PERSONAL INFORMATION COLLECTION STATEMENT-USER ACCOUNT REGISTRATION (PICS-UAR) OF PTI PROFESSIONAL DEVELOPMENT LIMITED (version 5.0)
Updated: August 2026
This PERSONAL INFORMATION COLLECTION STATEMENT FOR USER ACCOUNT REGISTRATION of PTI Professional Development Limited (“PERSONAL INFORMATION COLLECTION STATEMENT-USER ACCOUNT REGISTRATION” or “PICS-UAR”)
This Personal Information Collection Statement (“PICS-UAR”) defines the purposes, limitations, and regulatory safeguards governing the collection of your personal data by PTI Professional Development Limited (“PTI”, “we”, “our”) upon your registration and use of our AI Online Training Portal. This statement strictly satisfies the notification requirements of Data Protection Principle 1(3) (DPP1(3)) under the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”) and directly embeds the latest technical and administrative rules from the PCPD’s 2024 Model AI Protection Framework, the August 2026 Agentic AI Guidelines, the April 2021 Messaging Guidance, the February 2023 ICT Security Measures, and the April 2016 Identifier Code of Practice.
Purpose of Collection
- To validate, verify, and authenticate user accounts, institutional enrollments, and academic qualification records for distance learning portfolios.
- To process specialized Agentic AI system interaction logs, prompt strings, and long-term memory configurations solely to customize, fine-tune, and optimize real-time machine-learning educational tracks via Chain of Thought (CoT) paths and Retrieval-Augmented Generation (RAG) grounding checkpoints.
- To enforce academic fraud prevention and exam invigilation integrity utilizing biometric exam proctoring, keystroke dynamics, and behavioral video analytics managed strictly under transparent Human-in-the-Loop (HITL) manual veto controls.
- To administer encrypted internal instant messaging boards and peer portal utilities while aggressively suppressing platform data harvesting through network anti-data-scraping perimeters and the permanent ban of third-party social log-ins.
Classes of Persons to Whom Data May Be Transferred, If Required
- Authorized internal personnel, including our Committees or Advisors, compliance auditors, and academic review leads responsible for executing manual vetoes.
- External cloud infrastructure providers and upstream AI system suppliers bound by rigorous, legally binding Data Processing Agreements (DPAs) enforcing minimal necessary data transfer constraints and mandatory data breach notification loops.cessation notices under Section 64.
- Law enforcement agencies, courts, or the Office of the Privacy Commissioner for Personal Data (PCPD) where processing is demanded by statutory summons, criminal investigation, or to execute anti-doxxing
Personal Identifier & HKID Collection Limitations
In strict compliance with the PCPD Code of Practice on Identity Card Numbers, the provision of learner’s HKID number or physical card copy is completely non-compulsory during registration. PTI will always provide less privacy-intrusive alternatives, allowing you to authenticate using a passport number or alternative personal identifier of your choice. No digital or physical copies of your HKID card will ever be collected or held in anticipation of a relationship or merely to guard against clerical errors. If an HKID copy is legally collected under statutory mandate, it will be immediately watermarked with the word ‘COPY / 副本’ across the entire image and will never be publicly displayed or legibly printed on any portal credential.
Technical Security & Digital Footprint Controls
We endeavour to ensure your account credentials and digital identity profiles are secured through mandatory, separate-channel Multi-Factor Authentication (MFA) and non-overlapping password rules to block account compromise and phishing vectors. For interactive messaging boards, PTI’s policy is to provide immediate ‘unsend and delete for everyone’ controls to mitigate accidental data exposure. When your account is terminated or left unmanaged, a permanent database erasure sequence is triggered under Section 26 rules to fully purge your interaction logs, active skills, and long-term agent memory files, eradicating any perpetual digital footprints within our network.
Data Subject Access and Correction Rights
Under the PDPO, you possess an absolute statutory right to request access to and request the correction of your personal data held in our systems. This explicitly includes the right to contest and request a manual explanation of any algorithmically derived grading, risk profile score, or automated proctoring outcome.
All Data Access Requests (DAR) and Data Correction Requests (DCR) must be submitted in writing via email directly to our designated Data Protection Compliance Officer at pdc@the-pti.com. Validated requests will be fully processed and completed within 40 calendar days from the date of submission.
Enquiries
In case a User has any enquiry regarding our PPS or our PICS, please email us at: pdc@the-pti.com
Governing Laws
The PICS-UAR of PTI is construed and governed by the laws of the Special Administrative Region of Hong Kong (HKSAR).
