This section explains how ITNIO handles personal data, uses website technologies, processes data for business customers, and manages subprocessors.
Personal data refers to any information that directly identifies you, or that indirectly identifies or relates to you.
Privacy Statement
1. Scope
ITNIO TECH LIMITED, together with its affiliates ("ITNIO" or "we"), is a China Hongkong-based cloud communications service provider that delivers SMS, Voice, WhatsApp, RCS, MMS, contact centre, and authentication solutions to business customers through our products, platforms, and services.
ITNIO takes the protection of personal data seriously. We also believe that our data practices should be explained clearly and in a way that people can understand. This Privacy Policy (“This Policy”) describes how we collect, use, disclose, retain, and protect personal data when you visit a ITNIO website, register for or use our products and services, contact us, attend an event, or otherwise interact with us. It also explains the choices and rights that may be available to you.
This Policy applies where ITNIO acts as a controller and determines why and how personal data is processed, including in connection with our websites, account and customer relationship management, sales enquiries, marketing activities, and corporate operations.
When a customer uses ITNIO's SMS, Voice, WhatsApp, RCS, MMS, contact centre, authentication, or other communications services to process its end users' data, the customer generally determines the purposes and means of that processing, and ITNIO provides the services on the customer's instructions. In those circumstances, the customer is generally the controller and ITNIO generally acts as a processor or data intermediary. Such instructions are set out in the customer agreement, Data Processing Agreement (DPA), service-specific terms, or the customer's use or configuration of product features. This Policy does not replace the privacy notice that a customer must provide to its end users, and it does not change the allocation of responsibilities in our contract or data processing agreement.
If you are an end user of a ITNIO customer, the controller-related provisions of this Policy do not apply to you. Your personal information is controlled by the enterprise customer with whom you directly interact. Please refer to that customer's privacy policy first. ITNIO will assist our customer with your request as required by our contract and applicable law.
This Policy does not apply to independently operated third-party websites, products, or services, or to job applicants, for whom a separate notice may be provided.
2. Personal Data We Process
The information we process depends on your relationship with ITNIO and the services you use, and may include the following:
* Information you voluntarily provide to us
* Contact and professional information: name, company, job title, industry, business email address, phone number, country or region of residence, and social media details;
* Account information: username, account ID, login credentials and security verification data;
* Business and transaction information: consultation records, product preferences, contract and order details, billing and payment histories, purchase history, and bank account information. Full payment card information shall in principle be processed directly by authorized payment service providers;
* Compliance and qualification verification information: company registration documents, authorized representative details, identity credentials or operational purpose certification materials required for activating specific communication services, complying with operator regulations, fraud prevention, customer identity verification or statutory requirements;
* Customer support and feedback content: service tickets, emails, online chats, call recordings, troubleshooting logs, questionnaires and feedback submissions;
* Event and marketing information: registration data, event participation records, subscription preferences and marketing setting configurations.
* Information automatically generated or collected by the system when you access the website and services
* Device and network information: IP address, browser and operating system type, device model, language, time zone and approximate geographic location;
* Website browsing behavior data: pages visited, click records, referral pages, search records, browsing duration, session information and error logs;
* Account and service usage history: login activities, configuration settings, API requests, operation logs, usage volume, service status and error details;
* Communication metadata: sender and recipient identifiers, transmission routing, timestamps, communication type, call duration, send/delivery/failure status, as well as information related to unsubscription and complaints;
* Data generated by cookies and similar technologies, see Clause 8 for detailed provisions.
* Materials transmitted or uploaded by customers via the services
Such materials may include phone numbers, communication content, templates, audio recordings or video files, verification requests, communication records, and other data uploaded at the customer’s discretion. The actual scope is determined by the products used, system configurations and operational instructions selected by the customer.
Such data is not actively collected by ITNIO, but is provided by enterprise customers or generated through customers' use of the services. ITNIO processes such data solely to fulfill the communication services instructed by customers, and only to the extent technically and operationally necessary. ITNIO does not use such data for its own marketing, profiling, sale, or sharing.
Customers shall ensure they possess valid legal grounds for collecting, using and submitting the aforementioned data to ITNIO, and fulfill statutory obligations of notification and right of choice toward end users in accordance with applicable laws.
* Information obtained from third parties
Sources may include affiliated enterprises, channel partners, event organizers, public information platforms, identity verification and anti-fraud service providers, payment service vendors, telecommunications operators, data aggregators and other communication service providers.
Please only submit information necessary to fulfill relevant purposes. Unless required for service activation, identity verification, payment processing or explicitly stipulated by law, do not proactively submit identity documents, financial account details, health records, biometric data or other sensitive personal information via general consultation forms, emails or online chats.
| Role | Types of Data Processed |
|---|---|
| Controller |
Information you voluntarily provide to us: contact and professional information, account information, business and transaction information, compliance and qualification information, customer support and feedback, event and marketing information |
|
Information we automatically generate or collect when you use our websites and services: device and network information, website activity information, account and service usage information, communication metadata, information generated by cookies and similar technologies |
|
|
Information from third parties (where ITNIO determines the purposes and means of processing such information): from affiliates, channel or business partners, event organizers, public sources, identity and anti-fraud service providers, payment service providers, telecommunications operators, aggregators and other communication service providers |
|
| Processor |
Data submitted or transmitted by customers through the services: phone numbers, communication content, templates, recordings or media files, authentication requests, communication logs and other data the customer chooses to upload |
3. How and Why We Use Personal Data
We only process necessary personal data for legitimate, specific and business-related purposes, including:
• Providing, configuring, routing, maintaining and supporting products and services;
• Creating and managing accounts, fulfilling contracts, orders, billing, settlement and customer relationship management;
• Handling sales inquiries, demos, trials, event registrations and cooperation requests;
• Verifying identities or enterprise qualifications to meet requirements from operators, communication ecosystem partners and legal compliance obligations;
• Safeguarding the security of accounts, networks, platforms and communications, as well as detecting, investigating and preventing fraud, spam, abuse and unauthorized access;
• Monitoring service performance, troubleshooting faults, analyzing usage patterns, and improving products, services and user experience;
• Sending mandatory notifications regarding services, transactions, security or policy updates;
• Sending marketing communications where consent has been obtained or permitted by applicable laws, and managing your subscriptions and preferences;
• Complying with valid requirements from laws, regulatory authorities, courts, law enforcement agencies or government bodies, asserting legal rights and resolving disputes;
• Conducting corporate audits, financial operations, governance, business continuity planning, mergers and acquisitions, or other lawful business activities.
Where applicable laws require us to specify the legal bases for processing, we will rely on one or more of the following depending on the circumstances:
• performance of a contract or pre-contractual measures taken at your request;
• your consent;
• compliance with legal obligations;
• protection of vital interests of you or another individual; and
• legitimate interests pursued by us or a third party, provided such interests do not override your rights and freedoms in an undue manner.
• You may withdraw your consent at any time, but such withdrawal shall not affect the lawfulness of processing carried out prior to the withdrawal based on your consent.
4. How We Disclose Personal Data
Selling personal data is not part of our business model. We disclose personal data only as needed to provide services, operate our business, or comply with law, including to the following categories of recipients:
Communications ecosystem providers, such as mobile network operators, aggregators, number or voice providers, OTT communications platforms, and other providers needed to route and deliver communications;
Service providers, such as cloud hosting, content delivery, security, identity verification, payment, customer support, analytics, marketing, audit, and professional advisory providers;
Affiliates and authorised personnel, where needed for coordinated operations, customer support, finance, compliance, and security, subject to appropriate access controls and confidentiality obligations;
Customers and their authorised parties, as needed to provide services, reports, or support in accordance with customer configurations and instructions;
Transaction parties, including actual or prospective parties and advisers involved in a merger, acquisition, financing, restructuring, asset transfer, or similar transaction, subject to confidentiality and applicable law; and
Public authorities or other necessary recipients, where required by law or valid legal process, or where necessary to protect rights and safety, investigate fraud, or prevent abuse.
Where a vendor processes personal data on our behalf, we apply contractual, confidentiality, security, and access restrictions appropriate to the risk. Certain communications ecosystem providers may independently determine how they process particular metadata for their own legal obligations, network operations, or billing.
We do not sell mobile numbers or SMS consent information submitted through our website contact forms, and we do not provide that information to third parties for their own marketing purposes unless you separately and expressly agree.
5. International Transfers
ITNIO is headquartered in Hongkong China and operates across multiple countries and regions. To provide global communications, customer support, and corporate operations, personal data may be accessed, processed, or stored outside your country or region, where data protection laws may differ.
When transferring personal data across borders, we will implement appropriate safeguards in accordance with applicable laws, relevant regulatory guidance and the risks associated with the transfer. Such safeguards may include entering into data protection agreements with recipients, restricting access to personal data, implementing appropriate technical and organisational security measures, and, where appropriate, adopting the recommended model contractual clauses issued by the Office of the Privacy Commissioner for Personal Data, Hong Kong, or other lawful and appropriate transfer mechanisms. For cross-border transfers of personal data governed by Hong Kong’s Personal Data (Privacy) Ordinance (Cap. 486), we will take all reasonable and practicable steps to ensure that the personal data receives a level of protection outside Hong Kong that is no less stringent than that required under the Ordinance. The location and transfer arrangements applicable to specific services may vary depending on the relevant product, data routing, carrier networks and customer configurations, and may be further specified in the applicable contract or data processing agreement.
6. Information Security
We use reasonable technical and organisational measures appropriate to the nature, context, and risk of processing to protect personal data from unauthorised access, collection, use, disclosure, copying, modification, loss, or disposal. These measures may include access controls, authentication, encryption in transit, logging and monitoring, vulnerability and incident management, backups, and employee confidentiality requirements.
No network, system, or method of transmission can be guaranteed to be completely secure. If a personal data breach occurs, we will investigate, contain its impact, and notify relevant customers, individuals, and regulators where required by applicable law.
7. Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, to perform our contracts, comply with legal and carrier requirements, resolve disputes, and protect legitimate interests. In setting retention periods, we consider the amount, nature, and sensitivity of the data, the potential risk of unauthorised use or disclosure, the processing purpose, whether that purpose can be achieved by other means, and applicable legal, accounting, tax, and contractual requirements.
Data processed by customers through the Services is retained according to customer configurations, applicable product rules, and our contract or data processing agreement. At the end of the applicable period, we delete, anonymise, or securely isolate the data in accordance with our processes. Data in backups may remain until the relevant backup cycle expires, during which time it remains protected and is not used for other purposes.
8. Cookies and Similar Technologies
We may use cookies, pixels, web beacons, local storage, and similar technologies to:
operate and secure our websites, logins, and forms;
remember language, region, and other preferences;
understand website use and improve performance and experience; and
measure marketing and provide relevant content or advertising where we have consent or another basis permitted by law.
Except for strictly necessary technologies, we obtain your choice or consent before use where required by law. You can manage non-essential technologies through our website cookie settings tool or your browser settings. Rejecting some technologies may affect certain features. Cookie names, providers, purposes, and durations are displayed in the website cookie settings.
9. Your Choices and Rights
Depending on your location and applicable law, you may have the right to:
receive information about how we process your personal data;
request access to or a copy of your personal data;
correct inaccurate or incomplete data;
request deletion;
restrict or object to certain processing, including direct marketing;
withdraw consent;
request data portability where applicable;
challenge significant decisions based solely on automated processing; and
complain to a data protection authority with jurisdiction.
You may stop receiving marketing emails by using the unsubscribe link in the message. Opting out of marketing does not prevent us from sending necessary service, security, transaction, or legal notices.
To exercise a right, email privacy@itniotech.com and identify your name, relationship with ITNIO, the request, and the information reasonably needed to locate relevant records. To protect personal data, we may verify your identity and authority. We will respond within the time required by applicable law. Some rights are subject to legal exceptions.
If ITNIO processes your data only on behalf of a customer, we will generally refer or route your request to that customer.
10. Children's Privacy
Our products, services, and websites are intended for business customers and professionals. They are not directed to children and are not intended for children to register for or use independently. We do not knowingly collect personal data directly through our website from a child below the applicable legal age in their location. If you believe a child has provided personal data to us, contact privacy@itniotech.com so that we can investigate and take appropriate action.
Customers must not use the ITNIO Services to collect or process children's data unlawfully and are responsible for obtaining any required parent or guardian authorisation.
11. Third-Party Links and Services
Our websites or services may link to or connect with third-party websites, platforms, or services. Where a third party independently determines its processing, its own privacy policy governs. We encourage you to review that policy before providing personal data.
12. Changes to This Policy
We may update this Policy to reflect changes in our products, business, technology, or law. We will publish the revised version on this page and update the “Last updated” date. If a change materially affects your rights or how we process personal data, we will provide advance or timely notice through a prominent website notice, email, or another appropriate method.
13. Contact and Complaints
For questions, requests, or complaints about this Policy or ITNIO's privacy practices, contact:
ITNIO TECH LIMITED
Privacy email: privacy@itniotech.com
Address: Rm 704 CHEUK NANG CENTRE 9 HILLWOOD ROAD TSIM SHA TSUI HONG KONG.
We will review your request carefully and respond within the period required by applicable law. If you are not satisfied with our response, you may complain to a data protection authority with jurisdiction or seek another remedy available under applicable law.
Last updated: 11 September 2026
Cookie Policy
1. Technologies
ITNIO websites may use cookies, pixels, web beacons, local storage, and similar technologies to operate and secure websites, remember preferences, analyse performance, and measure marketing where required consent is obtained.
2. Categories
Strictly necessary cookies support login, security, load balancing, and forms. Functional cookies remember language and region. Analytics cookies help us understand website use. Advertising cookies measure marketing or provide relevant content and are used only where permitted or consented to.
3. Third Parties
Some technologies are set by providers of analytics, content, support, or advertising. They act under contract for us or under their own privacy policies where they independently determine processing.
4. Choices
Manage non-essential cookies through website settings or your browser. Choices are browser- and device-specific and may reset when cookies are cleared. Rejecting non-essential cookies does not prevent basic browsing but may limit features.
5. Retention
Session cookies expire when a browser session ends. Persistent cookies expire at their stated duration or when deleted. Names, providers, purposes, and durations appear in website cookie settings.
6. Contact
Questions: privacy@itniotech.com.
Data Processing Addendum
This DPA forms part of the Services agreement between Customer and ITNIO TECH LIMITED and applies when ITNIO processes Customer Personal Data on Customer's behalf.
1. Roles and Instructions
Customer is a controller or processor acting for a controller; ITNIO is a processor or subprocessor. ITNIO processes Customer Personal Data only under the Agreement, Orders, configurations, and documented instructions, unless law requires otherwise.
2. Customer Duties
Customer is responsible for lawfulness, accuracy, necessity, notice, consent, and other legal basis. A Customer acting as processor confirms that its controller authorised ITNIO as subprocessor.
3. Processing Details
Processing supports provision, protection, maintenance, and support of purchased Services for the Agreement term and lawful retention period. Data may include contact details, telephone numbers, communications content, authentication data, metadata, device/network data, and other submitted data. Data subjects may include Customer personnel, contacts, End Users, and recipients.
4. Confidentiality
Authorised personnel are subject to confidentiality and receive access only as needed
5. Security
ITNIO will maintain risk-appropriate measures including access control, authentication, transmission protection, logging, monitoring, vulnerability management, backups, incident response, and workforce security.
6. Subprocessors
Customer generally authorises subprocessors. ITNIO will impose equivalent protection and remains responsible for their processing on its behalf. Changes will be posted or notified. Customer may object in writing on reasonable data-protection grounds.
7. Transfers
ITNIO will use lawful transfer safeguards, including contractual protection, access restrictions, and standard contractual clauses where applicable. Customer authorises transfers necessary for global communications.
8. Data Subject Requests
ITNIO will reasonably assist Customer with access, correction, deletion, restriction, objection, and portability. Direct requests may be referred to Customer.
9. Security Incidents
After confirming an incident affecting Customer Personal Data, ITNIO will notify Customer without undue delay and provide available details on nature, effects, mitigation, and contacts, and reasonably assist required notification.
10. Assessments and Consultation
Where information is otherwise unavailable, ITNIO will reasonably assist with impact assessments and prior regulatory consultation.
11. Audit Information
ITNIO will provide reasonably necessary compliance information. If insufficient, Customer may conduct one scoped audit annually on notice, under confidentiality, without operational disruption, and at its cost, except for regulator requirements or a material incident.
12. Return and Deletion
After termination, ITNIO will return or delete Customer Personal Data at Customer's choice, except for legal retention or protected backup rotation. Retained data will not be used for another purpose.
13. Conflict
This DPA prevails over the Terms for personal data processing. The Terms govern other matters.
Subprocessors
ITNIO uses assessed providers for infrastructure, communications routing, security, support, analytics, payment, and necessary operations. Subprocessors processing Customer Personal Data for ITNIO are subject to appropriate confidentiality, security, and data protection duties.
The list identifies legal name, function, processing location, and applicable products. Email privacy@itniotech.com to subscribe to changes. A Customer may object on reasonable data-protection grounds within 10 days after notice. The parties will seek a solution in good faith. If unresolved and inseparable from the affected Service, Customer may discontinue and terminate that affected Service.
Privacy Rights Requests
Depending on applicable law, you may request access, correction, or deletion, withdraw consent, object to direct marketing, restrict certain processing, or request portability where applicable.
Email privacy@itniotech.com with the subject “Privacy Request” and provide your name, relationship with ITNIO, the specific request, and information needed to locate relevant records. We may verify identity and authority to protect personal data.
If ITNIO processes your information only for a business customer, we will refer or route the request to that customer.
Additional Notice for California Residents
This section applies to you if you are a resident of California. References to “Personal Data” shall include “personal information” and “sensitive personal information,” as these terms are defined under the California Consumer Privacy Act (“CCPA”) as amended by the CPRA.
In the preceding 12 months, we collected the following categories of Personal Data and sensitive personal information:
• Identifiers: such as real name, address, unique personal identifiers, e-mail address.
• Personal information categories listed in the California Customer Records statute: such as name, telephone number, email address, company name, job title, and financial information. In the provision of our services we may also process (a) the content of communications, such as message bodies, call recordings (if applicable), and images or files sent via our platform; and (b) service usage data, including call detail records, from/to phone numbers, device location data (inferred from IP), and IP addresses.
• Commercial information: such as records of products or services purchased, obtained, or considered.
• Internet or other similar network activity information: browsing history, search history, and other information regarding your interaction with our sites, applications, or advertisements.
• Inferences drawn from other Personal Data: such as inferences reflecting preferences, characteristics, behavior, or attitudes.
• Geolocation data: we may gain access to the approximate location of the device or equipment you are using if you interact with us online or use our services (e.g., through IP address).
• Sensory data: such as audio, electronic, or similar information when you contact us (e.g., call recordings with our support team, if any).
The categories of sources from which we collect your Personal Data, the recipients of your Personal Data, and the specific business or commercial purposes for which we collect and disclose your Personal Data are described in the main body of our Privacy Policy (see “How We Use Your Personal Data” and accompanying tables). The criteria we use to determine how long to retain your Personal Data are also described in our Privacy Policy.
We do not “sell” or “share” (as those terms are defined under the CCPA) your Personal Data with third parties for cross-context behavioral advertising or any other purpose that constitutes a “sale” or “share”. However, we may disclose Personal Data to our telecommunications partners, service providers, and affiliates solely to deliver the services you request. We do not have actual knowledge that we have sold or shared Personal Data of individuals under 16 years of age.
Your Privacy Rights
In addition to the rights described in the “Your Rights and Choices About Your Data” section of our Privacy Policy, California law provides you with the following rights, subject to certain exceptions:
• Right to Know: You have the right to request that we disclose the categories and specific pieces of Personal Data we have collected about you, the categories of sources, the business purpose, and the categories of third parties with whom we share it.
• Right to Delete: You have the right to request deletion of your Personal Data, subject to legal exceptions.
• Right to Correct: You have the right to request correction of inaccurate Personal Data.
• Right to Opt-Out: You have the right to opt out of the “sale” or “sharing” of your Personal Data (though we do not engage in such activities).
• Right to Limit Use of Sensitive Personal Data: You have the right to limit our use of your sensitive Personal Data to that which is necessary to provide the services, if applicable.
• Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
To exercise any of these rights, please submit your request through one of the following methods:
• Email us at privacy@itniotech.com; or
• Write to us at Rm 704 CHEUK NANG CENTRE 9 HILLWOOD ROAD TSIM SHA TSUI HONG KONG..
For requests submitted via an authorized agent, we may require written proof of your authorization and verify both your and the agent’s identity.
We will respond to verifiable requests within the timeframes required by California law. If we cannot fulfill your request, we will explain the reason. If you wish to appeal a decision, you may contact us using the same contact information above.