Legal
Privacy Policy
This policy explains what personal data Echofolk collects through this website, why we collect it, who we share it with, and how you can exercise your rights over it.
Last updated 2 September 2026
1. Who we are
This website is operated by [LEGAL ENTITY NAME] (company number [COMPANY REGISTRATION NUMBER]), a company incorporated in the Hong Kong SAR with its registered office at [REGISTERED OFFICE ADDRESS, HONG KONG]. We trade as Echofolk. In this policy, we, us and our mean that company.
We are the data user under the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (the PDPO), and the controller under the EU General Data Protection Regulation (GDPR) and the UK GDPR where those laws apply to our processing.
Our representative in the European Economic Area for the purposes of Article 27 GDPR is [EU ARTICLE 27 REPRESENTATIVE — NOT YET APPOINTED]. Our United Kingdom representative for the purposes of Article 27 UK GDPR is [UK ARTICLE 27 REPRESENTATIVE — NOT YET APPOINTED].
2. Scope of this policy
This policy covers personal data we process through the public echofolk.ai website, including the waitlist form and any email you send us. It does not cover:
- the Echofolk simulation platform itself, which is in private beta and is governed by the separate agreement we put in place with each customer;
- third-party websites we link to, which have their own privacy policies and which we do not control.
Echofolk simulates consumer behaviour using synthetic profiles built from census, behavioural and market datasets. Those synthetic profiles are generated constructs and are not intended to describe, identify or represent any real individual. This policy concerns data about you, the visitor to this website.
3. Personal data we collect
Data you give us
- Waitlist submissions. Your first name and work email address when you join the private beta waitlist.
- Correspondence. Your email address, name, and anything you choose to include when you write to us, including any details of the business decision you want to simulate.
Data collected automatically
- Server and delivery logs. Our hosting provider records your IP address, the pages requested, timestamps, referring page, and basic browser and device information. These logs exist to serve the site, keep it available, and protect it from abuse.
- Your cookie choice. Stored in your browser so we do not ask you again on every page. See the Cookie Policy.
We do not currently operate any analytics, advertising or tracking product on this website. If that changes, we will load it only after you have given consent through the cookie banner, and we will update this policy and the Cookie Policy first.
We do not ask for special category data, and we ask that you do not send it to us. We do not use your data for automated decision-making that produces legal or similarly significant effects on you.
4. How and why we use it
- To respond to your enquiry and to contact you about early access to the Echofolk platform.
- To operate, secure, debug and improve this website.
- To keep a record of the cookie preferences you have set.
- To comply with legal obligations and to establish or defend legal claims.
We do not sell your personal data, and we do not share it with third parties for their own marketing.
5. Legal bases (EEA and UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases under Article 6(1):
| What we do | Legal basis |
|---|---|
| Add you to the waitlist and contact you about access | Consent, given when you submit the form (Article 6(1)(a)) |
| Reply to an email or enquiry you send us | Legitimate interests in responding to the people who contact us, or steps taken at your request before entering a contract (Articles 6(1)(f) and 6(1)(b)) |
| Serve, secure and maintain the website | Legitimate interests in running a safe and functioning website (Article 6(1)(f)) |
| Store non-essential cookies | Consent, given through the cookie banner (Article 6(1)(a)) |
| Meet legal and regulatory obligations | Compliance with a legal obligation (Article 6(1)(c)) |
Where we rely on consent you may withdraw it at any time. Withdrawal does not affect the lawfulness of anything we did before you withdrew it.
Under the PDPO we collect personal data for a lawful purpose directly related to our business, we collect no more than is necessary for that purpose, and we use it only for that purpose or a directly related one unless you consent otherwise.
6. Cookies and local storage
We use strictly necessary browser storage to remember your cookie choice, and our host sets essential cookies needed to deliver and secure the site. Non-essential cookies are not set unless you allow them. The full inventory and the categories are set out in the Cookie Policy. You can change your choice at any time:
7. Who we share data with
We share personal data only with service providers who process it on our instructions:
| Provider | What it does | Where it processes data |
|---|---|---|
| Vercel Inc. | Website hosting, content delivery and server logs | United States and global edge locations |
| FormSubmit | Relays waitlist form submissions to our email inbox | United States |
| [EMAIL PROVIDER] | Hosts the inbox that receives your message | [REGION] |
We may also disclose personal data where we are required to by law, by a court, or by a regulator, and to our professional advisers where necessary. If our business is reorganised, sold or merged, personal data may be transferred as part of that transaction, and we will tell you before it becomes subject to a different privacy policy.
8. International transfers
We are based in Hong Kong and our providers operate internationally, so your personal data may be transferred to and processed in countries outside your own, including the United States. Those countries may not offer the same level of protection as the laws of your home jurisdiction.
Where we transfer personal data out of the EEA or the UK, we rely on the European Commission Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and we assess whether additional safeguards are needed. You can request a copy of the safeguards we use by writing to join@echofolk.ai.
9. How long we keep data
| Data | Retention |
|---|---|
| Waitlist name and email | Until the private beta closes and for up to 24 months afterwards, or until you ask us to delete it, whichever comes first |
| Email correspondence | Up to 36 months from our last exchange |
| Server logs | As retained by our hosting provider, typically no more than [LOG RETENTION PERIOD] |
| Cookie preference record | 12 months from the date you set it, then we ask again |
We keep data for longer only where we need it to comply with a legal obligation or to establish, exercise or defend a legal claim.
10. Security
We take reasonably practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss or use. These include encryption in transit across the whole site, access controls on the inbox that receives form submissions, and limiting access to the small number of people who need it. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, you, within the timeframes the applicable law sets.
11. Your rights
Under the PDPO you have the right to ask whether we hold data about you, to receive a copy of it, and to require correction of anything inaccurate. We may charge a fee for complying with a data access request, as the PDPO permits.
Where the GDPR or UK GDPR applies, you also have the right to:
- be told how we use your data, which is the purpose of this policy;
- access a copy of your personal data;
- have inaccurate data corrected and incomplete data completed;
- have your data erased in certain circumstances;
- restrict our processing in certain circumstances;
- receive your data in a portable, machine-readable format;
- object to processing carried out on the basis of legitimate interests;
- object at any time to direct marketing, which we will always act on; and
- withdraw consent at any time where we rely on it.
To exercise any of these rights, write to join@echofolk.ai. We will respond within the period the applicable law requires, which is one month under the GDPR and UK GDPR and 40 days under the PDPO. We may need to verify your identity first.
12. California residents
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know what personal information we collect and why, to access and delete it, to correct inaccurate information, and not to be discriminated against for exercising those rights.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA. We have not done so in the preceding twelve months. The categories of personal information we collect are identifiers such as your name, email address and IP address, and internet activity information such as the pages you visit, as described in section 3.
Submit a request to join@echofolk.ai. You may use an authorised agent, and we will ask for proof of their authority.
13. Children
This is a business website that is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to join@echofolk.ai and we will delete it.
14. Changes to this policy
We may update this policy as the product and the law develop. The date at the top of the page shows when it last changed. If a change materially affects how we use your personal data, we will take reasonable steps to tell you before it takes effect, and where the change requires your consent we will ask for it.
15. Contact and complaints
For any privacy question, or to exercise your rights, write to join@echofolk.ai, or to [LEGAL ENTITY NAME] at [REGISTERED OFFICE ADDRESS, HONG KONG].
If you are not satisfied with our response you may complain to a supervisory authority. In Hong Kong that is the Office of the Privacy Commissioner for Personal Data. In the EEA it is the authority in the country where you live or work. In the UK it is the Information Commissioner’s Office. We would appreciate the chance to address your concern before you approach a regulator.