1. Introduction

SINPAR TECHNOLOGY LIMITED (referred to as SINPAR TECHS, we, us, or our) is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at www.sinpar.autos (the Site) and when you engage our computer systems design, integration, and consulting services.

We are a company registered in Hong Kong with our registered office at Rm S239 2/F The Capital, 61-65 Chatham Road South, Tsim Sha Tsui, Kowloon, Hong Kong. As a company providing professional, scientific, and technical services in the computer systems design sector, we recognise the importance of handling personal data responsibly. Developed by SINPAR TECHS, this policy reflects our commitment to data protection principles and compliance with applicable privacy laws, including the Personal Data (Privacy) Ordinance of Hong Kong and the General Data Protection Regulation where it applies to our services involving European data subjects.

Please read this policy carefully to understand our views and practices regarding your personal data and how we will treat it. By using our Site or engaging our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, you should not use our Site or provide your personal information to us.

2. Information We Collect

We collect several types of information from and about users of our Site and recipients of our services. This information helps us improve our service delivery, communicate effectively with clients and prospects, and maintain the security of our systems.

2.1 Information You Provide Directly

When you fill out forms on our Site, submit enquiries, request proposals, or communicate with us through email or telephone, we collect the information you provide. This typically includes your full name, email address, telephone number, company name, job title, and details about your organisation's technology requirements. If you enter into a service agreement with us, we may collect additional business information such as billing addresses, payment details, and authorised representative contact information necessary for contract administration and service delivery.

2.2 Information Collected Automatically

When you visit our Site, we automatically collect certain technical information about your device and usage patterns. This includes your internet protocol (IP) address, browser type and version, operating system, referring URLs, pages viewed on our Site, the date and time of each visit, and the duration of your session. We use this information for system administration, to analyse usage trends, and to improve the functionality and user experience of our Site. This data is aggregated where possible and is not typically linked to individual user identities unless necessary for security investigations.

2.3 Information from Third Parties

In certain circumstances, we may receive information about you from third-party sources. This occurs when a client organisation provides us with contact details for their employees or representatives as part of an engagement, when we use credit reference agencies for due diligence purposes, or when we obtain publicly available information to verify business credentials. When we receive such information, we take steps to ensure that it was collected and shared in compliance with applicable data protection laws.

3. How We Use Your Information

We use the personal information we collect for the following purposes. Each purpose is grounded in a legitimate business need and, where required by applicable law, is supported by an appropriate legal basis.

3.1 Service Delivery and Contract Performance

We use your personal information to respond to enquiries, prepare proposals, enter into service agreements, and deliver the computer systems design, integration, and consulting services you have engaged us to provide. This includes communicating with you about project progress, scheduling on-site visits, coordinating with your technology team, and providing technical documentation and support. Where payment information is collected, it is used exclusively for billing and invoicing purposes related to services rendered.

3.2 Business Operations and Administration

Your information is used for internal administrative purposes including record keeping, compliance monitoring, quality assurance, and business planning. We maintain client relationship management systems that store contact history, project records, and service interaction notes to ensure continuity of service and effective account management. These records also support our financial reporting, audit, and regulatory compliance obligations.

3.3 Website Improvement and Analytics

We analyse usage data from our Site to understand how visitors interact with our content, which pages are most frequently accessed, and how users navigate through our information. This analysis helps us optimise the Site structure, improve content relevance, and identify technical issues that may affect user experience. Where analytics tools are used, we configure them to anonymise IP addresses and minimise the collection of personally identifiable information.

3.4 Security and Compliance

We process personal information to maintain the security of our systems, networks, and premises. This includes monitoring access logs, investigating security incidents, preventing fraudulent or unauthorised activity, and complying with legal obligations such as court orders, regulatory requests, and applicable data subject rights requirements. We also use contact information to send important service-related communications including changes to our terms, security updates, and policy notices.

3.5 Marketing and Business Development

With your consent or where we have a legitimate interest in doing so, we may use your contact information to send you information about our services, industry insights, and event invitations that we believe may be relevant to your organisation. You may opt out of receiving these communications at any time by using the unsubscribe link included in every marketing email or by contacting us directly at support@sinpar.autos. We do not sell or rent your personal information to third parties for their own marketing purposes.

4. Disclosure of Your Information

We may share your personal information with the following categories of recipients. In each case, we ensure that appropriate safeguards are in place to protect your data and that the recipient's use is limited to the purposes for which the information was originally collected.

4.1 Service Providers and Subcontractors

We engage third-party service providers to support our business operations, including cloud hosting providers, payment processing services, customer relationship management platforms, email communication services, and professional advisors such as accountants and legal counsel. These providers are contractually bound to process your information only on our instructions and in compliance with applicable data protection laws. We conduct due diligence on our providers and require them to maintain appropriate technical and organisational security measures.

4.2 Legal and Regulatory Disclosures

We may disclose your personal information where required to do so by law, regulation, or legal process. This includes responding to subpoenas, court orders, or other lawful requests from public authorities, including meeting national security or law enforcement requirements. Where permitted by law, we will notify you of such requests before disclosure unless doing so would prejudice the purpose of the disclosure or is prohibited by applicable law.

4.3 Business Transfers

In the event of a merger, acquisition, restructuring, sale of assets, or insolvency proceeding involving SINPAR TECHNOLOGY LIMITED, your personal information may be transferred to the acquiring or surviving entity as part of the business assets. In such cases, we will take steps to ensure that your information continues to be protected in accordance with this Privacy Policy and applicable law. We will notify affected individuals of any such transfer and the identity of the successor entity.

4.4 With Your Consent

We may share your personal information with third parties for purposes other than those described in this policy where we have obtained your explicit consent to do so. You may withdraw your consent at any time, although this will not affect the lawfulness of processing carried out before such withdrawal. Where consent is required for specific processing activities, we will seek it in a clear and unambiguous manner before commencing such processing.

5. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. For client records, we typically retain information for the duration of our contractual relationship plus a period of seven years after the conclusion of services to support potential legal claims, regulatory audits, and client re-engagement. For enquiry records, we retain information for two years following the last contact, after which it is securely deleted or anonymised for analytical purposes. Website analytics data is retained in aggregated form for a period of 26 months from the date of collection. When retention periods expire, your personal information is securely destroyed or permanently anonymised using industry-standard deletion methods.

6. Data Security

We implement a comprehensive set of technical and organisational security measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These measures are designed to provide a level of security appropriate to the sensitivity of the information processed and the nature of our business activities.

Our security measures include encryption of data in transit using TLS 1.2 or higher for all web traffic, encryption of data at rest on our servers using AES-256, strict access controls based on role-based permissions and the principle of least privilege, multi-factor authentication for all administrative systems, regular security awareness training for all staff members who handle personal data, automated intrusion detection and prevention systems monitoring network traffic 24 hours per day, regular vulnerability scanning and penetration testing conducted by independent third-party assessors, and documented incident response procedures that include breach notification protocols compliant with applicable law. We also maintain comprehensive backup procedures, disaster recovery capabilities, and business continuity plans that cover our data processing infrastructure. Despite these measures, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security of your information.

7. International Data Transfers

Your personal information may be stored and processed in any country where we have facilities or where we engage service providers. This includes countries outside Hong Kong, including the United States, Singapore, and the European Economic Area. When we transfer your personal information across borders, we take steps to ensure that it receives an equivalent level of protection as required under applicable data protection laws. This is achieved through the use of standard contractual clauses approved by relevant regulatory authorities, adherence to recognised international data protection frameworks where applicable, and verification that recipient organisations maintain appropriate certification and security practices. By submitting your personal information to us, you acknowledge that it may be transferred to and processed in locations outside your jurisdiction of residence.

8. Your Rights

Depending on your jurisdiction and the legal basis for our processing of your information, you may have the following rights regarding your personal data. We will respond to any valid request within the timeframes prescribed by applicable law, typically within 30 calendar days.

Right of Access: You have the right to request confirmation of whether we hold personal information about you and, if so, to request a copy of that information along with details about how it is processed.

Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal information we hold about you. We will make the necessary corrections promptly upon verification.

Right to Erasure: You have the right to request deletion of your personal information where it is no longer necessary for the purposes for which it was collected, where you withdraw consent on which processing is based, or where processing is otherwise unlawful.

Right to Restriction: You have the right to request that we restrict the processing of your personal information in certain circumstances, for example while we verify the accuracy of information you have contested or where processing is unlawful but you do not wish the data to be erased.

Right to Data Portability: You have the right to request that we provide your personal information to you in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.

Right to Object: You have the right to object to processing of your personal information for direct marketing purposes at any time. Where processing is based on legitimate interests, you may also object on grounds relating to your particular situation.

Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

9. Cookies and Tracking Technologies

Our Site uses cookies and similar tracking technologies to distinguish you from other users, improve your browsing experience, and analyse Site usage patterns. Cookies are small text files stored on your device by your web browser. We use essential cookies that are necessary for the functioning of the Site, analytics cookies that help us understand how visitors interact with our content, and preference cookies that remember your settings and choices. You can control cookie preferences through your browser settings. Most browsers allow you to block or delete cookies, although disabling essential cookies may affect the functionality of the Site. We do not use cookies for behavioural advertising or cross-context tracking purposes.

10. Third-Party Links

Our Site may contain links to third-party websites, plug-ins, and applications that are not owned or controlled by SINPAR TECHNOLOGY LIMITED. Clicking on these links or enabling third-party connections may allow those third parties to collect or share information about you. We do not control these third-party websites and are not responsible for their privacy practices. When you leave our Site, we encourage you to read the privacy policy of every website you visit. This Privacy Policy applies solely to information collected through our Site and our direct interactions with you in the course of service delivery.

11. Children's Privacy

Our services are directed to professionals and business organisations. We do not knowingly collect personal information from individuals under the age of 16. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us at support@sinpar.autos. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to delete that information from our systems promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational circumstances. When we make material changes, we will notify you by posting the revised policy on this page with an updated effective date. Where changes involve new purposes for processing your data or reduced protections, we will provide additional notice through our website or direct communication where appropriate. We encourage you to review this policy periodically to stay informed about how we are protecting your information.

13. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact us at the following address. We are committed to addressing your enquiries promptly and transparently.

SINPAR TECHNOLOGY LIMITED
Rm S239 2/F The Capital
61-65 Chatham Road South
Tsim Sha Tsui, Kowloon
Hong Kong

Email: support@sinpar.autos
Phone: +1 (434) 810-6617

We will acknowledge receipt of any privacy-related complaint or request within five business days and will work to resolve it within 30 calendar days. If you are dissatisfied with our response, you have the right to lodge a complaint with the Office of the Privacy Commissioner for Personal Data in Hong Kong or with the competent data protection authority in your jurisdiction.