P1 CONCEPT
Privacy Policy
Effective date: 2026-10-05
Revision: p1-policy-2026-10-05-v2
This notice explains how P1 Concept Limited (P1) handles information for its company website, inquiries and client portal, with a separate section for the controlled calendar service. Each client application is provided within an agreed scope.
Where this notice applies
The company website is at www.p1concept.com and the client portal is at app.p1concept.com. Viewing public pages does not require a client account. The website provides direct email and WhatsApp contact links; clicking a link is different from sending an inquiry or submitting data to an application.
The portal is for authorized client users. Email-code login does not itself authorize access to Google Calendar, an employer’s records or another organization’s information. Expenses and CRM are offered through agreed projects; their specific data handling must be explained before the relevant processing starts.
Website visits and inquiries
Hosting receives technical request information, such as IP address and request details, to deliver and protect the website. The Stage 1 website does not include advertising trackers, a public signup form or an inquiry form. Authentication uses session information needed to maintain your portal login.
If you contact P1, we receive the contact details and information you choose to send. We use them to respond, discuss a possible project and manage the relationship. Please send only what is needed for the inquiry; do not include passwords, login codes or confidential records you are not authorized to share. Email and WhatsApp also process information under their own service arrangements.
Client accounts and support
The portal uses account identifiers, email addresses, session information and organization membership to authenticate users and restrict access. Support requests may include your contact details, issue description and relevant operational information. We use this information to provide the agreed service, investigate problems and protect access.
A combined view of your responsibilities does not remove the boundaries between company, household and other people’s data. Access depends on the permissions and scope agreed for the service.
The existing portal implementation can send a typed note to Anthropic to extract proposed events. It then applies the household profile on the application server and stores the submitted text and resulting proposals. This extraction does not itself write to a calendar. The note may itself contain personal information; the separate household profile is not included in that model request. This describes the reviewed implementation, not confirmation that a particular submission has been processed or that real client use has passed acceptance.
Controlled WhatsApp calendar workflow: current status
The newer WhatsApp calendar workflow is being tested separately from the existing typed-note portal. It remains subject to controlled synthetic testing and separate release checks. Real family messages, documents and schedules must not be submitted to that test environment. A working login or published policy is not approval for live client processing.
The following paragraphs describe the intended calendar data flow and its present limits. We will update this notice to reflect the actual released service before its use changes.
Controlled workflow: information and purpose
The service receives messages, sender identifiers and attachments deliberately supplied to the assistant, including text, screenshots, photographs and PDFs. It uses authorized calendar lists and events, connection tokens, proposals, approval decisions, change results and dated PDF/JPEG exports.
The purpose is to interpret schedule information, present proposed changes, perform approved calendar actions and produce requested calendar copies. The client must approve the current proposal before publication. Operational records support troubleshooting and prevention of duplicate changes. Scheduled reports and proactive reminders are outside the current calendar scope.
Service providers and access
Providers receive information relevant to their part of the service. Not every provider receives every submission. Relevant content may be processed outside Hong Kong; we do not promise Hong Kong-only processing.
- Vercel hosts the website and application services. Supabase provides application authentication, database and storage services.
- Anthropic is used by the existing portal’s typed-note extraction implementation to produce proposed events. The application applies the household profile separately after extraction.
- For the separate controlled WhatsApp calendar workflow, Meta/WhatsApp carries messages and attachments and n8n coordinates workflows. OpenAI is the primary model API and DeepSeek is the backup. Relevant message or document content may be sent to the selected provider, including an eligible fallback. Document preprocessing may occur first. These are not a claim that the newer workflow is deployed to the existing production portal.
- Google hosts calendars that the client authorizes. The configured email service delivers authentication messages.
- P1 handles authorized service administration and support. Access to client content is limited to what is needed for the relevant purpose, subject to the Google restrictions below.
Google Calendar connection
The reviewed controlled WhatsApp calendar implementation requests calendar.events.owned to manage events on calendars the client owns, and calendar.calendarlist.readonly to read the calendar list. These permissions are separate from email-code login and are requested for the authorized calendar features.
P1’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including Limited Use requirements. We do not sell this data, use it for advertising, or use it to train general-purpose AI models. Human access is restricted to the circumstances permitted by that policy, including your agreement to view specific data for support or necessary security or legal purposes.
You can revoke the Google connection in your Google account settings. Revocation stops that connection; it does not itself delete data already held by P1.
How long information is kept
Inquiries that do not become client projects are retained for 12 months after the last meaningful contact. Active discussions and records needed for documented business or legal obligations are handled separately. This is a retention rule, not a claim of automatic mailbox deletion.
For the controlled calendar service, the approved targets are 30 days from receipt for raw messages/uploads, 30 days from generation for PDF/JPEG exports, and 12 months from creation for genuinely minimal audit records. Audit records must not contain full messages, documents or calendar snapshots. Investigation exceptions require a recorded reason and review.
Bounded deletion tests have passed for designated synthetic records. This does not establish automatic expiry across the whole production service. Coverage of all copies, workflow history and backups remains under verification; the controlled-test restriction remains. Other calendar records, client business records and future Expenses or CRM data do not automatically fall under the 30-day rule.
Backups and provider-held copies require separate handling. We do not promise immediate erasure from every backup. Events in your own calendar and copies already downloaded or shared remain under your control.
Retention of typed-note portal source text, drafts and profile-linked records must be assessed separately against the deployed controls. The controlled workflow’s bounded cleanup evidence does not prove expiry or deletion of these portal records.
Protecting information
P1 restricts application access by account, membership and role and verifies these controls before the relevant release. We limit information used for support and investigate access problems. No service can guarantee absolute security. Do not share verification codes or use another person’s account.
Access, correction and deletion
You may contact Michael to request access to or correction of your personal data, ask about its handling, or request deletion. We verify identity and authority using the existing account or contact relationship and ask only for information reasonably needed to handle the request.
We assess deletion requests against their scope, shared records and any documented obligation to retain information. We explain the outcome and remaining limitations. See the Data Deletion page for the process.
Changes to this notice
The published version will show its effective date. Material changes to service data handling will be explained before the affected processing changes, with additional authorization where required. The English and Hong Kong Traditional Chinese versions are intended to describe the same practices.
Contact P1
Michael Ho handles privacy inquiries and requests for P1 Concept Limited / 日熙(國際)有限公司.
Unit 1219, Peninsula Centre, 67 Mody Road, Tsimshatsui East, Kowloon, Hong Kong SAR