1. Introduction and Scope
This Privacy Policy explains how Hei Faai Limited collects, uses, stores, shares and protects personal data when you visit our website at https://www.heifaai.mom, when you send us an enquiry, and when you take part in a commercial engagement with our house. It applies to every visitor, enquirer, client, prospective client, supplier and partner who interacts with us through the website, by email, by telephone or in person at our office in Hong Kong.
The website and the services described on it are developed and operated by the independent developer HeiFaai on behalf of Hei Faai Limited, a company registered and domiciled in Hong Kong. By using this website or by providing personal data to us in any other way, you acknowledge the practices described in this Policy. If you do not agree with any part of it, please do not use the website or submit personal data through it.
This Policy is written in plain language because we believe that a privacy notice should be read, not merely published. Where any local law grants you rights that are broader than those described here, we will honour those rights to the extent required by the law that applies to you.
2. Who We Are
Hei Faai Limited is a heritage trading house engaged in computer integrated systems design consultancy, product trading, supplier coordination, market entry advisory, brand representation, logistics coordination and quality assurance. The company acts as the data controller for personal data collected through this website and through its commercial activities, which means that we decide how and why your personal data is processed.
Our registered office is located at Rm G06 SKY TWR, 38 SUNG WONG TOI RD, To Kwa Wan, Hong Kong (HK). You can reach our desk by email at service@heifaai.mom or by telephone at +18459167502 during Hong Kong business hours. If you have any question about this Policy or about the way we handle personal data, the contact details in section 18 will direct your message to the person responsible for privacy matters within the house.
Where we act as an agent or coordinator for a client or a supplier, the parties to the underlying commercial contract remain responsible for their own personal data and for their own compliance obligations. In those situations we may act as a processor, and our handling of data will follow the written instructions of the party that engaged us.
3. Information We Collect
We collect only the categories of personal data that are reasonably necessary to operate this website, to answer enquiries and to perform our trade and consultancy services. In general terms, the data we process falls into three groups: information you choose to give us, information collected automatically when you browse, and information generated during the course of a commercial engagement.
We do not seek special category data such as information about your health, your racial or ethnic origin, your political opinions, your religious beliefs, your trade union membership, your genetic data or your biometric data. We also do not request criminal records. If you send such information to us voluntarily, we will treat it with additional care and will retain it only for as long as the underlying purpose requires.
We ask that you do not send us confidential commercial documents through the public enquiry form. Sensitive transaction papers, price lists under embargo and technical drawings should be exchanged by direct email after an engagement has been confirmed, so that the protection described in our confidentiality practices can apply from the first exchange.
4. Information You Provide to Us
When you complete the enquiry form on our contact page, we receive the name, email address, subject and message that you submit. When you correspond with us by email or telephone, we receive the identity and contact details you provide together with the content of the correspondence. When a commercial engagement begins, we collect the information needed to perform it, which may include the name of your organisation, your role, your billing address, your delivery addresses, your tax registration details and the identities of your authorised representatives.
Suppliers and logistics partners who join our network provide company registration details, banking details for settlement of invoices, product information, certification documents and the contact details of the individuals who manage the account. Clients provide similar information on the buy side, together with specification documents, order records and shipment instructions.
We use this information solely for the purposes described in section 7 of this Policy. We do not use enquiry submissions to build marketing profiles, and we do not enrich your data with information purchased from third-party brokers. What you give us is used for the matter at hand and kept under the retention rules described in section 11.
5. Information Collected Automatically
Like most websites, ours records certain technical information automatically when you visit. This includes your internet protocol address, the type and version of your browser, the type of device you use, the operating system, the pages you view, the date and time of each visit, the page that referred you to us and general indicators of your approximate region derived from your network address.
This automatic information helps us to keep the website secure, to diagnose faults, to understand which pages are useful and to plan improvements. It is processed in aggregate form wherever possible, and it is not merged with advertising profiles held by third parties. We do not use it to attempt to identify you personally unless that becomes necessary to investigate a security incident or to comply with a legal obligation.
If you prefer to reduce the amount of technical data collected while you browse, you can disable cookies in your browser as described in section 6, use the privacy features of your operating system and avoid submitting form data unless you wish to contact us. The website remains fully readable with cookies disabled, because it does not place content behind a consent gate.
7. How We Use Information
We use the personal data described in this Policy for the following purposes: to respond to enquiries and provide quotations; to perform the trading, advisory and coordination services described on our services page; to manage accounts, orders, shipments, inspections and invoices; to maintain our supplier and client networks; to protect the security of the website and our records; to comply with tax, customs, accounting and other legal obligations; and to improve the website and the way we describe our services.
We do not sell personal data. We do not rent personal data. We do not trade in contact lists, and we do not disclose client information to other clients. Commercial information about one engagement is never used to inform the pricing of another, because discretion is part of the craft of a trading house.
Where we intend to process personal data for a new purpose that is not covered by this Policy, we will explain that purpose before the processing begins and, where required, seek your consent. Any processing that depends on consent can be withdrawn at any time by writing to service@heifaai.mom, and withdrawal will not affect the lawfulness of processing carried out before the withdrawal.
8. Legal Bases for Processing
Where the law of a jurisdiction requires us to identify a legal basis for each use of personal data, we rely on the following grounds. Performance of a contract covers the handling of client, supplier and shipment information needed to deliver the services you have engaged. Legitimate interests covers the security of the website, the maintenance of our business records and the improvement of our services, always balanced against your expectations and rights.
Consent covers optional communications such as newsletters or invitations to trade fairs, and you may withdraw that consent at any time. Compliance with a legal obligation covers record keeping required by tax and accounting rules in Hong Kong, responses to lawful requests from public authorities and the retention of transaction documents under commercial law.
In Hong Kong, the Personal Data (Privacy) Ordinance sets out data protection principles that we follow as a matter of practice: collection for a lawful and directly related purpose, accuracy and duration limits on retention, openness about our policies, and security safeguards proportionate to the data we hold. Where you are located in another jurisdiction, the local requirements that apply to the transfer and processing of your data are observed in addition to these principles.
10. International Transfers of Data
Because our trade crosses borders, personal data may be processed in jurisdictions other than Hong Kong. Email and hosting infrastructure may be located abroad, and shipment documents naturally travel with the goods to the destinations our clients request. When data leaves Hong Kong, we take steps to ensure that it receives an adequate level of protection wherever it goes.
Those steps include selecting reputable providers with published security practices, applying contractual safeguards with recipients, limiting the data transferred to the minimum necessary for the task, and using secure transmission channels such as encrypted connections. Where a client or supplier is located in a jurisdiction that imposes specific transfer conditions, we observe those conditions as part of the engagement.
If you would like to know more about the safeguards we apply to transfers that concern you, please write to service@heifaai.mom and we will describe the measures in place for your matter in terms that are specific enough to be meaningful, while preserving the confidentiality of other clients.
11. Data Retention
We keep personal data only as long as the purpose for which it was collected requires and only for the period that law or prudent commercial practice demands. Enquiry correspondence that does not lead to an engagement is normally kept for twenty-four months so that we can respond sensibly if the conversation resumes, after which it is deleted.
Records connected to completed engagements, including contracts, invoices, shipment documents and inspection reports, are retained for seven years after the end of the financial year in which the engagement closed, in line with Hong Kong accounting practice and the limitation periods that apply to commercial claims. Supplier and client account records are kept for the duration of the relationship and for the same seven-year period afterwards.
Aggregate analytics data is kept for no more than twenty-six months. When personal data reaches the end of its retention period it is deleted securely or, where deletion is impractical in a backup, it is isolated from active use until the backup is replaced. Deletion requests received under section 14 are honoured in line with the same rules, subject to the legal duties that require us to keep certain records.
12. Data Security
We apply technical and organisational measures that are proportionate to the data we hold. Access to client, supplier and engagement records is limited to the coordinators and advisers who need it for their work. Devices used by the house are protected with strong authentication, disk encryption and current security updates. Data in transit over public networks is protected with encryption, and access to our email and document stores requires verified accounts.
Staff and contractors are reminded at regular intervals of the confidentiality duties that come with trade information, and new collaborators are briefed on these expectations before access is granted. Paper documents containing personal data are stored in locked storage at our office in To Kwa Wan and are destroyed by secure shredding when their retention period ends.
No method of transmission or storage can be guaranteed as completely secure, and we do not pretend otherwise. We do, however, commit to notifying affected individuals and, where required, the relevant authorities, if a breach of personal data occurs, and to doing so without undue delay once the facts are established.
13. Privacy for Children
Our website and our services are directed to businesses and adults engaged in commerce. They are not directed to children, and we do not knowingly collect personal data from children below the age of thirteen. The enquiry form, the telephone line and the advisory desk all exist to serve commercial counterparties rather than young visitors.
If a child below that age has sent personal data to us, a parent or guardian may write to service@heifaai.mom and request its deletion. We will verify the request, delete the data and confirm the deletion. If we learn that we have collected such data through the website without the consent of a parent or guardian, we will delete it on our own initiative.
Young people who are curious about trade and about how a trading house works are welcome to read the public pages of this site, which describe our craft without requiring any submission of personal information at all.
14. Your Rights and Choices
Subject to the law that applies to you, you have the right to ask whether we hold personal data about you, to request a copy of that data, to ask us to correct data that is inaccurate, to ask us to delete data that we no longer need, to object to processing based on our legitimate interests, and to withdraw consent that you have previously given. Where processing is based on consent and the data is held electronically, you may also ask us to provide the data in a portable form.
To exercise any of these rights, write to service@heifaai.mom from the email address connected to your enquiry or engagement, or write to us at Rm G06 SKY TWR, 38 SUNG WONG TOI RD, To Kwa Wan, Hong Kong (HK). We will acknowledge your request, verify your identity where necessary to protect your data from disclosure to the wrong person, and respond within the period required by the applicable law.
We will not refuse a request lightly. If we cannot fulfil a request in full, for example because a legal duty requires us to keep certain transaction records, we will explain the specific reason, fulfil the request to the extent possible and tell you how to challenge our decision if you disagree with it.
15. Marketing Communications
We send marketing communications, such as occasional notes about new trade categories, changes to our services or invitations to meet at a fair, only where you have asked to receive them or where the law permits us to send them to existing business contacts. Every such message identifies Hei Faai Limited clearly and includes a simple way to opt out.
You can stop marketing messages at any time by replying to the message with the word unsubscribe, by writing to service@heifaai.mom, or by using any unsubscribe control included in the message. An opt-out request is honoured promptly and does not affect service messages connected to an active engagement, such as shipment notices or invoice reminders, which are part of the service rather than marketing.
We keep a short suppression record of people who have opted out so that we do not disturb them again. That record contains the minimum data needed to honour your choice and nothing more.
16. Links to Other Websites
Our website may contain links to third-party websites, such as the public sites of trade organisations, ports, customs authorities and partner institutions. Those websites have their own privacy policies, and this Policy does not extend to them. We encourage you to read the policy of any website you visit through one of our links.
We take reasonable care in choosing the destinations we link to, and we review links from time to time so that they remain relevant and trustworthy. However, we do not control external sites and cannot accept responsibility for their content or for their handling of personal data. If you believe that a link from our site leads to a page that behaves improperly, please tell us at service@heifaai.mom and we will review it.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, in technology or in the law. The version published on this page is always the current version, and the date at the top of the page shows when it last changed. Material changes, meaning changes that affect your rights or the way we use your data in a significant way, will be highlighted on the website or communicated directly where we hold your contact details in the course of an engagement.
Continued use of the website after a revised Policy takes effect means that you accept the revised version. If a change would require your consent under the applicable law, we will seek that consent rather than relying on continued use.
Earlier versions of this Policy are retained in our records so that we can evidence the terms that applied at any past date if a question ever arises about the handling of data in a previous period.
18. Contact Us
Questions, requests and complaints about privacy are welcomed, because they help us keep our standards honest. You can reach the house in any of the following ways. By post: Hei Faai Limited, Rm G06 SKY TWR, 38 SUNG WONG TOI RD, To Kwa Wan, Hong Kong (HK). By email: service@heifaai.mom. By telephone: +18459167502 during office hours, which are Monday to Friday from 9:00 to 18:00 Hong Kong Time, with Saturday meetings available by appointment.
If you are not satisfied with our response to a privacy concern, you may have the right to raise the matter with the privacy regulator in your jurisdiction, and in Hong Kong the relevant authority is the Office of the Privacy Commissioner for Personal Data. We would, however, always welcome the chance to resolve a concern directly and quickly at the counter before it goes further.