SUMMITLINK

Privacy Policy

Effective date: 25 August 2026 · Applies to summitlink.autos

Contents

  1. Introduction
  2. Information We Collect
  3. How We Use Your Information
  4. Legal Bases for Processing
  5. Information We Share
  6. Cookies and Tracking Technologies
  7. Data Retention
  8. International Data Transfers
  9. Security of Your Information
  10. Your Rights and Choices
  11. Privacy for Children
  12. Third-Party Services
  13. Automated Decision-Making
  14. Data Breach Notification
  15. Changes to This Privacy Policy
  16. How to Contact Us

Introduction

Summit Link Limited, a company registered in Hong Kong with its registered office at Rm F07 12/F WAICHEUNG IND CTR, 5 SHEK PAI TAU RD, Tuen Mun, Hong Kong (HK), provides computer systems design and computer integrated systems design services to clients in Hong Kong and around the world. This Privacy Policy explains how the Company collects, uses, discloses, and protects personal information when you visit the website at summitlink.autos, contact us by email or telephone, or use any of the services we offer.

The website and the systems behind it are developed and operated by the developer SummitLink. This policy covers all personal data handled by the Company, whether it comes from a website visitor, a client, a business partner, or a supplier. By using the website or by engaging the services, you agree to the practices described in this policy. If you do not agree with any part of this policy, please do not use the website and do not provide personal information to us.

We are committed to protecting the personal information you trust us with, and we design our systems and our processes with privacy in mind from the first line of code to the last operational report.

Information We Collect

The Company collects personal information in three ways, and in every case we limit the collection to what is relevant and necessary for the purpose at hand.

First, information you give us directly. When you complete the contact form, send us an email, or speak to us by telephone, you may provide your name, email address, telephone number, company name, job title, and the content of your message. We use this information only to respond to your enquiry and to progress the conversation.

Second, information collected automatically. When you visit the website, our servers and analytics tools may record your internet protocol address, browser type and version, operating system, device identifiers, the pages you visit, the time you spend on each page, and the website that referred you to us. This information is used to operate the site securely and to understand how visitors use it.

Third, information from business partners and public sources. For corporate and professional projects, we may obtain professional details, company records, and publicly available market information so that we can understand the context of an engagement and prepare an accurate proposal. We do not collect more information than we need, and we do not seek out sensitive data unless it is strictly necessary for a specific project.

How We Use Your Information

The Company uses personal information for a defined set of purposes, and we do not use it for anything beyond those purposes without telling you first.

We use contact details to respond to enquiries, prepare proposals, agree project terms, and deliver the services. We use technical and usage data to maintain the website, to diagnose faults, to defend the site against attack, and to improve the layout and content. We use professional information to plan, design, build, and operate computer systems and integrated systems projects, and to coordinate with the people you designate on your side of the engagement.

We may use your contact details to send you administrative notices that are necessary for the working relationship, such as updates to the terms, changes to the platform, or confirmation of scheduled work. Where we rely on consent for any use, we will use the information only for the specific purpose you agreed to, and you may withdraw that consent at any time by contacting us. We will never use personal information for purposes that are incompatible with the purposes described in this policy.

Legal Bases for Processing

We process personal information only where we have a lawful basis to do so. Under the Hong Kong Personal Data (Privacy) Ordinance and other data protection laws that may apply to our clients, the legal bases on which the Company relies include the following.

Consent, where you have freely given your agreement to the processing, for example when you ask us to add you to a mailing list. Contract, where processing is necessary to perform a contract with you or to take steps at your request before entering into a contract. Legal obligation, where processing is required to comply with a law or regulation that applies to the Company, such as record keeping obligations. Legitimate interests, where processing is necessary for the legitimate interests of the Company, such as improving our services, preventing fraud and abuse, keeping our systems secure, and understanding how our website is used, provided that those interests do not override your rights and freedoms.

When we rely on legitimate interests, we carry out a careful balance test, we document the reasoning, and we keep that assessment available for review. If you would like more detail about the specific legal basis for a particular processing activity, please contact us using the details at the end of this policy.

Information We Share

The Company does not sell, rent, or trade personal information to any third party, and we do not permit third parties to use your information for their own marketing. We share personal information only in the limited circumstances described below.

We share data with service providers who support our operations, such as hosting providers, email platforms, analytics services, legal advisers, and accountants. Those providers act on our behalf, and our contracts with them require them to protect the information, to use it only for the purposes we specify, and to delete it when the task is complete.

We may share information with regulators, law enforcement, or government bodies where the law requires us to do so, or where it is necessary to protect the rights, property, or safety of the Company, its clients, or the public. If the Company is involved in a merger, acquisition, restructuring, or sale of assets, personal information may be transferred as part of that transaction, and we will notify affected individuals where the law requires us to do so.

Cookies and Tracking Technologies

The website uses cookies and similar technologies to make the site work correctly and to understand how visitors use it. A cookie is a small text file placed on your device by the website when you visit.

Essential cookies are required for basic functions such as navigation, session security, and load balancing. These cannot be switched off, and they do not store personal information beyond what is necessary for the function. Analytical cookies help us measure how many visitors we receive, which pages are most popular, how long visitors stay, and where visitors come from, so that we can improve the content and layout of the site. Preference cookies remember choices such as language and display settings.

The Company does not use advertising cookies, and we do not engage in cross-site behavioural tracking for marketing purposes. You can control cookies through your browser settings, and most browsers allow you to block or delete them. If you block essential cookies, some parts of the website may not function correctly. For a full list of the cookies used on this site, contact us at the address set out at the end of this policy.

Data Retention

We keep personal information only for as long as necessary for the purposes described in this policy, and we review our retention periods regularly.

Contact and enquiry data is retained for a reasonable period after the last contact, so that we can follow up on business opportunities and maintain a history of our conversations. Client project data is retained for the duration of the engagement and for a further period required by law or as needed to defend against claims, which in Hong Kong can include a period of seven years for certain records. Technical logs and usage data are retained for a shorter period, typically no more than twelve months, unless a legal matter requires longer retention.

When personal information is no longer needed, we delete it or anonymize it so that it can no longer be linked to an identified individual. Our retention decisions are documented, and we make sure that data does not linger beyond its useful life just because it is easier to keep it than to remove it.

International Data Transfers

As a Hong Kong based company serving clients around the world, the Company may transfer personal information to other jurisdictions in the course of providing its services. This may happen when data is stored on servers located outside Hong Kong, when our service providers operate from other countries, or when we coordinate with counterparties and exchanges across borders.

Where personal information is transferred, we take steps to ensure that it receives a level of protection comparable to the protection it enjoys in Hong Kong. Those steps may include entering into contractual arrangements that require the recipient to safeguard the data, relying on an adequacy decision issued by the relevant authority, or implementing supplementary safeguards where the first line of protection is not sufficient.

By providing personal information to the Company, you understand that it may be transferred to, and processed in, jurisdictions outside your home country, and that such processing will be carried out in accordance with this policy and with applicable law. If you would like a copy of the safeguards we use for a particular transfer, please contact us.

Security of Your Information

Protecting personal information is a core part of the work the Company does. Because we design computer systems for a living, we apply the same security discipline to our own data that we apply to the platforms we build for clients.

We apply technical and organizational measures to keep data safe against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit, access controls that limit who can reach the information, secure development practices, continuous monitoring of our systems, and documented incident response procedures. We train our staff in data protection, and we expect our service providers to maintain standards at least as strong as our own.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of an incident that affects your personal information, we will follow our incident response plan, and we will notify you and the relevant authorities where the law requires it. You also play a part in security by keeping any account credentials safe and by reporting suspicious activity to us promptly.

Your Rights and Choices

Under applicable data protection law, you have rights in relation to the personal information the Company holds about you. The main rights are described here, and they apply subject to the conditions set out in the law.

You have the right to access the personal information we hold about you and to receive a copy of it. You have the right to request correction of inaccurate or incomplete information. You have the right to request deletion of your information where the legal basis for the processing no longer applies. You have the right to object to processing based on legitimate interests, and to request restriction of processing in certain circumstances. Where processing is based on consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights, contact us at contact@summitlink.autos. We will respond within the time frame required by law, which is usually within thirty days, and we may ask you to verify your identity before we act on a request. We will never charge you for making a request, although we may charge a reasonable fee where the law permits it.

Privacy for Children

The services and the website are directed at businesses and professional users, and they are not designed for children. We do not knowingly collect personal information from children under the age of thirteen, and we do not knowingly direct any part of the website at children.

If you are a parent or guardian and you believe that a child has provided personal information to the Company, please contact us using the details at the end of this policy, and we will take steps to delete that information from our records. We take the protection of young people seriously and we will act promptly on any report we receive.

Because our clients are organizations, the Company does not ordinarily interact with children at all. Where a project does involve data about children, we will handle that data with particular care, we will follow the instructions of the client, and we will apply the highest applicable standard of protection.

Third-Party Services

The website may contain links to websites and services operated by third parties, such as regulatory bodies, industry associations, exchanges, or business partners. The Company does not control those websites, and we are not responsible for their privacy practices, their security, or their content.

When you follow a link to a third-party website, the privacy policy of that website will apply to the information you provide there, and we encourage you to read it carefully before you proceed. We may also use third-party service providers to support parts of the website, and those providers may process certain data on our behalf under contract. The Company does not endorse the content of any third-party website linked from our pages.

If you have concerns about how a third party handles your information, we recommend that you contact that third party directly. If you prefer, you may also contact us, and we will assist where we reasonably can, for example by clarifying which elements of the website are served by external providers.

Automated Decision-Making

The Company does not make decisions that produce legal or similarly significant effects on individuals through automated decision-making alone, and we do not use personal information to build profiles that would be used in that way.

Where automated tools are used, they are limited to activities such as filtering spam, detecting security threats, and organizing data, and those tools are always subject to human oversight. The results of any automated processing are reviewed by our team before they affect a person.

If we ever introduce automated decision-making that affects you in a significant way, we will inform you before it takes effect, we will give you the opportunity to request human intervention, and we will provide a way for you to contest the decision. We believe that important decisions about people should involve people, and our practice reflects that principle.

Data Breach Notification

The Company maintains an incident response plan that describes how we detect, contain, and recover from security incidents that affect personal information. When a breach is identified, we act quickly to assess the scope, to protect the affected data, and to prevent further exposure.

Where the law requires it, we notify the relevant supervisory authority and the affected individuals without undue delay. In any notification we explain what happened, what information was involved, what steps we are taking to address the issue, and what the affected person can do to protect themselves, such as changing passwords or monitoring account activity.

We review every incident to understand how it happened and to improve our controls so that the same weakness does not recur. We treat each incident as a learning opportunity and as a reason to strengthen the ridge that protects your data. If you believe your information may have been affected by an incident, please contact us immediately.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, in the services we offer, or in applicable law. When we make material changes, we will update the effective date at the top of this page and, where appropriate, we will notify you by email or through a notice on the website.

We encourage you to review this policy regularly so that you are always aware of how the Company handles personal information. The version of this policy that applies is the version in force at the time of your visit or at the time you engage our services.

Your continued use of the website or the services after a change takes effect constitutes acceptance of the revised policy. If a change is significant and requires your consent under applicable law, we will seek that consent before the change takes effect.

How to Contact Us

If you have any questions about this Privacy Policy, about how the Company processes personal information, or about your rights, please contact us using the details below. You may also contact us if you wish to raise a concern about our handling of your personal information, and we will investigate and respond to you directly.

Summit Link Limited
Rm F07 12/F WAICHEUNG IND CTR, 5 SHEK PAI TAU RD, Tuen Mun, Hong Kong (HK)

Email: contact@summitlink.autos
Telephone: +16189128918

The Company is the data controller for the personal information described in this policy. If you are not satisfied with our response to a concern, you have the right to complain to the Office of the Privacy Commissioner for Personal Data in Hong Kong, or to the data protection authority in your jurisdiction.

Return to Homepage

© 2026 Summit Link Limited · Rm F07 12/F WAICHEUNG IND CTR, 5 SHEK PAI TAU RD, Tuen Mun, Hong Kong (HK)

Return to the Homepage · Terms of Service