasonable steps intended to keep it protected to a standard comparable to the PDPO, including using reputable providers and contractual protections.
9. How long we keep your data
- Waitlist data: kept until the beta opens and for a reasonable period after, or until you ask us to remove you, whichever is sooner.
- Account and Customer Content: kept while your account is active and for a reasonable period afterwards so you can reactivate or export your books.
- Statutory record-keeping: accounting and business records in Hong Kong are generally required to be kept for seven years (Inland Revenue Ordinance, Cap. 112, s.51C). Where you keep such records in dejima, we retain them consistently with your ability to meet that obligation, unless you delete or export and remove them.
- Everything else (logs, communications, marketing preferences): kept only as long as needed for its purpose or as required by law, then deleted or anonymised.
10. How we protect your data — and the honest position
Protecting financial data matters to us, and we will not overstate what is in place.
We are deliberately opening the beta only after core security hardening is complete — which is why, for now, sign-ups join a waitlist rather than upload live books.
In place today:
- Encrypted connections (TLS) for data in transit.
- Passwords stored only as salted hashes, never in plain text.
- Authenticated sessions, and access to production data limited to named members of our team on a need-to-know basis.
Being completed before the beta opens: encryption of data at rest, enforced multi-tenant isolation, least-privilege access controls with access logging, an independent penetration test, a tamper-evident audit trail, and verified backup-and-restore. We will update this Section as these land, and before you are invited to upload real books.
No method of transmission or storage is ever completely secure, and we cannot guarantee absolute security. During any early beta, please keep your own copy of anything important.
Data breaches. Hong Kong law does not currently make breach notification mandatory, but as a matter of practice we will notify affected users and the Privacy Commissioner for Personal Data as soon as reasonably practicable where a breach is likely to cause a real risk of harm, and tell you what happened and what to do.
11. The beta waitlist and beta programme
- Right now, signing up joins the beta waitlist. We will invite you to the beta when it opens, after security hardening.
- The beta, once open, is provided free of charge and is early-stage. Features may change, break or be removed, and it may be unavailable at times.
- Beta data may be reset, migrated or deleted during or at the end of the beta. We will give reasonable notice and a window to export your books before any planned deletion; do not treat the beta as durable storage.
- We may invite you to give feedback or join surveys or interviews. Participation is voluntary.
- If the Service moves to a paid or general-availability offering, we will make the applicable terms and any updated privacy notice available to you first.
12. Your rights and choices
Under the PDPO you have the right to:
- ask whether we hold personal data about you, and to access a copy of it (a data access request);
- ask us to correct personal data that is inaccurate;
- withdraw consent to direct marketing at any time, and opt out of marketing;
- ask about our privacy policies and practices and the kinds of personal data we hold.
You can also ask us to remove you from the waitlist, delete your account and associated data, and export your Customer Content in a portable format, subject to records we must keep by law (Section 9).
To exercise any of these, email studio@maryisgood.com. We may need to verify your identity and will respond within the time required by law. We do not charge for reasonable requests, though the PDPO permits a reasonable fee for complying with a data access request.
13. Children
dejima is a business tool intended for users aged 18 or over. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, contact us and we will delete it.
14. Third-party links and services
The Service may link to third-party websites and services (including your chosen AI provider). We are not responsible for their content or privacy practices. Review their terms and privacy notices before using them.
15. Changes to this Policy
We may update this Policy as dejima evolves — especially as we open the beta, complete security hardening, and move toward a paid service. When we make material changes, we will update the “Effective date” and, where appropriate, notify you. Continued use after an update means you accept the revised Policy.
16. Complaints and the regulator
Please contact us first at studio@maryisgood.com — we would like the chance to put things right. You also have the right to complain to Hong Kong’s regulator:
Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD)
Website: www.pcpd.org.hk · Enquiry hotline: (852) 2827 2827
17. Contact us
Dejima Live Limited (出島數據有限公司) — Business Registration application in progress
Unit 804A, 8/F, JCCAC, 30 Pak Tin Street, Shek Kip Mei, Kowloon, Hong Kong
studio@maryisgood.com
This Policy should be read together with the dejima live Terms & Conditions. By joining the waitlist or using the Service, you confirm you have read and understood this Policy.