What we hold, why, and how to get it deleted.
This is the notice the consent box on our application form points at. It is written to be read, not to be survived. Version privacy-2026-09, in force from 8 September 2026.
Who we are
Suma builds and runs this software, and is registered in Hong Kong.
We are the data user for everything described here. If you are an existing client, your own staff and patient records inside your app are held on your instructions and we act on them for you.
What we collect, and why
Three things, and nothing else:
- Contact details. Your name, your company name, your email address and your phone number, taken from the first page of the application form. We use them to reply to you, to send the messages the form promises (a confirmation, a receipt, a note when your build starts, a note when it is ready) and to open your account when the build lands.
- Your answers to the questionnaire. Free text you type about how the business runs. We use it to scope and build your software, and a founder reads it.
- The accounting files you upload. Spreadsheets, CSV exports, PDFs, and photos or scans of paper. We use them to understand the shape of your books and to import the opening data your app starts from.
We do not buy data about you, we do not sell or rent anything you give us, and we run no advertising or profiling on it. Payment card details are never seen by us at all: the card form is Stripe's, hosted by Stripe, and what comes back to us is a payment reference and a yes.
An AI model reads part of it
To tell you what we noticed about your business, and to ask you better follow-up questions, the structure of your uploaded files and your questionnaire answers are read by an AI model. Three things are true about that, and we would rather say them here than leave you to guess:
- Names, email addresses, phone numbers and identity card numbers are removed before the text is sent. What the model sees for the files is their structure, the column headings, the row counts, the date ranges and a few sample rows with personal fields replaced by markers.
- Nothing you give us is used to train any model, ours or anybody else's.
- The model never writes to your books. Every figure in your accounts is posted by ordinary deterministic code, and a person signs off anything that leaves Suma.
The model runs on Google Vertex AI, listed below.
Who processes it for us
This is the whole list. Each one is a supplier we actually call, not a category.
- Vercel hosts the website and runs the server code.
- Neon hosts the encrypted Postgres database your application and your books are stored in.
- Resend sends our transactional email (invitations, receipts, build notices, password resets).
- Stripe takes the engagement payment and holds the card details we never see.
- Google Vertex AI runs the model described above.
If we ever add one, this list changes before the supplier is called, not after.
Where it is held, and how
Your application, your answers and your uploaded files are encrypted at rest with a key unique to your company. The suppliers above operate outside Hong Kong, so your data is processed overseas; we pick suppliers who commit to protection at least equivalent to what the Personal Data (Privacy) Ordinance requires of us. How we protect it sets out the engineering.
Retention: how long we keep it
The files you upload are the sensitive part, and they have a hard limit. Uploaded files are deleted 90 days after your build is finished. That retention limit is automatic, it runs nightly, and it needs nobody to remember it. Until your build is finished the files are kept, because the build is made from them.
What survives that deletion is the record of the engagement: your reference number, your contact details, your questionnaire answers, the payment record and the dates the build moved. We keep those for as long as you are a client and for seven years afterwards, which is the period Hong Kong company and tax law expects business records to be available for. If you have asked us to delete your files early, the same rule applies to what is left.
Deleting your files, and asking what we hold
You can have your uploaded files deleted at any time, before or after your build, paid or unpaid. Ask us and we run it the same working day; the files and the bytes behind them are removed from the database, and we write an audit line saying we did. You do not have to give a reason and it costs nothing.
You can also ask us what we hold about you, ask us to correct it, or ask us to stop using it. Under the Personal Data (Privacy) Ordinance we have 40 days to answer a data access request. Write to sales@suma.hk with your reference number and we will confirm what we are doing.
The one thing we will not delete on request is the engagement record described above while a legal or tax obligation still requires it. If that applies to you we will say so plainly and tell you when it lapses.
Cookies
We set a signed session cookie when you sign in, and a signed cookie that identifies the application you are filling in so you can come back to it. Both are functional and neither tracks you across other sites. There is no advertising cookie on this domain.
When this changes
The consent you gave is stamped with the version of this notice that was in force on the day, and that stamp is never rewritten: it is the record of what you agreed to. A new version applies to consents given from the day it is published, and if a change matters we will tell existing clients rather than quietly reposting the page.
Ask us anything about this
A privacy notice you cannot get an answer about is a document, not a promise. Write to sales@suma.hk, or get in touch, and one of the founders answers.