Privacy Notice
How Afilcorp collects, uses, discloses, retains and protects personal data under Hong Kong law.
- Effective date
- 11 August 2026
- Last reviewed
- 11 August 2026
- Legal entity
- Afilcorp Capital Pte Limited
1. Data user
Afilcorp Capital Pte Limited is the data user responsible for personal data collected through the Website and related preliminary communications, unless another notice identifies a different data user for a specific engagement.
Contact:
2. Scope
This Notice applies when you:
- visit the Website;
- submit an enquiry;
- download a report;
- subscribe to an expressly offered update;
- communicate with Afilcorp;
- report fraud or a correction;
- participate in preliminary engagement discussions.
A separate engagement, employment, supplier, statutory-company-service or KYC notice may apply to other processing.
3. Personal data collected
Depending on the interaction, Afilcorp may collect:
- name;
- work email, telephone and business contact details;
- family office, company, employer or organisation;
- role, professional capacity and jurisdiction;
- enquiry category and content;
- correspondence and meeting records;
- relationship, referral and conflict information;
- records relating to eligibility, KYC/KYB or risk review where a matter progresses;
- IP address, browser, device, timestamp, security, anti-spam and server-log information;
- cookie, preference and analytics data where used;
- fraud, complaint, correction or incident information; and
- other information voluntarily provided.
Do not submit identity documents, bank statements, source-of-funds records, client files, passwords or sensitive family material through the public form.
4. Sources
Personal data may be obtained:
- directly from you;
- from an authorised representative;
- from a client or prospective client;
- from a referral source;
- from public registers or official sources;
- from service providers used to operate the Website;
- during lawful risk, conflict or compliance checks.
5. Purposes
Afilcorp may use personal data to:
- receive, assess and respond to enquiries;
- identify the person and organisation making contact;
- understand the proposed matter, jurisdiction, purpose and timetable;
- conduct conflict, eligibility, KYC/KYB, sanctions, fraud and risk checks;
- determine whether to accept or decline a matter;
- communicate and schedule discussions;
- prepare and administer Engagement Terms;
- provide accepted services;
- maintain company, TCSP, AML/CFT, governance, operational and evidence records;
- manage third-party providers where authorised;
- operate, secure, monitor and improve the Website;
- prevent and investigate abuse, fraud, cyber incidents or impersonation;
- comply with law, court orders, regulators, law enforcement and professional obligations;
- establish, exercise or defend legal rights;
- manage complaints and corrections; and
- send direct marketing only where the required notice and consent have been obtained.
6. Voluntary provision and consequences
Provision of Website enquiry data is generally voluntary.
If required contact, organisation or enquiry information is not provided, Afilcorp may be unable to assess or respond.
Information required for legal, conflict, KYC/KYB, AML/CFT or engagement purposes may be mandatory before Afilcorp can accept or continue work.
7. Data minimisation and accuracy
Afilcorp seeks to collect data that is adequate but not excessive for the relevant purpose.
You should provide accurate, current information and notify material changes.
Afilcorp may seek clarification or refuse unnecessary sensitive information.
8. Classes of recipients
Personal data may be disclosed, where reasonably necessary, to:
- Afilcorp directors, personnel and authorised contractors;
- hosting, database, email, security, analytics, document-management and communications providers;
- professional advisers appointed by Afilcorp;
- professional or regulated providers considered for or involved in a matter, with authority and appropriate notice;
- a prospective contracting entity or successor identified in Engagement Terms;
- courts, regulators, law-enforcement and public authorities where required or permitted by law;
- insurers, auditors or investigators in connection with risk, claims or security; and
- persons authorised by the data subject.
A recipient is not described as an “Afilcorp partner” merely because it processes data or receives a referral.
9. Service providers
The production system must maintain an internal processor register identifying actual providers, locations, functions, contracts, security and retention.
Public examples should be named only if actually used and approved for disclosure.
10. Processing outside Hong Kong
Some technology or professional providers may process data outside Hong Kong.
Afilcorp will take reasonable contractual, technical and organisational steps appropriate to the data and risk.
Section 33 of the Personal Data (Privacy) Ordinance is not currently in operation. Afilcorp nevertheless seeks to apply appropriate cross-border safeguards and data-minimisation controls.
11. Retention
Afilcorp retains personal data only for as long as reasonably necessary for the purpose, directly related purposes, legal obligations, risk management and legal claims.
The operational retention schedule must be approved and implemented before publication. Subject to that schedule:
- ordinary unaccepted enquiries may be retained for up to 24 months;
- spam, abuse and rejected submissions may be retained for up to 12 months where necessary for security;
- accepted-matter records are retained under the engagement, company-service, AML/CFT, legal and insurance schedule;
- security logs are retained according to incident and provider requirements;
- legal-hold records may be retained for the duration of the hold.
Afilcorp may retain a minimal suppression or opt-out record to honour a request.
12. Security
Afilcorp uses reasonable measures appropriate to the information and risk, which may include:
- access controls;
- authentication;
- encryption in transit;
- controlled storage;
- logging;
- backup;
- provider due diligence;
- staff confidentiality;
- incident procedures;
- secure document transfer.
No method is completely secure.
13. Cookies and analytics
The Cookie Notice explains the actual technologies used.
Afilcorp will not describe the Website as cookie-free unless verified.
Non-essential cookies will be managed through an appropriate consent mechanism where required.
14. Direct marketing
The public enquiry form does not automatically enrol a person in marketing.
Before using personal data for direct marketing, Afilcorp will provide the required notice and obtain the required consent or indication of no objection.
A person may request cessation of direct marketing without charge.
15. Access and correction
Under Hong Kong privacy law, a data subject may request access to and correction of personal data, subject to applicable procedures, exemptions and a reasonable fee where permitted.
Requests should identify:
- the data subject;
- the data requested;
- the relevant relationship or communication;
- the correction sought.
Identity verification may be required.
16. Erasure and objection requests
Hong Kong law does not provide an unqualified general “right to deletion” equivalent to every foreign privacy regime.
Afilcorp will consider a request to erase, restrict or cease use where appropriate, but may retain data required by law, AML/CFT duties, record-keeping, legal claims, security, suppression or legitimate directly related purposes.
17. Complaints
Privacy concerns may be submitted to the Data Protection Contact.
A person may also contact the Office of the Privacy Commissioner for Personal Data, Hong Kong.
18. Children
The Website is intended for professional and institutional users and is not directed to children.
Do not submit a child’s personal data unless lawfully authorised and necessary.
19. Changes
Afilcorp may update this Notice to reflect changes in law, technology, services or operations.
The version and effective date identify the current Notice.
