Privacy Policy.
01Scope
This Privacy Policy describes how Netser Holdings Limited and its operating subsidiaries (collectively, “Netser,” “we”) collect, use, retain, and protect personal information. It applies to all interactions with our websites, client portal, and direct services.
Where local law (such as the EU GDPR, UK GDPR, California Consumer Privacy Act, or Hong Kong PDPO) imposes additional requirements, those requirements supplement this policy and prevail in case of conflict.
02Data Controller
The data controller is:
Netser Holdings Limited
One Exchange Square, 8 Connaught Place, Central
Hong Kong SAR
[email protected]
For data processing activities specific to a regional subsidiary, the relevant entity is identified at the point of collection. Our designated EU representative for GDPR Article 27 purposes is available on request.
03Information We Collect
We collect only what we need to operate our services, comply with our obligations, and improve our offerings:
- Identity & contact data — name, business email, organization, role, jurisdiction, when you contact us or hold an account.
- Account data — credentials, authentication state, account preferences, tier, and entitlements held in our client portal.
- Communications data — the content of inquiries, support tickets, and official correspondence.
- Operational data — logs of actions taken in our systems, IP addresses, user-agent strings, and timestamps required for security and audit.
- Marketing data — subscription preferences for press, investor updates, or research output.
We do not knowingly collect data from children, and our services are not directed to individuals under 18.
04How We Use Your Information
We use personal information for purposes that include:
- Operating, maintaining, and securing our services;
- Authenticating and authorizing client portal access;
- Processing inquiries and providing requested information;
- Meeting regulatory, audit, and contractual obligations;
- Detecting, investigating, and preventing fraud, abuse, or security threats;
- Sending limited operational communications and (where you have opted in) editorial updates.
We do not sell personal information. We do not use personal information to train external machine-learning models without an explicit, separately documented agreement.
05Lawful Bases for Processing
Where European or UK law applies, we rely on the following lawful bases under GDPR Article 6:
- Performance of a contract — for client account, support, and service delivery.
- Legal obligation — for tax, audit, anti-money-laundering, and other regulatory requirements.
- Legitimate interests — for security monitoring, fraud prevention, and limited operational communications, balanced against data subject interests.
- Consent — for editorial subscriptions and any non-essential cookies, withdrawable at any time.
06Data Retention
We retain personal data only as long as necessary for the purpose it was collected, plus the period required by law:
- Inquiry data: 36 weeks from last contact, unless an active matter requires longer retention.
- Client account data: for the duration of the account plus 7 years for audit and contractual records.
- Subscriber data: until unsubscribe; suppression list retained indefinitely to honor opt-outs.
- Operational and security logs: 13 months rolling, except for incident-related logs which may be retained longer.
07International Transfers
Netser operates across multiple jurisdictions. Where personal data crosses borders, we rely on:
- European Commission adequacy decisions where available;
- Standard Contractual Clauses (SCCs) supplemented by appropriate technical and organizational measures;
- Binding Corporate Rules where established between our subsidiaries;
- Data residency commitments contractually pinned to specific Cloud Grid regions, where requested.
A current list of jurisdictions in which we host or process personal data is available in our Sovereignty Disclosure Register.
08Your Rights
Depending on your jurisdiction, you may have the right to:
- Request access to the personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request erasure (subject to legal retention requirements);
- Restrict or object to certain processing activities;
- Receive your data in a portable format;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with your supervisory authority.
To exercise any of these rights, contact [email protected]. We will verify your identity and respond within statutory timeframes.
10Security
Personal data is protected by technical and organizational measures appropriate to its sensitivity, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256-GCM);
- Strict role-based access control with least-privilege defaults;
- Audit logging on every privileged action against personal data;
- Independent annual security assessments and SOC 2 Type II review;
- Documented incident-response procedures with statutory notification timelines.
11Contact
For all privacy-related matters, contact our Data Protection Officer:
Office of the DPO
Netser Holdings Limited
[email protected]
This policy may be updated from time to time. We will publish a new effective date and version at the top of this page when material changes are made; subscribed clients receive notice in advance.