These public terms provide HaxLink’s standard framework. A signed master agreement, Order, statement of work, data processing agreement, or mandatory law prevails where it expressly differs.
1. Scope and roles
This Privacy Policy explains how HaxLink Limited ("HaxLink", "we", "us", or "our") handles personal data when you visit our website, join a waitlist, request or purchase Services, administer an account, receive support, or communicate with us.
For account, sales, website, and business-contact data, HaxLink generally acts as a data user or controller. For personal data contained in Customer workloads, HaxLink generally acts as a processor or service provider on Customer's documented instructions. The applicable service agreement and data processing agreement govern that processing.
This Policy applies subject to the Personal Data (Privacy) Ordinance of Hong Kong (Cap. 486) and, where applicable to particular processing, other privacy laws such as the EU or UK GDPR.
2. Personal data we collect
- Identity and contact data, such as name, business email, telephone number, job title, employer, and authorized contacts.
- Account and authentication data, such as username, tenant, role, login history, multi-factor authentication status, and security events.
- Commercial and billing data, such as company details, order history, invoices, tax information, payment status, and transaction references. Payment providers may process full card or bank details; HaxLink generally receives limited payment tokens or status information.
- Service and configuration data, such as selected regions, capacity, IP addresses, resource identifiers, operating requirements, support tier, change history, and service metadata.
- Usage and device data, such as browser type, device identifiers, approximate location derived from IP address, pages viewed, referral information, timestamps, portal activity, and diagnostic logs.
- Communications, such as waitlist submissions, sales discussions, support tickets, call notes, survey responses, and correspondence.
- Security, compliance, and abuse data, such as suspected malicious traffic, fraud indicators, sanctions screening results, incident evidence, complaint records, and identity verification where appropriate.
- Marketing preferences, including subscriptions, event interest, consent records, and opt-out choices.
3. Sources of personal data
We collect data directly from you and your organization, automatically through the website and Services, from Authorized Users, from infrastructure and security partners involved in service delivery, and from payment, identity, analytics, communications, or fraud-prevention providers.
We may also receive business contact and due-diligence information from public company registers, professional networks, event organizers, referrals, and lawful compliance databases.
4. Why we use personal data
- Respond to enquiries, assess waitlist applications, prepare proposals, and enter contracts.
- Create and administer accounts, provision infrastructure, coordinate partners, invoice, and deliver support.
- Authenticate users, maintain logs, detect abuse, investigate incidents, and protect people, systems, and networks.
- Monitor performance, troubleshoot faults, plan capacity, and improve the usability and reliability of the Services.
- Comply with legal, tax, accounting, sanctions, law-enforcement, and regulatory obligations.
- Establish, exercise, or defend legal claims and enforce our agreements.
- Send service notices and, where permitted, relevant business communications and direct marketing.
- Produce aggregated or de-identified statistics that do not reasonably identify an individual.
5. Legal bases and collection notices
Under Hong Kong law, we collect and use personal data for purposes stated at or before collection, directly related purposes, purposes you consent to, and purposes otherwise permitted by law. If providing particular data is obligatory, the collection notice or form will identify that fact and the consequences of not providing it.
Where the GDPR applies, our legal bases may include performance of a contract, steps requested before contract, legitimate interests in operating and securing a business infrastructure service, compliance with legal obligations, consent, and the establishment or defence of legal claims.
When relying on legitimate interests, we consider the necessity of the processing and balance it against individual rights. You may request information about the relevant assessment.
6. Direct marketing
We may use your name, business contact details, role, organization, service interests, and engagement history to send information about HaxLink infrastructure, events, and related business services where permitted by law.
Where Hong Kong's direct-marketing requirements apply, we will provide the required notice and obtain consent or an indication of no objection before first use. We do not provide personal data to another person for that person's direct marketing without the required notice and consent.
You may opt out at any time through the message link or by emailing contact@haxlink.com. Opting out of marketing does not stop transactional, security, billing, or service communications.
7. How we disclose personal data
- Affiliates and personnel who need the data to operate the business or Services.
- Regional data-centre, cloud, network, hardware, software, monitoring, backup, and support partners used to fulfil an Order.
- Payment, invoicing, customer-management, communications, analytics, identity, security, and fraud-prevention providers.
- Professional advisers, auditors, insurers, banks, and prospective financing or transaction parties under appropriate confidentiality duties.
- Government, regulators, courts, law enforcement, emergency services, and other persons where disclosure is required or permitted by law or reasonably necessary to protect rights, safety, or service integrity.
- A successor in connection with a merger, reorganization, financing, or sale of all or part of the business, subject to appropriate safeguards.
HaxLink does not sell personal data for money. We do not permit service providers to use personal data for their own unrelated advertising.
8. International transfers
HaxLink operates from Hong Kong and coordinates infrastructure in multiple regions. Personal data may therefore be processed in Hong Kong, the United States, Japan, Singapore, and other locations selected in an Order or used by our service providers.
Transfer destinations may have different privacy laws. We use contractual, organizational, and technical measures appropriate to the data and transfer, which may include data processing terms, confidentiality duties, security requirements, transfer impact review, recognized standard contractual clauses, and Hong Kong model contractual clauses.
Customer remains responsible for selecting permitted workload regions and providing transfer instructions for Customer Content.
9. Retention
We retain personal data only as long as reasonably necessary for the stated purpose, legal obligations, dispute resolution, security, and enforcement. Retention may be extended where a legal hold, investigation, or technical recovery cycle applies.
- Active account and contract records: for the relationship and generally up to seven years afterward for legal, tax, and audit needs.
- Billing and transaction records: generally seven years or the period required by applicable law.
- Support, change, and security records: generally two to seven years depending on severity, contractual need, and legal risk.
- Website analytics and routine logs: generally 30 days to 25 months, depending on purpose and configuration.
- Unsuccessful waitlist or sales enquiries: generally up to 24 months after the last meaningful interaction.
- Marketing records and suppression lists: until opt-out, then a minimal suppression record for as long as needed to respect the choice.
- Customer Content: as specified in the Order and deletion schedule, subject to backups, legal holds, and secure recovery cycles.
10. Security and incident response
We use administrative, technical, and physical safeguards designed for the nature of the data and Services. Measures may include access control, multi-factor authentication, encryption in transit, environment separation, logging, vulnerability management, backup controls, supplier review, personnel confidentiality, and incident procedures.
No security measure eliminates all risk. Customers must apply the shared-responsibility controls stated in their Orders and promptly notify us of suspected incidents.
If a personal-data incident occurs, we will investigate, contain, preserve evidence, assess risk, and notify affected Customers, individuals, the Hong Kong Privacy Commissioner, or other authorities where required or appropriate. Hong Kong breach notification is currently recommended rather than generally mandatory, but HaxLink may notify when it supports risk reduction and accountability.
11. Cookies and similar technologies
We may use strictly necessary technologies for security, routing, session continuity, and preferences, and limited analytics technologies to understand website performance. Where consent is legally required for non-essential technologies, we will request it before use.
Browser settings can block or delete cookies, but doing so may impair account or website functions. We do not respond to legacy Do Not Track signals where no uniform legal standard applies.
12. Your privacy rights
Subject to law, you may request access to and correction of personal data HaxLink holds about you. Under Hong Kong law, we ordinarily respond to a valid data access request within 40 days. We may request identity verification, clarification, or a permitted fee and may refuse only on lawful grounds.
Where applicable law provides them, you may also request deletion, restriction, portability, objection, withdrawal of consent, or review of certain automated decisions. Withdrawing consent does not affect earlier lawful processing.
If your data is controlled by a HaxLink Customer, first direct your request to that Customer. We will assist the Customer as required by contract and law.
13. Children
The Services are intended for business customers and are not directed to children. We do not knowingly collect personal data from children through account registration or marketing. If you believe a child has provided data, contact us so we can investigate and take appropriate action.
14. Changes to this Policy
We may update this Policy to reflect changes in law, technology, providers, or practices. We will post the revised version with a new effective date. If a change materially affects existing processing, we will provide additional notice where appropriate or legally required.
15. Contact and complaints
Send privacy enquiries, rights requests, or complaints to HaxLink Limited at contact@haxlink.com with the subject line “Privacy Request”. Please identify the relevant account or interaction and the right you wish to exercise.
You may also complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong, or another competent supervisory authority. We encourage you to contact us first so we can investigate promptly.
Authoritative resources
These external sources provide regulatory and statutory context. They do not replace the agreement between HaxLink and a Customer.
Contact HaxLink Limited
Include your organization, account or Order reference, and enough context for us to route your request.