top of page

PRIVACY POLICY

Last updated: 2026/09/12

 

This Privacy Policy explains how Pons Company Limited ("PONS.ai", "we", "us", or "our") collects, uses, shares, and protects personal data when you visit or use our website, products, services, AI solutions, and related platforms (collectively, the "Services").

We operate in Hong Kong, mainland China, Singapore, the United Kingdom, the United States, the United Arab Emirates and Saudi Arabia. This policy is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486), the PRC Personal Information Protection Law (PIPL), the UAE Federal Decree-Law No. 45 of 2021, the Saudi Personal Data Protection Law, and the California Consumer Privacy Act as amended by the CPRA. Region-specific rights are set out in sections 12–17.

 

Scope of This Privacy Policy

 

This Privacy Policy applies to personal data processed through:

 

  • the PONS.ai website (including pons.ai and subdomains), and

  • PONS.ai products and services, including AI Photo Booth solutions, personalization features, event-based activations, and related digital platforms,

 

where PONS.ai acts as a data controller.

 

B2B & Event-Based Processing

In many cases — including most event activations — PONS.ai processes personal data as a data processor on behalf of a corporate or institutional client. In those cases the client determines the purposes and means of processing and is the controller; PONS.ai acts on the client's documented instructions under a written data processing agreement. If you attended an event and want to exercise rights over your data, you may contact us at privacy@pons.ai and we will route your request to the relevant client, or handle it directly where we are the controller.

 

1. Data Controller and Contacts

The data controller responsible for your personal data is:

 

Pons Company Limited Unit 506, 5/F, New World Tower 1, 18 Queen's Road Central Hong Kong SAR

 

Privacy contact: privacy@pons.ai

General contact: support@pons.ai

 

Data Protection Officer: Kelvin Tang, support@pons.ai

 

Under the Hong Kong PDPO, requests for access to or correction of personal data should be addressed to the Privacy Officer at privacy@pons.ai or the postal address above.

 

2. Personal Data We Collect

 

  • Identity Data: name, username, job title

  • Contact Data: email address, phone number

  • Account Data: login credentials, user preferences

  • Image & Media Data: photographs, images, or videos captured at an activation or uploaded for AI Photo Booth or personalization features, and the AI-generated outputs derived from them

  • Transaction Data: billing details, payment confirmations (processed via third-party payment providers)

  • Technical Data: IP address, device type, browser type, operating system

  • Usage Data: interactions with our Services, analytics, logs

  • Marketing Data: communication preferences, campaign engagement

 

Providing your photograph at an activation is always voluntary. If you choose not to, you cannot receive an AI-generated portrait, but no other consequence follows.

 

3. Facial Imagery and Biometric Data

 

Our AI Photo Booth and personalization products process photographs of people's faces. We want to be precise about what that does and does not involve.

 

We process facial images solely to generate the visual output you requested. To produce it, your photograph may be sent to a third-party AI image provider, which may process it outside your country. See section 6 for who they are.

We do not create faceprints, face-geometry templates, or other biometric identifiers, and we do not use facial imagery to uniquely identify, recognize, match, or verify any individual, or to search for a person across images.

Because we do not process facial imagery for the purpose of unique identification, we do not consider it "biometric data" within the meaning of Art. 9 GDPR / UK GDPR. Where a client instructs us to configure a deployment that would involve identification, we treat that data as special category data and process it only on an Art. 9 lawful basis, with explicit consent.

We do not use images captured through our Services to train, fine-tune, or otherwise improve our own AI models. Your photograph is retained only for the period set out in section 8.

 

Where a US state biometric-privacy law applies — including the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and the Washington My Health My Data Act — we obtain any consent that law requires before capture, and we honour the retention limits in section 8.

 

4. How We Use Your Personal Data (Purposes & Legal Bases)

We process personal data only where a lawful basis applies. In the list below, each purpose is followed by its legal basis.

 

  • Provide and operate the Services — performance of a contract

  • Account creation and user support — performance of a contract

  • AI image generation and personalization — performance of a contract, or consent where the image is provided by an event guest rather than an account holder

  • Payment processing — performance of a contract, and legal obligation

  • Analytics and service improvement — consent for non-essential cookies and analytics; otherwise our legitimate interest in understanding and improving our Services

  • Marketing communications — consent

  • Security and fraud prevention — our legitimate interest in keeping the Services secure

  • Legal compliance — legal obligation

 

You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

 

Where Hong Kong law applies, we will not use your personal data in direct marketing without first notifying you and obtaining your consent, and we will provide an opt-out channel free of charge in every marketing message, as required by Part 6A of the PDPO.

 

5. AI, Automated Processing & Profiling

Our Services use automated processing and AI-based systems, including image generation and personalization features.

 

AI processing is used solely to deliver the outputs you requested.

We do not make automated decisions that produce legal or similarly significant effects concerning you.

You may request human review of, or deletion of, AI-processed data at privacy@pons.ai.

 

6. Data Sharing & Recipients

We share personal data with the following categories of recipient:

 

  • Cloud hosting and storage providers — Microsoft Azure, Google Cloud Platform, and Amazon Web Services

  • AI image and video providers — Google (Gemini), OpenAI, and BytePlus (ByteDance, Singapore region), etc. Which provider processes a given photograph depends on the style selected at the event; A current list is available on request at privacy@pons.ai.

  • Analytics providers — Google Analytics and Google Tag Manager, and Wix's own site analytics

  • Payment processors — Stripe

  • Error and performance monitoring — Sentry

  • Social media embeds — our website embeds an Instagram feed, which loads content from Meta. Meta may set cookies through that embed once you consent.

  • Professional advisers — legal and accounting

  • Corporate clients — where an activation is run on their behalf and they are the controller

  • Business partners involved in service delivery

 

We do not sell personal data, and we do not share personal data for cross-context behavioural advertising.

 

An up-to-date list of sub-processors is available on request at privacy@pons.ai.

 

7. International Data Transfers

We transfer personal data between the jurisdictions in which we operate. Where we do so, we rely on:

 

  • From the EEA: EU Standard Contractual Clauses, or a European Commission adequacy decision.

  • From the UK: the UK International Data Transfer Agreement, or the UK Addendum to the EU SCCs, or UK adequacy regulations.

  • From Saudi Arabia and the UAE: transfers to jurisdictions recognised as providing an adequate level of protection, or appropriate contractual safeguards, in line with the Saudi PDPL and UAE PDPL respectively.

  • From Hong Kong: contractual safeguards consistent with the PCPD's recommended model clauses.

 

You may request a copy of the relevant safeguard at privacy@pons.ai.

 

8. Data Retention

We retain personal data only as long as necessary. Our retention periods by data type are:

 

  • Account data — duration of the account, plus 24 months

  • AI images and media from event activations — deleted after 30 days by an automated nightly job.

  • Images you agreed we may use in our own marketing — 24 months from the event, unless you withdraw consent sooner. After 24 months we stop making new use of the image and delete our copy; material already published may remain published, and you can ask us to remove it at any time

  • Marketing data — until consent is withdrawn

  • Technical and log data — up to 12 months

  • Legal and financial records — as required by applicable law

 

Where we act as a processor for a corporate client, that client's contractual retention instruction governs, and may be shorter than the periods above.

 

9. Cookies & Tracking

We use cookies and similar technologies in four categories:

 

  • Essential — required for the site to function, including session management and security. These cannot be disabled.

  • Functional — remember your preferences.

  • Analytics — help us understand how visitors use the site.

  • Advertising — not currently used.

Non-essential cookies are set only after you consent via our cookie banner. You can change or withdraw your choice at any time using the Cookie settings button in the bottom-left corner of any page, or through your browser settings.

 

We honour the Global Privacy Control (GPC) signal as a valid opt-out of sale and sharing for California residents.

 

10. Security Measures

We implement appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, role-based access controls, and secure infrastructure.

 

Breach notification. If a personal data breach occurs, we will notify the relevant supervisory authority and, where the breach is likely to result in a high risk to your rights and freedoms, affected individuals — within the timeframes required by the applicable law (72 hours to the relevant EU/UK authority and to SDAIA in Saudi Arabia; without undue delay to the UAE Data Office). Where we act as a processor, we notify the controller without undue delay.

 

11. Children's Data

Our website and account-based software are not directed at children under 16.

 

Our event activations are a different matter: some are run at events intended for children, including family, school and brand events for young audiences. Where the person photographed is under 16, consent is taken from a parent, guardian, or the responsible adult supervising them, before any photograph is taken — and that adult also decides whether the image may be used in PONS.ai's own marketing.

 

If you believe a child's data has been processed without appropriate consent, contact privacy@pons.ai and we will delete it.

 

12. Your Rights — EU and UK (GDPR / UK GDPR)

 

You have the right to:

 

  • Access your personal data

  • Rectify inaccurate data

  • Request erasure ("right to be forgotten")

  • Restrict processing

  • Object to processing, including to direct marketing at any time

  • Data portability

  • Withdraw consent at any time

  • Not be subject to a decision based solely on automated processing with legal or similarly significant effects

  • Lodge a complaint with a supervisory authority

 

EU residents may complain to their local Data Protection Authority. UK residents may complain to the Information Commissioner's Office (ICO) at ico.org.uk, or call 0303 123 1113.

 

To exercise your rights, contact privacy@pons.ai. We respond within one month.

 

13. Your Rights — Hong Kong (PDPO)

Under the Personal Data (Privacy) Ordinance you have the right to:

 

  • Ascertain whether we hold personal data about you, and request a copy (a data access request)

  • Request correction of inaccurate data

  • Be informed of the classes of person to whom your data may be transferred

  • Opt out of the use of your personal data in direct marketing, free of charge

We respond to data access requests within 30 days and may charge a reasonable fee for complying, as permitted by the Ordinance. Requests go to the Privacy Officer at privacy@pons.ai.

 

You may complain to the Office of the Privacy Commissioner for Personal Data (PCPD) at pcpd.org.hk.

 

14. Your Rights — United Arab Emirates (PDPL)

Under Federal Decree-Law No. 45 of 2021 you have the right to request information about processing, to access your data, to request its transfer, to correct or erase it, to restrict or stop processing, and to object to automated processing. You may withdraw consent at any time.

 

Requests go to privacy@pons.ai. You may complain to the UAE Data Office.

 

Note: if your data is processed within the DIFC or ADGM financial free zones, the DIFC Data Protection Law 2020 or the ADGM Data Protection Regulations 2021 apply instead; contact us and we will confirm which regime governs.

 

15. Your Rights — Saudi Arabia (PDPL)

Under the Saudi Personal Data Protection Law you have the right to be informed of the legal basis and purpose of collection, to access your personal data, to request a copy in a readable format, to request correction, and to request destruction of personal data that is no longer needed.

 

Requests go to privacy@pons.ai. You may complain to the Saudi Data and AI Authority (SDAIA).

 

16. Your Rights — Mainland China (PIPL)

 

This section applies where you are in mainland China. 

 

Legal basis. We process your personal information on the basis of your consent, given at the point of collection. You may withdraw it at any time, and we provide a means to do so.

 

Sensitive personal information. Facial images are treated as sensitive personal information under Art. 28. We ask for your separate consent before processing them, and we tell you why. As set out in section 3, we do not use facial imagery to identify, recognise or match any individual, and we create no facial recognition template or face-geometry scan.

 

Cross-border transfer. To generate your image, your photograph is transferred outside mainland China to the AI providers named in section 6 — Google, OpenAI, and BytePlus. Under Art. 39 we obtain your separate consent for that transfer, and tell you each recipient's name, contact details, the purpose, and the categories of personal information involved. 

 

Minors under 14. Personal information of children under 14 is sensitive personal information under Art. 31. We process it only with the consent of a parent or guardian, and under a dedicated set of rules for handling children's information, available on request at privacy@pons.ai.

 

Your rights. You have the right to know how your personal information is handled and to decide about it; to access and obtain a copy; to request that it be transferred to another handler; to correct it; to delete it; to ask us to explain our handling rules; to withdraw consent; and to refuse decisions made solely by automated means. Where a person has died, their next of kin may exercise these rights in their interest.

 

To exercise any of these, contact privacy@pons.ai.

 

Complaints. You may complain to the Cyberspace Administration of China or your local cyberspace administration.

 

Language. Where we collect your personal information in mainland China, the notice at the point of collection is provided in Simplified Chinese.

 

17. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via the website or by email where appropriate. The "last updated" date at the top reflects the most recent change.

18. Contact Us

 

Questions or requests regarding this Privacy Policy or your personal data: privacy@pons.ai

© 2026 Pons Company Ltd. All rights reserved.

  • Instagram
  • LinkedIn

SSL/TLS Secured

bottom of page