Privacy Notice / Personal Data Collection Statement (PDCS)

For All Users of The Trust Loop Pilot (Hong Kong)

General enquiries: info@thetrustloop.ai

Privacy and data requests: privacy@thetrustloop.ai

1. Purpose of Collection

The Trust Loop ("we", "our", "us") collects and processes personal data of candidates, endorsers, recruiters, and administrative users solely for the purpose of conducting and evaluating a 3-month pilot of our peer-verification and trust-scoring platform in Hong Kong. The Trust Loop is operated by KL2 Technologies Limited, a company incorporated under the laws of Hong Kong with Business Registration Number 79712177.

Your data will be used only to:

  1. enable account access and user authentication;
  2. support endorsement and verification of professional experience or skills;
  3. generate trust scores through a combination of peer endorsements and algorithmic processing (see Section 3 for further detail);
  4. provide candidate profile information to authorised recruiters participating in the pilot; and
  5. compile anonymised pilot analytics for product evaluation.

2. Voluntary Provision of Data

Providing your personal data to The Trust Loop is voluntary. However, if you choose not to provide the data requested, we may be unable to create your account, deliver the relevant pilot services, or include you in the verification and matching process.

You will not suffer any penalty for declining to provide your data, but your participation in the pilot may be limited as a result.

3. Categories of Data Collected

Depending on your role, we may collect:

User RoleData TypesPurpose
Candidates

Name, contact details,

CV/resumé data, career history, endorsements,

optional profile photo

This data is used to create verified candidate records and generate trust scores.

Endorsers (Peers)

Name, email or LinkedIn ID,

endorsement message,

relationship to candidate

This data is used to verify the authenticity of candidate achievements and contribute to trust score calculation.

Recruiters / Hiring Managers / HR Leads

Name, business email,

organisation affiliation, role title,

feedback & usage data

This data is used for recruiter account management and workflow evaluation during the pilot.

Administrators

Name, work email,

system activity logs

This data is used for access control and system security audit.

We do not require or intentionally collect identity card numbers, financial data, or sensitive personal identifiers.

Trust Score Processing

Trust scores are generated through a combination of peer endorsement data and algorithmic processing, including the use of large language models. No trust score is based solely on automated processing without underlying human input in the form of peer endorsements. Candidates may request a summary explanation of how their trust score was derived by contacting privacy@thetrustloop.ai.

4. How Endorser Data Is Collected

When a candidate nominates an endorser, The Trust Loop sends an invitation to the endorser by email. That invitation includes a link to this Privacy Notice so that the endorser can review how their data will be used before deciding whether to participate. No endorsement data is recorded until the endorser has received this notice and actively submitted their endorsement through the platform. Candidates should only nominate endorsers whom they reasonably expect to be willing to participate, but the legal obligation to provide this notice to endorsers rests with The Trust Loop, not the candidate.

5. Use and Disclosure

We will process your personal data only for the pilot purposes described above and may disclose it to:

  1. Pilot recruitment organisations:

    Licensed recruitment agencies, startups, and SMEs and their designated hiring managers who are registered participants in the Hong Kong pilot programme. These organisations receive candidate profile data and trust scores only for roles to which the candidate has been matched or has applied.

  2. Other users within the verification workflow:

    Endorsers will see the candidate's name and the specific professional claim they are being asked to verify. Candidates will see the name of endorsers who have submitted endorsements on their behalf. Recruiters will see candidate profiles, endorsement summaries, and trust scores for candidates within their active workflows.

  3. Authorised service providers:

    Cloud-hosting, IT infrastructure, and large language model API providers engaged by The Trust Loop, strictly under written confidentiality obligations and data processing agreements.

We will not sell, rent, or use your data for marketing, customer profiling, or any commercial activity unrelated to the pilot.

6. Retention and Deletion

All identifiable data (CVs, endorsements, recruiter accounts, logs) will be deleted or irreversibly anonymised within 30 days after pilot completion or termination, unless legal or regulatory retention is required.

Aggregated, anonymised metrics (e.g., number of endorsements) may be retained for product research.

7. Consent Withdrawal and Account Deletion

You may withdraw your consent and request deletion of your personal data at any time during the pilot by contacting privacy@thetrustloop.ai. We will process your request within 14 days unless retention is required by law or necessary to comply with a legal obligation.

If you are a candidate, withdrawal will result in deactivation of your profile and removal of your data from active recruiter workflows. If you are an endorser, withdrawal will result in removal of your endorsement from the relevant candidate's record, which may affect their trust score. If you are a recruiter, withdrawal will result in deactivation of your account and removal of access to candidate data.

Please note that anonymised data that has already been incorporated into aggregated pilot analytics prior to your withdrawal request cannot be retrieved or deleted, as it can no longer be linked to you.

8. Access and Correction

All users have the right under Data Protection Principle 6 of the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") to:

  • request a copy of the personal data we hold about them; and
  • request correction of any inaccurate data.

To make a request, please email privacy@thetrustloop.ai. We aim to respond within 40 days, consistent with the timeframe prescribed by the PDPO. Data access requests during the pilot period will be processed free of charge.

9. Accuracy and User Responsibility

Each user must ensure that the personal data they provide, including endorsement content and account registration details, is true, accurate, and current. If you become aware that any data you have provided is inaccurate or outdated, please contact us promptly so that we can correct or update it.

10. Security Measures

We maintain reasonable technical and organisational safeguards in line with Data Protection Principle 4 (Security) of the PDPO, including:

  • encryption of data in transit (TLS/HTTPS) and at rest (AES-256);
  • role-based access controls and multi-factor authentication for all system accounts;
  • regular access log reviews and password policies; and
  • written confidentiality agreements with all staff and contractors who handle personal data.

Recruiters and administrators with system access must handle candidate data responsibly, avoid unauthorised exports or downloads, and report any suspected data incident to privacy@thetrustloop.ai immediately.

11. Cookies, Tracking, and Analytics

The Trust Loop platform uses essential session cookies to maintain your login state and ensure the platform functions correctly. These cookies are strictly necessary for operation and cannot be disabled while using the platform.

During the pilot, we may use privacy-respecting analytics tools to collect aggregated, non-personally-identifiable usage data such as page views, feature usage frequency, and session duration. This data is used solely to evaluate pilot performance and improve the platform. We do not use third-party advertising trackers, and no analytics data is shared with external parties for marketing purposes.

If our analytics practices change during the pilot, we will update this notice and notify active users by email.

12. Data Hosting and Transfers

All pilot data is hosted in Hong Kong SAR. Where cloud processing by our authorised service providers requires data to be processed outside Hong Kong, we will ensure that appropriate safeguards are in place, including written data processing agreements and selection of jurisdictions that provide privacy protection comparable to Hong Kong's PDPO.

Although the cross-border transfer provisions under Section 33 of the PDPO have not yet been brought into force, we adopt these protections voluntarily as a matter of best practice. We will not transfer personal data internationally without appropriate safeguards, and we will notify users if our hosting arrangements change materially during the pilot.

13. Data Breach and Notification

Although Hong Kong does not currently impose a mandatory data breach notification requirement, The Trust Loop voluntarily commits to the following as a matter of best practice and in line with guidance issued by the Office of the Privacy Commissioner for Personal Data ("PCPD"):

If any personal data incident occurs that may expose personal data to unauthorised access, loss, or misuse, we will notify affected participants and their organisations as soon as practicable, and cooperate fully with the PCPD in any investigation or enquiry.

14. Changes to This Notice

We may update this Privacy Notice during the pilot period to reflect changes in our practices, legal requirements, or platform functionality. If we make material changes, we will notify active users by email and publish the updated notice on the platform.

Continued use of the platform after notification constitutes acceptance of the updated terms.

15. Governing Law

This Privacy Notice is governed by, and construed in accordance with, the laws of the Hong Kong Special Administrative Region, including the Personal Data (Privacy) Ordinance (Cap. 486).

Last updated: 20 March 2026

Version: 1.0 — Pilot Phase