Data Storage Service Privacy and Data Processing Notice

[Cyber-Pro Technology Limited] (hereinafter referred to as “the Company,” “we,” or “our“) undertakes to protect the data privacy of its corporate clients and their authorized users in accordance with the Personal Data (Privacy) Ordinance (Chapter 486) (hereinafter referred to as the “Privacy Ordinance”) of Hong Kong. This notice aims to clarify our data processing practices as a data processor when providing commercial data storage and hosting services to corporate clients.

  1. Legal Relationship and Data Processing Purpose

Legal Positioning: In this service relationship, the corporate client is the “Data User” (the entity that controls the purpose of data collection and use), while the Company is the “Data Processor” (the entity that processes and stores data solely on behalf of the client).

Processing Purpose: We process and store client data (including any personal data that may be contained therein) solely in accordance with the service contract signed with the client and lawful written instructions for the following purposes:

Providing enterprise-grade cloud storage, data backup, system hosting, and related IT infrastructure management services.

Conducting corporate account administration, authentication, access control, and technical support.

Maintain server security, prevent cyberattacks, detect system vulnerabilities, and ensure service stability.

Fulfill mandatory compliance obligations imposed by Hong Kong law, court orders, or statutory regulatory bodies.

  1. Data Security Measures

As a data processor, we employ industry-standard technical and organizational measures to prevent unauthorized or accidental access, processing, erasure, loss, or use of customer data:

Encryption Technology: Data is protected using advanced encryption standards (such as AES-256) during in-transit and at-rest storage.

Access Control: Strict authentication (such as multi-factor authentication, MFA) and access control are implemented, restricting access to specific systems to authorized operations and technical personnel only in the performance of their duties.

Physical Security: Data centers are equipped with 24/7 monitoring, physical protection, and a strict visitor registration system.

Security Audit: Regular system vulnerability scans and security tests are conducted to ensure the defensive capabilities of the infrastructure.

  1. Subcontractors and Data Transfer

Third-Party Subcontractors: To maintain efficient storage services, we may engage third-party service providers (such as data center operators and cybersecurity experts) to assist in data processing. All subcontractors must sign strict confidentiality and data protection agreements, and their obligations are no less stringent than those stipulated in this notice.

Local Storage: Unless otherwise expressly agreed in writing, all customer data is stored by default in our data center located in Hong Kong.

  1. Data Retention and Destruction Policy

Retention as Instructed: We retain customer data for a period strictly limited to the time required to fulfill the service contract, or the period explicitly specified by the customer.

Handling After Contract Termination: Upon termination or expiration of the service contract, we will, in accordance with the contract terms, securely erase, overwrite, or physically destroy all customer data and copies thereof on the server within a grace period of [e.g., 30 days] (to allow customers to export their data), except for transaction records or audit logs that must be retained due to legal or regulatory requirements.

  1. Disclaimers and Limitation of Liability for Data Loss

Customer Backup Obligation: While our company employs industry-standard security measures to protect data, enterprise customers understand and agree that network environments and electronic storage inherently carry risks. Customers are responsible for regularly backing up all data stored on our systems and establishing off-site disaster recovery plans.

Scope of Disclaimer: To the maximum extent permitted by law, our company shall not be liable for any loss, damage, leakage, alteration, interruption, or inaccessibility of data caused by the following:

Force majeure events (including but not limited to natural disasters, fires, floods, war, terrorist attacks, government actions, large-scale network outages, power outages, or telecommunications malfunctions).

Original threats: Unknown zero-day attacks, Advanced Persistent Threats (APTs), or ransomware launched by malicious third parties.

Original threats: Negligence, improper operation, password disclosure, or vulnerabilities in the customer’s, their employees’, or any authorized user’s systems.

Further liability: Exclusion of Indirect Damages: Under no circumstances shall the Company be liable to customers for any indirect, incidental, consequential, or punitive damages arising from data loss, including but not limited to: loss of profits, business interruption, loss of business opportunities, damage to goodwill, or liability to third parties.

Limit of Damages: Regardless of whether based on contract law, tort law (including negligence), or other legal grounds, the maximum aggregate damages the Company may incur against a customer for the services (including data loss or damage) shall, in any event, not exceed [the total amount of service fees actually paid by the customer to the Company for the services within the [e.g., 3/6] months immediately preceding the occurrence of the claim].

  1. Cooperation in Access and Compliance Assistance

If your end user (data subject) requests access to or correction of your data, or if the Office of the Privacy Commissioner for Personal Data (HKPrivacy Commissioner) conducts a compliance investigation, the Company will provide necessary technical assistance to the extent commercially reasonable and contractually permissible to assist you in fulfilling your statutory obligations under the Privacy Ordinance.

For any inquiries regarding this notice or our data security measures, please contact us.