PRIVACY POLICY & COLLECTION NOTICE
Your information. Your rights.
HarbourMind 心港 ("HarbourMind", "we", "us") is a Hong Kong counselling matching and practice platform operated by Argo Technology Group Limited. This notice is our Privacy Policy Statement and Personal Information Collection Statement (PICS) under the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"). It explains what personal data we collect, why, who may receive it, how long we keep it, and how you can access or correct it.
1. Data user
The data user is Argo Technology Group Limited, trading as HarbourMind 心港. For privacy requests, write to the Privacy Officer at privacy@harbourmindhk.com.
For formal data-access or correction requests (including PCPD Form OPS003), you may also write by post to:
Privacy Officer
Argo Technology Group Limited (HarbourMind 心港)
RM 29-33, 5/F, Beverley Commercial Centre
87-105 Chatham Road, Tsim Sha Tsui
Hong Kong
We will acknowledge requests in writing within the PDPO timeframe (generally 40 days).
2. Personal Information Collection Statement
When we collect personal data from you directly, this section is the notice required under Data Protection Principle 1(3).
Is supply obligatory or voluntary?
- Account identity, contact details, eligibility confirmation, intake answers needed for matching, booking details, payment confirmation, telehealth safety checks, and session logistics are obligatory if you want to use that part of the service. If you do not supply them, we may be unable to create an account, match you, book a session, process payment, or start an online session.
- Optional preferences, marketing consent, free-text matching notes, and accessibility requests are voluntary.
Purposes of use
We use personal data to:
- operate accounts, verify eligibility, and prevent fraud or misuse;
- match clients with verified practitioners, including agency review and AI-assisted shortlisting that a trained person can override;
- schedule sessions, send reminders, and support communications;
- process payments, receipts, refunds, payouts and accounting records;
- support telehealth safety checks (location, privacy of surroundings, emergency contact, backup telephone);
- handle complaints, safety incidents, privacy requests and legal claims;
- secure, debug and improve the platform (including limited product analytics that do not train foundation models on session content); and
- send direct marketing only where you have given separate opt-in consent (see section 8).
Classes of persons to whom data may be transferred
- your selected practitioner, for care coordination and session logistics;
- authorised HarbourMind / agency staff who need the data to perform matching, verification, safety, privacy or support duties;
- contracted processors that host infrastructure, communications, payments, identity checks or video rooms on our instructions (see section 5 and /subprocessors);
- professional advisers (legal, clinical governance, accounting, insurance) under confidentiality duties; and
- courts, regulators, law-enforcement or other competent authorities where required or permitted by Hong Kong law, or where necessary to protect life, health or safety.
Your access and correction rights
You may request access to, and correction of, your personal data under the PDPO. Send requests to the Privacy Officer at privacy@harbourmindhk.com. We may need to verify your identity before disclosure. Where the PDPO allows, we may refuse a request and will tell you why. You may also ask in the app for export, or schedule irreversible account erasure (14-day cooling-off) for clients and counsellors, where that is available and not blocked by a legal hold, accounting duty or safety matter. De-identified financial shells may be retained as required by law.
3. What we collect
Depending on how you use HarbourMind, we may hold:
HarbourMind stores operational platform records. It is not a full electronic health record. Practitioners remain responsible for their own clinical notes where their professional duties require them.
- Identity and contact: name or display name, email, phone, language, time zone, age/eligibility confirmation.
- Matching and intake: preferences, concerns, budget, availability, free-text descriptions converted into structured fields with your review, and safety screening answers.
- Booking and payment: session times, status, receipt and refund metadata, payment-provider references. We do not store full card numbers on HarbourMind servers.
- Communications: in-app messages and support correspondence needed to operate the service.
- Telehealth operational data: connection tokens, limited telemetry, and pre-session safety confirmations. We do not record or transcribe counselling audio or video.
- Practitioner verification: credentials, membership or registration evidence, insurance declarations, supervision and fitness-to-practise information for counsellors.
- Technical data: device/app version, IP address, security logs, and cookie or similar identifiers on the website (see section 9).
4. Sensitive and counselling content
Intake and messaging may include health-related or other sensitive information. We collect only what is needed for matching, safety and service delivery. We do not sell personal data. We do not use session audio, video, transcripts or message content to train foundation models. AI tools used for matching or operations are decision-support only; they do not provide counselling or diagnosis.
Confidentiality has limits. Information may be shared, without your marketing-style consent, where necessary to address an imminent risk of serious harm, to comply with Hong Kong law, or as otherwise explained in telehealth consent and our Terms of Use.
5. Processors and transfers outside Hong Kong
We use contracted infrastructure and service providers ("subprocessors") that process limited personal data on our instructions — for example hosting, database, queues, object storage, payments, identity and video rooms. Current beta processing may occur in Singapore or other disclosed locations.
A public summary of named vendors, roles and regions is published at /subprocessors. We keep an internal subprocessor register and update it when vendors change.
Before production use, each processor must have contractual or other means covering security, retention, breach notification, audit, deletion, subcontracting and cross-border safeguards. Location hints (for example an "Asia-Pacific" storage preference) are not treated as a residency guarantee.
6. Retention
We keep personal data only as long as needed for the stated purposes, subject to legal, clinical, insurance and accounting requirements. Draft retention periods for the beta include:
When a period ends, data is deleted or irreversibly de-identified unless a legal hold applies. Final periods require Hong Kong legal and clinical approval before automatic production deletion is enabled.
- unsubmitted intake drafts: about 30 days;
- submitted matching intake and messages: active care relationship plus about 12 months, unless a complaint or safety matter requires longer;
- booking, receipt, refund and payout records: generally seven years after the relevant financial year;
- consent and policy acceptance: life of the related record plus about seven years;
- counsellor verification documents: engagement plus about two years, with decision/audit evidence kept longer where counsel approves;
- video tokens and transient connection telemetry: minutes to about 30 days; never session media;
- security logs: about 90 days searchable, up to about one year in restricted archive; and
- safety incident evidence: period approved by clinical governance and counsel, reviewed at least annually.
7. Security
We take practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss or use. Controls include access restriction by role, encryption in transit, audit logging of sensitive actions, signed payment webhooks, and vendor review before production. No method of transmission or storage is completely secure; if a personal-data security incident creates a real risk of harm, we will take steps required under Hong Kong law and our incident runbooks, including notifying affected individuals where appropriate.
8. Direct marketing
Under the PDPO, we will not use your personal data in direct marketing unless you have given consent and we have provided the required information about the kinds of data, the marketing subjects and the classes of marketing persons. Direct marketing may include emails or messages about HarbourMind features, practitioner onboarding, or wellbeing resources. Consent is optional and separate from account creation. You may withdraw consent at any time via the unsubscribe link or by emailing privacy@harbourmindhk.com. Withdrawal does not affect service notices needed to operate bookings or accounts.
9. Cookies and similar technologies
Our website uses only necessary cookies to run the site, remember language preference, and protect security. We do not use advertising pixels or similar technologies to send counselling intake answers to social-media advertisers.
During the supervised beta we do not currently set third-party analytics cookies. If we introduce non-essential cookies in future, we will seek consent where required and provide a way to refuse before they are set.
10. Children
The supervised beta is limited to adults aged 18 or above in Hong Kong. We do not knowingly collect personal data from children for this service. If you believe a minor has provided data, contact privacy@harbourmindhk.com and we will delete it where appropriate.
11. Your choices and requests
You may:
- access and correct personal data under the PDPO;
- withdraw optional consents (including direct marketing) at any time;
- request export in the app, or schedule irreversible account erasure (14-day cooling-off) where offered for clients and counsellors, subject to retention of de-identified financial shells and legal holds; and
- raise a concern with us first; you may also contact the Office of the Privacy Commissioner for Personal Data, Hong Kong (www.pcpd.org.hk).
12. Changes
We may update this notice as the product, vendors or law change. The effective date above will change when we publish a revision. Material changes that affect how we use personal data already collected will be brought to your attention in the app or by email where practicable. A versioned collection notice is shown at relevant collection points.
13. Contact
Privacy Officer · Argo Technology Group Limited (HarbourMind 心港)
Email: privacy@harbourmindhk.com
Postal address:
RM 29-33, 5/F, Beverley Commercial Centre
87-105 Chatham Road, Tsim Sha Tsui
Hong Kong
Related: /terms · /accessibility · security@harbourmindhk.com