Summit Link Limited, a company registered in Hong Kong with its registered office at Rm F07 12/F WAICHEUNG IND CTR, 5 SHEK PAI TAU RD, Tuen Mun, Hong Kong (HK), provides computer systems design and computer integrated systems design services to clients in Hong Kong and around the world. This Privacy Policy explains how the Company collects, uses, discloses, and protects personal information when you visit the website at summitlink.autos, contact us by email or telephone, or use any of the services we offer.
The website and the systems behind it are developed and operated by the developer SummitLink. This policy covers all personal data handled by the Company, whether it comes from a website visitor, a client, a business partner, or a supplier. By using the website or by engaging the services, you agree to the practices described in this policy. If you do not agree with any part of this policy, please do not use the website and do not provide personal information to us.
We are committed to protecting the personal information you trust us with, and we design our systems and our processes with privacy in mind from the first line of code to the last operational report.
The Company collects personal information in three ways, and in every case we limit the collection to what is relevant and necessary for the purpose at hand.
First, information you give us directly. When you complete the contact form, send us an email, or speak to us by telephone, you may provide your name, email address, telephone number, company name, job title, and the content of your message. We use this information only to respond to your enquiry and to progress the conversation.
Second, information collected automatically. When you visit the website, our servers and analytics tools may record your internet protocol address, browser type and version, operating system, device identifiers, the pages you visit, the time you spend on each page, and the website that referred you to us. This information is used to operate the site securely and to understand how visitors use it.
Third, information from business partners and public sources. For corporate and professional projects, we may obtain professional details, company records, and publicly available market information so that we can understand the context of an engagement and prepare an accurate proposal. We do not collect more information than we need, and we do not seek out sensitive data unless it is strictly necessary for a specific project.
The Company uses personal information for a defined set of purposes, and we do not use it for anything beyond those purposes without telling you first.
We use contact details to respond to enquiries, prepare proposals, agree project terms, and deliver the services. We use technical and usage data to maintain the website, to diagnose faults, to defend the site against attack, and to improve the layout and content. We use professional information to plan, design, build, and operate computer systems and integrated systems projects, and to coordinate with the people you designate on your side of the engagement.
We may use your contact details to send you administrative notices that are necessary for the working relationship, such as updates to the terms, changes to the platform, or confirmation of scheduled work. Where we rely on consent for any use, we will use the information only for the specific purpose you agreed to, and you may withdraw that consent at any time by contacting us. We will never use personal information for purposes that are incompatible with the purposes described in this policy.
We process personal information only where we have a lawful basis to do so. Under the Hong Kong Personal Data (Privacy) Ordinance and other data protection laws that may apply to our clients, the legal bases on which the Company relies include the following.
Consent, where you have freely given your agreement to the processing, for example when you ask us to add you to a mailing list. Contract, where processing is necessary to perform a contract with you or to take steps at your request before entering into a contract. Legal obligation, where processing is required to comply with a law or regulation that applies to the Company, such as record keeping obligations. Legitimate interests, where processing is necessary for the legitimate interests of the Company, such as improving our services, preventing fraud and abuse, keeping our systems secure, and understanding how our website is used, provided that those interests do not override your rights and freedoms.
When we rely on legitimate interests, we carry out a careful balance test, we document the reasoning, and we keep that assessment available for review. If you would like more detail about the specific legal basis for a particular processing activity, please contact us using the details at the end of this policy.
We keep personal information only for as long as necessary for the purposes described in this policy, and we review our retention periods regularly.
Contact and enquiry data is retained for a reasonable period after the last contact, so that we can follow up on business opportunities and maintain a history of our conversations. Client project data is retained for the duration of the engagement and for a further period required by law or as needed to defend against claims, which in Hong Kong can include a period of seven years for certain records. Technical logs and usage data are retained for a shorter period, typically no more than twelve months, unless a legal matter requires longer retention.
When personal information is no longer needed, we delete it or anonymize it so that it can no longer be linked to an identified individual. Our retention decisions are documented, and we make sure that data does not linger beyond its useful life just because it is easier to keep it than to remove it.
As a Hong Kong based company serving clients around the world, the Company may transfer personal information to other jurisdictions in the course of providing its services. This may happen when data is stored on servers located outside Hong Kong, when our service providers operate from other countries, or when we coordinate with counterparties and exchanges across borders.
Where personal information is transferred, we take steps to ensure that it receives a level of protection comparable to the protection it enjoys in Hong Kong. Those steps may include entering into contractual arrangements that require the recipient to safeguard the data, relying on an adequacy decision issued by the relevant authority, or implementing supplementary safeguards where the first line of protection is not sufficient.
By providing personal information to the Company, you understand that it may be transferred to, and processed in, jurisdictions outside your home country, and that such processing will be carried out in accordance with this policy and with applicable law. If you would like a copy of the safeguards we use for a particular transfer, please contact us.
Protecting personal information is a core part of the work the Company does. Because we design computer systems for a living, we apply the same security discipline to our own data that we apply to the platforms we build for clients.
We apply technical and organizational measures to keep data safe against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit, access controls that limit who can reach the information, secure development practices, continuous monitoring of our systems, and documented incident response procedures. We train our staff in data protection, and we expect our service providers to maintain standards at least as strong as our own.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of an incident that affects your personal information, we will follow our incident response plan, and we will notify you and the relevant authorities where the law requires it. You also play a part in security by keeping any account credentials safe and by reporting suspicious activity to us promptly.
Under applicable data protection law, you have rights in relation to the personal information the Company holds about you. The main rights are described here, and they apply subject to the conditions set out in the law.
You have the right to access the personal information we hold about you and to receive a copy of it. You have the right to request correction of inaccurate or incomplete information. You have the right to request deletion of your information where the legal basis for the processing no longer applies. You have the right to object to processing based on legitimate interests, and to request restriction of processing in certain circumstances. Where processing is based on consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, contact us at contact@summitlink.autos. We will respond within the time frame required by law, which is usually within thirty days, and we may ask you to verify your identity before we act on a request. We will never charge you for making a request, although we may charge a reasonable fee where the law permits it.
The services and the website are directed at businesses and professional users, and they are not designed for children. We do not knowingly collect personal information from children under the age of thirteen, and we do not knowingly direct any part of the website at children.
If you are a parent or guardian and you believe that a child has provided personal information to the Company, please contact us using the details at the end of this policy, and we will take steps to delete that information from our records. We take the protection of young people seriously and we will act promptly on any report we receive.
Because our clients are organizations, the Company does not ordinarily interact with children at all. Where a project does involve data about children, we will handle that data with particular care, we will follow the instructions of the client, and we will apply the highest applicable standard of protection.
The website may contain links to websites and services operated by third parties, such as regulatory bodies, industry associations, exchanges, or business partners. The Company does not control those websites, and we are not responsible for their privacy practices, their security, or their content.
When you follow a link to a third-party website, the privacy policy of that website will apply to the information you provide there, and we encourage you to read it carefully before you proceed. We may also use third-party service providers to support parts of the website, and those providers may process certain data on our behalf under contract. The Company does not endorse the content of any third-party website linked from our pages.
If you have concerns about how a third party handles your information, we recommend that you contact that third party directly. If you prefer, you may also contact us, and we will assist where we reasonably can, for example by clarifying which elements of the website are served by external providers.
The Company does not make decisions that produce legal or similarly significant effects on individuals through automated decision-making alone, and we do not use personal information to build profiles that would be used in that way.
Where automated tools are used, they are limited to activities such as filtering spam, detecting security threats, and organizing data, and those tools are always subject to human oversight. The results of any automated processing are reviewed by our team before they affect a person.
If we ever introduce automated decision-making that affects you in a significant way, we will inform you before it takes effect, we will give you the opportunity to request human intervention, and we will provide a way for you to contest the decision. We believe that important decisions about people should involve people, and our practice reflects that principle.
The Company maintains an incident response plan that describes how we detect, contain, and recover from security incidents that affect personal information. When a breach is identified, we act quickly to assess the scope, to protect the affected data, and to prevent further exposure.
Where the law requires it, we notify the relevant supervisory authority and the affected individuals without undue delay. In any notification we explain what happened, what information was involved, what steps we are taking to address the issue, and what the affected person can do to protect themselves, such as changing passwords or monitoring account activity.
We review every incident to understand how it happened and to improve our controls so that the same weakness does not recur. We treat each incident as a learning opportunity and as a reason to strengthen the ridge that protects your data. If you believe your information may have been affected by an incident, please contact us immediately.
We may update this Privacy Policy from time to time to reflect changes in our practices, in the services we offer, or in applicable law. When we make material changes, we will update the effective date at the top of this page and, where appropriate, we will notify you by email or through a notice on the website.
We encourage you to review this policy regularly so that you are always aware of how the Company handles personal information. The version of this policy that applies is the version in force at the time of your visit or at the time you engage our services.
Your continued use of the website or the services after a change takes effect constitutes acceptance of the revised policy. If a change is significant and requires your consent under applicable law, we will seek that consent before the change takes effect.
If you have any questions about this Privacy Policy, about how the Company processes personal information, or about your rights, please contact us using the details below. You may also contact us if you wish to raise a concern about our handling of your personal information, and we will investigate and respond to you directly.
Summit Link Limited
Rm F07 12/F WAICHEUNG IND CTR, 5 SHEK PAI TAU RD, Tuen Mun, Hong Kong (HK)
Email: contact@summitlink.autos
Telephone: +16189128918
The Company is the data controller for the personal information described in this policy. If you are not satisfied with our response to a concern, you have the right to complain to the Office of the Privacy Commissioner for Personal Data in Hong Kong, or to the data protection authority in your jurisdiction.