1. Introduction
Hong Kong Ho Yau Chien Trading Limited respects the privacy of every person who interacts with this website and with the services we provide. This Privacy Policy explains, in plain language, what information we gather, why we gather it, how we protect it and what choices are available to the people whose information we hold. The developer name associated with the preparation of this policy is HoYauChien Trade, and the operating company is Hong Kong Ho Yau Chien Trading Limited, whose registered place of business is Rm 9042 9/F CHUNG MEI CTR BLK B, 15-17 HING YIP ST, Kwun Tong, Hong Kong (HK).
We are a computer integrated systems design firm. Our work involves designing, building and supporting technical estates for other organisations. Because of that work we handle two broad categories of information: information about visitors to this website, and information that belongs to our clients and their own users when we are engaged to run or improve client systems. This policy addresses both categories and explains the different responsibilities that apply to each.
We have written this document to be read without legal training. Where a concept is technical we explain it in ordinary terms. Where a term has a specific meaning in data protection law we say so. If anything here remains unclear, please write to info@eduway.lol and we will explain it further.
2. Who We Are
The organisation responsible for the personal information described in this policy is Hong Kong Ho Yau Chien Trading Limited. We are registered and operate from Rm 9042 9/F CHUNG MEI CTR BLK B, 15-17 HING YIP ST, Kwun Tong, Hong Kong (HK). Our telephone number is +16414363407 and our email address is info@eduway.lol.
For the purposes of applicable data protection law, Hong Kong Ho Yau Chien Trading Limited acts as the controller of information collected through this website and through our direct business relationships. When we deliver managed services inside a client estate and process information that belongs to that client, we generally act as a processor on the instructions of the client, who remains the controller of that information.
We do not appoint a separate statutory data protection officer because our processing activities are limited in scale and do not meet the thresholds that require one. Privacy enquiries are handled by a named member of our team, and every enquiry receives a direct reply rather than an automated acknowledgement alone.
3. Scope of This Policy
This policy applies to information collected through the website published at eduway.lol, through email and telephone correspondence with our team, through proposals, statements of work and contracts, and through the delivery of our professional services. It also applies to information we collect in the course of normal business administration, such as supplier records and accounting entries.
This policy does not apply to third party websites that we may link to, nor to software products that a client operates under its own separate agreement. Where a client engages us to work inside a system that the client controls, the client privacy notice governs the personal information held in that system, and our own obligations are set out in the contract between the client and Hong Kong Ho Yau Chien Trading Limited.
If you are an employee or a customer of one of our clients, and you have a question about information held in a client system that we help to operate, please contact that client first. We will assist the client in responding, but the client remains responsible for its own privacy notice and for decisions about its own users.
4. Information We Collect
We collect the minimum information needed to answer an enquiry, deliver an engagement and keep proper business records. The categories we may collect are described below.
Information you give us directly
- Your name, organisation name and job title.
- Your email address, telephone number and postal address.
- The content of messages you send to us, including attachments.
- Details of the systems, projects and requirements you describe to us.
- Contract, billing and payment references needed to administer an engagement.
Information collected automatically
- Standard technical log data such as the pages requested and the time of a request.
- The referring address that led you to our website, where your browser supplies it.
- Aggregate information about how the website is used, used only to keep it working correctly.
Information created during delivery
- Notes, diagrams, registers and reports that record work performed for a client.
- Change records and support tickets that reference named individuals in a client team.
- Test evidence and review records produced as part of quality assurance.
We do not seek sensitive categories of personal information such as health data, biometric data, political opinions or religious beliefs, and we ask that you do not send such information to us through the website or by email unless it is genuinely necessary for a matter you have raised.
5. How We Collect Information
Most information reaches us because somebody chooses to send it. You may complete a contact form, send an email to info@eduway.lol, telephone us on +16414363407, or exchange documents during a proposal or project. In each case the information is provided deliberately by you or by a colleague acting on your behalf.
A smaller amount of information is generated automatically when a browser requests a page from our website. This technical record helps us confirm that the site is available and that requests are being served correctly. It is not used to build a profile of individual visitors and it is not combined with information from other sources to identify you.
We may also receive information about you from a client, for example when a client introduces a member of its team as a named contact for an engagement, or when a client supplies a list of system owners who will take part in discovery. In that situation we rely on the client to have informed you that your details would be shared with us.
6. Why We Use Information
We use personal information for the following purposes, and for no others without first telling you.
- To reply to an enquiry and to decide whether an engagement is a good fit.
- To prepare proposals, statements of work and contracts.
- To deliver, support and administer the services we have agreed to provide.
- To maintain accurate records of work performed, decisions taken and changes made.
- To protect the security and integrity of our own systems and those we are engaged to run.
- To meet accounting, tax and other legal obligations that apply to our business.
- To improve the clarity of our website and the usefulness of our published material.
We do not sell personal information. We do not rent contact lists. We do not use personal information to send unrelated advertising, and we do not pass information to advertising networks. Our business depends on clients trusting the way we handle their systems, and that trust would be impossible to maintain if we treated personal information as a commodity.
7. Legal Bases for Processing
Where data protection law requires us to identify a lawful basis for processing, we rely on the following bases according to the situation.
- Contract. Processing that is necessary to enter into or perform an agreement with you or with your organisation.
- Legitimate interests. Processing that is necessary for the ordinary running of our business, such as responding to enquiries, maintaining records and securing our systems, where those interests are not outweighed by your rights.
- Legal obligation. Processing that is necessary to comply with accounting, tax, record keeping or other statutory duties.
- Consent. Processing for which you have given a clear and specific permission, which you may withdraw at any time.
Where we rely on legitimate interests we consider carefully whether the processing is proportionate and whether a less intrusive approach would achieve the same purpose. Where we rely on consent we keep a record of when and how that consent was given.
8. Client Systems and Managed Services
A significant part of our work involves operating inside systems owned by our clients. Those systems frequently contain personal information about the client staff, the client customers and other individuals. When we access such information, we do so only as needed to perform the agreed services, and we follow the written instructions set out in the contract between the client and Hong Kong Ho Yau Chien Trading Limited.
We apply the same technical safeguards to client systems that we apply to our own, including least privilege access, named accounts, session controls and logging. Access is removed promptly when an engineer leaves a project or leaves the company. Where we must copy client data for testing, we prefer to use disguised or synthesised data, and where production data is unavoidable we restrict the copy, protect it and delete it once the test is complete.
If you are an individual whose information is held in a client system, we cannot directly amend or delete that information on our own initiative, because the client controls it. We will however pass your request to the client promptly and assist the client in responding, in line with our contractual commitments.
11. International Transfers
Hong Kong Ho Yau Chien Trading Limited operates from Hong Kong and may work with clients and suppliers in other jurisdictions. As a result, personal information may be stored or processed outside the jurisdiction in which it was collected, including in cloud regions operated by our hosting providers.
Where information moves across borders we take steps to ensure that it continues to receive an appropriate level of protection. Those steps may include contractual commitments between the parties, the use of providers that maintain recognised safeguards, and technical measures such as encryption in transit and at rest. We review these arrangements periodically and adjust them when the legal landscape changes.
If you would like to know more about the specific safeguards that apply to your information, please write to info@eduway.lol and we will explain them in writing.
12. Data Retention
We keep personal information only for as long as it is needed for the purpose for which it was collected, and then we delete it or make it anonymous. Retention periods are set by reference to the type of record rather than by a single blanket rule.
- Enquiries that do not lead to an engagement are kept for a short period and then removed.
- Contract and project records are kept for the duration of the relationship and for a following period required by accounting and legal rules.
- Support tickets and change records are kept while the related system is supported, and for a short period afterwards for audit purposes.
- Technical logs are kept for a limited period sufficient to diagnose faults and investigate incidents.
When the retention period for a record ends, we delete it from active systems and from backups as those backups roll over in the ordinary course. Where deletion is not immediately possible, we restrict access to the record and hold it only until deletion becomes feasible.
13. Security of Information
The security of information is central to our business, not an add on. We apply a set of controls that are proportionate to the sensitivity of the information and to the risk of harm if it were lost or disclosed.
- Access is granted on a least privilege basis and reviewed periodically.
- Accounts are individual, and shared credentials are avoided for administrative access.
- Multi factor authentication is used for remote access and for administrative consoles.
- Information is encrypted in transit and at rest where the platform supports it.
- Systems are patched on a staged schedule, and backups are verified by restoration.
- Activity is logged, and logs are kept separate from the systems they observe.
- Team members receive regular briefings on privacy and security practice.
No set of controls can remove every risk. If you believe that information you have shared with us has been compromised, please contact us immediately at info@eduway.lol or on +16414363407 so that we can investigate without delay.
14. Your Privacy Rights
Subject to the law that applies to you, you may have the following rights in relation to personal information that we hold about you.
- Access. To ask whether we hold information about you and to receive a copy of it.
- Correction. To ask us to correct information that is inaccurate or incomplete.
- Erasure. To ask us to delete information where there is no continuing lawful reason to keep it.
- Restriction. To ask us to limit how we use information while a question about it is resolved.
- Objection. To object to processing that we carry out on the basis of legitimate interests.
- Portability. To receive information you provided to us in a structured, commonly used format.
- Withdrawal of consent. To withdraw a consent you previously gave, without affecting earlier lawful processing.
To exercise any of these rights, write to info@eduway.lol with enough detail for us to identify you and understand your request. We will respond within the period required by applicable law, and we will explain clearly if we are unable to meet a request and why. You also have the right to complain to a data protection authority in your jurisdiction, although we would ask you to contact us first so that we have the chance to resolve the matter directly.
15. Privacy for Children
Our services are designed for organisations and for adults acting in a professional capacity. This website is not directed at children, and we do not knowingly collect personal information from children through it.
If we learn that we have collected information from a child without appropriate permission, we will delete that information promptly. If you believe that a child has provided information to us, please write to info@eduway.lol so that we can act. Where a client project involves information about children, for example in an education related integration, the client remains the controller of that information and is responsible for obtaining any consent that the law requires. We support the client by applying strict access controls and by minimising the data we copy for testing.
16. Third Party Links
Our website may contain links to resources operated by other organisations, for example standards bodies or software vendors. Those resources sit outside our control, and their privacy practices may differ from ours. We provide such links because they are useful to readers, not as an endorsement, and we encourage you to read the privacy notice of any website that you visit.
We are not responsible for the content, security or privacy practice of resources that we do not operate. If you follow a link from our site and believe that the destination treats your information unfairly, please tell us so that we can review whether the link still belongs on our pages.
17. Automated Decisions and Profiling
We do not make decisions that produce legal or similarly significant effects about individuals through automated processing alone. We do not build advertising profiles, we do not score individuals for marketing, and we do not use behavioural tracking to vary the content that a visitor sees.
Where we build automation for a client, for example a data pipeline that routes records or a monitoring rule that raises an alert, those mechanisms support human decisions rather than replace them. A named person reviews anything that affects a customer outcome. If a future project were ever to involve a decision made without human involvement, we would describe it to the client, assess its impact and build in a clear route for a person to ask for a review.
18. Incident and Breach Notification
We maintain a written procedure for responding to a suspected privacy incident. The procedure covers how an incident is reported internally, how it is contained, how its scope is assessed and how affected parties are informed. Speed matters more than appearance, so reporting is encouraged and no team member is criticised for raising a concern in good faith.
Where an incident is likely to result in a risk to the rights of individuals, we will notify the relevant authority without undue delay and, where required, notify the affected individuals directly. Where we act as a processor for a client, we will notify that client promptly so that the client can meet its own obligations. Every significant incident is followed by a review that produces concrete changes rather than a promise to be more careful.
19. Changes to This Policy
We review this policy periodically and update it when our practice changes or when the law requires. When we make a material change we will update the date shown at the top of this page and, where the change significantly affects how we use information, we will make the change prominent on our website.
Continued use of the website after an update indicates that you accept the revised policy. If you do not agree with a change, please stop using the website and write to us so that we can discuss any information we hold about you. We keep earlier versions available on request so that anyone can see how our practice has evolved.
20. How to Contact Us
If you have a question about this policy, a request about your information, or a concern about the way we have handled it, please contact us. We prefer a short written note that explains the situation, because it gives us something concrete to investigate.
Hong Kong Ho Yau Chien Trading Limited
Rm 9042 9/F CHUNG MEI CTR BLK B, 15-17 HING YIP ST, Kwun Tong, Hong Kong (HK)
Email: info@eduway.lol
Telephone: +16414363407
Please note: privacy enquiries are answered by a named member of our team during Hong Kong business hours. If your matter is urgent, please telephone +16414363407 rather than relying on email alone.