Version: 1.0
Applicable product version: Public Release 1.0
Effective date: September 2026
Personal information processor / data controller: PENTACREST TECHNOLOGY LIMITED, a limited company incorporated in Hong Kong.
1. Scope
This Policy explains how we collect, use, retain, share and protect personal information when users access, register for and use the EVcando website, applications, repair conversations, material browsing, history, subscriptions and support services, and how users may exercise their rights.
This Policy does not apply to processing carried out by independent third-party websites, payment pages or services in their own name. Those third parties process information under their own privacy policies. Information we receive from third parties, and information we engage suppliers to process for EVcando, remain subject to this Policy.
The service is named EVcando, and the personal information processor is PENTACREST TECHNOLOGY LIMITED. The User Agreement addresses users’ authorization to submit information, prohibited conduct and indemnification obligations. The Repair Safety Statement addresses repair risks. Those documents do not expand the processing purposes described in this Policy or replace separate consent required by law.
2. Information We Process
The following categories apply according to the features users actually use, the information they provide, and the transactions or events involved. Listing a category does not mean that we collect every item from every user, or that all listed input methods are currently available.
2.1 Account and Preference Information
- Email addresses, verification-code delivery and verification results;
- account identifiers, registration times, account status and records of acceptance of terms;
- selected language, market and corresponding vehicle-display settings;
- names, business details, occupations, addresses, payment authorizations or identity information voluntarily provided by users or requested during risk verification.
We do not collect users’ real names, business details or occupations by default solely for registration where that information is unrelated to current features. If payment, regional, account-security or abuse concerns arise, we may request reasonable additional information.
2.2 Conversations, Materials and Feedback
- User messages, fault codes, vehicle symptoms, measurement data, on-site judgments and other repair descriptions;
- uploaded images, photos, audio, files and recognition results;
- assistant answers, material cards, source references, selected vehicles and materials;
- conversation branches, history and the Free or Pro entitlements applicable when an answer was generated;
- submissions through “Report a problem with this answer”, explanations, support requests and related complete conversations.
Users should submit only information needed for repair or support. Before uploading content containing license plates, people, identity documents, customer details or other third-party information, users should obtain necessary authorization, provide required notices and remove or obscure unrelated information. They must not rely on the platform to identify or obscure every item of personal or confidential information.
By submitting third-party information, users represent that there is a valid legal basis for the submission and processing described in this Policy, including any required consent or authorization. Users must be able to provide evidence when we reasonably request it. On discovering an unauthorized submission, users must stop further submissions, promptly notify us and cooperate with lawful correction, restriction, deletion, notification or other remedial measures.
Our receipt, storage, automated processing or review of information does not mean that we have verified or endorsed the user’s authorization. User responsibility for unauthorized submissions, missing notices, breaches of confidentiality or unlawful instructions, and recovery of third-party claims and remediation costs, are governed uniformly by Section 6, Section 13 and Section 14 of the User Agreement. This allocation does not relieve us of our own non-excludable data-protection obligations or authorize processing beyond this Policy.
2.3 Usage, Device and Security Information
- IP addresses, device and browser types, operating systems, application versions, language and time zone;
- login sessions, current devices, request times, pages visited, feature operations and errors;
- quota usage, material access, activities relating to downloading or copying, account watermark identifiers and timestamps;
- request identifiers, session identifiers, model execution status, model and material versions, latency, token usage and reference records;
- records of unusual access, bulk scraping, circumvention of permissions, account sharing, payment fraud and security incidents.
We may use cookies, local storage, session tokens and similar technologies to maintain login status, retain language and market selections, implement security controls, remember necessary settings and understand whether the services are functioning properly. For non-essential analytics, advertising or similar technologies requiring consent by law, we will provide a separate choice before enabling them. Refusing non-essential technologies should not affect basic features that can be provided without them.
If the public website enables Google Analytics 4 (GA4) and the CookieYes consent-management tool, information such as visits, devices, page usage and consent status will be processed according to the features actually enabled and users’ choices, for website statistics and management of technology preferences. Whether they are enabled and which options can be managed depend on the notices and settings displayed at the time of access. Naming these tools does not mean that analytics tracking is enabled on every page or for every user.
2.4 Subscription and Transaction Information
- Plans, prices, currencies, purchase channels, order and subscription identifiers;
- payment success, failure, refund, cancellation, renewal and expiry status;
- billing country or region, payment-method type and transaction metadata returned by payment providers.
Full payment-card numbers and payment-authentication information are generally processed directly by payment providers or app stores. As a general rule, we do not store full payment-card information.
2.5 Contact and Legal Information
- Verification, transaction, account, security and policy notices sent to users;
- complaints, rights requests, investigations, disputes, legal notices and related identity-verification information;
- legal requirements, law-enforcement requests and records needed to protect rights.
3. Sources of Information
We obtain information from:
- information submitted directly by users or generated through their use of the services;
- users’ devices, browsers and applications;
- payment, email, model, hosting, app-store and other service providers;
- security investigations, support communications, and public or third-party sources that may lawfully be used.
4. Purposes of Processing
We process information to:
- create and maintain accounts, send verification codes and enforce the single-device login rule;
- provide repair conversations, material browsing, history, branching, restoration, and personalized language and market displays;
- call model services, organize answers, display sources and maintain conversation context;
- determine Free, Pro or educational entitlements, calculate quotas, and handle subscriptions, payments, cancellations and refunds;
- lock Pro history after entitlements expire and, under Section 8 of the User Agreement, restore retained content eligible for access when the required entitlements are regained;
- respond to feedback, support requests, privacy requests and account issues;
- allow authorized personnel to review conversations for answer-quality evaluation, troubleshooting, improvements to material indexing, display and source associations, model and product effectiveness testing, and service optimization; this purpose does not change the commitments in Section 6 concerning original repair materials and source facts;
- identify and prevent account sharing, cross-region access on behalf of others, bulk scraping, circumvention of permissions, extraction of system prompts, fraud, infringement and other abuse;
- protect the safety, security and lawful rights of the services, users, people associated with vehicles and third parties;
- fulfill accounting, tax, consumer-protection, privacy, law-enforcement and other legal obligations;
- establish, exercise or defend legal claims and retain evidence relating to incidents and disputes;
- use aggregated, statistical or reasonably de-identified information to analyze service usage and improve the product.
We do not use conversations to create advertising profiles unrelated to the services. If we intend in the future to use identifiable user conversations to train general-purpose public models or for materially different purposes, we will give separate notice and obtain separate consent where applicable law requires it.
5. Legal Bases for Processing
We process personal information under Hong Kong’s Personal Data (Privacy) Ordinance and other applicable laws. Information is used for purposes notified at collection or directly related purposes. For a new purpose, we will obtain the data subject’s express and voluntary consent as legally required, unless a lawful exemption applies.
Depending on the requirements of applicable law for a particular processing activity, we may rely on one or more of the following grounds to the extent recognized by that law. These grounds do not replace the purpose limitations above or any legally required consent:
- fulfilling a user’s request or a contract between us and the user;
- complying with legal obligations;
- protecting the vital interests of users, us or others;
- our legitimate interests in providing, protecting, preventing abuse of, troubleshooting and reasonably improving the services, provided that users’ rights do not override those interests;
- users’ express consent.
Where processing must rely on consent, users may withdraw consent in accordance with law. Withdrawal does not affect the lawfulness of prior processing, but may mean that relevant features can no longer be provided. Withdrawal of consent for one purpose does not automatically require us to stop separate processing supported by another valid legal basis, such as retaining legally required transaction records or information needed to handle disputes.
6. Conversation Retention, Internal Access and Quality Improvement
Actual conversations are saved on our servers by default and associated with accounts to provide history, cross-device access, branching, entitlement-based locking, troubleshooting and quality improvement. Clearing browser data does not delete server-side account history.
Retention and access are separate matters. Retaining a conversation does not entitle users to view locked subscription content, restore suspended accounts or obtain unrestricted copies of Platform Materials. Statutory rights concerning personal information are handled separately under Section 11.
Authorized personnel may view relevant complete conversations and source references to handle answer reports, security incidents, support matters or quality reviews. Internal access is limited to personnel performing the relevant duties and should be subject to logging or controls.
We may use conversations to assess whether models are faithful to source materials, identify errors and improve prompts and product workflows. Quality improvement will not modify original repair materials or restate user judgments as source facts or manufacturer-confirmed conclusions. This requirement does not mean that AI outputs will be error-free. Sections 3–5 of the Repair Safety Statement explain the distinction between displayed materials and generated content, and the verification required before use.
Users must not assume that saved conversations are absolutely confidential. Users should not enter unnecessary customer personal information, trade secrets or information that cannot lawfully be provided to us.
7. Sharing and Recipients
To the extent necessary for the purposes described in this Policy, we may provide information to:
- Model providers: To process user input, relevant conversation context and source materials that may be provided, in order to generate answers. Their processing is subject to applicable contractual, privacy, security and data-use restrictions.
- Hosting and infrastructure providers: To provide servers, databases, storage, networks, security and backups.
- Email providers: To send verification, transaction, account and security notices.
- Payment providers and app stores: Website payments are processed by Stripe as identified at checkout. If in-app purchases are offered in the future, the relevant stores will process purchases under their own privacy policies.
- Website analytics and consent-management providers: Where actually enabled on the public website and allowed by the applicable choices, providers such as Google Analytics 4 (GA4) and CookieYes process information needed for website statistics or management of consent to technologies.
- Professional advisers and service personnel: Lawyers, auditors, accountants, insurers, incident investigators and technical support personnel, subject to confidentiality and necessity restrictions.
- Affiliates and transaction successors: In reorganizations, financing, mergers, sales or business transfers, subject to reasonable safeguards.
- Governments, courts and law-enforcement authorities: To comply with law or valid orders, protect rights and safety, or prevent fraud.
- Third parties designated by users: In accordance with users’ express instructions or consent.
We do not sell personal information. Where applicable law requires, we will provide further information about relevant suppliers, processing purposes, data types and principal processing locations through the services or in response to valid requests.
8. Cross-Border Processing
Depending on the services used and providers involved, personal information may be stored, accessed or processed outside the user’s country or region.
Before cross-border processing, we will take reasonable measures required by applicable law, which may include:
- assessing the laws of the destination or the recipient’s level of protection;
- entering into data-protection terms with recipients;
- limiting processing purposes, access and onward transfers;
- using encryption, de-identification or other appropriate measures;
- obtaining consent, completing required filings or using recognized transfer mechanisms where legally required.
Processing locations vary according to the user’s location, the services used and the model, hosting, email, payment and other providers involved.
9. Retention
Account and conversation information is retained while the account exists and for as long as necessary to provide history and restoration of entitlements, improve quality and resolve disputes.
Payment and transaction records are retained according to tax, accounting, consumer-protection and fraud-prevention requirements.
Security, abuse, watermark, access and incident records may be retained for as long as necessary to investigate matters, enforce agreements, protect materials and handle claims.
Canceling a subscription or allowing it to expire does not itself request deletion of an account or account information. Retention under this Policy is not a promise of permanent archiving or uninterrupted access through history.
After account closure or a deletion request, we will delete or de-identify information no longer needed. Information may continue to be retained where necessary to fulfill legal obligations, handle pending disputes, prevent fraud and abuse, protect rights, complete backup rotation or retain evidence of consent.
Deletion from backups may be delayed until the normal backup-rotation cycle is completed. During that period, the information will no longer be used for routine business activities.
10. Information Security
We take technical and organizational measures proportionate to risks, including access controls, account isolation, server-side entitlement verification, protection in transit, activity logging, supplier management and incident handling. Only personnel actually performing quality, security, support or legal duties may access conversations within their authorization.
No network or storage method can guarantee absolute security. Users must protect their email, verification codes and devices and contact us immediately if they suspect account misuse or information disclosure.
Where notification of a data breach is required by law, we will notify regulators and affected individuals in accordance with applicable law, explaining known impacts and recommended measures.
11. User Rights
Depending on applicable law, users may have the right to:
- know about and access personal information we hold;
- correct inaccurate or incomplete information;
- request deletion, anonymization or restriction of processing;
- object to certain processing or withdraw consent;
- obtain a portable copy of data;
- object to significant decisions based solely on automated processing;
- complain to a competent data-protection or consumer authority.
Users may submit requests to contact@evcando.com or use the privacy, support or contact channels provided within the services or on the EVcando website at https://evcando.com. To protect accounts and others’ information, we may verify the requester’s identity and may lawfully refuse requests that are manifestly unfounded, excessive, harmful to others’ rights or inconsistent with legally required information retention. Response periods are determined by the law applicable in the user’s location.
We may request information reasonably necessary to identify the requester and locate relevant records. A personal-information request does not itself grant a license to proprietary repair materials, system prompts, software or others’ information. Where a record contains both the requester’s personal information and protected content, we will handle the request as applicable law requires while protecting others’ rights.
12. Children and People Without Capacity to Contract
The services are available only to people who meet the age and contractual-capacity requirements in Section 3 of the User Agreement. They are not directed at children below that age or people lacking the relevant capacity. If we discover that such a person has provided information, we may restrict the account and take deletion or other appropriate measures. Guardians or others lawfully authorized to represent a data subject may submit requests through privacy contact channels. Making a privacy request or giving data-processing consent on someone’s behalf does not change the service’s user-eligibility requirements.
13. Notices and Marketing
Verification, payment, account, entitlement, security and policy notices are service notices. Users generally cannot opt out while continuing to use the relevant services.
Marketing communications are handled separately from necessary service notices. We send marketing communications only where permitted by law or after obtaining required consent, and provide an unsubscribe option.
Unsubscribing from marketing does not affect necessary account and transaction notices.
For non-essential analytics technologies actually enabled, we provide notice and appropriate choices under Section 2.3. If cross-site advertising, marketing profiling or other materially different analytics purposes are added, we will update notices before enabling them and separately obtain consent where the law requires. General statements in this Policy do not replace that consent.
14. Updates to This Policy
We may update this Policy because of changes in law, suppliers, processing activities or the product. Material changes will be notified through the product, email or other reasonable means as required by law. Where renewed consent is required, we will obtain it before the relevant processing begins.
This Policy may be provided in different languages. If official versions are ambiguous or inconsistent, the English version prevails, without reducing rights that cannot lawfully be excluded.
15. Contact Us
Data controller / personal information processor: PENTACREST TECHNOLOGY LIMITED, a limited company incorporated in Hong Kong.
Privacy requests and complaints: Email contact@evcando.com or use the privacy, support or contact channels provided within the services or on the EVcando website at https://evcando.com. Requests and complaints will be handled within the periods required by applicable law.