Data protection
Privacy Policy
How we collect, use, store, share and protect personal data, and the rights you have over that data.
Operated by
Business-to-business services only
INSTANT PAYMENTS LIMITED
Trading as Webics Consulting
- Company registration number
- 79468211
- Place of registration
- Hong Kong SAR
- Registry
- Companies Registry, Hong Kong
- Registered office address
-
RM 701, UNIT 127, 7/F, TWR B
NEW MANDARIN PLAZA
14 SCIENCE MUSEUM RD
TSIM SHA TSUI
HONG KONG - Customer service email
- info@webicsconsulting.online
- Telephone
- +852 13157549890
- Website
- webicsconsulting.online
- Office hours
- Monday to Friday, 09:00 – 18:00 (HKT, UTC+8)
- Response time
- Within 1 business day
01 Who is responsible for your data
The data controller for the personal data described in this policy is INSTANT PAYMENTS LIMITED, trading as Webics Consulting, company registration number 79468211, registered at RM 701, Unit 127, 7/F, Twr B, New Mandarin Plaza, 14 Science Museum Rd, Tsim Sha Tsui, Hong Kong.
For any privacy question, request or complaint, contact our privacy team at info@webicsconsulting.online or by telephone on +852 13157549890. We answer privacy requests within 1 business day and resolve them within one month.
This policy covers our website, our proposal and enquiry process, and our client engagements. Where we handle personal data inside a client's own system, we act as a processor on that client's instructions and their privacy notice applies to their end users.
02 The data we collect
| Category | Examples | How we get it |
|---|---|---|
| Identity and contact data | Name, job title, company name, email address, telephone number, country | You provide it in the proposal form, by email or on a call |
| Project and enquiry data | Project description, website or product URL, budget range, timeline, files you send us | You provide it |
| Contract and correspondence data | Proposals, statements of work, emails, meeting notes, feedback threads | Generated during the engagement |
| Billing data | Invoice details, billing address, tax or company number, payment reference | You provide it; payment confirmations come from our payment providers |
| Technical data | IP address, browser type and version, device type, operating system, referring page, timestamps | Collected automatically by our servers and, where consented, analytics |
| Usage data | Pages viewed, time on page, navigation path, whether a form was submitted | Collected only if you consent to analytics cookies |
| Client system data | Any personal data present inside a system we are given access to during an engagement | Provided by the client as controller |
We do not deliberately collect special category data such as health, biometric, religious or political information, and we ask you not to send it. We do not knowingly collect data from anyone under 18; our services are directed exclusively at businesses.
03 Why we use your data and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Responding to a proposal request or enquiry | Identity, contact, project data | Steps taken at your request prior to entering a contract |
| Preparing proposals and statements of work | Identity, contact, project data | Pre-contractual steps; legitimate interests in running our business |
| Delivering an engagement and communicating about it | Contract, correspondence, project data | Performance of a contract |
| Invoicing and collecting payment | Billing, identity, contract data | Performance of a contract; legal obligation |
| Keeping accounting and tax records | Billing, contract data | Legal obligation |
| Securing our website and preventing abuse | Technical data | Legitimate interests in protecting our systems |
| Measuring how the website is used | Usage, technical data | Consent (analytics cookies) |
| Sending occasional service or account emails | Identity, contact data | Performance of a contract; legitimate interests |
| Establishing, exercising or defending legal claims | Any relevant category | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have assessed that our interest in operating, securing and improving a professional services business does not override your rights and freedoms. You can ask us for that assessment at any time.
We do not sell personal data, we do not share it with data brokers, and we do not use it for automated decision-making or profiling that produces legal or similarly significant effects.
04 Marketing
We only send marketing email to business contacts who have asked to hear from us or who have an existing engagement with us, and every such message contains a one-click unsubscribe link. Withdrawing marketing consent does not affect emails that are necessary to run a live engagement, such as milestone notices or invoices.
05 Who we share data with
We share personal data only with the categories of recipient below, each bound by a written contract requiring confidentiality and appropriate security.
- Hosting and infrastructure providers that operate the servers on which this website and our email run.
- Email and productivity providers used for correspondence, documents and file transfer.
- Payment and invoicing providers that process invoices and card or bank payments. Card details are handled by them and never stored by us.
- Analytics providers, only where you have consented to analytics cookies.
- Professional advisers such as accountants, auditors and lawyers, where necessary.
- Subcontractors and specialist collaborators engaged on a specific project, limited to the data they need.
- Public authorities, where we are legally required to disclose.
- A successor entity, if our business is reorganised, merged or acquired; we would notify affected individuals.
06 International transfers
We are established in Hong Kong SAR and our clients and service providers are located in a number of countries, so personal data may be transferred outside your country of residence, including outside the European Economic Area and the United Kingdom.
Where such a transfer takes place, we put in place an appropriate safeguard: transfer to a jurisdiction recognised as providing adequate protection, or a contract incorporating the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where relevant), together with any supplementary technical measures the transfer risk assessment identifies. You can request a copy of the safeguard used by contacting us.
07 How long we keep data
| Record | Retention period |
|---|---|
| Enquiries that do not become engagements | 24 months from the last contact, then deleted |
| Proposals and statements of work | 7 years from the end of the engagement |
| Project correspondence and feedback threads | 3 years from the end of the engagement |
| Design source files and code repositories | 24 months from handover, unless you ask us to delete sooner |
| Invoices and accounting records | 7 years, as required by applicable tax law |
| Client system access credentials | Revoked and deleted within 5 business days of handover |
| Personal data inside a client system | Deleted or returned at the end of the engagement, on the client's instruction |
| Website server logs | 12 months |
| Cookie consent records | 12 months from the consent choice |
When a retention period ends we delete the data or irreversibly anonymise it. Data held in encrypted backups is removed on the normal backup rotation cycle, which does not exceed 90 days.
08 Your rights
Depending on where you are located, you may have some or all of the following rights. We apply them to every request we receive, regardless of location, as a matter of policy.
- Access — obtain confirmation of whether we hold data about you and receive a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have data deleted where we no longer have a lawful reason to keep it.
- Restriction — have processing paused while a dispute about accuracy or lawfulness is resolved.
- Portability — receive data you provided to us in a structured, machine-readable format, or have it sent to another controller.
- Objection — object to processing based on legitimate interests, and object to direct marketing at any time with no reason required.
- Withdraw consent — withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Complain — lodge a complaint with a supervisory authority.
To exercise a right, email info@webicsconsulting.online with the words "Privacy request" in the subject line and tell us which right you are exercising. We will acknowledge within 5 business days and respond within one month. We may ask for proof of identity so that we do not disclose data to the wrong person. Exercising your rights is free; we may charge a reasonable fee only for manifestly unfounded or excessive repeat requests, and we will tell you before doing so.
If you are in the EEA or UK you may complain to your national data protection authority. In Hong Kong SAR you may complain to the Office of the Privacy Commissioner for Personal Data (PCPD). We would appreciate the chance to resolve the matter directly first.
09 How we protect data
- TLS encryption on all connections to this website and to our email systems.
- Encryption at rest for laptops, backups and file storage.
- Role-based access on a need-to-know basis, with unique accounts and multi-factor authentication.
- Password manager use for all shared credentials; no credentials shared over plain email or chat.
- Client credentials issued with the minimum privilege required and revoked at handover.
- A preference for anonymised, redacted or synthetic data during design and testing.
- Written confidentiality and data protection obligations for every subcontractor.
- Periodic review of access rights, retention schedules and provider security posture.
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it, and we will notify affected individuals and affected clients directly where the risk is high.
10 Cookies and tracking
This website uses a small number of cookies. Non-essential cookies are set only after you consent, and you can change or withdraw that choice at any time. The full list, the purpose of each cookie and the instructions for controlling them are in our Cookie Policy.
11 Third-party links
Our website may link to external sites. We are not responsible for their content or privacy practices, and this policy does not apply to them. Please read their own notices before providing data.
12 Changes to this policy
We keep this policy under review and update it when our practices, providers or legal obligations change. The version published on this page is the version in force. Where a change materially affects how we use data about you, we will notify active clients and enquirers directly by email.
13 Privacy contact
Privacy enquiries and data subject requests: info@webicsconsulting.online. Telephone: +852 13157549890. Post: INSTANT PAYMENTS LIMITED, RM 701, Unit 127, 7/F, Twr B, New Mandarin Plaza, 14 Science Museum Rd, Tsim Sha Tsui, Hong Kong.
Questions about this policy
Write to info@webicsconsulting.online or call +852 13157549890. Postal correspondence: INSTANT PAYMENTS LIMITED, RM 701, Unit 127, 7/F, Twr B, New Mandarin Plaza, 14 Science Museum Rd, Tsim Sha Tsui, Hong Kong.
Request a proposal