Security & privacy

Our deployment policy and relevant data protection requirements for customer services. Data flows, suppliers and responsibilities will be agreed for each project before the service goes live.

Data hosting location

Our deployment policy is to keep the primary operational data and backups for customer systems in the region served: Hong Kong for services provided in Hong Kong, and the UK for services provided in the UK. The service agreement will identify the relevant region, hosting location and backup arrangements before deployment.

This policy covers customer systems deployed under a service agreement. This website’s enquiry form, email and security services use Cloudflare and Gmail. The policy should not be read as a promise that all website enquiries or email are processed exclusively in Hong Kong or the UK; see our website privacy notice.

Staff access and retention

Before a service goes live, we will agree access responsibilities with the customer and configure access according to job needs and least privilege. Authorisation, access reviews and withdrawal of access for administrators, support staff and suppliers will form part of the project’s data handling and security requirements.

Retention periods, deletion arrangements and backup retention will be specified according to the processing purpose, applicable law and service agreement, rather than leaving records to be kept indefinitely.

Call recording and transcription notices

Where a deployment requires call recording or speech transcription, we will agree its necessity, applicable lawful basis, purposes, recipients and retention period with the customer before enabling it. Callers will be told about recording or transcription before that collection begins and directed to further privacy information. Appropriate consent will be obtained where the law requires it.

Whether recordings or transcripts are retained depends on the deployment; recording is not a requirement of every AI telephone service. Arrangements for staff follow-up and data enquiries will be explained as part of the service.

Hong Kong and UK data protection requirements

Hong Kong services: processing within the scope of the Personal Data (Privacy) Ordinance (Cap. 486) must meet the Ordinance and its six Data Protection Principles. These cover collection, accuracy and retention, use, security, openness, and access and correction. Outsourced processing also requires consideration of appropriate contractual or other safeguards.

UK services: processing within scope must meet the UK GDPR and the Data Protection Act 2018, as amended by provisions in force, including relevant changes under the Data (Use and Access) Act 2025. PECR requirements must also be considered where applicable to electronic communications, direct marketing or cookies. An appropriate lawful basis, purpose limitation, data minimisation, retention controls, security and individual rights are relevant requirements.

The applicable rules depend on the processing and legal scope, not simply the server location; a project may involve both jurisdictions. The respective responsibilities of the customer and Triple-Two as data user, controller or processor will be agreed according to their actual roles.

Third-party services and international transfers

AI inference, speech recognition, email, technical support or remote access from abroad may involve processing outside the primary storage location. Before deployment or a supplier change, we will check processing regions, subprocessors, retention and any model-training use, and explain and agree the arrangements with the customer.

Cross-border processing must first be assessed against applicable law and safeguards, with the necessary customer authorisation; customer agreement alone does not satisfy statutory transfer requirements. UK restricted transfers need a valid transfer mechanism, such as adequacy regulations or appropriate safeguards with any required risk assessment. Hong Kong data remains subject to applicable use, security and outsourcing requirements; PCPD guidance on contractual safeguards can support that assessment. If the agreed regional or legal requirements cannot be met, we will use a suitable alternative or leave the relevant function disabled.

AI limitations and alternative models

AI does not create, hold, change or cancel bookings, and does not make payments on behalf of callers. Answers depend on approved knowledge and deployment settings. AI can make mistakes: decisions and confirmations require staff review, with handover to people according to the service configuration.

If a model cannot lawfully be provided in Hong Kong or another service region because of applicable export controls, sanctions, a provider’s regional restrictions or licence terms, we will assess and use a legally available alternative rather than bypass those restrictions. A provider’s decision not to serve a region does not necessarily mean that the model is prohibited there by law.

A replacement must be checked for processing location, licensing, security and the language and functional performance needed for the deployment, with changes agreed with the customer. Models may perform differently; identical results are not guaranteed. If no suitable lawful alternative meets the requirements, the affected AI function will remain disabled.

Official guidance

Updated 07/10/2026. This page provides general service policy and legal information; the applicable requirements and contract terms need to be assessed for each project.

For data handling enquiries, email [email protected].

Read the website privacy notice