LEGAL
Privacy Policy
Last Updated: 28 March 2025 | Effective: 28 March 2025
1. Introduction
Tulloch Consulting Limited ("Tulloch", "we", "us", "our"), with registered office at 12/F, Champion Tower, 3 Garden Road, Central, Hong Kong, is committed to protecting the privacy of individuals who interact with our services, website, and enquiry processes.
This policy describes how we collect, use, store, and protect personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") of Hong Kong. If you have questions regarding this policy, please contact us at [email protected].
2. Data We Collect
We collect personal data in the following ways:
Contact and enquiry data
When you submit an enquiry through our website or contact us directly, we collect name, email address, telephone number, and the content of your message. This data is used to respond to your enquiry and to determine whether a consulting engagement may be appropriate.
Engagement data
When you engage Tulloch for consulting services, we collect and process additional personal and business data as necessary to deliver the agreed scope of work. This may include business performance data, organisational information, and employee-related data where relevant to the engagement.
Website usage data
We collect anonymised data about website visits through analytics tools. This includes page views, session duration, and general geographic region. This data does not identify individual visitors.
3. How We Use Personal Data
Personal data collected is used for the following purposes:
- Responding to enquiries and assessing engagement suitability
- Delivering contracted consulting services
- Maintaining records required for legal and contractual purposes
- Improving our website and service quality based on aggregated data
- Complying with applicable Hong Kong legal requirements
We do not use personal data for unsolicited marketing communications. We do not sell personal data to third parties under any circumstances.
4. Legal Basis for Processing
Under the PDPO, we process personal data on the following bases:
- Contractual necessity — where processing is required to perform consulting services under a signed engagement agreement
- Legitimate interest — where processing enquiry data is necessary to respond to a request made by you
- Legal obligation — where processing is required by applicable Hong Kong law
5. Data Retention
We retain personal data for no longer than is necessary for the purpose for which it was collected:
- Enquiry data where no engagement follows: deleted within 12 months of last contact
- Engagement-related data: retained for 7 years from engagement close, in accordance with standard business records requirements under Hong Kong law
- Website analytics data: aggregated and anonymised; no individual-level retention
6. Data Protection Measures
We apply the following measures to protect personal data:
- Data stored on access-controlled systems with encryption at rest
- Access limited to staff with a direct need to access the data
- All engagement data handled under confidentiality agreements
- Incident response procedures in place for data breach scenarios
7. Cookies
Our website uses cookies to understand how visitors interact with the site. For full details of the types of cookies used and your options for managing them, please refer to our Cookie Policy.
8. Third Parties
We may share personal data with the following categories of third party where necessary:
- Technology service providers (hosting, analytics) bound by appropriate data processing terms
- Legal and professional advisers where required for a specific matter
- Regulatory or law enforcement bodies where required by applicable Hong Kong law
We do not share personal data with any other third parties and do not transfer data outside Hong Kong except where necessary for a specific engagement and agreed in writing with the relevant client.
9. Your Rights
Under the PDPO, you have the following rights with respect to personal data we hold about you:
- Right of access — to obtain confirmation of whether we hold personal data about you and to request a copy
- Right to correction — to request correction of inaccurate personal data
- Right to object — to object to the use of your personal data for direct marketing purposes (we do not conduct such activities)
- Right to erasure — to request deletion of personal data where we have no ongoing legal or contractual basis to retain it
To exercise any of these rights, please contact [email protected]. We will respond within 40 days in accordance with PDPO requirements.
10. Supervisory Authority
If you believe your personal data has been handled in a manner inconsistent with this policy or your rights under the PDPO, you may lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (www.pcpd.org.hk).
11. Children's Privacy
Our services are directed at business organisations and are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors.
12. Policy Updates
We may update this policy from time to time. Material changes will be communicated via our website. The date at the top of this document indicates when the policy was most recently revised. Continued use of our website or services following notification of changes constitutes acceptance of the updated policy.
13. Contact
Data privacy enquiries should be directed to:
Tulloch Consulting Limited
12/F, Champion Tower, 3 Garden Road, Central, Hong Kong
Email: [email protected]
Telephone: +852 2891 6374