1. Scope and responsibility
This Notice applies when personal data is handled through trustcome.com, the TrustCome digital headquarters, the Public Legal Library, the Private Enquiry Office, authorised email channels, meetings, events, professional introductions, due-diligence processes, supplier or adviser engagement, and other interactions expressly linked to this Notice.
“TrustCome”, “we”, “us”, and “our” refer to the TrustCome office, entity, or authorised representative responsible for the relevant interaction. Pending completion of the formal operating structure, TrustCome Legal & Governance coordinates privacy enquiries from the Hong Kong contact address stated below. Where another TrustCome entity acts as the relevant data user or controller, additional information may be provided at the point of collection.
This Notice is a general transparency statement. A more specific notice, consent statement, contractual provision, regulatory notice, or secure-room notice may supplement or prevail over it for a particular activity.
2. Personal data we may collect
Depending on the interaction, personal data may include:
- Identity and contact information: name, title, business address, email address, telephone number, signature, preferred language, and contact preferences.
- Professional and organisational information: employer, position, authority, ownership or control information, professional history, qualifications, and relationship to a proposed matter.
- Enquiry and transaction information: the nature of an enquiry, project or mandate details, communications, meeting notes, documents supplied, proposed counterparties, and instructions.
- Compliance and due-diligence information: identification evidence, beneficial-ownership information, source-of-funds or source-of-wealth information, sanctions or politically exposed person screening results, and information needed to prevent fraud, corruption, money laundering, or other unlawful conduct.
- Technical and security information: IP address, browser and device information, access time, requested pages, routing information, security events, diagnostic data, and identifiers generated by essential website technologies.
- Communication and relationship records: correspondence, call details, authorised-channel records, event attendance, introductions, preferences, and records of approvals, objections, or consents.
- Public and third-party information: information from professional directories, corporate registers, sanctions lists, public authorities, advisers, counterparties, referees, or reputable public sources.
We aim to collect only information reasonably necessary for an identified purpose. We may decline or delete information that is excessive, irrelevant, unlawfully obtained, or submitted through an unsuitable channel.
3. How personal data is obtained
We may obtain personal data:
- directly from you through a form, email, meeting, call, document, event, or authorised digital channel;
- from your organisation, authorised representative, adviser, introducer, referee, counterparty, or another person involved in a matter;
- from public registers, official lists, professional databases, sanctions and compliance providers, or other lawful public sources;
- automatically through essential server, security, and website-operation logs; and
- from service providers acting under instruction, such as hosting, communications, document-management, identity-verification, or security providers.
Where information is obtained from another source, we will provide appropriate privacy information when required, subject to lawful exceptions including where you already have the information, disclosure is legally prohibited, or providing it would involve disproportionate effort and suitable safeguards are applied.
4. Purposes and lawful grounds
We may use personal data to:
- operate, secure, maintain, and improve the website and digital headquarters;
- receive, authenticate, route, assess, respond to, or decline enquiries;
- evaluate proposed mandates, relationships, introductions, transactions, suppliers, advisers, or counterparties;
- perform identity, authority, conflict, sanctions, anti-money-laundering, anti-bribery, fraud, and reputational checks;
- establish, manage, document, and protect professional or contractual relationships;
- communicate about a matter, meeting, publication, service, security issue, or legal requirement;
- protect TrustCome, its personnel, visitors, counterparties, systems, assets, and legal rights;
- comply with law, regulation, court orders, professional duties, lawful government requests, and recordkeeping requirements;
- investigate concerns, preserve evidence, manage disputes, and establish, exercise, or defend legal claims; and
- carry out other compatible purposes described at the point of collection.
The applicable legal ground depends on the jurisdiction and activity. It may include your consent; steps requested before entering a contract; performance of a contract; compliance with a legal or regulatory duty; protection of vital interests; performance of a task in the public interest where applicable; or legitimate interests pursued by TrustCome or another person, balanced against your rights and interests.
Where consent is relied upon, it may be withdrawn for future processing. Withdrawal does not affect processing already lawfully carried out or processing supported by another lawful ground.
5. Voluntary and required information
Browsing public pages generally does not require you to identify yourself, although essential technical and security data may be generated automatically. Information requested in an enquiry or due-diligence process may be voluntary, contractually required, or legally required.
Mandatory fields should be identified at the point of collection. If required information is not supplied, we may be unable to authenticate you, assess or accept an enquiry, establish a secure channel, perform required checks, enter or perform a contract, or continue the relevant relationship.
6. Sensitive, regulated, and restricted data
Do not submit passports, identity cards, banking credentials, medical information, criminal-record information, biometric data, privileged documents, trade secrets, classified information, or highly sensitive transaction material through an ordinary public form or unsecured email unless TrustCome has expressly requested it and confirmed an authorised channel.
Where sensitive or specially protected data is necessary, we will seek to apply an appropriate legal condition, enhanced access restrictions, data minimisation, secure transmission, and additional retention or deletion controls. We may quarantine, return, restrict, or securely delete unsolicited sensitive material.
8. International processing and transfers
TrustCome’s activities and professional relationships may be international. Personal data may therefore be accessed, stored, reviewed, or transferred in Hong Kong, the United Kingdom, the European Economic Area, Switzerland, North or South America, or another jurisdiction connected with an authorised service provider, adviser, institution, counterparty, or matter.
Privacy laws and government-access rules differ between jurisdictions. Where required, we will use an available transfer mechanism or safeguard, which may include an adequacy decision, approved standard contractual clauses, a United Kingdom transfer mechanism, binding obligations, consent for a specific transfer, necessity for a contract or legal claim, or another lawful exception. We may also use encryption, access controls, transfer assessments, data minimisation, and contractual audit or deletion duties.
Information about the relevant safeguard may be requested using the contact details below, subject to confidentiality, security, and legal restrictions.
9. Retention and disposal
Personal data is retained only for as long as reasonably necessary for the purpose for which it was collected, compatible purposes, or a lawful institutional requirement. Retention is determined by factors including:
- the nature, sensitivity, volume, and risk of the information;
- whether an enquiry was accepted, declined, inactive, or converted into a continuing relationship;
- legal, regulatory, tax, accounting, audit, sanctions, anti-money-laundering, and professional recordkeeping duties;
- security, fraud-prevention, evidence-preservation, limitation-period, and dispute requirements;
- contractual obligations and the expectations of affected individuals; and
- whether the information can be securely deleted, anonymised, or aggregated.
A legal hold, investigation, regulatory request, threatened dispute, or security incident may require information to be retained beyond the ordinary period. When retention is no longer justified, data should be securely deleted, destroyed, anonymised, or placed beyond operational use.
10. Security and personal-data incidents
We seek to apply proportionate technical and organisational measures, including access restriction, authentication, secure configuration, encryption where appropriate, logging, backup controls, personnel duties, supplier controls, incident management, and secure disposal.
No internet transmission or storage system is completely secure. You should use only an authorised channel and avoid sending sensitive material through ordinary email. If we identify a personal-data incident, we will assess it, contain it, preserve relevant evidence, take corrective action, and notify affected individuals or authorities where legally required.
12. Automated tools and artificial intelligence
Approved automated or artificial-intelligence-assisted tools may support security monitoring, spam detection, routing, translation, transcription, document organisation, duplicate detection, compliance screening, or preliminary risk identification. Their use must remain subject to confidentiality, access, accuracy, human-oversight, and supplier controls.
TrustCome does not intend to make a decision producing legal or similarly significant effects solely by automated means without providing any notice, safeguards, or rights required by applicable law. Material acceptance, rejection, escalation, due-diligence, and relationship decisions should remain subject to meaningful human review.
13. Direct marketing and communications preferences
TrustCome may send operational, security, legal, or relationship communications where necessary. Promotional or direct-marketing communications should be sent only where permitted by applicable law and, where required, with consent.
You may object to or withdraw consent for direct marketing at any time by using an unsubscribe mechanism or contacting us. Such a request does not prevent essential non-marketing communications concerning an existing matter, legal obligation, security issue, or requested service.
14. Your privacy rights
Depending on the applicable law and circumstances, you may have rights to:
- receive information about how your personal data is handled;
- request confirmation of processing and access to your personal data;
- request correction or completion of inaccurate or incomplete data;
- request deletion, erasure, anonymisation, blocking, or restriction;
- object to particular processing, including direct marketing;
- request portability of information in an applicable format;
- withdraw consent for future processing;
- request review of a qualifying automated decision;
- opt out of a legally defined sale, sharing, or targeted-advertising activity;
- limit certain uses of sensitive personal information where the law provides; and
- complain to TrustCome or a competent privacy or supervisory authority.
Rights are not absolute. A request may be limited or refused where an exemption applies, identity cannot reasonably be verified, disclosure would adversely affect another person, information is protected by privilege or confidentiality, or retention is required by law or for a legal claim. We will explain a refusal where required.
To protect individuals and confidential matters, we may request information sufficient to verify identity, authority, jurisdiction, and the scope of the request. An authorised agent may be required to provide written proof of authority. We do not discriminate against an individual for exercising a privacy right protected by applicable law.
15. Regional privacy information
Hong Kong
Where the Personal Data (Privacy) Ordinance applies, individuals may request access to and correction of personal data and may opt out of direct marketing. Collection notices should identify the purposes of use, whether supply is obligatory or voluntary, the consequences of not supplying required data, and the classes of persons to whom data may be transferred.
European Economic Area and United Kingdom
Where European or United Kingdom data-protection law applies, additional rights may include erasure, restriction, objection, portability, withdrawal of consent, and complaint to the competent supervisory authority. Applicable legal grounds and international-transfer safeguards will be identified where required. United Kingdom requests and complaints will be handled in accordance with the UK GDPR, Data Protection Act 2018, and amendments in force.
Canada
Where Canadian private-sector privacy law applies, TrustCome will seek to maintain accountability, identify purposes, limit collection, use and retention, apply safeguards, remain open about practices, and provide access, correction, and a complaint process subject to lawful exceptions.
United States
Privacy rights differ by state and the legal thresholds for coverage vary. Where an applicable state law provides rights to know, access, correct, delete, opt out, limit sensitive-data use, appeal, or receive equal service, TrustCome will honour those rights to the extent required. TrustCome does not currently sell personal data or share it for cross-context behavioural advertising as those terms are commonly used in United States state privacy laws.
Brazil and other South American jurisdictions
Where Brazil’s Lei Geral de Proteção de Dados Pessoais applies, rights may include confirmation, access, correction, anonymisation, blocking, deletion, portability, information about sharing, withdrawal of consent, review of certain automated decisions, and petition to the competent authority. Other South American privacy laws may confer comparable rights, which will be addressed according to the law applicable to the particular interaction.
16. Children
TrustCome’s public website and institutional services are not directed to children. We do not knowingly seek personal data from a child through a general enquiry channel. If information concerning a child is required for a legitimate matter, it should be handled only through an authorised process with appropriate authority, necessity, safeguards, and regard for the child’s best interests.
A parent, guardian, or authorised person who believes a child’s information has been submitted improperly should contact us so that the circumstances can be assessed and appropriate action taken.
17. Third-party websites and services
The website may link to or use services controlled by third parties. Their privacy practices, security, and terms are governed by their own notices. A link or technical integration does not make TrustCome responsible for all processing performed independently by that third party.
Where a third party processes personal data on TrustCome’s instructions, TrustCome should seek appropriate contractual, confidentiality, security, retention, deletion, assistance, and audit protections proportionate to the risk and applicable law.
18. Changes to this Notice
This Notice may be revised to reflect changes in law, organisational structure, services, technologies, processing activities, or risk controls. The current version, publication date, and review date will be displayed on this page. Material new uses of personal data should be brought to affected individuals’ attention before the new use begins where required.
19. Contact, requests, and complaints
Privacy questions, rights requests, objections, or complaints may be sent through the TrustCome Private Enquiry Office
TrustCome Legal & GovernancePrivacy and Data Protection Enquiries
One International Finance Centre
1 Harbour View Street
Central, Hong Kong
Please write “Privacy Request” in the subject line and do not send identity documents or confidential matter files until a secure channel is confirmed. We will acknowledge and address requests within the period required by the law that applies, subject to permitted verification, clarification, extension, or refusal procedures.
We encourage you to contact TrustCome first so the issue can be investigated. Where applicable, you may also complain to the Privacy Commissioner for Personal Data in Hong Kong, the United Kingdom Information Commissioner, an EEA supervisory authority, the Office of the Privacy Commissioner of Canada, Brazil’s National Data Protection Authority, a competent United States state regulator, or another authority with jurisdiction.
Confidential enquiries: ordinary email is not an approved channel for passports, financial records, privileged documents, or highly sensitive transaction material. Use the Private Enquiry Office to request an authorised channel.