Privacy Policy and PICS

Hong Kong Wellness Hub is operated by JDCoreDev Ltd as an intermediary and discovery platform. This Privacy Policy and Personal Information Collection Statement (PICS) explains what personal data we collect, why we collect it, who it may be shared with, how long it is kept, and your rights under the Personal Data (Privacy) Ordinance (PDPO).

Discovery call requests

When you submit a request for a free discovery call through Hong Kong Wellness Hub, we collect the following personal data on your behalf:

  • Your name
  • Your contact details (email address or phone number)
  • Your preferred times for the call
  • An optional reason or note you choose to provide

Purpose: This information is used only to arrange a free discovery call between you and the practitioner you contact. It is not used for marketing or shared with third parties.

Who receives it: Your request is forwarded to the practitioner you contact. That practitioner acts as an independent data controller for the discovery call request; JDCoreDev Ltd operates Hong Kong Wellness Hub as a data intermediary only and does not retain a copy for its own purposes beyond the retention period stated below.

Retention: Call-request records are retained for 90 days, after which they are deleted.

Your PDPO rights: If you are a data subject in Hong Kong, you may request access to or correction of personal data we hold about you under the Personal Data (Privacy) Ordinance. To make such a request, please contact JDCoreDev Ltd using the details below.

Collection purpose

Information is collected only for matching, follow-up with consent, practitioner onboarding, credential verification, and platform operations.

Who we share data with

Your personal data may be transferred to the following classes of persons, only for the purposes described in this statement:

  • The practitioners and practices you contact, who act as independent data controllers for the requests you send them.
  • Our infrastructure and service providers acting on our instructions, including Cloudflare (hosting, content delivery, and cookieless analytics), Resend (transactional email), and Anthropic (AI-assisted drafting of provider and marketing content).
  • Where a provider chooses to connect them, that provider's own Google or Microsoft (calendar) and Meta or LinkedIn (social) accounts.

We do not sell personal data. Some of these service providers may process data outside Hong Kong; where they do, the transfer is made under contractual and technical safeguards appropriate to the data. External providers you continue to (such as a booking or payment provider) are governed by their own privacy terms.

Voluntary provision

Providing personal data is voluntary. If data is not provided, Hong Kong Wellness Hub may be unable to follow up or complete onboarding.

Practitioner and practice profiles

Profile information for practitioners and practices is provided by those practitioners and practices and published to enable client discovery. Practitioners and practices are independent data controllers for their own professional information. JDCoreDev Ltd publishes this information as an intermediary.

Booking provider handoff and settings

Practitioners or practices may configure optional booking-system settings, including provider name, external calendar identifiers, public booking links, availability-check URLs, reminder preferences, and last-checked availability metadata. Hong Kong Wellness Hub uses these settings to show availability or hand visitors off to the practitioner's chosen booking provider.

Provider credentials, API tokens, webhook secrets, and passwords are not shown in browser pages and are not part of the public booking response. When you continue to an external booking provider, that provider's own privacy terms apply to the information you submit there.

Talks, groups, and RSVPs

When you RSVP to a talk or group through Hong Kong Wellness Hub, we collect the name, contact detail, optional note, event identifier, consent reference, and RSVP timestamp needed to manage attendance and capacity. Free-text RSVP notes are checked for crisis language before they are stored.

If an event requires payment, Hong Kong Wellness Hub may show an external payment link after a valid RSVP. Payments are handled outside the platform by the practitioner, practice, or their selected payment provider; Hong Kong Wellness Hub does not process card details or store payment transaction data for these events.

Email automations and preferences

When you provide a contact email and the required consent, Hong Kong Wellness Hub may queue RSVP confirmations and event reminders for talks or groups. Discovery-call confirmations, provider notifications, reminders and follow-ups may also be queued after a valid discovery-call request so the practitioner and client can coordinate the requested contact.

Email jobs are stored for delivery and audit purposes. These records may include the recipient, template/job type, source reference, scheduled time, status, attempt count, failure reason, and suppression state. Delivery failures are logged for operational troubleshooting and do not guarantee that an email was received.

Marketing/newsletter email requires consent or another operator-confirmed lawful basis before it is queued. Newsletter-style email includes an unsubscribe path, and active suppression records are checked before sending further email to the same recipient.

Managed website service

Practitioners and practices using the managed website service may have service records such as domain names, hosting status, maintenance notes, requested website copy, supplied assets, support requests, and update timestamps. These records are used to coordinate external website hosting, maintenance, and support work handled by JDCoreDev Ltd under the applicable service arrangement.

The Hong Kong Wellness Hub profile remains a separate platform profile used for discovery, matching, and contact workflows. External provider websites are managed outside the HWH profile publishing workflow and may have their own privacy notices or service terms.

Assisted onboarding and profile building from sources

For assisted practitioner onboarding, an authorised JDCoreDev Ltd operator may use provided website URLs and pasted profile text to prepare a draft practitioner profile. This may include public professional biography text, public contact or booking links, language and service format information, and practitioner-provided credential claims.

Raw fetched website text and pasted source text are used transiently for profile drafting and are not stored as raw source material. Structured extracted draft data, confidence notes, source URL references, and photo-candidate metadata may be stored for review until the draft is submitted, corrected, discarded, or otherwise handled through the dashboard/admin process.

Practitioners can correct draft profile information before submission and may request deletion or correction of onboarding draft data through the dashboard or JDCoreDev Ltd admin support. Scraped photo candidates are advisory only and are not published unless the practitioner or authorised account confirms and uploads an appropriate image.

AI marketing pack drafts

Providers and authorised JDCoreDev Ltd operators may use AI tools to create marketing pack drafts for review. Source text may be processed to generate channel-specific drafts, including text from a transcript, outline, existing post or article, event details, profile update, or operator prompt.

Raw transcript text and raw operator prompt text are not stored as source records by this feature. Hong Kong Wellness Hub stores bounded source labels or excerpts, generated drafts and review status, channel metadata, compliance flags, and revision notes until they are deleted or handled through the normal retention and review process.

Generated drafts require human review and compliance checks before publication, posting, scheduling, or sending. Phase 31 generation does not approve, publish, schedule, post, send, or email any marketing content automatically.

Content calendar workflow

Providers and authorised JDCoreDev Ltd operators may move generated marketing drafts into a content calendar for review, approval, scheduling, and manual export tracking. Calendar workflow items may store generated copy, source references, channel, approval status, scheduled time, owner or practitioner scope, update history, and audit timestamps.

Manual export and manual completion actions are recorded for operational accountability, including who marked an item as posted or sent and when. This workflow does not connect to social, email, or calendar accounts and does not auto-post or auto-send content.

Generated content still requires human review and compliance checks before external use. Later email, calendar, or social integrations would require separate consent, configuration, and privacy review before activation.

Automation rules and observability

JDCoreDev Ltd may configure automation rules and pause or disable settings to coordinate marketing draft generation, reminders, and operational follow-up. Automation rules may store practitioner, practice, channel, trigger, rule status, configuration, actor, and timestamp metadata so authorised operators can review what is enabled or paused.

Automation runs may store trigger and source references, bounded input summaries, output refs, actor or system source, status, attempt counts, retry timing, run events, and bounded failure reasons. These logs are used for audit, support, troubleshooting, and to show providers whether work is queued, skipped, paused, retryable, failed, or completed.

Reminder automation may create scheduled email jobs only when the required consent or lawful basis is present and active suppression checks pass. The existing email dispatcher remains the sender; automation does not send email directly.

Marketing automation creates reviewable drafts and safe output refs for later review. It is not automatic publication, posting, scheduling, social publishing, or email delivery. Connected social, calendar, and email dispatchers keep their existing approval, consent, token, and operator-key boundaries.

Social publishing integrations

Manual export remains available for social and email calendar items. Manual export may be tracked as workflow or audit state, including the item, channel, actor, and timestamp needed to show whether a draft was copied, posted, sent, or otherwise handled outside the platform.

Providers may optionally configure connected social channels for LinkedIn or Instagram where platform permissions and account setup allow it. Hong Kong Wellness Hub may store connected social channels metadata, provider account labels or identifiers, scopes, status, and encrypted social tokens for server-side use only. Browser pages and public API responses do not expose social tokens, provider secrets, OAuth verifier material, or raw provider responses.

Direct social publishing stores publish jobs, publish attempts, provider response status, external post or media identifiers, bounded failure reasons, retry state, and timestamps. LinkedIn and Instagram publishing require human-approved content and configured connected channels; Instagram also requires an eligible media asset. Facebook remains manual export unless a later separately reviewed integration is enabled.

Calendar downloads and optional connected sync

Hong Kong Wellness Hub may provide calendar file downloads for public talks or groups and scheduled discovery-call appointments. These downloads contain bounded event or appointment details such as title, time, location, and a platform calendar link; RSVP notes, call reasons, contact details, and free-text preferred times are not used to generate calendar files.

Providers may optionally connect Google or Outlook calendar sync. When enabled, Hong Kong Wellness Hub stores Google/Outlook connection metadata, provider account labels, sync job status, external provider event identifiers, external provider responses, and bounded failure reasons needed to create, update, retry, or troubleshoot approved calendar sync jobs.

Refresh tokens used for connected calendar sync are stored as encrypted calendar tokens and used server-side only. Browser pages and public API responses do not expose calendar tokens, provider secrets, raw provider responses, or OAuth verifier material.

Providers can disconnect or disable calendar sync from the dashboard. Disable calendar sync stops future provider writes while retaining operational history needed for audit, retry review, and support.

Practice account access

Where a practice account manages a roster, practice owners or admins may help supply and review practitioner profile information. Production practice agreements must define who controls, accesses, and updates practice and practitioner data.

Practice-admin dashboard tools may store roster metadata, practitioner visibility overrides, and pending practice page edits submitted for JDCoreDev Ltd review before publication. Practice admins may also see practice-wide analytics aggregated across managed practitioner slugs, the status of practice-level add-ons, and the manual billing reference field named billing_ref. Practice admins can submit billing change requests for account, practice, and managed practitioner add-ons through that single practice billing relationship. Those request records may include the requested add-on, scope and target, account/practice billing reference, requester email, request status, and timestamps. JDCoreDev Ltd reviews, confirms, and provisions billing. Hong Kong Wellness Hub does not collect card, bank, checkout, invoice, payment-method, refund, or transaction details. JDCoreDev Ltd is the billing authority and sends Hong Kong Wellness Hub only normalized subscription and entitlement state, such as status, billing reference, period end, and add-on/package entitlement keys.

Practice admins may also use refresh-from-website tools to fetch public website text for a bounded pending review update. Raw fetched website text and HTML are used transiently, stripped to plain text, and not retained as raw source material. Refresh output does not publish directly and cannot update credentials, verification status, or add-on entitlement fields.

Retention and access

Raw concierge text is not retained by default. Access and correction requests should be directed to JDCoreDev Ltd. Retention periods specific to discovery-call requests are described in the Discovery call requests section above.

Analytics

Hong Kong Wellness Hub may use cookieless analytics (Cloudflare Web Analytics) to understand aggregate site usage. No personal data is collected by the analytics layer.

Featured placement and match-priority reporting also uses cookieless platform analytics. These records may count profile views, search impressions, concierge surfaces, external-link clicks, and discovery-call submissions by practitioner slug, referrer host, event type, source, and timestamp. They do not store IP addresses, user-agent strings, cookies, visitor identifiers, or client accounts.

Newsletter subscriptions

If you subscribe to a practitioner's newsletter, we store your email, an optional name, a consent reference, and an unsubscribe token — only after you tick the consent box. We do not track email opens or link clicks. Sending is handled by the platform email pipeline; every newsletter carries a one-click unsubscribe link, and unsubscribing stops further newsletter emails from that practitioner. The practitioner writes and sends the content; JDCoreDev Ltd operates the platform as a data intermediary.

Contact

For data access, correction, or deletion requests, or for any privacy enquiry, contact JDCoreDev Ltd at privacy@hkwellnesshub.com.

Last updated: 16 June 2026.