Privacy Policy
Effective date: 18 August 2026 · Last updated: 18 August 2026
1. Who we are
Chinglink Business Limited (CR 75604219), a Hong Kong company licensed as a Trust or Company Service Provider (TC009047) under the Companies Registry, is the data controller for the personal data described in this policy.
| Registered office | RM 1921, 19/F, Star House, 3 Salisbury Road, Tsim Sha Tsui, Kowloon, Hong Kong |
| [email protected] | |
| WhatsApp / phone | +852 6892 0818 |
| Data protection contact | Eric Lau, Compliance Officer / MLRO |
This policy applies to chinglink.com (all three language mirrors) and to the personal data we collect when you enquire about or engage our services.
2. Scope and applicable law
We are based in, and primarily regulated from, Hong Kong. This policy is written primarily against the Personal Data (Privacy) Ordinance (Cap. 486). Because we serve clients internationally, we also apply, as a matter of good practice, rights modelled on the EU/UK GDPR and the California Consumer Privacy Act (CCPA) to all visitors and clients regardless of location, as set out in Section 8 — without representing that we are subject to those regimes as a matter of law.
3. Personal data we collect
| Category | What we collect | When |
|---|---|---|
| Enquiry data | Name, email, phone/WhatsApp number, company name, and the content of your message | When you contact us via the website, WhatsApp, Facebook, Messenger or Instagram |
| Client due diligence (CDD) data | Identity document, proof of address, source of funds/wealth, nature and purpose of business; for corporate clients also beneficial ownership (>25% holders) and corporate structure | When you engage us as a client, before we begin work — required by our TCSP licence |
| Verification data | Details taken during identity-verification phone or video calls | During onboarding, for non-face-to-face clients |
| Payment data | Where you pay on-site, payment is processed by our third-party payment provider; we do not store full card numbers ourselves. Where you pay off-site (bank transfer/invoice), we hold the transaction reference and amount | At time of payment |
| Service delivery data | Company records, filings, correspondence with regulators, banks, our compliance partner and audit vendors, generated in the course of delivering your service | Throughout the engagement |
| Website usage data | Pages visited, general location (country/city level), device/browser type, via cookies | Automatically, on every visit → see our Cookie Policy |
We do not knowingly collect personal data from children, and our services are not directed at anyone under 18.
4. Why we collect it (purpose and legal basis)
| Purpose | Basis |
|---|---|
| Responding to enquiries and providing quotes | Your consent / steps taken at your request before a contract |
| Performing customer due diligence and ongoing monitoring | Legal obligation under the AML/CTF Ordinance, attaching to TCSP licence TC009047 |
| Delivering company formation, secretarial, virtual office, bookkeeping, tax and related services | Performance of our contract with you |
| Reporting to regulators (e.g. Companies Registry, Inland Revenue Department) where required | Legal obligation |
| Filing a suspicious transaction report where required | Legal obligation — we may not be able to tell you if this happens (“tipping-off” restrictions apply by law) |
| Website analytics and marketing | Your consent, given by continuing to browse this site as described in our cookie notice → see our Cookie Policy |
5. Who we share data with
| Recipient | Why |
|---|---|
| Audit vendor panel | External CPA firms we engage to perform your statutory audit and related accounting/tax work |
| Mainland China partner agents (Shenzhen, Qianhai, Guangzhou) | Deliver WFOE registration on our behalf where you engage that service — this involves transferring your data outside Hong Kong |
| Banks and payment partners (e.g. for account-opening introductions and payment processing) | To open accounts or process payments you request |
| Regulators (Companies Registry, Inland Revenue Department, and others where legally required) | Statutory filings and inspection duties attached to our licence |
| IT and hosting providers | Operating the website and storing records |
| Google, Meta, LinkedIn | Only the usage data described in our Cookie Policy |
We do not sell personal data, and we do not share CDD/AML data for marketing purposes.
6. International data transfers
Because we deliver mainland China company registration through local partner agents, and may use cloud service providers, your data may be transferred outside Hong Kong. Where we transfer data this way, we take reasonable steps to ensure the recipient protects it to a standard consistent with this policy — including only sharing what each partner needs to perform the specific service, and expecting partners to handle it in confidence.
7. Retention
| Data | Retention |
|---|---|
| Accounting and statutory records | 7 years, per Hong Kong requirements |
| CDD/AML records | 7 years from the end of the client relationship, in line with our accounting record retention. The company has operated since August 2023, so no record has yet reached this deadline |
| Website analytics data | Per Google Analytics / Meta / LinkedIn default retention, unless you block cookies → Cookie Policy |
| Enquiry data from non-clients | Kept only as long as needed to respond to your enquiry; inactive enquiries are deleted or anonymised periodically |
8. Your rights
Under the Personal Data (Privacy) Ordinance, you may request access to, and correction of, your personal data. As a matter of policy — not because we are necessarily subject to these laws — we also extend the following to all visitors and clients:
- Access — a copy of the personal data we hold about you
- Correction — fix inaccurate or incomplete data
- Deletion — request erasure, subject to our legal retention obligations (we cannot delete CDD/AML records before their statutory retention period ends)
- Objection / opt-out — object to marketing use of your data, or opt out of the analytics and advertising cookies described in our Cookie Policy
- Portability — receive certain data in a portable format, where technically feasible
To exercise any of these, contact [email protected]. We may need to verify your identity before acting on a request, and some requests may be limited where we have a legal obligation to retain data (for example, CDD records tied to TC009047).
9. Security
We hold physical CDD records at our registered office in locked storage with access restricted to authorised staff, and digital records on access-controlled systems, backed by standard IT safeguards (including account access controls and software kept up to date). No system is completely secure, but we take reasonable steps to protect your data against unauthorised access, loss or misuse, and to act promptly if a breach occurs.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with a new “last updated” date.
11. Contact
Questions or requests about your personal data: [email protected] or WhatsApp +852 6892 0818, attention Eric Lau (Compliance Officer).
