1. Scope of This Policy

This policy governs all personal data handled by COLLECTION INDUSTRIES LIMITED across every channel through which the counter operates. Those channels include the website at collectioncore.buzz, email correspondence, telephone calls, written correspondence, in-person meetings at the counter, field visits made by our officers, and any document or message exchanged in the course of a recovery engagement. It applies whether the data arrives on paper, by voice, over the internet or in person.

This policy does not govern the independent practices of third parties. When a creditor client, a legal firm, a credit reference provider or any other organisation receives data from us, that organisation becomes responsible for its own handling under its own privacy framework. We encourage every reader to review the privacy notices of any organisation that receives personal data, because those notices, and not this one, describe the practices of those organisations.

By visiting this website, by sending a message to the counter, by placing an account with us, or by corresponding with an officer, a person acknowledges that this policy has been made available and understands how personal data is handled. Where consent is required by applicable law, we ask for it separately and clearly, and we do not treat a visit to the website as consent for anything beyond the technical processing described in the sections that follow.

2. Key Definitions

The following terms carry the meanings given here throughout this policy. Personal data means any information relating to an identifiable individual, including a name, an email address, a telephone number, a job title, an identification number or any combination of details that allows a person to be singled out from a crowd. A data subject is the individual to whom personal data relates. Processing means any operation performed on personal data, whether collecting it, storing it, reading it, sharing it, correcting it, archiving it or destroying it.

The controller is the organisation that decides why and how personal data is processed. For the purposes of this policy, COLLECTION INDUSTRIES LIMITED is the controller of the personal data described here, and the developer and operator of the website is COLLECTION INDUSTRIES. A processor is an organisation that handles personal data on behalf of a controller and under the instructions of that controller. A creditor client is the business that places an overdue balance with the counter. A counterparty or debtor is the person or business that owes that balance. Each of these roles shapes the way data moves through the counter.

3. Data We Collect

We collect identity data such as names, company names, job titles, registration numbers and the capacity in which a person acts within an organisation. We collect contact data such as postal addresses, email addresses, telephone numbers and messaging handles. We collect financial and commercial data such as outstanding invoice amounts, payment histories, agreed instalment schedules, banking details supplied for remittance and correspondence that discusses a balance.

We collect correspondence data, which means the content of letters, emails, call notes, meeting notes and field visit reports. We collect technical data such as internet protocol addresses, browser type, device type, referring pages and the times at which a website was visited. We collect usage data describing which pages were viewed and for how long. We collect verification data that appears in identity documents, authority letters or signed acknowledgments gathered during a field visit or at the counter.

We do not seek so-called sensitive data such as health details, religious beliefs, political opinions or trade union membership, and we ask that no person send such details to the counter. If sensitive data is offered to us without request, we take reasonable steps to delete it where it is not necessary for a legitimate purpose.

4. Sources of Personal Data

Most personal data reaches the counter from three directions. The first direction is the person themselves, when an individual completes a contact form, sends an email, telephones an officer or attends the counter. The second direction is the creditor client, which supplies the details of its counterparties, its own staff contacts and the references named within a file. The third direction is public and commercial sources, including company registries, credit reference agencies, published directories, official notices and publicly accessible records that allow us to confirm a fact or locate a party.

We may also receive data from professional advisers, including legal firms, insolvency practitioners and accountants, who pass us information in connection with a matter. Where such data is received, we treat it with the same care as data received directly, and we use it only for the purpose for which it was provided or for a purpose closely related to it.

5. Purposes of Processing

We process personal data so that we can open and maintain recovery files, contact counterparties through a reminder ladder, negotiate and monitor payment plans, arrange field verification visits, prepare documented legal handoffs and operate the cross-border receivables desk. We process data to answer enquiries submitted through the website or by telephone, to provide a named officer with the history of a file, and to record every step in a log that a creditor client can review.

We also process data to improve our service, to train officers on realistic cases, to detect and prevent fraud, to comply with legal and regulatory obligations, to enforce agreements, to establish or defend legal claims and to manage the everyday administration of the business. Where technical data is processed, it is used to keep the website available, safe and reasonably fast, and to understand in aggregate how visitors use the pages.

6. Lawful Basis for Processing

Different activities rest on different lawful bases. Where a person has asked the counter to act, the processing is necessary to take steps at that person request before entering a contract or to perform a contract already in place. Where we pursue a balance under an engagement with a creditor client, the processing rests on the legitimate interests of the client and of the counter in recovering lawfully owed amounts and in maintaining accurate commercial records. Where we answer an enquiry, the processing rests on the legitimate interest in responding to a person who has chosen to make contact.

Where we are required to keep records for tax, accounting or other legal purposes, the processing rests on compliance with a legal obligation. Where we rely on consent, for example for an optional marketing message, a person may withdraw that consent at any time without affecting earlier processing. Where a lawful basis is legitimate interest, we balance that interest against the rights of the individual and we limit the data to what the purpose genuinely requires.

7. Data in Debt Recovery Files

A recovery file is the working record of a single account. It may contain the name of a counterparty, the name of the person who handles the balance, the contact details used to reach that person, the invoice history, the correspondence log, plan documents, verification reports and, where relevant, notes about the capacity in which a person signed a document. The file exists so that the creditor client can see what happened, and so that any later legal step rests on a complete account of events.

Because a recovery file contains information about a person who has not necessarily chosen to deal with us, we apply extra care. We limit the file to what is needed to pursue the balance, we restrict access to the officer handling the account and to those who supervise the counter, and we avoid recording opinions that are not relevant to recovery. Where a person asks what is held about them in a recovery file, we handle that request under the rights section of this policy, subject to any legal restriction that applies to the disclosure.

8. Sharing and Disclosure

We share personal data with the creditor client that placed the account, because the client is entitled to see the progress of its own file. We share data with legal firms where a matter is handed to counsel, with credit reference agencies where screening or monitoring requires it, with banks and payment channels to receipt and trace money, and with service providers who host the website, manage email or store documents under our instruction. Each such recipient receives only the data needed for its role.

We may disclose data where the law requires it, where a court or regulator compels it, where disclosure is needed to establish, exercise or defend a legal claim, or where disclosure is necessary to prevent fraud or harm. We do not sell personal data. We do not rent personal data. We do not trade personal data for marketing lists. Where a recipient acts as a processor, it is bound to handle the data only on our instructions and to protect it to a standard consistent with this policy.

9. Cross-Border Transfers

The counter serves Hong Kong exporters and mainland suppliers, so a file may legitimately involve more than one jurisdiction. When personal data moves across a border, we take steps to keep protection intact. Those steps include confirming that the recipient is bound by a contract that mirrors our own safeguards, limiting the data transferred to what the purpose requires, and keeping a record of the transfer so that it can be explained to a creditor client or to a regulator.

Where a transfer would place data at risk, we either decline the transfer, anonymise the data first, or put an additional safeguard in place. A person who wishes to know whether their data has been transferred across a border, and on what basis, may make a request using the contact details at the end of this policy and will receive a clear reply.

10. Retention of Records

We keep personal data only for as long as it is needed for the purpose for which it was collected, plus any additional period required by law. Recovery files are typically retained for the duration of the engagement and for a further period so that a client can defend or pursue a matter that resurfaces, to satisfy accounting and tax obligations, and to answer a legitimate query about an old account. Website enquiry records are kept for a shorter period because the purpose they serve is immediate.

When a retention period ends, we delete or anonymise the data in a manner that is reasonable and secure. Where deletion is impossible because data sits in a backup, we isolate the backup and allow it to expire in the ordinary cycle. We review retention on a regular schedule so that files do not linger simply because nobody remembered to close them.

11. Security Measures

We protect personal data with a combination of technical and organisational measures. Access to a file is limited to the officer handling it and to the supervisors of the counter. Accounts are protected by individual credentials, and we avoid sharing passwords. Documents are held in controlled storage, whether electronic or physical, and paper files are kept in a locked area when not in use. Communications that carry confidential material are handled with care, and we prefer verified channels for anything sensitive.

We train officers on confidentiality and on the correct handling of personal data, and we review our practices when a process changes. No system is perfect, and we do not claim otherwise. If a security incident occurs that is likely to result in a risk to personal data, we take prompt steps to contain it, to assess it and to notify affected persons and any relevant authority where the law requires notification.

12. Cookies and Tracking

The website uses a small number of technical cookies and similar mechanisms to keep pages working, to remember a visitor preference such as a navigation state, and to gather aggregate statistics about how the site is used. These mechanisms do not by themselves identify a person, though they may be linked to a technical identifier such as an internet protocol address.

A visitor may control cookies through browser settings, including blocking them or clearing them after a visit. Blocking strictly necessary cookies may affect how parts of the site behave, but it will not prevent a person from reading the pages or from contacting the counter. We do not use cookies to build advertising profiles, and we do not permit third parties to use our site to track a visitor across unrelated websites for advertising purposes.

13. Marketing Communications

We send service updates and occasional industry notes to clients and to persons who have asked to receive them. We do not send marketing to a person who has not shown a relevant interest in the counter, and we do not pass contact details to outside marketing lists. Every marketing message includes a clear way to stop future messages, and we honour a stop request promptly.

A person may also ask to be removed from a contact list by writing to the counter directly. Where a person is named in a recovery file, we distinguish between marketing messages, which are optional, and operational messages about the file itself, which may continue because they are part of the service that the creditor client has engaged us to provide.

14. Rights of Data Subjects

Subject to applicable law, a person may ask to see the personal data that the counter holds about them, may ask for a correction where the data is inaccurate, may ask for deletion where there is no continuing lawful reason to keep it, may ask for a restriction on processing, may object to processing that rests on legitimate interests, and may ask for a copy of certain data in a portable form. A person may also withdraw consent where consent is the basis for a particular activity.

To exercise a right, a person should write to the counter using the contact details at the end of this policy and describe the request clearly. We may ask for proof of identity so that we do not release data to the wrong person. We answer requests within the period required by applicable law, and if we cannot comply in full we explain why and identify any exception that applies. There is no charge for a reasonable request, although a fee may apply to a request that is manifestly unfounded or excessive.

15. Privacy for Children

The counter provides commercial debt recovery and receivables management to businesses. It is not directed at children, and we do not knowingly collect personal data from a child. If a person believes that a child has provided personal data to the counter, that person should contact us using the details below and we will investigate and delete the data where appropriate.

A recovery file may occasionally name a young person who acts as a contact at a family business. In such a case we collect only the minimum business contact details required to pursue the balance, and we apply the same safeguards described in this policy without exception.

16. Third-Party Websites

The website may contain links to websites operated by other organisations, including legal firms, trade bodies and public registries. Those websites are not controlled by COLLECTION INDUSTRIES LIMITED, and this policy does not apply to them. We provide a link because it may help a reader, not because we endorse or assume responsibility for the practices of the linked site.

A person who follows a link leaves our pages and becomes subject to the privacy notice of the destination. We encourage a reader to check that notice before providing personal data to any external site. We are not responsible for the content, security or privacy practices of an external site that we do not operate.

17. Changes to This Policy

We may update this policy from time to time to reflect a change in the law, a change in our practices, or a change in the services that the counter offers. When we update it, we revise the effective date shown at the top of the page and, where the change is significant, we take reasonable steps to bring it to the attention of clients and correspondents.

We encourage readers, clients and counterparties to review this page occasionally so that they remain aware of how personal data is handled. A continued relationship with the counter after an update indicates that the updated policy has been made available, without prejudice to any right that applicable law gives to an individual.

18. Contacting Us

Questions, requests and concerns about this policy or about the handling of personal data should be directed to the counter using the details below. We prefer a written request because it creates a clear record, but a telephone enquiry is welcome where writing is not practical. A named officer will review the matter and reply.

This policy forms part of the way the counter operates and should be read together with our Terms of Service, which describe the commercial terms on which services are provided. Both documents are available from every page of this website, and both are written to be read without legal assistance.