This policy explains how UniTrade Group Limited (“UniTrade”, “we”, “us”) collects, uses and protects personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (“PDPO”) and its six Data Protection Principles. If you visit this site from the European Union or the United Kingdom, the GDPR / UK GDPR additionally apply and we provide an equivalent level of protection.
1. Data User (Controller)
UniTrade Group Limited
Unit G15, Tin Hau Apple SOLO, 14 Kings Road, Tin Hau, Hong Kong
Company Registration No. 78405604
Email: [email protected]
2. Personal Data We Collect
We collect the minimum data needed to respond to business enquiries and to deliver our sourcing services:
- Identification data: name, job title, company.
- Contact data: work email, phone number, business address.
- Enquiry data: the content of your message, product categories, quantities, target markets and timelines you share with us.
- Technical data: IP address, browser type, pages visited — for security and aggregate analytics only.
3. Sensitive Data and Children
We do not ask for or intentionally collect sensitive personal data such as health, biometric, genetic, criminal-record, religious or identity-card data. Athlete-support enquiries are handled at a business level; please do not send medical information through this site. The site is intended for adult business clients and we do not knowingly collect personal data from anyone under 18. If we discover that such data has reached us inadvertently, it will be deleted without delay.
4. Purposes and Lawful Basis
In line with Data Protection Principle 1 (DPP1) we collect data only for lawful purposes directly related to our business, and under DPP3 we use it only for those purposes (or directly related ones) unless you give prescribed consent.
| Data category | Purpose | Basis (GDPR, where applicable) |
|---|---|---|
| Identification + contact + enquiry | Respond to enquiries, prepare proposals, source suppliers, manage orders and after-sale support. | Contract / pre-contract steps (Art. 6(1)(b)) |
| Invoices + transaction records | Accounting and tax records required by Hong Kong law. | Legal obligation (Art. 6(1)(c)) |
| Technical data (IP, logs, browser) | Site security, abuse prevention, aggregate analytics. | Legitimate interest (Art. 6(1)(f)) |
| Non-essential cookies | Only after explicit opt-in via the cookie banner. | Consent (Art. 6(1)(a)) |
5. Direct Marketing
We do not use your personal data for direct marketing, and we do not provide it to others for direct marketing, unless you have given your express consent as required by Part 6A of the PDPO. You may withdraw that consent at any time by emailing [email protected], free of charge.
6. Retention Period
Under DPP2 we keep personal data no longer than necessary for the purpose it was collected for:
- Enquiries and business correspondence — 3 years from the last message.
- Invoices and transaction records — 7 years (Inland Revenue Ordinance s. 51C; Companies Ordinance, Cap. 622).
- Technical logs — 12 months.
- Cookie consent records — 6 months from the last acceptance.
7. Disclosure to Third Parties (Processors)
We do not sell personal data. We share it only with service providers that process it on our behalf, under contracts that require them to protect it (PDPO s. 65(2) and DPP2(3) / DPP4(2)):
| Recipient | Purpose | Location |
|---|---|---|
| Website hosting provider | Hosting of this site and its server logs. | Outside Hong Kong |
| Google LLC (Gmail, Google Fonts) | Business email inbox; delivery of web fonts (your IP address is sent to Google when fonts load). | USA |
| Verified manufacturers, suppliers and wellness partners | Only the details needed to fulfil a specific sourcing request you asked us to handle. | Asia / EU |
| Logistics providers and freight forwarders | Delivery address, name, phone — for shipping. | International |
| Hong Kong authorities (e.g. Inland Revenue Department) | Where disclosure is required by law. | Hong Kong |
8. Cross-border Transfers
Because we source across Asia and the EU, some recipients above are located outside Hong Kong. We transfer data only where it is needed for the purposes above and take reasonable steps — including contractual safeguards consistent with the PCPD’s Recommended Model Contractual Clauses and, for EU/UK data, the Standard Contractual Clauses — to ensure it receives protection comparable to that under the PDPO and GDPR.
9. Your Rights
Under the PDPO (DPP6, ss. 18 and 22) you have the right to:
- Ask whether we hold personal data about you and receive a copy (data access request).
- Ask us to correct data that is inaccurate.
- Be informed of our policies and practices on personal data and the kinds of data we hold.
- Withdraw consent to direct marketing or to non-essential cookies at any time.
If the GDPR / UK GDPR applies to you, you also have the right to:
- Erase your data, subject to lawful retention periods.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Lodge a complaint with your local supervisory authority.
Contact [email protected] to exercise these rights. We respond to data access and correction requests within 40 days, as required by the PDPO. We may charge a fee for a data access request that is not excessive, as permitted by s. 28 of the PDPO. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (www.pcpd.org.hk).
10. Security
In line with DPP4 we use TLS for all data transfers, restrict access to staff who need it for their work, and select service providers that maintain recognised security standards. In the event of a data breach that poses a real risk of harm, we will notify affected individuals and the Privacy Commissioner as soon as practicable.
11. Changes to this Policy
We may update this policy from time to time. The effective date at the top reflects the latest revision. When a change is material, the consent banner is shown again so you can review and accept the updated policy.
Questions?
Email [email protected].