Hereditarius Privacy Policy

Hereditarius Policy Number: HN006 Effective: 20 July 2026 Review cycle: Yearly

Policy ownership, review and status

Policy owner and ultimate responsibility: This Privacy Policy is owned by, and the Hereditarius Board (the Board of Directors) has ultimate responsibility for the adoption, maintenance, and oversight of this Policy. The Board holds final accountability for ensuring that the Policy is effective and compliant with all relevant data protection legislation.

Review period: The Hereditarius Board shall review this Policy at least annually, or more frequently if deemed necessary by the Board, the Data Protection Officer, or in response to changes in legislation, statutory guidance, or operational need. The Board may determine that a review is required at any time, and such review shall be conducted as soon as reasonably practicable.

Policy status and amendments: This Policy is subject to change at any time at the discretion of the Hereditarius Board. Any amendments, revisions, or updates shall be approved by the Board and take effect immediately upon publication of the revised version. The most recent version of this Policy, as published and maintained by the Hereditarius Board, shall at all times be the operative and binding version. Previous versions are superseded and shall not be relied upon.

Name of PolicyPrivacy Policy
Policy NumberHN006
Scope of PolicyAll Users, Clients, and Individuals Interacting with Hereditarius
Approved byHereditarius Board
Date of Adoption20 July 2026
Review cycleYearly
Applicable LawUK GDPR, Data Protection Act 2018, Hong Kong PDPO
Last Updated: 20 July 2026 DPO: Data Protection Officer Version: 2.0
1. Data Controllers 2. Personal Data We Collect 3. How We Use Your Personal Data 4. Marketing and Communications 5. Data Transfers and Sharing 6. Data Security and Retention 7. Your Data Protection Rights 8. Children's Data 9. Third-Party Links 10. Complaints 11. Contact Us

This Privacy Policy explains how Hereditarius, its subsidiaries, and affiliates (collectively, "Company", "we", "us", or "our") collect, use, and protect your personal data when you visit our website or interact with our services. We are committed to protecting your privacy and complying with the Hong Kong Personal Data (Privacy) Ordinance (PDPO) and the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, where applicable.

This Policy should be read in conjunction with our Cookies Policy. By using our Website or services, you consent to the collection and use of your personal data as described in this Policy.

1. Data Controllers

For the purposes of data protection law:

For all data protection matters, you may contact our Data Protection Officer (DPO) using the details in section 11.

2. Personal Data We Collect

We may collect the following types of personal data:

2.1 Information You Provide Directly

2.2 Information Collected Automatically

When you visit our Website, we may automatically collect:

2.3 Information from Third Parties

We may receive information about you from third parties, including:

3. How We Use Your Personal Data and the Legal Basis

We use your personal data for the following purposes and rely on the following legal bases:

Purpose HK PDPO Basis UK GDPR Basis
To provide and manage our Services Lawful purpose directly related to our functions Performance of a contract with you
To process payments and transactions Lawful purpose Performance of a contract / Legal obligation
To respond to enquiries and provide customer support Lawful purpose Legitimate interests (to respond to you)
To send you service-related communications (e.g., confirmations, updates, security alerts) Lawful purpose Performance of a contract / Legitimate interests
Marketing and business development (including direct marketing) Consent (for direct marketing) Legitimate interests (with opt-out rights)
To improve, personalise, and enhance your experience on our Website Lawful purpose Legitimate interests (to improve our services)
To analyse Website usage and performance Consent required for non-essential cookies Consent required for non-essential cookies (PECR)
To comply with legal obligations, including fraud prevention and regulatory compliance Compliance with PDPO and other HK laws Compliance with UK legal obligations
To protect the security of our systems and prevent unauthorised access Lawful purpose Legitimate interests / Legal obligation

4. Marketing and Communications

We may use your contact information to send you marketing communications about our services, news, and offers that we believe may be of interest to you.

5. Data Transfers and Sharing

5.1 Within the Group

We may share your personal data within our group of companies for internal administrative purposes, to provide our Services, and for business development. This may involve cross-border data transfers between Hong Kong and the United Kingdom.

5.2 To Third-Party Service Providers

We engage trusted third-party processors who help us operate our business and provide our Services. These may include:

We ensure that all third-party processors provide adequate security measures. Under UK GDPR, we require them to comply with GDPR standards. Under HK PDPO, we adopt contractual or other means to ensure they comply with security and retention requirements.

5.3 For Legal Compliance

We may disclose your personal data to law enforcement, regulatory bodies, or other public authorities if required to do so by law, or where such disclosure is necessary to:

5.4 Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business, your personal data may be transferred to the acquiring entity as part of the transaction. You will be notified of any such transfer and any changes to this Policy.

6. Data Security and Retention

6.1 Security Measures

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include:

However, no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.

6.2 Retention Periods

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

Retention periods vary depending on the type of data and the purpose of processing. Examples of retention criteria include:

7. Your Data Protection Rights

Depending on your location, you have the following rights concerning your personal data:

Right HK PDPO UK GDPR
Right to access – request a copy of your personal data. Yes Yes
Right to rectification – request correction of inaccurate or incomplete data. Yes Yes
Right to erasure – request deletion of your data (the "right to be forgotten"). Not provided under PDPO. Yes, in certain circumstances (e.g., where data is no longer needed for its original purpose).
Right to restrict processing – request that we limit how we use your data. Not provided. Yes (e.g., while verifying accuracy or during legal claims).
Right to data portability – request your data in a structured, machine-readable format. Not provided. Yes (for data processed with consent or for contractual purposes).
Right to object – object to processing based on legitimate interests or direct marketing. Only to opt out from direct marketing. Yes, including the right to object to processing based on legitimate interests.
Right to withdraw consent – withdraw your consent where processing is based on consent. Yes Yes
Right not to be subject to automated decision-making – including profiling. Not provided. Yes, in certain circumstances.

How to exercise your rights: To exercise any of these rights, please contact our Data Protection Officer at the details in section 11. We will respond:

We may ask you to verify your identity before processing your request to ensure we do not disclose information to unauthorised persons.

8. Children's Data

Our Website and Services are not directed to children under the age of 13 (or 16 in the UK where applicable). We do not knowingly collect personal data from children under these ages. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us. If we become aware that we have collected personal data from a child without verification of parental consent, we will take steps to delete that information.

9. Third-Party Links

Our Website may contain links to third-party websites, applications, or services that are not operated by us. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services. We encourage you to review the privacy policies of any third-party sites you visit.

10. Complaints

If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the relevant data protection authority:

We would, however, appreciate the opportunity to address your concerns directly before you approach a regulator. Please contact us first using the details in section 11.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact our Data Protection Officer:

Data Protection Officer · Hereditarius Policy owner: Hereditarius Board (ultimate responsibility)