1. Scope
This Notice applies to trustcome.com, the TrustCome digital headquarters, the Public Legal Library, the Private Enquiry Office, and any other TrustCome-controlled digital property that links to this Notice. A secure room, application, event page, or third-party platform may provide a more specific technology notice where its configuration differs materially.
This Notice should be read with the TrustCome Privacy Notice and the Website Terms of Use. The Privacy Notice explains the wider handling of personal data; this Notice addresses storage and access technologies specifically.
2. What cookies and similar technologies are
A cookie is a small data file that a website may place on a browser or device. Similar technologies include local or session storage, pixels, tags, scripts, software development kits, device identifiers, cache identifiers, and other tools that store information on, or retrieve information from, a device.
Some technologies operate only for a browser session. Others may remain until they expire or are deleted. Some are controlled by the website being visited; others may be controlled by an integrated service provider.
3. Current TrustCome position
The reviewed Public Legal Library pages are static and do not intentionally deploy optional analytics, advertising, cross-site tracking, social-media tracking, or third-party embedded content. They contain no external script calls in the supplied build.
TrustCome’s wider digital environment may still generate ordinary hosting, security, routing, and diagnostic records, and a host or security provider may use a technology that is strictly necessary to deliver or protect a requested service. Those technologies must be verified against the live deployment, and this Notice must be updated if the deployed environment differs materially.
No optional tracking by default. Until TrustCome has an approved technology inventory and, where required, a functioning consent mechanism, non-essential analytics, advertising, personalisation, and social-tracking technologies should remain disabled on public pages.
4. Technology categories
Strictly necessary
These technologies support delivery of a service requested by the visitor, communications transmission, security, authentication, session integrity, load balancing, fraud prevention, or storage of a visitor’s privacy choice. They are not classified as necessary merely because they are convenient or commercially useful.
Preferences and functionality
These technologies remember choices such as language, accessibility, display settings, or workflow state. Consent or another choice mechanism may be required unless the technology is genuinely necessary for a feature specifically requested by the visitor.
Measurement and analytics
These technologies help measure availability, performance, navigation, errors, audience, and content use. Where deployed, they should minimise identifiers, avoid sensitive content, prevent unrelated cross-site use, apply proportionate retention, and follow applicable consent or exemption conditions.
Personalisation, advertising, and attribution
These technologies adapt content, build profiles, select or measure promotional material, or attribute conversions. TrustCome does not approve their use merely because a platform enables them by default. They require a documented purpose, legal assessment, provider review, and effective user controls before activation.
Embedded and social technologies
Video players, maps, document viewers, chat, scheduling, payment, social media, translation, and other embedded services may store or access device information when loaded. Optional embedded content should remain blocked or use a privacy-preserving mode until the required visitor choice is made.
5. Current technology register
The table below records the present position of the reviewed public Legal Library build. It is not a substitute for a live production scan and must be updated if the deployed environment differs.
| Technology or activity | Present status | Purpose | Typical duration | Choice |
|---|---|---|---|---|
| Public Legal Library HTML and CSS | Active | Display approved legal pages and responsive layout. The supplied pages do not require a browser cookie for this function. | Page request and browser cache settings | Necessary to view the requested page |
| Hosting, network, and security logs | To be verified live | Delivery, traffic routing, availability, misuse prevention, diagnostics, and incident investigation. Server logs are not necessarily cookies. | Provider and security retention settings | May be necessary for delivery and security |
| Essential session or security storage | If deployed | Session integrity, form protection, authentication, load balancing, consent storage, or fraud prevention. | Session or limited operational period | May be necessary for the requested service |
| Analytics and measurement | Not active in reviewed Legal Library | Potential future aggregate performance and service-improvement measurement. | Not applicable | Must follow applicable consent or exemption rules before activation |
| Advertising, profiling, or cross-site attribution | Not active | No present approved purpose for the reviewed public legal pages. | Not applicable | Would require prior governance approval and applicable consent or opt-out controls |
| Third-party social or media embeds | Not active in reviewed Legal Library | No present embedded service in the reviewed pages. | Not applicable | Would be blocked or privacy-preserving until the required choice |
6. Consent and preference controls
Where the law requires consent before a technology is stored or accessed, the technology should remain inactive until the visitor makes a valid choice. A valid choice should be informed, specific, freely given where required, capable of withdrawal, and implemented technically rather than merely recorded.
If optional technologies are introduced, TrustCome should provide a visible Cookie Settings control that allows visitors to accept or reject categories with comparable ease and to change their choice later. Rejecting optional technologies should not prevent access to public legal information.
7. Third-party services
A third-party provider may supply hosting, security, communications, scheduling, mapping, document viewing, media, analytics, payments, or other functions. Before a provider that uses storage or access technologies is enabled, TrustCome should assess its purpose, configuration, data use, retention, locations, onward transfers, security, sub-processors, and available privacy controls.
A provider’s default configuration does not determine TrustCome’s legal category or justify activation. TrustCome remains responsible for deciding whether and how a technology is used on a TrustCome-controlled property.
8. Server logs and technical data
A website host, network, firewall, or security provider may record IP address, request time, requested page, browser or device information, response status, referrer, error data, and security events. These records may be generated without placing an optional browser cookie.
Technical data should be limited to legitimate operational and security purposes, protected against unauthorised access, retained only for a justified period, and handled in accordance with the Privacy Notice.
9. Browser and device controls
Most browsers and devices allow visitors to inspect, block, or delete cookies and other stored data. Private-browsing modes may limit persistence. Blocking a strictly necessary technology can prevent a requested form, authentication step, preference, or security function from operating.
Browser controls are separate from a TrustCome Cookie Settings interface. A visitor may need to repeat a choice after clearing storage, changing browser or device, using a private session, or visiting another domain.
10. Global privacy and opt-out signals
Browser signals such as Global Privacy Control or Do Not Track do not have uniform legal or technical effect in every jurisdiction. Where applicable law requires TrustCome to recognise a valid signal for a regulated activity, TrustCome should implement and document the required response. Visitors may also communicate a specific privacy objection through the contact channel below.
11. International processing and transfers
Hosting and technology providers may process technical information in more than one jurisdiction. Where that information is personal data, TrustCome should apply the international-transfer safeguards, provider controls, and regional information described in the Privacy Notice and required by the law that applies to the relevant activity.
12. Retention
A cookie or similar technology should not remain active longer than reasonably necessary for its stated purpose. Session technologies should ordinarily end with the session. Persistent technologies require a defined duration, and providers should not renew them automatically without a documented reason.
Consent and preference records may be retained long enough to enforce and evidence a visitor’s choice, subject to minimisation and periodic review.
13. Security
TrustCome should use appropriate cookie attributes, transport security, domain and path restrictions, access controls, controlled expiry, provider safeguards, and revocation mechanisms where relevant. Identifiers must not contain readable passwords, payment credentials, confidential document content, or other highly sensitive information.
A misconfigured tag, consent bypass, uncontrolled provider call, or exposed identifier may constitute a privacy or security incident and should be contained, investigated, documented, and remediated.
14. Children
TrustCome’s public website is not designed to profile children through optional tracking. If a digital service is likely to be used by children or vulnerable persons, TrustCome should apply heightened transparency, minimisation, age-appropriate design, and consent or parental-authority requirements where applicable.
15. Changes to this Notice
This Notice may be revised when TrustCome changes its website, providers, technologies, purposes, legal obligations, or consent configuration. The current version and issue date will appear on this page. A material change that affects an existing visitor choice should be addressed before the new technology or purpose is activated.
16. Contact and complaints
Questions about cookies, tracking, technology choices, or suspected preference failures may be sent through the TrustCome Private Enquiry Office.
TrustCome Legal & GovernancePrivacy and Technology Enquiries
One International Finance Centre
1 Harbour View Street
Central, Hong Kong
Please write “Cookie or Tracking Enquiry” in the subject line and identify the page, approximate time, browser or device, and the choice or behaviour observed. Do not send passwords, identity documents, financial records, or confidential matter files through ordinary email.
Where applicable, a visitor may also complain to a competent privacy, communications, or consumer-protection authority. TrustCome encourages the visitor to contact us first so the configuration can be investigated and corrected where necessary.