Privacy Policy

BlackwellCloud is committed to protecting your privacy and handling your personal data with transparency and care. This policy explains how we collect, use, share, and safeguard your information when you interact with our website and services.

Version 2.1 Compliant with HK PDPO & UK GDPR

1. Introduction

Welcome to BlackwellCloud ("we", "us", "our"). We are a cross‑border financial services firm headquartered in Hong Kong, serving clients globally. This Privacy Policy applies to all personal information collected through our website (blackwellcloud.io), client portals, and any related services or communications.

We take our responsibility to protect your privacy seriously. We are committed to complying with the Hong Kong Personal Data (Privacy) Ordinance (PDPO), the UK General Data Protection Regulation (UK GDPR), and other applicable data protection laws.

Data Controller: BlackwellCloud (Hong Kong) Limited is the data controller for your personal information. Our contact details are provided at the end of this policy.

2. Information We Collect

We may collect the following categories of personal information:

  • Identity and Contact Data: Full name, title, postal address, email address, telephone number, and other identifiers you provide when you register, enquire, or use our services.
  • Financial and Transactional Data: Information about your financial position, investment objectives, risk tolerance, transaction history, and other financial details necessary for providing our advisory and wealth management services.
  • Technical and Usage Data: Internet Protocol (IP) address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our website.
  • Marketing and Communication Data: Your preferences in receiving marketing from us and our third parties, and your communication preferences.
  • Special Category Data: We do not routinely collect sensitive personal data (such as racial or ethnic origin, political opinions, religious beliefs, or health data) unless required by law or with your explicit consent.

3. How We Collect Your Data

We collect personal information in the following ways:

  • Direct interactions: You provide data when you complete forms, correspond with us by post, phone, email, or through our website contact forms.
  • Automated technologies: As you interact with our website, we may automatically collect Technical and Usage Data using cookies, server logs, and similar technologies.
  • Third parties: We may receive data from third parties such as financial institutions, credit reference agencies, or publicly available sources, where permitted by law.

4. How We Use Your Data

We use your personal information for the following purposes:

  • Service Delivery: To provide our wealth management, investment advisory, family office, and cross‑border advisory services.
  • Client Relationship Management: To manage and maintain our relationship with you, including client onboarding, due diligence, and ongoing communication.
  • Legal and Regulatory Compliance: To comply with our legal obligations, including anti‑money laundering (AML), counter‑terrorist financing (CTF), and tax reporting requirements.
  • Website Improvement: To administer and improve our website, including analytics and user experience optimisation.
  • Marketing: To send you relevant updates, insights, and promotional materials, where you have consented or where we have a legitimate interest to do so. You may opt‑out at any time.

Legal Basis: We process your data based on: (a) your consent; (b) the performance of a contract with you; (c) compliance with a legal obligation; or (d) our legitimate business interests, provided such interests do not override your fundamental rights and freedoms.

5. Data Sharing and Disclosure

We may share your personal information with the following parties, strictly as necessary:

  • Service Providers: Trusted third‑party vendors who support our business operations, such as technology providers, custodians, asset managers, legal advisers, and auditors. These parties are contractually bound to protect your data.
  • Regulatory Authorities: Where required by law, we may disclose data to regulatory bodies, government agencies, or law enforcement authorities.
  • Corporate Transactions: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the relevant successor entity.

We do not sell your personal information to third parties for marketing purposes.

6. International Transfers

As a global financial services firm, we operate across multiple jurisdictions, including Hong Kong, the United Kingdom, Singapore, and the United States. Your personal information may be transferred to, and processed in, countries outside your country of residence.

We ensure that appropriate safeguards are in place for such transfers, including the use of Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms under UK GDPR and HK PDPO, to ensure that your data is protected to the same high standard.

7. Data Security

We implement robust technical and organisational measures to protect your personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

  • Encryption of sensitive data in transit and at rest.
  • Access controls and multi‑factor authentication for our systems.
  • Regular security audits and vulnerability assessments.
  • Mandatory data protection and privacy training for all staff.

While we strive to protect your personal information, no transmission over the internet is completely secure. We encourage you to take appropriate precautions when transmitting sensitive data online.

8. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law (e.g., for regulatory, tax, or legal compliance purposes).

Generally, we retain client data for a minimum of seven years following the end of our relationship, in accordance with financial services regulatory requirements. Thereafter, data is securely deleted or anonymised.

9. Your Rights

Under applicable data protection laws, you have the following rights regarding your personal information:

  • Right of Access: You may request a copy of the personal data we hold about you.
  • Right to Rectification: You may request that we correct any inaccurate or incomplete data.
  • Right to Erasure: In certain circumstances, you may request the deletion of your personal data (the "right to be forgotten").
  • Right to Restriction: You may request that we restrict the processing of your data in certain situations.
  • Right to Data Portability: You may request to receive your data in a structured, commonly used, and machine‑readable format.
  • Right to Object: You may object to the processing of your data for direct marketing purposes or where we rely on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time.

To exercise any of these rights, please contact us at privacy@blackwellcloud.io. We will respond to your request within 30 days.

10. Cookies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse site traffic, and personalise content. Cookies are small text files stored on your device.

You can manage your cookie preferences through your browser settings. However, disabling certain cookies may affect the functionality of our website. For more information, please see our Cookie Policy.

11. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us immediately.

12. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory standards. We will notify you of any material changes by posting the updated policy on our website and updating the "Effective Date" above.

We encourage you to review this policy periodically to stay informed about how we are protecting your information.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, please contact our Data Privacy Officer:

  • Email: privacy@blackwellcloud.io
  • Postal Address: 803B, 8/F, West Bund Garden, 290-296 Un Chau Street, Cheung Sha Wan, Kowloon, Hong Kong

If you are not satisfied with our response, you have the right to lodge a complaint with the Hong Kong Office of the Privacy Commissioner for Personal Data (PCPD) or the relevant data protection authority in your jurisdiction.