Policy owner and ultimate responsibility: This Privacy Policy is owned by, and the Hereditarius Board (the Board of Directors) has ultimate responsibility for the adoption, maintenance, and oversight of this Policy. The Board holds final accountability for ensuring that the Policy is effective and compliant with all relevant data protection legislation.
Review period: The Hereditarius Board shall review this Policy at least annually, or more frequently if deemed necessary by the Board, the Data Protection Officer, or in response to changes in legislation, statutory guidance, or operational need. The Board may determine that a review is required at any time, and such review shall be conducted as soon as reasonably practicable.
Policy status and amendments: This Policy is subject to change at any time at the discretion of the Hereditarius Board. Any amendments, revisions, or updates shall be approved by the Board and take effect immediately upon publication of the revised version. The most recent version of this Policy, as published and maintained by the Hereditarius Board, shall at all times be the operative and binding version. Previous versions are superseded and shall not be relied upon.
| Name of Policy | Privacy Policy |
|---|---|
| Policy Number | HN006 |
| Scope of Policy | All Users, Clients, and Individuals Interacting with Hereditarius |
| Approved by | Hereditarius Board |
| Date of Adoption | 20 July 2026 |
| Review cycle | Yearly |
| Applicable Law | UK GDPR, Data Protection Act 2018, Hong Kong PDPO |
This Privacy Policy explains how Hereditarius, its subsidiaries, and affiliates (collectively, "Company", "we", "us", or "our") collect, use, and protect your personal data when you visit our website or interact with our services. We are committed to protecting your privacy and complying with the Hong Kong Personal Data (Privacy) Ordinance (PDPO) and the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, where applicable.
This Policy should be read in conjunction with our Cookies Policy. By using our Website or services, you consent to the collection and use of your personal data as described in this Policy.
For the purposes of data protection law:
For all data protection matters, you may contact our Data Protection Officer (DPO) using the details in section 11.
We may collect the following types of personal data:
When you visit our Website, we may automatically collect:
We may receive information about you from third parties, including:
We use your personal data for the following purposes and rely on the following legal bases:
| Purpose | HK PDPO Basis | UK GDPR Basis |
|---|---|---|
| To provide and manage our Services | Lawful purpose directly related to our functions | Performance of a contract with you |
| To process payments and transactions | Lawful purpose | Performance of a contract / Legal obligation |
| To respond to enquiries and provide customer support | Lawful purpose | Legitimate interests (to respond to you) |
| To send you service-related communications (e.g., confirmations, updates, security alerts) | Lawful purpose | Performance of a contract / Legitimate interests |
| Marketing and business development (including direct marketing) | Consent (for direct marketing) | Legitimate interests (with opt-out rights) |
| To improve, personalise, and enhance your experience on our Website | Lawful purpose | Legitimate interests (to improve our services) |
| To analyse Website usage and performance | Consent required for non-essential cookies | Consent required for non-essential cookies (PECR) |
| To comply with legal obligations, including fraud prevention and regulatory compliance | Compliance with PDPO and other HK laws | Compliance with UK legal obligations |
| To protect the security of our systems and prevent unauthorised access | Lawful purpose | Legitimate interests / Legal obligation |
We may use your contact information to send you marketing communications about our services, news, and offers that we believe may be of interest to you.
We may share your personal data within our group of companies for internal administrative purposes, to provide our Services, and for business development. This may involve cross-border data transfers between Hong Kong and the United Kingdom.
We engage trusted third-party processors who help us operate our business and provide our Services. These may include:
We ensure that all third-party processors provide adequate security measures. Under UK GDPR, we require them to comply with GDPR standards. Under HK PDPO, we adopt contractual or other means to ensure they comply with security and retention requirements.
We may disclose your personal data to law enforcement, regulatory bodies, or other public authorities if required to do so by law, or where such disclosure is necessary to:
In the event of a merger, acquisition, or sale of all or part of our business, your personal data may be transferred to the acquiring entity as part of the transaction. You will be notified of any such transfer and any changes to this Policy.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include:
However, no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
Retention periods vary depending on the type of data and the purpose of processing. Examples of retention criteria include:
Depending on your location, you have the following rights concerning your personal data:
| Right | HK PDPO | UK GDPR |
|---|---|---|
| Right to access – request a copy of your personal data. | Yes | Yes |
| Right to rectification – request correction of inaccurate or incomplete data. | Yes | Yes |
| Right to erasure – request deletion of your data (the "right to be forgotten"). | Not provided under PDPO. | Yes, in certain circumstances (e.g., where data is no longer needed for its original purpose). |
| Right to restrict processing – request that we limit how we use your data. | Not provided. | Yes (e.g., while verifying accuracy or during legal claims). |
| Right to data portability – request your data in a structured, machine-readable format. | Not provided. | Yes (for data processed with consent or for contractual purposes). |
| Right to object – object to processing based on legitimate interests or direct marketing. | Only to opt out from direct marketing. | Yes, including the right to object to processing based on legitimate interests. |
| Right to withdraw consent – withdraw your consent where processing is based on consent. | Yes | Yes |
| Right not to be subject to automated decision-making – including profiling. | Not provided. | Yes, in certain circumstances. |
How to exercise your rights: To exercise any of these rights, please contact our Data Protection Officer at the details in section 11. We will respond:
We may ask you to verify your identity before processing your request to ensure we do not disclose information to unauthorised persons.
Our Website and Services are not directed to children under the age of 13 (or 16 in the UK where applicable). We do not knowingly collect personal data from children under these ages. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us. If we become aware that we have collected personal data from a child without verification of parental consent, we will take steps to delete that information.
Our Website may contain links to third-party websites, applications, or services that are not operated by us. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services. We encourage you to review the privacy policies of any third-party sites you visit.
If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the relevant data protection authority:
We would, however, appreciate the opportunity to address your concerns directly before you approach a regulator. Please contact us first using the details in section 11.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact our Data Protection Officer: