1. Scope of This Policy

This policy applies to all personal data handled by Shining Solutions Property (Hong Kong) Limited in connection with this website and with our professional practice. Personal data means information relating to an identifiable individual, whether a client, a prospective client, a supplier contact, a contractor, a website visitor or another person who interacts with us.

The policy covers data collected through written correspondence, telephone conversations, project documentation, site surveys and any enquiry submitted through this website. It does not govern the independent practices of third parties, even where those parties work alongside us on a building project. Where a third party handles data on our behalf, we require that party to protect it to standards consistent with this policy and with the law of the Hong Kong Special Administrative Region.

By using this website or by engaging our services, you confirm that you have read this policy and understand how your data may be handled. If you do not agree with the practices described here, please do not submit personal data to us and contact us instead so that we can discuss your concerns.

2. Our Role and Responsibilities

In most situations Shining Solutions Property (Hong Kong) Limited acts as the controller of the personal data that is collected through this website and through our direct professional relationships. This means that we decide why the data is collected, how it is used and how long it is kept.

In some project settings we may handle personal data on behalf of a client, for example when we design and commission systems that store the credential records of building occupants. In those cases the client is the controller of that building data and we act in a service role, processing the information only on documented instructions. We describe this distinction clearly in the relevant project agreements.

Our internal oversight of privacy sits with the team identified by the ShiningProp name, which holds responsibility for applying this policy consistently across every engagement, regardless of which engineer or consultant is assigned to a particular building.

3. Categories of Data We Collect

We aim to collect only what is necessary for the purpose at hand. The categories of personal data we may hold include the following.

Identification and contact data

This includes names, job titles, employer names, business addresses, business email addresses and business telephone numbers. It may also include the address of a property under consideration, together with the identity of the person who represents the owner or occupier.

Enquiry and correspondence data

This includes the content of messages sent to us through the website enquiry form or by email, the subject line you choose, any attachments you provide, and the record of our replies. Because the website form opens your own email application, the message travels to us as ordinary email rather than through a database on our servers.

Project and technical data

In the course of designing integrated building systems, we may hold records that mention individuals indirectly, such as access schedules listing staff credential groups, commissioning records naming responsible persons, or maintenance logs recording who attended a site. We collect this information only where a project requires it.

Website usage data

Our hosting environment may record standard technical information such as the pages requested, the time of a request, a truncated network address and the general type of device used. This information is used in aggregate to keep the site available and secure.

4. How We Collect Personal Data

We collect personal data in several ordinary ways. You may provide it directly when you complete the enquiry form on this website, when you email us, when you telephone us, or when you exchange business cards and documents with our team during a meeting or site visit.

We also receive data indirectly when a client, a managing agent or a contractor introduces a contact to us as part of a project. In that situation we ask the introducing party to ensure that the individual has been informed that their details will be shared. We may also receive limited technical information automatically from the web server, as described in the section on website usage data.

We do not purchase personal data from data brokers and we do not gather personal data from social media profiles for marketing purposes. If information reaches us unexpectedly, we assess whether we have a legitimate reason to keep it and delete it if we do not.

5. Purposes for Processing

We process personal data for a defined set of purposes, each connected to the professional services we provide.

We do not use personal data for purposes that are incompatible with those listed above without first informing you and, where required, obtaining your consent.

8. Cookies and Local Storage

This website is deliberately simple. It does not use advertising cookies, cross site tracking cookies or third party analytics scripts that profile visitors. Any storage used by the site is limited to what the browser technically requires to display the pages correctly and to remember interactive state such as an open navigation menu or an expanded answer panel.

Because we do not run tracking cookies, we do not operate a cookie consent banner. If this changes in future, we will update this policy and, where the law requires it, ask for your consent before setting any non essential cookie. You can always control cookies through your browser settings, though disabling all storage may affect how interactive elements behave.

9. Disclosure to Third Parties

We do not sell personal data. We share it only where there is a clear reason and appropriate protection. The parties to whom data may be disclosed include professional advisers such as accountants and legal counsel, contractors and sub-contractors engaged on a project, information technology suppliers who support our systems, and public authorities where the law compels disclosure.

When we engage a service provider that handles personal data on our behalf, we require it to act only on our instructions, to apply appropriate security, and to return or delete the data when the engagement ends. We keep the number of such providers to a minimum and review their arrangements periodically.

10. International Data Transfers

Our practice is based in Hong Kong and our records are ordinarily held within the Hong Kong Special Administrative Region. Some technology suppliers may store data in other jurisdictions as part of their service. Where personal data is transferred outside Hong Kong, we take steps to ensure that it continues to receive a comparable level of protection.

Those steps may include contractual commitments that bind the recipient to protect the data, limiting transfers to what a project genuinely requires, and preferring suppliers who can keep data within the region. If you would like to know where a particular set of your data is held, please contact us and we will explain.

11. Data Retention

We keep personal data only for as long as it is needed for the purpose for which it was collected, or for as long as the law requires. Enquiry correspondence that does not lead to a project is usually deleted within a reasonable period once the enquiry is closed. Project records are kept for the life of the installation and for a further period that reflects our contractual and legal obligations, because building documentation must remain available for maintenance and handover purposes.

Accounting and tax records are retained for the period required by Hong Kong law. When a retention period ends, we delete or anonymise the data using methods appropriate to its sensitivity. Where data exists only in a backup, it is removed in line with our normal backup rotation.

12. Security Measures

We protect personal data using a combination of technical and organisational measures. Access to systems and project records is limited to team members who need it to do their work. Devices are protected with authentication, and our correspondence and documents are stored in environments that are reasonably secured. Physical records are held in premises with controlled access.

We train our team to handle personal data carefully, to recognise phishing and social engineering attempts, and to report any suspected incident without delay. If a personal data breach occurs that is likely to result in a risk to individuals, we will take immediate steps to contain it and will notify the affected individuals and the relevant authority as required by law.

13. Accuracy and Correction

We take reasonable care to keep the personal data we hold accurate and up to date. Because much of the information we handle is supplied by others, we rely on you to tell us when your details change. If you believe that any information we hold about you is inaccurate, please contact us and we will correct it promptly.

Where a correction affects an active project or a live system record, we will also update the related documentation so that the installed building records remain consistent with reality. Accurate records are part of professional practice, not merely a privacy formality.

14. Your Access Rights

Subject to the law of the Hong Kong Special Administrative Region, you have the right to request access to the personal data we hold about you, to request correction of inaccurate data, and to ask us to cease using your data for direct marketing. You may also ask us to delete data where there is no ongoing lawful reason for us to keep it.

To make a request, write to strategy@shiningprop.surf with enough detail for us to identify you and understand what you are asking. We may ask for proof of identity to protect your data from disclosure to the wrong person. We will respond within a reasonable period and, where we decline a request, we will explain our reasons.

15. Privacy for Children

Our services are directed at businesses, property owners, managing agents and professional project teams. We do not knowingly collect personal data from children, and this website is not designed for use by children. If you believe that a child has provided personal data to us, please contact us and we will delete it promptly.

Where a building system we design might incidentally record the presence of minors, the deploying organisation is responsible for ensuring that such use is lawful and proportionate, and we support clients in designing systems that respect the privacy of everyone who uses the premises.

16. Direct Marketing

We send marketing messages only where we have a lawful basis to do so. If you have asked us for information about our services, we may contact you to follow up on that enquiry. We do not pass your details to third parties for their own marketing, and we do not send unrelated promotional material.

Every marketing message we send includes a simple way to opt out, and we act on opt out requests promptly. You may also ask us at any time to stop using your details for marketing while continuing to hold them for the purposes of an active or past project.

18. Changes to This Policy

We review this Privacy Policy from time to time so that it continues to reflect our practices and the requirements that apply to us. When we make material changes, we will update the date shown at the foot of this page and, where appropriate, draw attention to the change on the website.

We encourage you to review this page occasionally. Continued use of the website or continued engagement with our services after an update indicates that you accept the revised policy. If you have questions about any change, please contact us using the details below.

19. How to Contact Us

If you have a question about this policy, a request about your personal data, or a concern about how your information has been handled, please contact us by email or telephone. We will investigate every concern promptly and work with you to resolve it.