Data controller

Cloudopstools is the data controller for personal data submitted through cloudopstools.digital and collected during professional engagements. Contact: info@cloudopstools.digital · +852 2527 8899 · Admiralty Centre Tower 1, 18 Harcourt Road, Admiralty, Hong Kong.

Data we collect

  • Contact details from enquiry forms (name, email, optional engagement interest and period, message content)
  • Correspondence by email or phone
  • Documents and extracts you provide for vendor invoice verification, which may contain names, employee identifiers, or vendor contact details incidental to the review
  • Technical data such as IP address and basic server logs when you visit the site
  • Cookie-related data as described on our cookies page

Purposes

We use personal data to respond to enquiries, perform contracted reviews, maintain engagement records, improve site reliability, and meet legal or regulatory obligations applicable in Hong Kong.

Where the Personal Data (Privacy) Ordinance applies, we process data for purposes directly related to our functions and activities as a professional services practice, with your consent where required (for example, non-essential cookies), and where necessary to perform a contract or take steps at your request before a contract.

Retention

Enquiry records are typically kept for up to 24 months if no engagement follows. Engagement files, including working papers and reports, are retained for seven years unless a longer period is required by law or agreed in writing. Server logs are rotated on a shorter cycle, generally within 90 days.

Your rights

Subject to Hong Kong law, you may request access to personal data we hold about you, and correction of inaccurate data. To exercise these rights, email info@cloudopstools.digital with enough detail for us to locate your records. We may need to verify your identity before responding.

International transfers

Our primary operations and storage are in Hong Kong. If a subprocesser or secure file tool stores data outside Hong Kong, we take reasonable steps to ensure comparable safeguards and will inform clients in the scope letter when material transfers are expected for an engagement.

Sharing

We do not sell personal data. We may share data with professional advisers, IT hosts under contract, or authorities when legally required. Engagement findings are shared with the commissioning client and, if you instruct us in writing, with your external auditors.

Security

We use access controls, secure transfer methods for client files, and staff confidentiality undertakings. No method of transmission is perfectly secure; please avoid sending unnecessary sensitive identifiers in initial web-form messages.

Updates

This notice may be updated periodically. The version on this page is current as of the last site publication.