Privacy Policy
Important Notice
Please read this privacy policy carefully to understand how we handle your personal data.
Effective and last updated: 29 July 2026
1. Introduction
We respect your privacy and are committed to protecting your personal data. This privacy policy is prepared with reference to the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (PDPO) and, where applicable, the European Union General Data Protection Regulation (GDPR). Hong Kong Business Services Centre Limited is the data user under the PDPO and, where GDPR applies, the controller of the personal data described in this policy.
2. Types of Data Collected
We may collect, use, store, and transfer different kinds of personal data about you depending on the service, enquiry, or secure invitation link involved:
- Identity and contact data, such as name, company name, role, email address, telephone number, correspondence address, and billing or service contact details.
- Client verification and KYC data, such as identity documents, HKID or passport numbers, address proof, birth place, source of funds, source of wealth, business background, uploaded files, and verification status.
- Company formation and corporate service data, such as proposed company names, directors, shareholders, beneficial owners, shareholdings, residential or correspondence addresses, business details, declarations, and signatures.
- Financial and payment data, such as bank account details, payment references, invoices, service fees, transaction records, and payment provider records.
- Service and transaction data, such as services requested or purchased, statutory filing information, document support records, cloud storage records, and correspondence relating to your matter.
- Technical, security, and usage data, such as IP address, user agent, browser and device information, cookies, submission timestamps, Turnstile verification results, and analytics or site usage information.
- Communications data, such as contact form messages, emails, calls, WhatsApp or other messages, meeting notes, and support requests.
- AI chat data, where you choose to use the optional AI chat feature, including the text you submit, selected language, technical request data, and security verification results.
- Google OAuth data when you choose Google sign-in. We access your Google account name, email address, profile image and provider account identifier, and process OAuth tokens and authorization metadata needed for sign-in and account linking. We use and store this data only to create, link, secure and authenticate your Client Portal account; we do not request Google Drive, Calendar or other Google service content, sell this data, or disclose it except to providers needed to operate, secure and support the portal as described in section 5. We may also collect other data you or an authorised contact provide in connection with our services.
3. How We Collect Your Data
We use different methods to collect personal data from and about you, including:
- Direct interactions with you, such as when you complete a website form, contact us by email, phone, WhatsApp or other channels, request a quotation, instruct us, or provide documents.
- Secure invitation-only links sent to a client or authorised contact for KYC uploads, onboarding, company formation, or other client-specific workflows.
- Automated technologies or interactions, such as cookies, server logs, analytics tools, security verification tools, browser/device information, IP address, user agent, and submission timestamps.
- Third parties or public sources where appropriate, such as authorised representatives, professional advisers, banks, brokers, registries, regulators, public registers, or service providers involved in your matter.
4. How We Use Your Data
We use personal data only for lawful, service-related, compliance, security, and administrative purposes, including:
- To respond to enquiries, prepare quotations, communicate with you, and provide the services you request.
- To perform or take steps to enter into a contract with you or the client you represent.
- To carry out KYC, client due diligence, anti-money laundering, company formation, company secretarial, accounting, tax, audit arrangement, cloud storage, document support, and other service workflows.
- To comply with legal, regulatory, accounting, tax, reporting, record-keeping, sanctions, fraud prevention, or law enforcement requirements.
- To maintain website, AI chat, account, document, and system security; prevent abuse; verify legitimate access; and troubleshoot technical issues.
- To manage our business, keep internal records, improve website and service operations, and send service-related updates or direct marketing only where permitted by law.
5. Disclosure of Your Data
We may have to share your personal data with third parties, including:
- HKBSCL directors, employees, contractors, agents, and authorised staff who need the data for service, support, compliance, or security purposes.
- Providers supporting our email, database, analytics, security, payment, AI, communications and other workflows, which may include Microsoft, Google, Amazon Web Services, MongoDB, Cloudflare and relevant hosting or service providers. These supporting providers do not host the agreed Cloud Document Storage archive unless data is exported, emailed or shared through the relevant workflow.
- Professional advisers and service partners such as lawyers, tax advisers, accounting advisers, insurers, banks, brokers, registered agents, and independent auditors for audit arrangement or audit coordination.
- Government departments, registries, tax authorities, regulators, law enforcement bodies, courts, or other authorities where required or permitted by law.
- Client companies, authorised contacts, directors, shareholders, beneficial owners, signatories, or representatives connected with the relevant matter.
- Other parties where you instruct us, authorise disclosure, or where disclosure is reasonably necessary for the relevant service.
6. Data Security
We use administrative, technical, and physical safeguards designed to protect personal data against accidental loss, unauthorised access, alteration, disclosure, or misuse. These safeguards may include access controls, secure invitation-only links, encryption or provider security controls where appropriate, file validation, staff confidentiality obligations, and limits on access to people and providers who need the data for authorised purposes. No internet transmission or storage system is completely secure, but we work to keep protections proportionate to the sensitivity of the data.
7. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected and for applicable legal, accounting, tax, compliance, regulatory, audit-arrangement, dispute and security requirements. KYC, client due diligence, transaction, company administration, accounting, tax and statutory records may need to be retained for at least 5 years after the end of the business relationship or relevant transaction where applicable rules require or permit it. The live Cloud Document Storage archive and client access are separate from compliance copies: access is not guaranteed after the paid service term, while limited copies may be retained where legally required. Physical ordinary mail may be destroyed after the stated 30-day holding period, but agreed scans, handling logs and legally required records may follow a different retention period. When data is no longer needed, we delete, anonymise or restrict it where reasonably practicable.
8. Your Legal Rights
Depending on the privacy law that applies to you, your rights in relation to personal data may include:
- Under the PDPO, request access to personal data we hold about you.
- Under the PDPO, request correction of inaccurate personal data.
- Where GDPR applies, request erasure of your personal data in applicable circumstances.
- Where GDPR applies, object to processing based on applicable grounds.
- Where GDPR applies, request restriction of processing.
- Where GDPR applies, request transfer or portability of personal data.
- Withdraw consent where processing is based on consent, without affecting prior lawful processing.
- Opt out of direct marketing communications where applicable.
- Raise a privacy concern with us, the Hong Kong Privacy Commissioner for Personal Data, or an EU/EEA supervisory authority where applicable.
To exercise access, correction, or other privacy rights, contact our Privacy/Data Protection Contact at info@HKBSCL.com or Unit 744, 7/F, Star House, 3 Salisbury Road, Tsim Sha Tsui, Kowloon, Hong Kong. Please mark the request as a personal data access or correction request. We may verify your identity and may charge any fee permitted by applicable law before handling the request.
9. Third-Party Links
This website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.
10. Data Transfer
HKBSCL's business operations are based in Hong Kong. We use approved cloud infrastructure providers, including Amazon Web Services (AWS), to store and process service data. For new online formation submissions completed through this workflow, HKBSCL creates a server-generated official formation evidence PDF containing the complete submitted form, signature and accepted terms snapshot. The exact PDF object version is stored in the relevant client's Amazon S3 Documents/company_secretary area with AWS KMS encryption and S3 Versioning; HKBSCL records its exact VersionId and SHA-256 hash and makes the document available to authenticated authorised clients. These controls provide verifiable evidence and an audit trail, not immutable storage: authorised users or systems with sufficient AWS permissions may delete an object version, upload a replacement or change which version is current. The MongoDB/controlled-database record is currently retained as an operational copy and index for ERP compatibility, while the PDF is the formal archived evidence. This statement does not mean that historical submissions or records created through other systems have been migrated. Other client documents within scope may also be stored in the relevant client's Documents area. Cloud, email, database, security, analytics and communications systems may store, back up, replicate or process encrypted or access-controlled data in Hong Kong, elsewhere in the Asia-Pacific region or other locations according to their service architecture and configuration. We do not promise that all data is stored only in Hong Kong unless this is confirmed in writing for the relevant service. Where a cross-border transfer occurs, we use practical safeguards appropriate to the data and service; where GDPR applies, we refer to applicable transfer safeguards.
11. Updates to Our Privacy Policy
We may update this policy from time to time. We will post the current version and effective date on this page. Where a change materially affects an active client service or how we use personal data, we will normally give at least 30 calendar days' notice by email before it takes effect. A shorter period may apply where a legal, regulatory, security or urgent operational requirement makes advance notice impracticable; in that case, we will notify affected clients as soon as reasonably practicable.
12. Contact Information
For privacy questions, data access or correction requests, or concerns about this policy, please contact our Privacy/Data Protection Contact at info@HKBSCL.com or Unit 744, 7/F, Star House, 3 Salisbury Road, Tsim Sha Tsui, Kowloon, Hong Kong.
13. Personal Information Collection Statements
Some website forms and secure client links include a short collection notice at the point where data is collected. Those notices should be read together with this policy.
- Contact and enquiry forms are voluntary. If you do not provide the requested contact details and message, we may be unable to respond.
- Secure KYC upload and company formation links are sent only to specific clients or authorised contacts. Required fields and documents are generally necessary for onboarding, client due diligence, service delivery, statutory records, and compliance.
- If required KYC, formation, identity, address, source-of-funds, signature, or business information is not provided, HKBSCL may be unable to continue onboarding, perform the requested service, or satisfy legal or regulatory requirements.
- Each collection notice identifies the main purposes, whether provision is voluntary or required, likely transferee classes, and how to contact our Privacy/Data Protection Contact at info@HKBSCL.com or Unit 744, 7/F, Star House, 3 Salisbury Road, Tsim Sha Tsui, Kowloon, Hong Kong for access or correction.
14. AI Chat and Automated Security Verification
The AI chat is an optional website feature for general HKBSCL service enquiries. Please do not submit sensitive personal data through AI chat.
- Submission is voluntary. If you type a message, we use it to generate an answer to your enquiry and to maintain the security and fair use of the AI chat feature.
- AI chat messages may include the text you submit, your selected language, technical request data, and security verification results.
- Messages are sent to our configured AI service provider for processing. Provider-side retention, logging, and training controls depend on the active provider account and settings.
- HKBSCL does not store AI chat transcripts in this website database and does not use AI chat messages to train HKBSCL models.
- Cloudflare Turnstile is used to help distinguish legitimate users from automated abuse before AI chat is available.
- After successful verification, the website sets a signed HTTP-only AI verification cookie for up to 2 hours so you do not need to repeat the same security check during that period.
