HESTIA SYNCKITCHEN PRIVACY POLICY
SyncKitchen Recipe Management Application & Hestia v6 Pro Cooking Robots
Version update date: [●] | Version effective date: [●] | Version: 1.0
The SyncKitchen App is a recipe-management and cooking-robot-control application provided by Hestia Technology Limited, a company incorporated in the Hong Kong Special Administrative Region of the People’s Republic of China with registered office at 4/F, Excelsior Building, 68–76 Sha Tsui Road, Tsuen Wan, Hong Kong (in this Privacy Policy, "Hestia", "the Company", "we", "us" or "our"). Through the SyncKitchen App and the Hestia SyncKitchen platform (together, the "Services"), we offer functions including recipe browsing and management, menu and Branch organisation, ingredient and Larder configuration, AI-assisted recipe assistance, and the operation, monitoring and synchronisation of Hestia v6 Pro and successor Cooking Robots.
If you have any questions or concerns regarding this Hestia SyncKitchen Privacy Policy ("this Policy" or "this Privacy Policy") or related matters, please contact us using the information provided in Section 10 ("How to Contact Us") of this Policy.
We are well aware of the importance of personal information to you. We will take corresponding security protection measures in accordance with the requirements of the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (the "PDPO"), and where applicable to you, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (collectively, the "CCPA/CPRA"), the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and other applicable data-protection laws, and use commercially reasonable efforts to protect the security and controllability of your personal information.
This Privacy Policy explains to you how we collect, use, store, share, transfer and protect information about you, and how we keep that information secure. Before becoming a User of the SyncKitchen App, you must read this Privacy Policy carefully and agree to it. The terms of this Privacy Policy take effect immediately when you register as a User and are binding on you and the Company.
This Privacy Policy is incorporated by reference into the Hestia SyncKitchen Platform User Service Agreement (the "Terms of Service"), in particular Sections 5 (Authentication, Cloud Infrastructure and Third-Party Service Providers), 6 (Import/Export, Encryption and Data Portability) and 13 (Privacy and Personal Information) of the Terms of Service. Capitalised terms used but not defined in this Privacy Policy have the meanings given to them in the Terms of Service.
The SyncKitchen App is provided to Users free of charge: there are no in-app purchases, no paid subscriptions, no in-App advertising and no in-App monetisation. We do not sell or share your personal information for cross-context behavioural advertising or any other purpose. The costs of operating the Services, including cloud infrastructure and data processing, are borne by Hestia and are not offset by any sale or sharing of personal information. If our business model changes in the future, we will notify you in accordance with Section 7. Hardware (Hestia v6 Pro and above Cooking Robots) is sold or leased separately under separate Hardware Sale Documents (defined below).
This Privacy Policy is issued by Hestia Technology Limited as the controller of personal information processed through the SyncKitchen App and the Services. The supply of Hardware (including the Hestia v6 Pro Cooking Robot and successor models) and Robotics-as-a-Service ("RaaS"), lease, subscription and similar arrangements may be contracted with, and personal information in connection with such arrangements may be processed by, other members of the Hestia group of companies, including without limitation Hestia Robotics, Inc., a company incorporated in the United States with business address at 135-17 Northern Blvd, Unit 1B, Flushing, New York 11354 ("Hestia US" and, together with Hestia Technology Limited and other Hestia group entities, the "Hestia Group"). Where personal information is processed by Hestia US or another Hestia Group entity under a Hardware Sale Document, RaaS order form, lease, subscription, services agreement or related documentation (collectively, the "Hardware Sale Documents"):
the relevant Hestia Group entity acts as the controller of such personal information for the purposes of the relevant contract, and the privacy notice, governing law and dispute-resolution provisions of the relevant Hardware Sale Documents may apply in addition to, or in place of, this Privacy Policy;
we apply a Hestia Group-wide standard of data protection that is, in substance, no less protective than this Privacy Policy, supported by intra-group data-processing arrangements in accordance with Section 6;
personal information may be shared between Hestia Group entities on a need-to-know basis for the purposes of contract performance, invoicing, shipment and customs, installation, support and maintenance, warranty administration, financial and tax reporting, anti-fraud and anti-money-laundering screening, and legal-and-regulatory compliance; and
where there is any conflict between this Privacy Policy and the privacy provisions of an executed Hardware Sale Document in respect of the specific commercial relationship governed by that document, the privacy provisions of the Hardware Sale Document shall prevail to the extent of the conflict for that relationship.
When we provide the Services, we may collect, store and use the following categories of information about you. If you do not provide relevant information, you may not be able to register, log in or enjoy some features of the Services, or you may not be able to achieve the intended effect of the relevant features.
Registration and Account information you provide when creating, configuring or maintaining an Account, including your email address, given name, family name, display name and (if you choose to provide them) organisation, role, Branch name and Branch address;
Information you provide when you submit User Content, including recipes, recipe titles and names, dish names, ingredient names and ingredient lists, methods of preparation, plating instructions, photographs, illustrations, instructional videos, audio recordings, menus, descriptive text, tags, comments, ratings and screen names;
Information you provide when you participate in market research, customer questionnaires, beta-feature programs, product surveys or marketing activities initiated or participated in by us;
Information you provide when you contact our customer-service personnel or other staff (for example, by email, support ticket or in-App chat), including the content of your communications and any photographs, videos or attachments you submit in connection with technical-support tickets;
Information you provide when configuring connected Hardware, including Cooking Robot pairing identifiers, Larder and Sauce Dispenser layouts, sync configurations and Branch-to-Hardware mappings.
Use of the SyncKitchen App requires registration and login verification. Authentication, login verification, session management, multi-factor verification (where applicable), magic-link delivery and single-sign-on integration (including Google sign-in and Apple sign-in) are operated by Stytch, Inc. ("Stytch") on our behalf as a Sub-Processor. The Company does not itself store User passwords; password material, where used, is processed and held by Stytch in accordance with its security architecture. Information processed in this context includes your email address, given name, family name, display name, authentication credentials, session tokens, sign-in events and device fingerprints.
We may receive information about you that is shared by other parties when you use the Services, including (a) information shared by other Users in connection with collaborative recipe-development, Branch operations or shared menus and (b) information made available by an authentication provider you choose to use (for example, your Google account name and email address if you sign in via Google sign-in, or your Apple ID and the email address you elect to share if you sign in via Apple sign-in).
We may collect the following categories of information when you use the Services:
Log information — technical information that the system may automatically collect when you use the Services, including device or software information (such as your mobile device type, operating-system version, web-browser type, application version, device serial number, IP address, application logs and crash reports), and details of the actions you take and content you request when using the Services.
Coarse network-derived location — we may derive an approximate location from your IP address for security, abuse-prevention and service-availability purposes. We do not collect precise device geolocation through the App. If you connect your device location services for any feature, you can stop the collection of location information by turning off the relevant permission in your device settings.
Recipe Data and synchronisation events — the recipes, dish names, ingredient lists, plating instructions, photographs, instructional videos, menus, Branch settings, Larder and Sauce Dispenser layouts that you upload, and the synchronisation, edit and operation events generated when you use the App or sync with connected Hardware.
Cooking Robot telemetry — where you operate Hestia Hardware, technical telemetry (such as cooking-cycle status, sensor readings, error codes, firmware version, network connectivity, sync timestamps and device-pairing identifiers) generated by the Hardware and transmitted via Microsoft Azure (including Azure IoT Central) for control, monitoring and remote-diagnostic purposes.
Camera and barcode scans — if you grant the App access to your device camera, image data captured for the limited purpose of QR-code or barcode scanning of ingredient packaging, mobile-device-to-Hardware pairing or capturing photographs for technical-support tickets.
"Boot Startup" Permission (Android only) — on Android devices, the App may automatically resume pending download or sync tasks after a system reboot, solely to ensure data integrity and a consistent User experience. This permission is not used to access any additional personal information beyond what is described in this Policy. to ensure that the recipes, menus and Cooking Robot data you have downloaded within the App can continue to be scheduled and downloaded after a device restart, the App uses Android’s WorkManager component in the background and listens for the system’s BOOT_COMPLETED event. This permission is used solely to automatically resume unfinished download or sync tasks after a reboot, in order to improve your User experience and to ensure data integrity. We do not access any other personal information through this permission.
On our web App we use a small number of strictly first-party cookies and equivalent local-storage tokens for the following purposes only: (a) authenticating your session through Stytch; (b) remembering your language, locale and theme preferences; and (c) measuring aggregate, non-identifying performance and stability metrics. We do not use third-party advertising cookies, pixels or behavioural-advertising trackers, and we do not use cookies for cross-context behavioural advertising or to "sell" or "share" personal information within the meaning of the CCPA/CPRA.
You acknowledge that, to the extent permitted by applicable law, we do not need to obtain your separate authorisation and consent to collect and use personal information in the following limited situations:
where required for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract;
where necessary for compliance with a legal obligation to which we are subject (including the PDPO and other applicable laws);
where necessary to protect the vital interests of you or another natural person, such as the prevention of imminent injury or harm;
where necessary for the prevention or detection of crime, the apprehension or prosecution of offenders, the assessment or collection of any tax or duty, or in connection with criminal investigation, prosecution, trial or judgment execution;
where the personal information has been disclosed to the public by the data subject on his or her own initiative, or has been collected from sources that are lawfully and publicly available (such as legal news reports or government information disclosures);
where necessary to maintain the safe and stable operation of the Services (such as discovering and handling product or service failures, security incidents and abuse);
for the purpose of legitimate news reporting in the public interest;
where necessary for an academic-research institution to conduct statistical or academic research in the public interest, on the basis that any externally published results contain only de-identified information;
any other situation expressly stipulated by applicable laws and regulations.
1.7 Commercial-customer and Hardware-lessee information
Where a corporate or other business customer (a "Commercial Customer") enters into a Hardware Sale Document with a Hestia Group entity to purchase, lease, subscribe to or otherwise obtain access to Hestia Hardware or RaaS, we may collect, store and process the following additional categories of personal information about the Commercial Customer’s authorised signatories, points-of-contact, operators and other relevant natural persons:
Identification and contact information — including given name, family name, job title or role (such as Chief Executive Officer, Authorised Representative), business email address, business telephone number, business postal address, and copies of identity documents required for know-your-customer ("KYC"), anti-money-laundering ("AML"), sanctions-screening or signatory-verification purposes;
Billing, banking and payment information — including invoicing details, deposit and subscription-fee payment records, bank account or wire-transfer instructions, payment-processor identifiers, late-payment and interest records, and credit-related information;
Tax and regulatory information — including business registration numbers, tax identification numbers (such as EIN or VAT numbers), importer-of-record details, customs broker information, and other information required by applicable tax, customs, food-safety or import/export laws;
Shipment, installation and operations information — including delivery and installation addresses, site-survey details, on-site training attendance records, and Hardware serial numbers and pairing identifiers associated with the Commercial Customer’s premises;
Insurance information — including certificates of insurance evidencing comprehensive general liability and workers’ compensation coverage maintained by the Commercial Customer in accordance with the Hardware Sale Documents, the name and contact details of the Commercial Customer’s insurance broker and named additional insureds, and claims-related information; and
Contractual correspondence — including notices, change requests, support tickets, service-level reports, complaints and dispute correspondence exchanged in the course of performance of the Hardware Sale Documents.
We process the categories of personal information described in this Section 1.7 for the following purposes: negotiation, formation and performance of the Hardware Sale Documents; invoicing and collection of fees, deposits and chargebacks; shipment, customs clearance, installation, training, support and maintenance; warranty administration and end-of-life processing; insurance, indemnity and claims handling; KYC, AML, sanctions, export-control and other regulatory compliance; financial, tax and statutory record-keeping; defence and pursuit of legal claims; and other purposes ancillary to the foregoing.
Personal information collected under this Section 1.7 is retained for the periods required by applicable tax, accounting, anti-money-laundering, customs, product-liability and statutory limitation laws (typically not less than seven (7) years from the end of the relevant accounting period or the end of the Hardware Sale Documents, whichever is later), or for such longer period as may be required by a legal hold, regulatory investigation or pending or threatened claim. The lawful bases for processing under this Section 1.7 are (a) performance of a contract to which the Commercial Customer is a party (and, in relation to natural persons acting on its behalf, our legitimate interests in the performance of that contract), (b) compliance with our legal obligations, and (c) where applicable, the consent of the relevant individual.
We process your personal information for the following purposes:
Identity verification, login authentication, session management, security prevention, fraud monitoring, abuse mitigation, archiving and back-up purposes, in order to ensure the security and integrity of the Services;
Provision and operation of the Services, including the recipe-management, AI-assisted recipe-suggestion, Branch-management, Larder/Sauce-Dispenser layout, synchronisation and Cooking Robot control features;
Designing new features and improving our existing Services, including by analysing aggregated and de-identified usage patterns;
Better understanding how you access and use the Services so that we can present recipes, menus and tools that are relevant to you, and respond to your needs in a targeted manner;
Software certification, integrity-checking and management of software upgrades, including over-the-air firmware updates for connected Hardware;
Inviting you to participate in surveys, beta programs and feedback channels regarding our products and Services;
Communicating with you about platform-policy changes, service-content changes or other matters affecting your use of the Services, and otherwise contacting you when necessary;
Training, evaluating and refining recommendation, search, moderation and machine-learning systems associated with the Services, in accordance with the Recipe Data training licence in Section 4.5 of the Terms of Service and the User Content licence in Section 12.3 of the Terms of Service.
We will use the personal information collected in accordance with this Privacy Policy and only to the extent necessary to operate the features of the Services.
After collecting your personal information, we may de-identify or aggregate the data through technical means. Where information has been irreversibly de-identified or aggregated such that it cannot reasonably be used to identify you, we may use it for analytics, product improvement, recommendation-system development, AI training and other lawful business purposes.
Personal information you provide while using the Services will continue to be authorised for our use for so long as you use the Services, unless you delete it, withdraw your consent through the App or your device settings, or close your Account in accordance with Section 5.4. When you cancel your Account, we will cease using your personal information and delete or anonymise it in accordance with Section 4.4 below, save where retention is required by applicable law or to preserve evidence in connection with a dispute.
When we display your personal information within the Services, we will desensitise it where appropriate (for example, by truncating email addresses or masking display names) to protect the security of your information.
In order to provide a better experience and to improve our Services, we may combine information collected through one feature with information collected through another feature for the purposes set out in this Policy. We will not, however, combine personal information in any way that is inconsistent with the purpose for which it was originally collected, or in a way that would surprise a reasonable User in your position.
We engage a limited set of third-party service providers ("Sub-Processors") to provide the Services. The Sub-Processors that have access to personal information as at the date of this Privacy Policy are set out in the table below. We maintain appropriate written data-processing arrangements with each Sub-Processor obliging it to use personal information only for the purposes described in this Policy and the relevant data-processing arrangement, and to maintain appropriate technical and organisational security measures.
| Sub-Processor | Function | Data categories | Privacy / DPA URL |
|---|---|---|---|
| Stytch, Inc. | Authentication, login verification, magic-link delivery, multi-factor verification, single-sign-on (Google sign-in, Apple sign-in), session management. | Email address; given name; family name; display name; authentication credentials; session tokens; sign-in events; device fingerprints. | stytch.com/privacy | DPA |
| MongoDB, Inc. (Atlas, hosted on Amazon Web Services) | Primary database hosting for Account information, Recipe Data, User Content, Branch and Larder layouts, menus and application metadata. | All Account information; profile data; Recipe Content; User Content; Branch settings; Larder and Sauce Dispenser layouts; menus; application logs. | mongodb.com/legal/privacy-policy | AWS Privacy |
| Microsoft Corporation (Microsoft Azure, including Azure IoT Central) | IoT control plane, device-to-cloud and cloud-to-device messaging for Cooking Robot Hardware, secondary application and storage services. | Hardware identifiers; firmware version; telemetry; sync events; device pairing tokens; control payloads. No User passwords are processed by Azure. | microsoft.com/privacy | Azure DPA |
| Cloudflare, Inc. | Edge network, content delivery, transport-layer security termination, DDoS mitigation, encryption-in-transit and bot management. | IP address; HTTP request metadata; TLS handshake data; coarse geolocation; security event logs. | cloudflare.com/privacypolicy | DPA |
We will publish updates to this list in this Privacy Policy. Where a new Sub-Processor processes personal information for a materially different purpose, we will provide notice in accordance with Section 7 (Changes to this Privacy Policy) before the change takes effect.
3.1 Intra-Hestia Group recipients
In addition to the Sub-Processors listed above, personal information may be shared on a need-to-know basis with other members of the Hestia Group, including Hestia US, acting as a Hestia Group recipient or affiliate-controller for the purposes described in Section 1.7 (Commercial-customer and Hardware-lessee information) and the Introduction. Intra-Hestia Group sharing is governed by binding intra-group data-processing arrangements that apply a Hestia Group-wide standard of data protection no less protective than this Privacy Policy, and (where required) incorporates the standards and applicable laws as stated in Section 6. Hestia Group entities are not "third parties" for the purposes of the CCPA/CPRA "sale" or "sharing" definitions, and no personal information is sold or shared for cross-context behavioural advertising as a result of such intra-group transfers.
We may share your personal information in the following additional circumstances:
with your consent, with such third parties as you direct;
with administrative, judicial, law-enforcement and regulatory authorities of competent jurisdiction in response to a binding order, demand or request, or where disclosure is otherwise required by applicable law;
where we determine, in good faith, that you have violated the Terms of Service or applicable law, and disclosure is reasonably necessary to investigate, prevent or take action against suspected illegal activities, fraud or threats to the safety of any person or property, or to enforce the Terms of Service;
with third-party providers from whom you have requested products or services through the SyncKitchen App, to the extent necessary to provide those products or services;
in connection with a corporate transaction such as a merger, acquisition, reorganisation, financing, sale of assets or insolvency proceeding, on terms that protect your information consistently with this Privacy Policy.
Authorised partners and Sub-Processors will only access your personal information to the extent necessary to perform their duties on our behalf and may not use such information for any other purpose, save as expressly permitted by this Privacy Policy or by applicable law.
We will publicly disclose your personal information only in the following circumstances: (a) with your express consent or based on your active choice (for example, where you elect to publish a recipe or menu publicly within the Services); or (b) where we determine, acting reasonably, that you have violated applicable laws or seriously violated the Terms of Service, and disclosure is necessary in accordance with law or your consent in order to protect the personal and property safety of other Users or members of the public from infringement, including disclosure of relevant violations and the measures we have taken in response. Where permitted by applicable laws, we will provide you with prior notice of such disclosure unless doing so would compromise the purpose of the disclosure or violate a legal obligation.
We use security technologies and procedures consistent with industry standards and reasonably feasible for an organisation of our size and the sensitivity of the data, including encryption-in-transit (TLS 1.2 or higher, terminated at our Cloudflare edge), encryption-at-rest in our MongoDB Atlas cluster, password isolation through Stytch, network segregation between environments, role-based access controls, audit logging and periodic security reviews. However, you acknowledge that, due to inherent technical limitations and the existence of malicious actors, no Internet-facing system can be guaranteed to be 100% secure, and that the systems and communication networks you use to access the Services may be subject to factors beyond our control.
The Internet is not an absolutely secure environment, and we cannot guarantee that means of communication outside the Services (such as email, instant messaging or social-media platforms) are fully encrypted. We recommend that you use a strong, unique password, enable any multi-factor authentication options offered through Stytch, and exercise care in protecting your personal information.
When using the Services, please share your personal information (such as contact details or address) only when necessary, and only with parties whom you trust. If you discover that your personal information — in particular your Account or sign-in credentials — has been compromised or leaked, please contact us immediately via the channels in Section 10 so that we can take appropriate measures.
Please note that information you voluntarily share or make public through the Services (for example, in a publicly published recipe, photograph or comment) may involve your or a third party’s personal information, including in some cases sensitive personal information. Please consider carefully whether to share such information publicly.
In the event of a personal-information security incident, we will inform you in accordance with the requirements of applicable laws (including, in Hong Kong, the recommended practice of the Office of the Privacy Commissioner for Personal Data and, where applicable, the timelines and disclosure requirements of the CCPA/CPRA, GDPR or other applicable laws). Such notification will set out, to the extent then known, the basic facts and possible impact of the incident, the measures we have taken or will take in response, and the steps that you can take to mitigate risk on your own (including suggested precautions and remedies). We will notify you by email, in-App push notification, telephone or other reasonable means and, where individual notification is impracticable, by published announcement. We will also report the incident to relevant regulatory authorities to the extent required by applicable law.
We take reasonable and feasible steps to avoid collecting personal information that is not relevant to the operation of the Services. We retain personal information only for the period necessary to fulfil the purposes set out in this Policy, unless a longer retention period is required or permitted by law. Our retention criteria include:
whether the retention is necessary to complete the transaction or service for which the information was collected, to maintain corresponding records and to respond to your possible inquiries or complaints;
whether the retention is necessary to ensure the safety, integrity and quality of the Services;
whether you have agreed to a longer retention period;
whether any other special agreement (including the Terms of Service) provides for a different retention period (for example, the Recipe Data training licence in Section 4.5 of the Terms of Service which is irrevocable in respect of Recipe Data uploaded prior to termination); and
any retention requirement imposed by applicable law (including tax, accounting, anti-money-laundering and litigation-hold obligations).
After your personal information exceeds the applicable retention period, we will delete it or render it anonymous in accordance with applicable laws, save where deletion from back-up systems is technically deferred, in which case we will isolate the relevant information from any further active processing until secure purging or anonymisation can be completed.
You have the following rights in respect of your personal information. The Hong Kong PDPO confers in particular the rights set out in Sections 5.1 to 5.4 (data-access and correction rights under Data Protection Principle 6 of Schedule 1 to the PDPO). Additional or different rights may apply to you under your local law (including, for California residents, the rights set out in Section 9 of this Policy).
You have the right to inquire about, correct or supplement your information. You can log in to the SyncKitchen App and navigate to [Me] > [Account Manage] (or the equivalent in your version of the App) to query and correct your Account information and Recipe Data. Where a correction cannot be made through the App, please contact us via the channels in Section 10 and we will assist you within the time periods required by applicable law.
You can delete some of your information through the methods listed in Section 5.1. You may also request deletion of personal information in the following circumstances:
our processing of your personal information violates applicable laws or regulations;
we have collected or used your personal information without your required consent;
our handling of your personal information seriously violates the Terms of Service or this Policy;
you no longer use the Services, or you voluntarily close your Account; or
we permanently cease providing the Services to you.
Where we agree to act on your deletion request, we will use reasonable efforts to notify the Sub-Processors and other recipients that have received your personal information from us, and to request those recipients to delete it in a timely manner (unless retention is otherwise required by applicable law, or those recipients have separately obtained your authorisation). Where deletion from back-up or audit-trail systems is technically deferred, we will isolate the relevant information from any further active processing until secure purging or anonymisation can be completed.
Each feature of the Services requires some basic personal information to function. Subject to that, you may grant or withdraw your authorisation by contacting customer service or by changing the relevant settings on your device or within the App. When you withdraw consent, we will no longer process the corresponding personal information for the affected purpose, but withdrawal will not affect the lawfulness of any processing carried out on the basis of your prior authorisation.
You may apply to close your Account through the following methods: (a) by contacting customer service through the channels in Section 10; or (b) by selecting [Me] > [Account Manage] > [Delete Account] (or the equivalent) within the SyncKitchen App. After your Account has been closed, we will cease to provide the Services to you and will, in accordance with applicable laws, delete or anonymise your personal information associated with the Account, save (i) where retention is required by applicable laws, regulatory authorities or legal hold; (ii) where retention is necessary to defend or pursue a legal claim; and (iii) the limited rights granted under the Recipe Data training licence and User Content licence in the Terms of Service that survive Account closure in respect of content uploaded before closure. If anonymisation is technically achievable and anonymised data has already been incorporated into our AI training corpus, such anonymised data will not be deleted as it can no longer be linked to you, consistent with Section 2.2 of this Policy.
In limited features (for example, recipe-recommendation ranking, AI-assisted recipe suggestion or moderation pre-filtering), we may make decisions based wholly or in part on non-human automated decision-making mechanisms, including information systems, algorithms and machine-learning models. If such a decision significantly affects your legitimate rights or interests, you have the right to ask us for an explanation, to express your point of view and to request human review, and we will provide an appeal channel without infringing the trade secrets of the Company or the rights of other Users or the public interest.
For security reasons, we may require you to submit a written request through the channels in Section 10, or to verify your identity (for example, by responding to a verification email sent to the address on your Account, or by providing additional information reasonably necessary to authenticate you).
In principle, we do not charge a fee for reasonable requests. However, for repeated requests that exceed reasonable limits, we may charge a reasonable fee or refuse to act, in each case to the extent permitted by applicable law. We may also reject requests that are not directly related to your identity, are repeated without good reason, would require disproportionate technical effort, would pose risks to the legitimate rights and interests of other persons, or are otherwise impracticable.
We may not be able to respond to your request, or may need to limit our response, in the following circumstances:
where the request relates to national security, national defence or public safety;
where the request relates to public health or significant public interest;
where the request relates to a criminal investigation, prosecution, trial or judgment execution;
where there is sufficient evidence that the requesting individual has acted in subjective bad faith or has abused their rights;
where responding to the request would seriously prejudice the legitimate rights and interests of you, of any other natural person or organisation, or of the Company;
where responding would involve the disclosure of trade secrets.
Hestia Technology Limited is established in the Hong Kong Special Administrative Region of the People’s Republic of China. The Services rely on a globally distributed Sub-Processor stack, and accordingly your personal information may be processed and stored in jurisdictions outside the one in which you reside, including (without limitation) the United States, the European Union, Singapore, Japan and other regions in which our Sub-Processors operate. We will only transfer personal information internationally where: (a) the transfer is necessary for the performance of the Services or for the purposes set out in this Policy; (b) we have implemented appropriate safeguards where required by applicable law including, for transfers covered by the GDPR, the EU Standard Contractual Clauses or UK International Data Transfer Addendum, as applicable. For transfers not subject to such legal requirements, we ensure a level of protection consistent with this Policy through other adequate measures where required by applicable law; (c) the transfer is otherwise permitted under the PDPO and any other data-protection law applicable to you; and (d) the recipient is bound by confidentiality and security obligations consistent with this Policy.
In all such cases we will continue to ensure that your personal information is afforded a level of protection consistent with this Privacy Policy.
Due to changes in laws or regulations, and in order to keep pace with new developments in the Services and the wider digital environment, we may modify this Policy from time to time. Where such modifications cause significant changes to your rights under this Policy, we will, before the modifications take effect, prompt you in a prominent location within the App, send a push notification, send an email to the address associated with your Account or notify you by other reasonable means. Significant changes referred to in this Policy include but are not limited to:
material changes in our service model — such as the purposes of processing personal information, the categories of personal information processed, or the way personal information is used;
material changes in our control or corporate structure — such as a change in data controller resulting from a merger, acquisition or reorganisation;
material changes in the categories of recipients with whom we share, transfer or disclose personal information (including the addition or replacement of a Sub-Processor in Section 3.1 that processes a materially new category of personal information);
material changes in your rights to participate in the processing of personal information and the manner in which those rights are exercised;
material changes in our department or contact details for handling personal-information security and complaints; or
the results of a personal-information security impact assessment indicating a high level of residual risk.
Without prejudice to the foregoing, we will provide at least seven (7) days’ prior notice of any material change before it takes effect. If you continue to use the Services after the effective date of the revised Policy, you will be deemed to have agreed to the revised Policy.
The Services are intended for adult food-industry professionals and adult consumers. The Services are not directed to children under the age of thirteen (13), and we do not knowingly collect personal information from children under that age. Consistent with the United States Children’s Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506 ("COPPA") and equivalent legislation in your jurisdiction, if you are under thirteen (13) you must not register, log in, submit User Content or otherwise use the Services. If you are between thirteen (13) and the age of majority in your jurisdiction, you may use the Services only with the involvement of, and to the extent permitted by, a parent or legal guardian.
If we become aware that we have collected personal information from a child under thirteen (13) without verifiable parental consent, we will delete that information as soon as reasonably practicable. If you believe that we may have collected personal information from a child under thirteen, please contact us via the channels in Section 10.
This Section 9 applies if you are a natural person resident in the State of California, United States ("California Resident"), and supplements the rest of this Privacy Policy. Capitalised terms used in this Section 9 and not otherwise defined have the meanings given to them in the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act, codified at Cal. Civ. Code §§ 1798.100 et seq. ("CCPA/CPRA").
In the twelve (12) months preceding the effective date of this Policy, we have collected, and may continue to collect, the following statutory categories of personal information about California Residents. The same categories may be disclosed to the Sub-Processors identified in Section 3.1 for the business purposes described in Sections 2.1 and 3.1.
| Statutory category (Cal. Civ. Code § 1798.140) | Examples we collect | Disclosed for a business purpose to |
|---|---|---|
| A. Identifiers | Email address, given name, family name, display name, IP address, account identifier, device identifier. | Stytch (auth), MongoDB Atlas/AWS (storage), Microsoft Azure (IoT), Cloudflare (edge). |
| B. Customer records (Cal. Civ. Code § 1798.80(e)) | Name, email address, organisation, role, Branch. | Stytch, MongoDB Atlas/AWS. |
| F. Internet / network activity | Application logs, crash reports, sync events, in-App interaction history. | MongoDB Atlas/AWS, Cloudflare. |
| G. Geolocation (coarse only) | Approximate location derived from IP address. We do not collect precise device geolocation through the App. | Cloudflare. |
| I. Professional / employment-related | Job title, organisation, Branch assignment. | MongoDB Atlas/AWS. |
| K. Inferences | Recipe preferences, frequently used ingredients, cooking-frequency patterns derived from your in-App activity. | MongoDB Atlas/AWS. |
| Sensitive personal information (Cal. Civ. Code § 1798.140(ae)) | Account log-in credentials handled by Stytch (we do not ourselves store passwords). Used solely for authentication and security; we do not use Sensitive Personal Information for any purpose requiring a right to limit under § 1798.121. | Stytch. |
Sources of personal information: directly from you (when you register, log in, submit User Content, configure Hardware or contact us); automatically through your device when you use the Services; and from authentication providers (Google sign-in, Apple sign-in) and Sub-Processors identified in Section 3.1.
Business and commercial purposes: those identified in Section 2.1 of this Policy, including authentication and security, provision and operation of the Services, software upgrades, customer-service and communications, training and refinement of recommendation, search and machine-learning systems, fraud prevention, debugging and audit. We do not use Sensitive Personal Information for any purpose that would, under Cal. Civ. Code § 1798.121, give rise to a right to limit its use or disclosure.
We do not sell your personal information, and we do not share your personal information for cross-context behavioural advertising, in each case within the meaning of the CCPA/CPRA. We have not done so in the twelve (12) months preceding the effective date of this Policy. We do not knowingly sell or share the personal information of consumers under sixteen (16) years of age. Accordingly, no separate "Do Not Sell or Share My Personal Information" link is required, but you may, at any time, exercise the rights set out in Section 9.3 to confirm this position and to obtain or correct your personal information.
Subject to verification of your identity and to the exceptions permitted by the CCPA/CPRA, you have the following rights:
Right to know — to request that we disclose to you the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose for collection, the categories of third parties with whom we share or to whom we disclose your personal information, and the specific pieces of personal information we have collected, in each case during the preceding twelve (12) months (or, on request, the longer period permitted by Cal. Civ. Code § 1798.130(a)(2)(B)).
Right to delete — to request that we delete personal information we have collected from you, subject to the statutory exceptions in Cal. Civ. Code § 1798.105(d) (including completion of the transaction for which the information was collected, security and integrity, debugging, exercise of free speech, internal use reasonably aligned with your expectations, and compliance with legal obligations).
Right to correct — to request that we correct inaccurate personal information that we maintain about you, taking into account the nature of the personal information and the purposes of processing.
Right to opt out of sale or sharing — to direct us not to sell or share your personal information for cross-context behavioural advertising. As stated in Section 9.2, we do not sell or share your personal information; this right is therefore satisfied by default.
Right to limit use of Sensitive Personal Information — to direct us to limit the use or disclosure of Sensitive Personal Information to those uses permitted by Cal. Civ. Code § 1798.121(a). As stated in Section 9.1, we do not use Sensitive Personal Information for any purpose that would trigger this right; this right is therefore satisfied by default.
Right to data portability — to receive a copy of the personal information you have provided to us, in a portable and, to the extent technically feasible, readily usable format. This right is operationalised by the export functionality described in Section 6 of the Terms of Service.
Right to non-discrimination — we will not discriminate against you for exercising any of your CCPA/CPRA rights. Because the SyncKitchen App is supplied free of charge with no in-App monetisation, we do not offer financial incentives in exchange for personal information.
California Residents may exercise their CCPA/CPRA rights by sending a verifiable request to support@hestia.kitchen with the subject line "California Privacy Request", or by writing to us at the postal address set out in Section 10. We will acknowledge receipt of your request within ten (10) business days and substantively respond within forty-five (45) calendar days, with one further forty-five (45)-day extension if reasonably necessary, all as permitted by Cal. Civ. Code § 1798.130. We may need to verify your identity by reference to information already associated with your Account (such as your email address, recent sign-in events through Stytch and a re-authentication link) before we can act on your request.
You may designate an authorised agent to make a request on your behalf in accordance with Cal. Civ. Code § 1798.135(c) and 11 CCR § 7063. We may require the authorised agent to provide written authorisation signed by you and to provide proof of their own identity, and we may require you separately to verify your own identity directly with us before acting on the request.
California Residents may, once per calendar year, request information regarding our disclosure of personal information to third parties for those third parties’ own direct-marketing purposes during the immediately preceding calendar year, in accordance with California Civil Code §§ 1798.83 to 1798.84. We do not disclose personal information to third parties for their own direct-marketing purposes. Requests for further information may be sent to support@hestia.kitchen with the subject line "Shine the Light Request".
We do not offer any "financial incentive" within the meaning of Cal. Civ. Code § 1798.125(b) in exchange for the collection, sale, sharing, retention, deletion or correction of personal information.
We retain personal information about California Residents for the periods set out in Section 4.4. We do not retain personal information for longer than is reasonably necessary for the disclosed purpose, in accordance with Cal. Civ. Code § 1798.100(a)(3).
You can contact us through the following methods, and we will use reasonable efforts to respond to your request within the time periods required by applicable law (and in any event acknowledge receipt within forty-eight (48) hours of the responding Hestia Group entity, with a substantive response provided within the time periods required by applicable law,:
Data-protection contact (including PDPO data-access and CCPA/CPRA requests): support@hestia.kitchen
General legal contact: support@hestia.kitchen
Hardware, lease, RaaS and Commercial-Customer contact: support@hestia.kitchen (Hardware Sale Document matters; routed to the relevant Hestia Group entity, including Hestia Robotics, Inc. for US Hardware Sale Documents)
DMCA / copyright agent: support@hestia.kitchen
Postal address: Hestia Technology Limited, 4/F, Excelsior Building, 68–76 Sha Tsui Road, Tsuen Wan, Hong Kong Special Administrative Region of the People’s Republic of China.
You may also contact us at any time through the in-App "Help" or "Support" channel. If you are not satisfied with our response — in particular, if you consider that our processing of your personal information has harmed your legitimate rights and interests — you may also lodge a complaint with the relevant supervisory authority, including (a) for Hong Kong residents, the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD); (b) for California Residents, the California Privacy Protection Agency or the California Attorney General; (c) for residents of the European Economic Area or the United Kingdom, your local data-protection authority; and (d) for residents of other jurisdictions, the data-protection or consumer-protection authority of competent jurisdiction.
ACKNOWLEDGEMENT
BY CREATING AN ACCOUNT, LOGGING IN, OR CONTINUING TO USE THE SYNCKITCHEN APP OR ANY HESTIA COOKING ROBOT HARDWARE, YOU CONFIRM THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY, INCLUDING THE SUB-PROCESSOR DISCLOSURES IN SECTION 3.1, THE GLOBAL TRANSFER POSITION IN SECTION 6, AND, WHERE APPLICABLE TO YOU, THE CALIFORNIA-RESIDENT RIGHTS IN SECTION 9, AND THAT YOU AGREE TO ITS TERMS.