Back to Home

Privacy Policy

Xinhuayuan Co., Limited · Rm 5, 8/F, Mega Cube, 8 Wang Kwong Rd, Kowloon Bay, Hong Kong (HK)

Contents

  • 1. Introduction
  • 2. Who We Are
  • 3. Scope of This Policy
  • 4. Information We Collect
  • 5. How We Collect Information
  • 6. Why We Use Information
  • 7. Our Legal Basis for Processing
  • 8. Client Project Data
  • 9. Cookies and Similar Technologies
  • 10. When We Share Information
  • 11. Service Providers and Processors
  • 12. International Transfers
  • 13. How Long We Keep Information
  • 14. How We Protect Information
  • 15. Your Privacy Rights
  • 16. Privacy for Children
  • 17. Direct Marketing and Choices
  • 18. Third Party Links and Services
  • 19. Automated Decisions and Profiling
  • 20. Data Breach Response
  • 21. Changes to This Policy
  • 22. How to Contact Us

1. Introduction

This Privacy Policy explains how Xinhuayuan Co., Limited collects, uses, stores, shares and protects personal information when you visit our website, contact our team, or engage us for software development and systems integration work. The policy is maintained by the developer team known as XHY DEV TEAM, which operates the engineering and support functions of the company. We have written this document in plain language so that a reader without a legal background can understand what happens to personal information and what choices remain available.

Privacy matters to a software studio for a simple reason. We build systems that hold other people information, and we cannot reasonably ask clients to trust our engineering with their data unless we hold ourselves to the same standard. This policy therefore describes not only how we handle the personal information of visitors and prospective clients, but also how we approach the project data we process on behalf of the clients who hire us. The two are related but distinct, and they are treated separately below.

By using our website or contacting us, you acknowledge that you have read this policy. If you do not agree with the practices it describes, please do not submit personal information to us. You are always welcome to raise a question before providing any information at all.

2. Who We Are

Xinhuayuan Co., Limited is a company registered in Hong Kong that provides computer systems design and related professional services. Our registered and operating address is Rm 5, 8/F, Mega Cube, 8 Wang Kwong Rd, Kowloon Bay, Hong Kong (HK). We build web platforms, mobile applications, systems integrations, e-commerce solutions and related services for small and mid-size clients.

For the purposes of applicable data protection law, Xinhuayuan Co., Limited is the controller of personal information that we collect through this website and through our own business communications. Where we process personal information that belongs to a client system, we act as a processor on behalf of that client, and the client remains the controller of that data. Section eight of this policy explains that distinction in more detail.

Our contact point for all privacy matters is the email address hello@xinhuayuan.lat and the telephone number +85269296834. You can also write to us at the postal address above. We ask that privacy requests be marked clearly so that they reach the right person without delay.

3. Scope of This Policy

This policy applies to personal information collected through the website at xinhuayuan.lat, through email and telephone contact with our team, through proposals and contracts, and through the ordinary course of delivering professional services. It also applies to information we receive from business partners and suppliers in connection with our operations.

This policy does not apply to third party websites that we may link to, nor to software that we build for a client where the client has its own separate privacy notice. When we build a custom system, the way that system handles end user data is governed by the client privacy notice and by our data processing agreement with that client, not by this document. We encourage you to read the privacy notice of any client system you use.

4. Information We Collect

We aim to collect only what we genuinely need. The categories of personal information we may collect include the following.

  • Identity details such as your name, the organisation you represent and your role.
  • Contact details such as your email address, telephone number and postal address.
  • Correspondence content, including the messages you send through our contact form, by email or by telephone.
  • Project information that you choose to share with us when describing a problem or a requirement.
  • Billing and payment details where a contract is in place, limited to what is needed to invoice and collect payment.
  • Technical information such as the pages you visit on our website, the approximate region from which you connect and the device or browser type you use.

We do not seek sensitive categories of personal information, such as health data, biometric data, political opinions or religious beliefs. If you send such information to us unsolicited, we will take reasonable steps to delete it unless we are legally required to keep it. Please do not send sensitive information through the general contact form.

5. How We Collect Information

We collect personal information in several ways. You provide most of it directly when you complete our contact form, send us an email, place a telephone call, sign a proposal or participate in a project review. We collect some technical information automatically when your browser requests a page from our website, through ordinary server logging and any analytics tools we deploy.

We may also receive information about you from a colleague at your organisation, from a referral partner, or from a public source such as a company website. When we receive your information from someone else, we will use it only for the purpose for which it was shared with us, and we will tell you about it within a reasonable period if we plan to keep it.

6. Why We Use Information

We use personal information for specific and limited purposes. The principal purposes are to respond to your enquiries, to prepare proposals and estimates, to deliver and support the services you engage us for, to manage our business relationships, to issue invoices and collect payment, to improve our website and service quality, to maintain security, and to comply with legal and accounting obligations.

We also use information to keep records of decisions made during a project, because written records reduce the risk of misunderstanding and help us support a system months or years after release. We may use aggregated and de-identified information to understand which pages of our website are most useful, but we do not attempt to re-identify individuals from such data.

7. Our Legal Basis for Processing

Where data protection law requires a legal basis for processing, we rely on one or more of the following. We process information to perform a contract with you or to take steps at your request before entering a contract. We process information on the basis of our legitimate interests in operating and improving our business, provided those interests are not overridden by your rights. We process information with your consent where consent is the appropriate basis, for example for optional marketing messages. We also process information to comply with legal obligations, such as tax and accounting rules.

You may withdraw consent at any time where consent is the basis for processing. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and it does not prevent us from processing information on another lawful basis where one applies.

8. Client Project Data

Much of our work involves building systems that process personal information on behalf of a client. In those situations the client is the controller and Xinhuayuan Co., Limited is the processor. We process client project data only on the documented instructions of the client, and only for the purposes set out in the applicable contract. We do not use client production data for our own marketing, we do not sell it, and we do not mine it to train general models.

Where practical, we work with realistic but synthetic test data rather than live personal information. When access to live data is unavoidable for diagnosing a fault, we limit that access to named engineers, log the access, and remove local copies as soon as the work is finished. On the termination of a contract we return or delete client data according to the terms agreed with the client and our legal retention obligations.

9. Cookies and Similar Technologies

Our website may use a small number of cookies and similar technologies to keep the site working and to understand how it is used. Strictly necessary cookies support basic functions such as security and session handling. Analytics cookies, where used, help us see which pages are visited and how visitors move through the site. We do not use cookies to build advertising profiles of visitors.

You can control cookies through your browser settings. Blocking certain cookies may affect how the website behaves, but the core content of the site remains readable. Where required by law, we will ask for your consent before setting non-essential cookies, and you may refuse or withdraw that consent without losing access to the site.

10. When We Share Information

We do not sell personal information. We share it only in the limited circumstances described in this policy. We may share information with service providers who help us operate our business, such as hosting providers, email providers and accounting services, and we require those providers to protect the information and to use it only for the agreed purpose. We may share information with professional advisers where necessary to obtain legal, tax or accounting advice.

We may also share information where we are required to do so by law, by a court order, or by a regulator with lawful authority. If we are ever involved in a merger, acquisition or transfer of business assets, we will handle personal information in accordance with applicable law and will inform affected individuals where required. We do not share information with advertisers or data brokers.

11. Service Providers and Processors

We rely on a small group of third party service providers to run our business. These may include providers of cloud hosting, domain services, email delivery, source code hosting, customer relationship management and accounting software. Each provider is selected with care, and each is bound by a written agreement that imposes obligations of confidentiality, security and limited use.

Where a provider acts as our processor, we remain responsible for the personal information under our control. We review our provider arrangements periodically and remove providers that no longer meet our standards. Where a provider acts as an independent controller, its own privacy notice governs its handling of the information, and we encourage you to review it.

12. International Transfers

Xinhuayuan Co., Limited is based in Hong Kong, and our primary operations are conducted there. Some of our service providers may store or process information in other jurisdictions. When we transfer personal information across borders, we take steps to ensure that the information continues to receive an appropriate level of protection, using recognised safeguards such as contractual clauses, security assessments and vendor due diligence.

If you are located in a jurisdiction with specific transfer rules, you may contact us to learn more about the safeguards that apply to your information. We will answer reasonable questions about our transfer practices and, where possible, about the locations in which information is held.

13. How Long We Keep Information

We keep personal information only for as long as it is needed for the purposes described in this policy, or for as long as the law requires. Enquiries that do not become projects are normally kept for a limited period and then deleted. Contract and billing records are kept for the period required by tax and accounting rules. Project documentation that does not contain personal information may be kept for longer so that we can support a system and maintain an accurate history of its design.

When information is no longer needed, we delete it or render it anonymous. Where deletion is not immediately possible, for example because information is held in a backup archive, we isolate it from ordinary use and delete it when the archive is next refreshed.

14. How We Protect Information

We take the security of personal information seriously. We use a combination of technical and organisational measures, including access controls, encryption in transit, least privilege accounts, managed devices, security patching and regular review of our practices. Access to personal information is limited to team members who need it for a legitimate business purpose.

No system can be guaranteed completely secure, and no amount of care can eliminate every risk. We therefore design our work to limit the damage that any single failure could cause, and we review incidents carefully when they occur. If you believe that your information has been handled insecurely, please contact us immediately so that we can investigate.

15. Your Privacy Rights

Depending on where you live, you may have a range of rights over your personal information. These can include the right to know what information we hold about you, to request a copy, to ask for corrections, to request deletion, to restrict or object to certain processing, and to request portability of information you provided to us. You may also have the right not to be subject to a decision based solely on automated processing that produces a legal or similarly significant effect.

To exercise any of these rights, contact us using the details in section twenty two. We will respond within the timeframe required by applicable law. We may need to verify your identity before acting, and we may decline a request where the law permits, for example where we must retain information to comply with a legal obligation. You also have the right to lodge a complaint with your local data protection authority.

16. Privacy for Children

Our website and services are directed at businesses and professional users, not at children. We do not knowingly collect personal information from children. If a system we build is intended to be used by children, the client is responsible for obtaining any consents required and for providing an appropriate notice to parents or guardians. Privacy for Children is a matter that we address in the design of such systems, and we expect clients to raise it with us at the drawing stage.

If you believe that a child has provided personal information to us through our website without appropriate consent, please contact us and we will take reasonable steps to remove it.

17. Direct Marketing and Choices

We send marketing messages only where we have a lawful basis to do so. Where we rely on consent, you can withdraw it at any time by using the unsubscribe link in a message or by contacting us directly. Even if you opt out of marketing, we may still send you service messages that are necessary for a contract, such as invoices, security notices or important changes to a system we support.

We keep marketing lists separate from project records so that an opt out affects only the marketing channel and does not remove your information from the records we need to run our business and meet our legal obligations.

18. Third Party Links and Services

Our website may contain links to third party sites and may embed content or services from other providers. We do not control those sites, and this policy does not apply to them. When you follow a link away from our site, the privacy notice of the destination applies. We encourage you to review the privacy notices of any external services you use.

Where we integrate a third party service into a client system, we document the data that crosses the boundary and the terms under which it is shared. That documentation forms part of the integration record described in our services, and it is available to the client as part of the handover.

19. Automated Decisions and Profiling

We do not make decisions about individuals based solely on automated processing where that decision would produce a legal or similarly significant effect. We may use simple automation to route an enquiry to the right team member or to filter unwanted messages, but a person reviews any decision that materially affects you. Where a client system that we build includes automated decisions, we work with the client to document those decisions, to explain them to affected users and to provide a route for human review where the law requires it.

20. Data Breach Response

We maintain a response process for incidents that affect personal information. When an incident is detected, we take steps to contain it, assess its scope and impact, and restore normal operations. Where the law requires, we notify affected individuals and the relevant authority without undue delay. We also review each incident after the fact to identify the cause and to improve our safeguards.

Where an incident affects a client system that we operate on behalf of a client, we notify the client promptly so that the client can meet its own notification obligations as the controller of that data.

21. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, in technology or in the law. When we make a material change, we will update the effective date and, where appropriate, provide a more prominent notice on the website. We encourage you to review this page periodically so that you remain aware of how we protect personal information.

The version of this policy published on this page is the version that applies. If a change reduces your rights in a significant way, we will take reasonable steps to bring it to your attention before it takes effect.

22. How to Contact Us

If you have a question about this policy, a request about your personal information, or a concern about how your information has been handled, please contact us. The privacy contact is Xinhuayuan Co., Limited, Rm 5, 8/F, Mega Cube, 8 Wang Kwong Rd, Kowloon Bay, Hong Kong (HK). You can reach us by email at hello@xinhuayuan.lat or by telephone at +85269296834.

We take every privacy question seriously and will work with you to resolve it. If you are not satisfied with our response, you have the right to contact the data protection authority in your jurisdiction. Thank you for taking the time to read this policy.

Xinhuayuan Co., Limited · Rm 5, 8/F, Mega Cube, 8 Wang Kwong Rd, Kowloon Bay, Hong Kong (HK)

hello@xinhuayuan.lat · +85269296834

Back to Home Privacy Policy Terms of Service