1. Scope of This Policy

This Privacy Policy governs the collection and use of personal information by BALU ECOMMERCE LIMITED in connection with this website and the professional services we provide. It covers visitors to our website, prospective clients who submit an enquiry, existing clients, suppliers, and any other individual whose personal information reaches our practice.

The policy does not apply to websites operated by other organisations, even where those websites are linked from our pages. It also does not replace any separate agreement that governs a specific client engagement. Where a written services agreement contains privacy terms that differ from this policy, the terms of that agreement take precedence for the engagement concerned.

This policy also describes the choices that are available to you and the steps you can take if you wish to access, correct, or remove information that we hold. We have written it in plain language so that it can be read without legal training, while still covering the detail that a professional practice is expected to provide.

By using this website or contacting our practice, you acknowledge that you have read this Privacy Policy. If you do not agree with the handling described here, please refrain from submitting personal information through our channels.

2. Information We Collect

We collect information in several ordinary ways. The amount and type of information depends on how you interact with our practice.

Information you provide directly

When you complete our contact form, send an email, or speak with us by telephone, you may provide your name, email address, telephone number, organisation, role, and the content of your message. If you engage us for services, you may also provide billing details, contracting information, and the technical documentation needed to perform the work.

Information collected automatically

When you visit this website, our hosting infrastructure may automatically record technical information such as the internet protocol address from which you connect, the browser and device type you use, the pages you request, and the date and time of each request. This information is used for security, reliability, and aggregate usage analysis.

Information arising from services

In the course of delivering systems design, integration, cloud engineering, operations, data, and security services, we may encounter technical records that belong to a client. Those records are handled under the terms of the relevant engagement and are addressed separately in the Client System Data section of this policy.

We do not ask for information that we do not need. Where a field on our contact form is optional, you may leave it blank. Where a piece of information would help us respond more precisely, we will explain why we are asking so that you can decide whether to provide it.

3. How We Use Information

We use personal information for purposes that are necessary to run our practice and to deliver the services a client requests. Those purposes include responding to enquiries, preparing proposals, performing contracted work, issuing invoices, maintaining business records, and meeting legal obligations.

We also use information to improve the reliability and security of this website, to understand which pages are useful to visitors in aggregate, and to detect and prevent misuse. Where you have asked to receive updates about our services, we use your contact details to send those updates until you ask us to stop.

We do not use personal information for automated decision making that produces legal effects, and we do not build advertising profiles from the information collected through this website.

4. Legal Bases for Processing

Where applicable law requires a legal basis for processing personal information, we rely on one or more of the following.

We process information to perform a contract when you engage our services or when we take steps at your request before entering a contract. We process information based on our legitimate interests in operating a professional practice, maintaining security, and communicating with clients and prospects, provided those interests are not overridden by your rights.

We process information to comply with legal obligations, including tax, accounting, and record keeping requirements. Where we rely on consent, such as for optional marketing messages, you may withdraw that consent at any time by contacting us. Withdrawing consent does not affect processing that occurred before the withdrawal, nor does it affect processing based on other lawful bases.

5. Cookies and Similar Technologies

This website is designed to be lightweight and does not use advertising cookies or cross site tracking cookies. Any cookies that may be set are limited to those needed for basic site functionality, security, and the protection of forms against abuse.

If our use of cookies changes, we will update this policy and, where required, present an appropriate notice when you visit. You can control or delete cookies through the settings of your browser. Disabling certain cookies may affect the operation of some parts of the website, but it will not prevent you from reading our public pages or contacting our practice by email.

6. Information Sharing

We do not sell personal information. We do not rent personal information. We do not trade personal information for commercial advantage. We share information only in the limited circumstances described in this policy and only to the extent necessary.

We may share information with professional advisers such as accountants and legal counsel where necessary to run the practice. We may disclose information where required by law, by a court order, or by a regulator with lawful authority. We may also disclose information where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of our practice, our clients, or the public.

If the practice is reorganised, merged, or transferred, information may be transferred as part of that transaction, subject to this policy or to a policy that provides equivalent protection.

7. Service Providers

We use a small number of service providers to operate our website and business. These may include website hosting, email delivery, domain registration, and accounting platforms. Each provider receives only the information necessary to perform its function and is expected to protect that information.

Where a provider processes personal information on our behalf, we seek contractual commitments that the information will be used only for the agreed purpose and will be protected with reasonable safeguards. We review our providers periodically and replace any provider that does not meet the standard we require.

8. International Transfers

BALU ECOMMERCE LIMITED operates from Hong Kong (HK). Some of our service providers may store or process information in other jurisdictions. When information is transferred across borders, we take reasonable steps to ensure that it remains protected.

Those steps may include selecting providers that maintain recognised safeguards, entering agreements that impose confidentiality and security obligations, and limiting transfers to what is necessary for the service concerned. By using this website or engaging our services, you understand that information may be processed in a jurisdiction other than your own.

9. Data Retention

We keep personal information only for as long as it is needed for the purpose for which it was collected, for the duration of any engagement, and for the period required by law. Business and accounting records are retained for the period that applicable rules require, after which they are securely deleted or anonymised.

Enquiry correspondence that does not lead to an engagement is normally retained for a limited period so that we can respond to follow up questions and maintain a record of our communications. When information is no longer needed, we remove it from active systems and from backups according to our retention schedule.

Retention periods are reviewed periodically so that they continue to reflect the purpose for which information was collected and the requirements that apply to our practice. Where information is kept for statistical or archival purposes after the original purpose has ended, we take steps to remove identifiers so that it can no longer be linked to a particular person.

10. How We Protect Information

We apply a layered approach to protecting information. Access to systems that hold personal information is restricted to personnel who need it to perform their work. Accounts are protected with strong credentials, and administrative access is limited and reviewed.

Data in transit and at rest is protected using encryption where appropriate. We maintain monitoring and logging so that unusual activity can be detected and investigated. We also train our personnel on handling information responsibly and on recognising attempts to obtain information improperly.

No system can promise absolute security. We work to reduce risk continuously, and we maintain procedures to respond to incidents, including assessing whether notification is required and, where it is, informing affected individuals and authorities without undue delay.

11. Your Privacy Rights

Depending on where you live, you may have the right to request access to the personal information we hold about you, to ask us to correct information that is inaccurate, and to ask us to delete information that we no longer have a lawful reason to keep.

You may also have the right to object to certain processing, to ask us to restrict processing while a concern is investigated, and to request a portable copy of information you provided to us. Where processing depends on consent, you may withdraw that consent at any time.

To exercise any of these rights, contact us using the details in the Contacting Us section. We will verify your identity before acting on a request and will respond within the period required by applicable law. If we cannot fulfil a request, we will explain why. You also have the right to complain to a data protection authority in your jurisdiction.

12. Privacy for Children

This website and our professional services are intended for organisations and for adults acting in a professional capacity. We do not knowingly collect personal information from children. If you believe that a child has provided personal information to us, please contact us and we will take reasonable steps to remove it.

If a client engagement ever involves information about minors, that information is handled strictly under the terms of the engagement, with heightened care, and with access limited to the personnel who need it to perform the agreed work.

13. Client System Data

Our systems design, integration, cloud, operations, data, and security services sometimes require access to technical environments that contain client records. When we access such records, we act under the written instructions of the client and treat the records as confidential.

Client records encountered in this way are used only to perform the contracted services. They are not used for our own marketing, they are not sold, and they are not disclosed except as necessary to deliver the work or as required by law. Where possible, we work with test data and limited access so that production records are touched as little as necessary.

When an engagement ends, we return or delete client records according to the agreement and our retention obligations, and we confirm the disposition in writing on request.

14. Marketing Communications

We send marketing communications only where we have a lawful basis to do so, such as your consent or a legitimate interest arising from an existing relationship. Messages are limited to information about our practice, our service lines, and updates that we believe are relevant to organisations that depend on integrated systems.

Every marketing message includes a straightforward way to opt out. You may also contact us at any time to ask that your details be removed from our marketing list. We honour opt out requests promptly, and we keep a minimal record of the request so that we do not inadvertently contact you again after you have asked us to stop.

We do not purchase contact lists and we do not share your details with other organisations for their own marketing. Where a message is sent because of an existing client relationship, you may still opt out at any time, and doing so will not affect the delivery of services you have already engaged.

15. Third Party Links

Our website may include links to third party websites, resources, or tools. Those destinations are governed by their own privacy policies, which we do not control and cannot change. We encourage you to review the privacy notice of any site you visit before providing personal information there.

Including a link does not imply that we endorse the third party or guarantee the accuracy, security, or reliability of its content. We accept no responsibility for the privacy practices of third party destinations that you reach from our pages.

16. Changes to This Policy

We review this Privacy Policy from time to time and may update it to reflect changes in our practice, in technology, or in applicable law. When we update the policy, we revise the effective date shown at the top of this page. Material changes will be communicated in a manner appropriate to their significance.

Your continued use of this website after an updated policy is posted indicates that you accept the revised terms. Before relying on any particular handling practice, please check this page for the current version.

17. Contacting Us

Questions, requests, and concerns about this Privacy Policy or about the way we handle personal information are welcome. Please direct them to our practice using the details below.

Developer and data controller: BaluEcom, operating as BALU ECOMMERCE LIMITED.

Address: Rm 1120 11/F OCEAN CTR HARBOUR CITY, Tsim Sha Tsui, Hong Kong (HK).

Email: support@baluecom.buzz. Telephone: +15418041783.

We will review your message and respond within the timeframe required by applicable law. Where a request concerns a client engagement, please include enough detail for us to identify the relevant records.

18. Governing Framework

This Privacy Policy is maintained by BALU ECOMMERCE LIMITED in accordance with the laws applicable to our operations in Hong Kong (HK) and, where relevant, the laws applicable to the individuals with whom we interact. Nothing in this policy limits any right that applicable law grants to you.

If any provision of this policy is found to be unenforceable, the remaining provisions continue in effect. Our commitment to handling personal information responsibly does not depend on any single clause and continues regardless of changes in format or presentation.