TC-LEGAL-004

Cookie Notice

This Notice explains how TrustCome uses cookies and other technologies that store information on, or access information from, a visitor’s device. It also explains the present deployment position, available controls, and the standards that apply before optional technologies may be activated.

Version
1.0 — Approved Public Version
Issued
1 August 2026
Effective
1 August 2026
Review date
31 August 2026

Deployment validation and change control. This approved Notice reflects the public Legal Library files supplied for review. Those pages do not contain third-party analytics, advertising, social-tracking, or embedded-media scripts. TrustCome must verify the live host, content-delivery network, security services, form endpoint, plugins, and technologies loaded elsewhere in the digital headquarters, and update this Notice if the deployed environment differs materially.

1. Scope

This Notice applies to trustcome.com, the TrustCome digital headquarters, the Public Legal Library, the Private Enquiry Office, and any other TrustCome-controlled digital property that links to this Notice. A secure room, application, event page, or third-party platform may provide a more specific technology notice where its configuration differs materially.

This Notice should be read with the TrustCome Privacy Notice and the Website Terms of Use. The Privacy Notice explains the wider handling of personal data; this Notice addresses storage and access technologies specifically.

2. What cookies and similar technologies are

A cookie is a small data file that a website may place on a browser or device. Similar technologies include local or session storage, pixels, tags, scripts, software development kits, device identifiers, cache identifiers, and other tools that store information on, or retrieve information from, a device.

Some technologies operate only for a browser session. Others may remain until they expire or are deleted. Some are controlled by the website being visited; others may be controlled by an integrated service provider.

3. Current TrustCome position

The reviewed Public Legal Library pages are static and do not intentionally deploy optional analytics, advertising, cross-site tracking, social-media tracking, or third-party embedded content. They contain no external script calls in the supplied build.

TrustCome’s wider digital environment may still generate ordinary hosting, security, routing, and diagnostic records, and a host or security provider may use a technology that is strictly necessary to deliver or protect a requested service. Those technologies must be verified against the live deployment, and this Notice must be updated if the deployed environment differs materially.

No optional tracking by default. Until TrustCome has an approved technology inventory and, where required, a functioning consent mechanism, non-essential analytics, advertising, personalisation, and social-tracking technologies should remain disabled on public pages.

4. Technology categories

Strictly necessary

These technologies support delivery of a service requested by the visitor, communications transmission, security, authentication, session integrity, load balancing, fraud prevention, or storage of a visitor’s privacy choice. They are not classified as necessary merely because they are convenient or commercially useful.

Preferences and functionality

These technologies remember choices such as language, accessibility, display settings, or workflow state. Consent or another choice mechanism may be required unless the technology is genuinely necessary for a feature specifically requested by the visitor.

Measurement and analytics

These technologies help measure availability, performance, navigation, errors, audience, and content use. Where deployed, they should minimise identifiers, avoid sensitive content, prevent unrelated cross-site use, apply proportionate retention, and follow applicable consent or exemption conditions.

Personalisation, advertising, and attribution

These technologies adapt content, build profiles, select or measure promotional material, or attribute conversions. TrustCome does not approve their use merely because a platform enables them by default. They require a documented purpose, legal assessment, provider review, and effective user controls before activation.

Embedded and social technologies

Video players, maps, document viewers, chat, scheduling, payment, social media, translation, and other embedded services may store or access device information when loaded. Optional embedded content should remain blocked or use a privacy-preserving mode until the required visitor choice is made.

5. Current technology register

The table below records the present position of the reviewed public Legal Library build. It is not a substitute for a live production scan and must be updated if the deployed environment differs.

Technology or activityPresent statusPurposeTypical durationChoice
Public Legal Library HTML and CSS Active Display approved legal pages and responsive layout. The supplied pages do not require a browser cookie for this function. Page request and browser cache settings Necessary to view the requested page
Hosting, network, and security logs To be verified live Delivery, traffic routing, availability, misuse prevention, diagnostics, and incident investigation. Server logs are not necessarily cookies. Provider and security retention settings May be necessary for delivery and security
Essential session or security storage If deployed Session integrity, form protection, authentication, load balancing, consent storage, or fraud prevention. Session or limited operational period May be necessary for the requested service
Analytics and measurement Not active in reviewed Legal Library Potential future aggregate performance and service-improvement measurement. Not applicable Must follow applicable consent or exemption rules before activation
Advertising, profiling, or cross-site attribution Not active No present approved purpose for the reviewed public legal pages. Not applicable Would require prior governance approval and applicable consent or opt-out controls
Third-party social or media embeds Not active in reviewed Legal Library No present embedded service in the reviewed pages. Not applicable Would be blocked or privacy-preserving until the required choice

7. Third-party services

A third-party provider may supply hosting, security, communications, scheduling, mapping, document viewing, media, analytics, payments, or other functions. Before a provider that uses storage or access technologies is enabled, TrustCome should assess its purpose, configuration, data use, retention, locations, onward transfers, security, sub-processors, and available privacy controls.

A provider’s default configuration does not determine TrustCome’s legal category or justify activation. TrustCome remains responsible for deciding whether and how a technology is used on a TrustCome-controlled property.

8. Server logs and technical data

A website host, network, firewall, or security provider may record IP address, request time, requested page, browser or device information, response status, referrer, error data, and security events. These records may be generated without placing an optional browser cookie.

Technical data should be limited to legitimate operational and security purposes, protected against unauthorised access, retained only for a justified period, and handled in accordance with the Privacy Notice.

9. Browser and device controls

Most browsers and devices allow visitors to inspect, block, or delete cookies and other stored data. Private-browsing modes may limit persistence. Blocking a strictly necessary technology can prevent a requested form, authentication step, preference, or security function from operating.

Browser controls are separate from a TrustCome Cookie Settings interface. A visitor may need to repeat a choice after clearing storage, changing browser or device, using a private session, or visiting another domain.

10. Global privacy and opt-out signals

Browser signals such as Global Privacy Control or Do Not Track do not have uniform legal or technical effect in every jurisdiction. Where applicable law requires TrustCome to recognise a valid signal for a regulated activity, TrustCome should implement and document the required response. Visitors may also communicate a specific privacy objection through the contact channel below.

11. International processing and transfers

Hosting and technology providers may process technical information in more than one jurisdiction. Where that information is personal data, TrustCome should apply the international-transfer safeguards, provider controls, and regional information described in the Privacy Notice and required by the law that applies to the relevant activity.

12. Retention

A cookie or similar technology should not remain active longer than reasonably necessary for its stated purpose. Session technologies should ordinarily end with the session. Persistent technologies require a defined duration, and providers should not renew them automatically without a documented reason.

Consent and preference records may be retained long enough to enforce and evidence a visitor’s choice, subject to minimisation and periodic review.

13. Security

TrustCome should use appropriate cookie attributes, transport security, domain and path restrictions, access controls, controlled expiry, provider safeguards, and revocation mechanisms where relevant. Identifiers must not contain readable passwords, payment credentials, confidential document content, or other highly sensitive information.

A misconfigured tag, consent bypass, uncontrolled provider call, or exposed identifier may constitute a privacy or security incident and should be contained, investigated, documented, and remediated.

14. Children

TrustCome’s public website is not designed to profile children through optional tracking. If a digital service is likely to be used by children or vulnerable persons, TrustCome should apply heightened transparency, minimisation, age-appropriate design, and consent or parental-authority requirements where applicable.

15. Changes to this Notice

This Notice may be revised when TrustCome changes its website, providers, technologies, purposes, legal obligations, or consent configuration. The current version and issue date will appear on this page. A material change that affects an existing visitor choice should be addressed before the new technology or purpose is activated.

16. Contact and complaints

Questions about cookies, tracking, technology choices, or suspected preference failures may be sent through the TrustCome Private Enquiry Office.

TrustCome Legal & Governance
Privacy and Technology Enquiries

One International Finance Centre
1 Harbour View Street
Central, Hong Kong

Please write “Cookie or Tracking Enquiry” in the subject line and identify the page, approximate time, browser or device, and the choice or behaviour observed. Do not send passwords, identity documents, financial records, or confidential matter files through ordinary email.

Where applicable, a visitor may also complain to a competent privacy, communications, or consumer-protection authority. TrustCome encourages the visitor to contact us first so the configuration can be investigated and corrected where necessary.