Privacy Policy
This Privacy Policy explains how Galaxias Labs Limited, the operator of Galaxias Labs, collects, uses, stores, and protects personal data when you use our CRM and customer data platform.
1. Overview
This Privacy Policy explains how Galaxias Labs Limited ("we", "our", or "us"), as the operator of Galaxias Labs (www.galaxiaslabs.com), collects, uses, stores, and protects personal data when you use our software-as-a-service (SaaS) platform.
Galaxias Labs is designed as a customer relationship management (CRM) and customer data platform (CDP) for businesses. In using the platform, you ("User" or "Subscriber") may upload and manage sensitive business and customer data, including CRM records, customer profiles, order history, and communication content. We take the security and confidentiality of this data seriously.
This Policy applies to all persons who access or use Galaxias Labs, including company administrators, team members, and any authorized users of Subscriber accounts. It should be read together with our Terms & Conditions.
2. Information We Collect
2.1 Account & Registration Data
When you register for Galaxias Labs, we collect:
- Name, business email address, and password (hashed)
- Company name, industry, and company size
- Billing information handled by third-party payment processors; we do not store full credit card details
- Subscription tier and plan details
2.2 Customer Data You Upload (CRM/CDP Data)
As a CRM and CDP platform, Users may upload, import, or generate significant amounts of customer data, including:
This data is referred to as "Customer Data". You, as the Subscriber, are the data controller of all Customer Data. Galaxias Labs Limited acts as a data processor on your behalf.
- Customer personal details such as names, email addresses, phone numbers, and mailing addresses
- Order history, transaction records, and purchase behaviour
- Customer segmentation data, tags, and notes
- Custom attributes and field data as defined by the User
- Loyalty programme data, membership records, and reward points
2.3 Communication Content
When you use Galaxias Labs to send communications to customers through email, WhatsApp, or other integrated channels, we collect and process:
- Message content and templates
- Recipient contact information and delivery metadata
- Send, open, click, and delivery status logs
- Campaign settings and scheduling data
2.4 AI Interaction Data
Galaxias Labs includes AI-powered features. When you use these features, we may collect:
Please refer to Section 5 for more information on how AI interaction data is handled.
- Your queries, prompts, and inputs submitted to the AI
- AI-generated responses and outputs
- Metadata related to AI sessions, including timestamps, feature type, and session identifiers
2.5 Usage & Technical Data
- Log data such as IP address, browser type, operating system, pages visited, and timestamps
- Device identifiers and session tokens
- Feature usage patterns and in-app behaviour for product improvement
- Error logs and crash reports
3. How We Use Your Information
3.1 Service Delivery
- To operate, maintain, and improve the Galaxias Labs platform
- To process and store your CRM/CDP data as instructed by you
- To facilitate communications sent through the platform on your behalf
- To provide AI-assisted features and recommendations
3.2 Account Management
- To manage your account, subscription, and billing
- To authenticate users and maintain access security
- To send service-related notifications such as payment confirmations and system updates
3.3 Support & Communication
- To respond to your support enquiries
- To send product updates, feature announcements, and tips, with opt-out available at any time
3.4 Security & Compliance
- To detect and prevent fraud, abuse, and unauthorised access
- To comply with applicable legal obligations under Hong Kong law and international regulations
3.5 Product Improvement
- To analyse aggregated usage patterns and improve platform performance
- To develop new features and enhance AI capabilities using anonymised or aggregated data where possible
4. Data Sharing
We do not sell your personal data or your Customer Data to third parties. We may share data only in the following limited circumstances.
4.1 Sub-Processors & Service Providers
We engage trusted third-party service providers to help us operate the platform, including:
All sub-processors are required to handle data in accordance with our instructions and applicable data protection laws.
- Cloud infrastructure providers for hosting and data storage
- Email and messaging delivery providers such as SMTP or WhatsApp Business API partners
- Payment processors for billing and subscription management
- Analytics and monitoring tools for platform performance and error tracking
- AI model providers for AI-powered features described in Section 5
4.2 Legal Requirements
We may disclose information where required by law, court order, or government authority in Hong Kong or other applicable jurisdictions, or where we believe disclosure is necessary to protect rights, property, or safety.
4.3 Business Transfers
If Galaxias Labs Limited undergoes a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will provide advance notice and ensure that your data remains protected.
5. AI Features & Data Usage
Galaxias Labs integrates artificial intelligence features to support your CRM workflows. We want to be transparent about how AI interaction data is handled.
5.1 What We Collect
When you use the platform's AI features, such as content generation, customer insight queries, or AI-assisted suggestions, we collect the prompts, inputs, and outputs generated during those interactions. These interactions may be logged for service delivery, quality assurance, and platform improvement.
5.2 How AI Interaction Data Is Used
- To provide accurate and contextual AI responses within your session
- To improve AI model quality and platform accuracy using anonymised or aggregated data
- To monitor for misuse, safety, and compliance with our Acceptable Use Policy
5.3 Third-Party AI Providers
Some AI features may rely on third-party AI model APIs. Your prompts and relevant contextual data may be sent to those providers so that a response can be generated. We select AI partners that commit to protecting data confidentiality and that do not use your data to train their general models without explicit consent.
5.4 Your Responsibility
You are responsible for ensuring that any Customer Data or personal data included in AI prompts complies with applicable privacy laws and your obligations as a data controller. We recommend that you avoid submitting unnecessary personal data in AI queries.
6. Communications Sent via the Platform
Galaxias Labs allows you to send emails, WhatsApp messages, and other communications to your customers. In this context:
- You are the sender and data controller responsible for the content and lawfulness of all communications
- We act as a data processor, transmitting messages on your behalf
- You must ensure you have obtained proper consent from your customers to receive marketing or transactional communications
- You must comply with applicable laws, including Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486), the Unsolicited Electronic Messages Ordinance (Cap. 593), and WhatsApp Business Platform policies
- We store message logs, delivery metadata, and engagement statistics on your behalf for the duration of your subscription or as required by law
7. Data Security
We implement industry-standard technical and organisational security measures to protect your data, including:
If a data breach occurs that is likely to affect your rights, we will notify impacted Subscribers within a reasonable time as required by applicable law.
However, no method of transmission over the internet is 100% secure. We encourage you to use strong passwords, enable MFA, and restrict access to your account to authorised personnel only.
- Encryption of data in transit (TLS/HTTPS) and at rest
- Access controls and role-based permissions within the platform
- Regular security audits and vulnerability assessments
- Multi-factor authentication options for account access
- Incident response procedures in the event of a data breach
8. Data Retention
We retain your data for as long as your account remains active or as needed to provide the service. Specifically:
Data Type
Account data
Retention Period
Duration of subscription + 90 days after account closure
Data Type
Customer Data (CRM/CDP)
Retention Period
Duration of active subscription; deleted within 60 days of account closure
Data Type
Communication logs
Retention Period
Up to 2 years
Data Type
AI interaction data
Retention Period
Up to 12 months, anonymised sooner where possible
Data Type
Billing records
Retention Period
7 years to meet Hong Kong tax and accounting requirements
You may request deletion of your data at any time, subject to legal retention obligations.
9. Your Rights
Under Hong Kong's Personal Data (Privacy) Ordinance (PDPO, Cap. 486) and other applicable international data protection laws, including the GDPR where relevant, you may have the following rights:
To exercise any of these rights, please contact us using the details in Section 13. We will respond within 40 days where required under Hong Kong law.
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request erasure of your personal data, subject to legal obligations
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to certain uses of your data, including direct marketing
- Restriction: Request restriction of processing in certain circumstances
- Opt-out: Unsubscribe from marketing communications at any time
10. Cookies & Tracking
We use cookies and similar tracking technologies to operate and improve the platform. These include:
You can manage cookie preferences through your browser settings, but disabling certain cookies may affect platform functionality.
- Essential cookies: Required for the platform to function, such as session authentication
- Analytics cookies: Used to understand how the platform is used and improve performance
- Preference cookies: Used to remember your settings and preferences
11. International Data Transfers
Galaxias Labs is operated by Galaxias Labs Limited, which is based in Hong Kong. Your data may be processed or transferred outside Hong Kong, including to locations where our cloud infrastructure or AI providers operate. When this happens, we implement appropriate safeguards, including standard contractual clauses or equivalent measures, to protect your data in line with applicable law.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. Where material changes occur, we will give you at least 14 days' notice by email or prominent in-platform notice before the changes take effect. Continued use of the platform after that date constitutes acceptance of the updated Policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or how personal data is handled, please contact us:
Galaxias Labs Limited
Email: [email protected]
Address: Unit 307A, 3/F., Building 1E, Phase 1, Hong Kong Science Park, Pak Shek Kok, N.T. Hong Kong