COOKIE POLICY
1. Introduction
This Cookie Policy explains how we use cookies and similar technologies on our website to improve user experience, analyze traffic, and deliver personalized content. This policy complies with the Hong Kong Personal Data (Privacy) Ordinance (PDPO) and relevant international frameworks.
2. Types of Cookies We Use
Essential Cookies: Required for core functions like site navigation and access to secure areas.
Performance Cookies: Collect aggregated data on user interactions to improve site functionality.
Functional Cookies: Enable enhanced personalization, such as remembering preferences.
Marketing/Advertising Cookies: Track visits to deliver relevant promotions or ads.
3. How We Use Cookies
Cookies are used to:
Enable essential website operations
Measure site usage and performance
Remember user preferences (e.g., language, region)
Deliver content tailored to your interests
4. Third-Party Cookies
We may permit select partners such as analytics or ad networks (e.g., Google Analytics, Meta Pixel) to set cookies that assist in analyzing aggregated data trends.
5. Cookie Lifespan
Session cookies expire when you close your browser; persistent cookies remain for up to 12 months unless deleted sooner.
6. Managing Cookies
You can manage or delete cookies in your browser settings. Note that disabling cookies may affect website functionality.
7. Updates
We may revise this policy periodically. The latest version will always be available on this page.
8. Contact
For questions, contact us via the methods mentioned on this website.
Security Policy
1. Purpose
This policy explains our approach to protecting our data and systems.
2. Security Measures
We employ:
Encryption: TLS/SSL protocols for secure transmission.
Access Controls: Role-based permissions and multi-factor authentication.
Firewalls and Intrusion Detection: Regular monitoring of network security.
Employee Training: Data protection and cybersecurity compliance programs.
3. Data Storage
All data is stored in secure cloud/datacenter environments ensuring compliance with PDPO standards.
Data transfers outside Hong Kong are protected by appropriate safeguards.
4. Incident Response
We maintain an incident response plan that includes prompt assessment, containment, and notification in the event of any data breach.
5. Continuous Improvement
Systems are regularly audited, and security measures are updated to reflect evolving threats.
Terms of Service
1. Introduction
By accessing or using our website, you agree to abide by these Terms of Service (“Terms”). If you do not agree, please discontinue use immediately.
2. Use of the Website
You agree to use the website only for lawful purposes and not to:
Upload or transmit malicious code or conduct activities that interfere with site operation.
Attempt unauthorized access to any part of our systems or networks.
We reserve the right to deny access, suspend accounts, or take legal action in response to violations.
3. Information Accuracy
While we make reasonable efforts to maintain accurate and updated content, we do not guarantee that all information is complete, reliable, or free of errors. The content provided is for general informational purposes only.
4. Security Disclaimer
Despite employing advanced security measures — including encryption, firewalls, and vulnerability monitoring — no system is completely secure. You acknowledge that:
We do not warrant that the website will be free of viruses, malware, or unauthorized third-party access.
We shall not be liable for any loss, damage, or exposure of information resulting from unauthorized access, data interception, or security breaches beyond our reasonable control.
We shall not be responsible for user-uploaded content or third-party integrations that may introduce vulnerabilities.
5. Indemnity
You agree to indemnify and hold responsible our company, its affiliates, directors, employees, and service providers harmless from any claims, damages, losses, or expenses (including legal costs) resulting from:
Your use or misuse of the website;
Your violation of these Terms;
Any security incidents, malware uploads, or script injections originating from your access point.
6. Limitation of Liability
To the maximum extent permitted by law:
We exclude all implied warranties and representations related to the website’s availability, performance, or security.
We will not be liable for any indirect, consequential, or incidental damages, including but not limited to data loss, service interruption, reputational harm, or financial losses arising from site use or breach.
7. Third-Party Services
Our site may contain third-party links or services. We do not control, endorse, or assume responsibility for their content or security practices. Use of such services is at your own risk.
8. Data Protection:
We comply with the PDPO and implement reasonable measures to protect user data. However, we disclaim liability for unauthorized access that occurs despite industry-standard safeguards.
9. Termination of Access
We may suspend or terminate user access without notice in cases of abuse, attempted exploitation, or potential harm to our digital infrastructure.
10. Governing Law
These Terms are governed by and construed in accordance with the laws of Hong Kong SAR and any country in which a user may be located.
11. Contact for legal or security concerns via the methods listed on this website.
12. Cross-Site Scripting (XSS) Disclaimer
12.1 Understanding XSS
Cross-Site Scripting (“XSS”) refers to a cybersecurity vulnerability where an attacker injects or executes malicious scripts (typically JavaScript) within a legitimate website or application.
Such scripts may manipulate website content, impersonate users, or collect session tokens, personal information, or cookies from visitors.
12.2 Risk Acknowledgment
While we implement industry-standard input sanitization, content security policies, and real-time monitoring to mitigate XSS vulnerabilities, it is technically impossible to guarantee absolute immunity from such attacks.
You acknowledge that:
Any website allowing user-generated input is inherently susceptible to limited XSS risk.
We are not liable for damages, data loss, unauthorized disclosures, or any consequences arising from cross-site scripting incidents, whether caused directly or indirectly.
Your continued use of our platform constitutes acceptance of these risks.
12.3 User Responsibilities
You agree not to: Attempt to exploit, inject, or manipulate code on our website. Upload, transmit, or distribute any content designed to trigger a cross-site scripting event.
Users found engaging in such behavior will have access immediately revoked and may face civil or criminal liability.
12.4 Limitation of Liability
In the event of a cross-site scripting or similar code-injection attack that compromises your account, session, or data: We shall not be responsible for any losses, reputational harm, or indirect damages resulting from the incident.