VHIS Hong Kong
Privacy

What we collect, and why

Last updated 24 September 2026

This service is built to need as little about you as possible. There is no account, no sign-in and no advertising. What follows is exactly what is collected, by which part of the service, and why.

Who we are

vhishongkong.com and the MCP server at mcp.vhishongkong.com are operated by Instly Technologies Co., Ltd. (Thailand, registration 0105567135903). Contact: mo@instlytechnologies.com.

Using the website

Quoting

To price plans the site uses the details you give Nomi: age, sex as the premium schedules rate it, whether you smoke, room preference and deductible preference. These are used to calculate premiums and are not, on their own, capable of identifying you. They are not stored against a name unless you later ask to be contacted.

Nomi, the assistant

Your messages to Nomi are sent to Google's Gemini model on Vertex AI to generate a reply. Do not type medical details, identity document numbers or payment details into the chat. Nomi does not need them and is built not to ask.

Browser storage

The site keeps a few things in your own browser using local storage: your shortlist, whether the assistant panel is open, and whether you have seen the swipe explainer. This stays on your device, is not sent to us and is not shared with anyone. There are no advertising cookies and no third-party analytics.

Asking to speak to an adviser

If, and only if, you ask to be contacted or to have your shortlist sent to you, we store: your name, the phone number or email address you gave, which you preferred to be contacted on, the plans you saved, the quote details above, and a reference number. This is passed to a licensed adviser so they can contact you.

Health details are never stored on an enquiry. If you mention a condition in a note, it is removed automatically before the enquiry is saved, and the adviser asks you directly instead.

If you asked for follow-up messages, we keep the thread of those messages so later ones make sense. Reply STOP, or unsubscribe, and it stops.

Using the MCP server

Agents connect to mcp.vhishongkong.com without signing in. For each call we log the date and time, which tool was called, the arguments it was given (an age, a plan certification number, an insurer name and the like), the calling IP address, the client's user agent string, how long the call took and whether it succeeded.

This exists to enforce the rate limit, to spot abuse, and to know which tools people actually use. The open tier's tools are read-only and carry no personal data. The only tool that handles personal data is create_lead, which needs no key but only runs when a person has given a name and a way to reach them and asked to be contacted, and it follows the adviser section above.

If you request an API key, we store the name, work email, company and description of intended use that you supply, so the key can be issued, its quota managed and its holder contacted. The key itself is stored only as a hash and cannot be recovered from us.

Who else sees it

Nothing is sold, and nothing is shared with insurers for marketing.

How long it is kept

Enquiries are kept while the enquiry is open and afterwards as a record of the introduction, until you ask us to delete them. MCP usage records are kept while the service runs, for the operational reasons above. Ask and we will delete what relates to you.

Your choices

Email mo@instlytechnologies.com to see what is held about you, to correct it, or to have it deleted. Clearing your browser data removes everything the site stored locally.

Children

This service is for adults arranging their own or their family's cover and is not directed at anyone under 18.

Changes

If this policy changes, the date above changes with it.

Instly Technologies Co., Ltd., Bangkok, Thailand (registration 0105567135903). Questions: mo@instlytechnologies.com. vhishongkong.com · Privacy · Terms · Support · MCP server