Privacy Policy
How Lifewood handles personal data when you visit lifewood.com, contact us, apply for a role, engage with us in business, or participate in a Lifewood-managed project.
Version 2.0 | Last updated: 9 September 2026
This policy explains how Lifewood handles personal data when you visit lifewood.com, contact us, apply for a role, engage with us in business, or participate in a Lifewood-managed project where Lifewood acts as a data controller. It also explains Lifewood’s role when we process data on behalf of enterprise clients.
Website: https://lifewood.com/ | Cookie Policy: https://lifewood.com/legal/cookie-policy
Privacy at a glance
Website controller
Lifewood Data Technology Limited, Hong Kong, unless a local Lifewood entity tells you that it is responsible for a specific interaction.
Core business context
Enterprise AI data services, AIGC, AEO/GEO, LLM training data, multilingual data collection, scanning/indexing, autonomous-driving data and related edge-intelligence services.
Client project data
When Lifewood processes personal data only on a client’s documented instructions, the client is normally the controller and Lifewood acts as processor/service provider. Project-specific notices may apply.
International operations
Personal data may be processed across Lifewood’s global delivery network and by approved service providers, subject to applicable cross-border transfer safeguards.
Privacy contact
Email [email protected] with the subject “Privacy Request”.
1. About this Policy and its scope
Lifewood Data Technology Limited and, where relevant, its affiliated companies (“Lifewood”, “we”, “us” or “our”) provide enterprise AI data and digital services through a global delivery network. This Policy applies to personal data for which Lifewood determines the purposes and means of processing, including personal data collected through lifewood.com, business enquiries, supplier and customer relationships, recruitment, events, marketing and certain Lifewood-managed data collection activities.
This Policy does not replace project-specific privacy notices, consent forms, client privacy notices or contractual data-processing terms. Where Lifewood processes personal data solely for an enterprise client and under that client’s documented instructions, Lifewood is normally acting as a processor, data intermediary or service provider (terminology varies by jurisdiction). In that situation, the client determines the purposes of processing and should be your primary contact for exercising rights relating to the client project.
Local supplements. A Lifewood affiliate may provide a local or project-specific privacy notice where local law requires additional information or where that affiliate is the relevant controller. If a local notice conflicts with this global Policy for that activity, the local notice will apply to the extent required by law.
2. Who is responsible for your personal data
Website and general enquiries. For the Lifewood corporate website and general global enquiries, the primary controller is Lifewood Data Technology Limited, Unit 19, 9/F, Core C, Cyberport 3, 100 Cyberport Road, Hong Kong.
Local interactions. If you contract, work, apply, supply services or participate in a project directly with another Lifewood group company, that company may be the controller for the relevant processing and may provide additional contact information.
Controller/processor distinction. Lifewood may act as a controller for its own corporate purposes and as a processor for client-directed AI data operations. We do not treat client project data as Lifewood’s general-purpose data merely because it passes through our systems or delivery centers.
3. Personal data we may collect
The categories we collect depend on how you interact with us. They may include:
- Identity and contact data: name, business email, telephone number, country, job title, employer or organisation, postal address and similar contact details.
- Business and contractual data: enquiry details, project goals, scope and timelines, proposals, contracts, purchase orders, invoicing and payment records, business correspondence and relationship history.
- Website and technical data: IP address, browser and device information, cookie identifiers, page interactions, referral information, security logs and similar online activity information.
- Recruitment data: CV/resume, work and education history, professional qualifications, contact information, interview notes, right-to-work information and other information you choose to provide during recruitment.
- Communications data: emails, contact-form messages, meeting records, support requests, survey responses, feedback and other communications with Lifewood.
- Project and content data: where relevant to an authorised project: text, documents, audio, voice, images, video, annotations, translations, prompts, responses, sensor or interaction data, 3D or mobility-related data, and associated metadata.
- Likeness, voice and performance data: where an AIGC, speech, video or data-collection project requires it, we may process a participant’s image, voice, performance or related attributes within the scope described in the applicable project notice or consent.
- Sensitive or special-category data: only where necessary for a specific authorised purpose and where the applicable legal conditions are met. This may include biometric identifiers if a project specifically requires identification or verification using biometric characteristics.
- Public and third-party data: business contact information, professional information, public web content, client-provided materials and information received from authorised partners or data suppliers, where permitted by law.
Mandatory or optional information. Where information is marked mandatory, or is necessary to enter into or perform a contract, failure to provide it may prevent us from responding to your enquiry, onboarding you, processing an application or delivering the requested service. Other information is generally optional unless a project-specific notice states otherwise.
4. How we collect personal data
- Directly from you, for example when you submit a contact form, communicate with us, apply for a role, sign a contract, attend an event or participate in an authorised project.
- Automatically from your device when you use our website, through essential technologies and, where enabled and permitted, analytics or functional cookies.
- From clients, suppliers, data partners, subcontractors, recruitment platforms, professional networks and other authorised third parties.
- From publicly available sources where lawful and appropriate for business development, due diligence, AEO/GEO work, research or verification.
5. Why we use personal data
We process personal data only for specified purposes and under the conditions required by applicable law. The concepts below describe common legal grounds used in some jurisdictions (such as the GDPR/UK GDPR); other laws, including Hong Kong and Malaysian privacy laws, use different statutory frameworks.
| Purpose | Typical data | Why / processing condition |
|---|---|---|
| Responding to enquiries and business development | Contact details, company information, enquiry/project details | To respond, scope opportunities, prepare proposals and manage potential customer or partner relationships. Depending on law: steps toward a contract, legitimate business interests, or consent where required. |
| Contracts, customer and supplier management | Business contacts, contractual, billing and communications data | To negotiate and perform contracts, administer projects, invoice, pay suppliers, manage accounts and maintain business records. |
| AI data collection, annotation, validation and LLM-related services | Authorised project/content data | Where Lifewood acts for a client, processing is limited to client instructions, the agreed project scope and applicable contractual/privacy safeguards. The client is responsible for establishing its lawful basis and notices unless Lifewood is expressly designated otherwise. |
| AIGC and multilingual content production | Authorised text, image, video, audio, voice, likeness and brand materials | To create, localise, review and deliver authorised content. Personal likeness or voice is used only within the permitted project scope and applicable consent/licence terms. |
| AEO/GEO and digital visibility services | Client content, public business/professional information, analytics | To research, structure and optimise enterprise content for search and generative-answer environments. We do not use AEO/GEO activities to make legally or similarly significant decisions about individuals. |
| Autonomous driving and edge-intelligence data services | Sensor, image, video, audio, interaction, 3D/mobility data and metadata where authorised | To collect, annotate, validate and quality-control data for authorised mobility and edge-AI projects under the relevant client or project instructions. |
| Website operation, analytics and improvement | Technical, cookie and usage data | To operate, secure and improve the website. Non-essential analytics/functional cookies are used subject to the Cookie Policy and consent requirements where applicable. |
| Security, fraud prevention and compliance | Identity, access, technical and transaction data | To protect systems and data, detect misuse, investigate incidents, comply with law, respond to lawful requests and establish or defend legal claims. |
| Recruitment and workforce administration | Recruitment and professional data | To assess applications, communicate with candidates, verify qualifications and comply with employment-related obligations. |
| Marketing and relationship communications | Business contact details and preferences | To send relevant Lifewood news, event invitations or service information where permitted. You can opt out of direct marketing at any time. |
| Corporate administration and transactions | Relevant business, financial and contact data | For audit, insurance, professional advice, internal governance, restructuring, merger, investment or acquisition activities, subject to confidentiality and legal safeguards. |
6. AI, training data and responsible use
Client data is not general-purpose training data by default. Lifewood does not use identifiable client-provided personal data to train, fine-tune or evaluate unrelated Lifewood or third-party models unless the client has expressly authorised that use, the use is documented within the agreed scope, and all applicable privacy and contractual conditions are satisfied. Client project data is ordinarily segregated and used for the relevant project purpose.
De-identification and minimisation. Where practical, we minimise personal data and use anonymisation, pseudonymisation or other de-identification techniques appropriate to the project. Data that can reasonably be re-linked to a person remains subject to applicable privacy protections.
Image, voice and digital likeness. Where a project involves identifiable images, voice, video or performances, Lifewood processes those materials only within the authorised scope. If Lifewood is acting for a client, the client or authorised data supplier is responsible for obtaining required notices, consents, licences, publicity/portrait rights or performer permissions unless the contract assigns that responsibility to Lifewood.
External AI tools and subprocessors. Where approved third-party AI or cloud services are used in delivery, access is restricted to the authorised purpose and subject to appropriate contractual, security and transfer safeguards. We do not permit independent reuse of client project data by subprocessors except as expressly authorised.
Automated decision-making. We do not ordinarily use solely automated decision-making on visitors to our corporate website that produces legal or similarly significant effects. If a Lifewood-controlled service introduces such processing, we will provide the disclosures and controls required by applicable law.
7. When we share personal data
We may disclose personal data only as necessary and subject to appropriate safeguards, including to:
- Lifewood affiliates and authorised personnel who need the information for service delivery, corporate administration, security or support;
- approved processors and service providers, such as hosting, cloud infrastructure, communications, analytics, security, recruitment, payment or professional-service providers;
- project subcontractors or delivery partners where access is required for the authorised client project and is contractually restricted;
- professional advisers such as lawyers, auditors, accountants, insurers and banks;
- regulators, courts, law-enforcement or government authorities where disclosure is required or permitted by law; and
- a potential buyer, investor or successor in connection with a corporate transaction, subject to appropriate confidentiality controls.
No independent reuse. We do not permit processors or project partners to use client-provided personal data for their own unrelated purposes. Lifewood does not sell personal data for monetary consideration. Where a privacy law uses broader definitions of “sale” or “sharing”, we will provide any legally required notice or opt-out mechanism.
8. International and cross-border processing
Lifewood operates through a global network of offices, delivery centers, affiliates, contributors and service providers. As a result, personal data may be accessed, transferred or stored outside the country in which it was collected, including in jurisdictions whose privacy laws may differ from your own.
Where cross-border transfer restrictions apply, we use one or more safeguards appropriate to the relevant law and transfer, such as contractual data-protection terms, approved standard contractual clauses where applicable, transfer assessments, access restrictions, encryption or other technical controls, and documented vendor/recipient due diligence. Where consent or another statutory transfer condition is required, we will rely on it only where appropriate and lawful.
For Malaysia-related processing, Lifewood entities responsible for transferring personal data out of Malaysia will apply the requirements of the Personal Data Protection Act 2010 and applicable cross-border transfer guidance. For EEA/UK transfers, appropriate GDPR/UK GDPR transfer mechanisms are used where those laws apply.
9. Data security
We maintain technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Depending on the system and risk, measures may include role-based access controls, secure delivery environments, network and account security, encryption where appropriate, logging and monitoring, segregation of client projects, confidentiality obligations, staff training, vendor controls, backups and incident-response procedures.
No security system is completely risk-free. If a personal data breach occurs, Lifewood will investigate, contain and remediate the incident and will notify clients, regulators and affected individuals where and within the timeframes required by applicable law or contract.
10. How long we keep personal data
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to meet contractual requirements, to comply with legal, tax, accounting or regulatory obligations, to maintain appropriate security and audit records, or to establish, exercise or defend legal claims.
Retention periods vary by data category and jurisdiction. In particular, client project data is retained according to the applicable client contract, project instructions and legal requirements; recruitment data is retained in accordance with applicable recruitment/HR schedules; marketing preference records may be retained as suppression records so that we can respect an opt-out; and legal or financial records may be retained for statutory periods.
At the end of the applicable retention period, we delete, securely destroy or irreversibly anonymise personal data, subject to permitted backup and archival cycles.
11. Cookies and similar technologies
Our website uses cookies and similar technologies for core site functionality and may use analytics or functional technologies in accordance with our Cookie Policy. The current Cookie Policy states that essential cookies are used for core functionality, analytics cookies may include Google Analytics 4, functional cookies may remember preferences, and marketing cookies are not currently used.
Where consent is required for non-essential cookies, we will request it before activating the relevant technology. You can manage preferences through the website’s Cookie Settings and your browser controls. Embedded third-party content, such as YouTube, may be subject to the third party’s own privacy and cookie practices.
12. Your privacy rights
Depending on your location and the law that applies, you may have one or more of the following rights:
- to ask whether we process your personal data and request access to it;
- to request correction of inaccurate or incomplete personal data;
- to request deletion or erasure where the applicable legal conditions are met;
- to request restriction of processing or object to certain processing;
- to receive certain personal data in a portable format where data portability applies;
- to withdraw consent where processing is based on consent, without affecting prior lawful processing;
- to opt out of direct marketing at any time;
- to exercise rights relating to certain automated decision-making or profiling where applicable; and
- to lodge a complaint with the competent privacy or data-protection authority.
How to exercise a right. Email [email protected] with the subject “Privacy Request” and describe the request and the Lifewood service, project or entity involved. We may ask for information reasonably necessary to verify identity and authority before disclosing or changing personal data. We will respond within the timeframe required by applicable law. If Lifewood is acting only as a processor for a client, we may direct the request to the relevant client or assist that client in responding.
Regional rights. For Malaysia, rights are provided under the Personal Data Protection Act 2010 (as amended) and related instruments. For Hong Kong, relevant rights include data access and correction rights and protections concerning direct marketing under the Personal Data (Privacy) Ordinance. If the GDPR or UK GDPR applies, additional rights may include erasure, restriction, portability and objection. Residents of certain U.S. states may have additional rights under applicable state privacy laws, including rights concerning sale/sharing or sensitive personal information where relevant.
13. Children and minors
Lifewood’s corporate website and enterprise services are not directed to children. We do not knowingly collect personal data from children through the general website where parental or guardian authorisation is legally required.
Some client-authorised data projects may involve minors where lawful and appropriate. In such cases, Lifewood and/or the client will use project-specific notices, consent or guardian authorisation and additional safeguards as required by applicable law and the project design.
14. Third-party websites and services
Our website may link to third-party websites, social media platforms, video providers or other services that Lifewood does not control. Their privacy practices are governed by their own notices. We encourage you to review those notices before providing personal data to a third party.
15. Changes to this Policy
We may update this Policy when our services, technologies, legal obligations or data practices change. The “Last updated” date will identify the current version. If a change materially affects how we use personal data and applicable law requires additional notice or consent, we will provide it through an appropriate channel.
16. Contact us and complaints
Privacy requests and questions
Lifewood Data Technology Limited
Unit 19, 9/F, Core C, Cyberport 3
100 Cyberport Road, Hong Kong
Email: [email protected] (subject: “Privacy Request”)
If your concern relates to a specific Lifewood affiliate or client project, please identify it in your message so that the request can be routed correctly. You may also have the right to complain to the data-protection regulator in your jurisdiction, including the Office of the Privacy Commissioner for Personal Data in Hong Kong or the Personal Data Protection Commissioner in Malaysia, where applicable.
Effective date: 9 September 2026 | Version 2.0