中文

Legal & privacy

Privacy Policy Statement

How we handle personal data, described against each of the six Data Protection Principles in the Personal Data (Privacy) Ordinance (Cap. 486).

TMT Services LtdCentral, Hong Kong SARLast updated: 21 September 2026
Chinese version. A Traditional Chinese translation of this page is available at /zh/privacy-policy.html. In case of any discrepancy or conflict, the English version prevails.
Short version: we are a Hong Kong data user under the Personal Data (Privacy) Ordinance (Cap. 486). We collect only the personal data we need to answer you and to run our business, we use it only for the purpose we collected it for, we do not sell it, and we do not use it for direct marketing without your consent.

1. Who we are

TMT Services Ltd ("TMT Services", "we", "us") is a company incorporated in Hong Kong SAR with its business office in Central, Hong Kong SAR. We provide corporate consulting, technology and trade services.

For the purposes of the Personal Data (Privacy) Ordinance (Cap. 486) (the "PDPO"), TMT Services Ltd is the data user in respect of personal data collected through this website and in the course of our business, and you are the data subject.

2. The law we follow

Our handling of personal data is governed by the PDPO, which is administered and enforced by the Office of the Privacy Commissioner for Personal Data, Hong Kong ("PCPD"). The PDPO is principle-based: the Data Protection Principles ("DPPs") are set out in Schedule 1 to the PDPO. This is what they require, and what we do about each of them.

PrincipleWhat it requiresHow we comply
DPP1
Purpose and manner of collection
Personal data may only be collected for a lawful purpose directly related to a function or activity of the data user; the data must be necessary and adequate but not excessive for that purpose; collection must be by lawful and fair means. We collect only what is needed for the purpose stated at the point of collection, and we state that purpose on the form or in our Personal Information Collection Statement.
DPP2
Accuracy and duration of retention
Data must be accurate, and must not be kept longer than necessary for the purpose for which it is used. We keep records up to date and apply a retention schedule; data no longer required is erased (see also section 7 below).
DPP3
Use of personal data
Data must not be used for a new purpose unrelated to the original purpose, unless the data subject gives express and voluntary consent. Consent can be withdrawn by written notice. We use personal data only for the purpose we collected it for. If we ever need to use it for something else, we ask you first and we honour any withdrawal of consent.
DPP4
Data security
All practicable steps must be taken to protect personal data against unauthorised or accidental access, processing, erasure, loss or use. Data processors must be bound by contractual or other means to meet the same standard. Access is limited to staff who need it; we use encryption in transit and contractual data-processing terms with our service providers.
DPP5
Openness and transparency
Data users must be open about their personal data policies and practices, the kinds of personal data they hold and the main purposes for holding it. This Privacy Policy Statement, our Personal Information Collection Statement and our Cookie Policy are published on this website and are kept current.
DPP6
Access and correction
Data subjects have the right to request access to, and correction of, their own personal data. Reasons must be given if a request is refused. We handle access and correction requests as described in section 10 below, and we give reasons if we refuse a request.

Where our website or our engagements involve service providers that process personal data on our behalf (data processors), the PDPO holds us — not them — responsible: we are required to ensure by contractual or other means that they meet the applicable requirements.

3. Personal data we collect

We collect personal data in these situations:

We do not use this website to collect identity documents, financial account numbers, health data or any other special category of data, and we ask you not to send such data through the website contact form.

4. How we use it

We use personal data for the following purposes only:

5. Who we may share it with

We do not sell, rent or trade personal data. We may disclose it to the following classes of persons, and only so far as is necessary for the purposes above:

6. Direct marketing

We will not use your personal data for direct marketing, and we will not provide it to a third party for direct marketing, unless we have first obtained your informed consent in accordance with the applicable provisions of the PDPO.

Where we ask for such consent we will tell you: that we intend to use or provide the data for direct marketing, that we cannot do so without your consent, the kinds of personal data involved, the classes of marketing subjects involved, whether the data would be provided to a third party and, if so, the classes of recipients and whether the data would be provided for gain — and we will tell you how to opt out. Silence is not consent.

You may withdraw your consent at any time by writing to us at the address in section 14. We will stop using your data for direct marketing within the period required by the PDPO, and at no cost to you.

7. Retention

We keep personal data only for as long as is necessary to fulfil the purpose for which it was used, plus any period required by law:

DataTypical retention period
Unsuccessful enquiry / general correspondenceUp to 24 months from the last contact
Client engagement records7 years after the end of the engagement, or longer where the engagement requires it
Recruitment records for unsuccessful applicantsUp to 24 months, unless you ask us to keep them longer
Accounting and tax recordsAs required by Hong Kong law

When data is no longer required we take all practicable steps to erase it, unless erasure is prohibited by law or it is not in the public interest to erase it.

8. Security

We take all practicable steps to protect personal data held by us against unauthorised or accidental access, processing, erasure, loss or use. These steps include limiting access to staff and contractors who need it for their work, requiring confidentiality, using access controls and up-to-date software, and securing data in transit. We review our security measures as the nature of the data we hold and the risks change.

No method of transmission over the internet is completely secure. If you have reason to believe your interaction with us is no longer secure, please contact us immediately.

9. Overseas storage and processing

We are a Hong Kong company and our own records are held in Hong Kong, but we use reputable cloud service providers for email, documents and web hosting. Those providers may store or process data on servers located outside Hong Kong. Where personal data is transferred outside Hong Kong in this way, we continue to take the steps required of us under DPP4, and we assess our providers' security and contractual terms before use.

10. Your rights: access and correction

Under the PDPO you have the right to:

Requests should be made in writing to the address in section 14 and should identify you and the data concerned. We will respond within the period prescribed by the PDPO, which is generally 40 days after receiving the request and any fee. The PDPO permits a data user to charge a fee for complying with a data access request; where a fee applies we will tell you the amount before we proceed.

If you consider that we have not handled your personal data in accordance with the PDPO, you may complain to us first, or make a complaint to the Office of the Privacy Commissioner for Personal Data (PCPD), whose website is www.pcpd.org.hk. You also have the right to seek compensation from us in the courts for damage caused by a contravention of the PDPO.

11. Cookies

This website sets no cookies of its own and uses no analytics, advertising or tracking technologies. See our Cookie Policy for the full position, including the effect of the web font service we load from Google.

12. Children

Our website and our services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 18 through this website. If you believe a child has provided us with personal data, please contact us and we will delete it.

13. Changes to this statement

We may update this Privacy Policy Statement to reflect changes in our practices or in the law. The current version is always published on this page with the date it was last updated. Material changes will be given prominence on the website.

14. How to contact us

For any privacy question, or to make a data access or data correction request, please write to:

Data protection contact
The Director, TMT Services Ltd
Address
Central, Hong Kong SAR
Email
info@tmtserviceshk.com

Please mark the subject line "Personal Data" so that your message is handled by the right person.

Bilingual site. This page is also published in Traditional Chinese at /zh/privacy-policy.html. The English text is the authoritative version; the Chinese translation is provided for convenience and prevails only where English wording is unclear. Legal wording is drafted in English.