Privacy Policy

Peblx Limited · Version 1.0 · Effective 1 September 2026

1. Who we are

1.1 Peblx Limited (“Peblx”, “we”, “us”, “our”) is a company incorporated in Hong Kong with company number 78460589, whose registered office is at the address shown in the records of the Hong Kong Companies Registry and published on our website. We are licensed as a trust or company service provider under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615), licence number TC011104.

1.2 This policy explains how we collect, use, disclose and protect personal data in connection with our website, our platform and our services, and serves as our Personal Information Collection Statement for the purposes of the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”). We are the data user in respect of that personal data.

1.3 By providing personal data to us, or by using our website or platform, you acknowledge this policy. Where you provide us with personal data of other people — such as your directors, shareholders, beneficial owners or colleagues — you confirm that you are entitled to do so and that they have been made aware of this policy.

2. What we collect

2.1 Identity and contact data: name, identity document details and copies, date of birth, nationality, residential address, proof of address, email address and phone number — collected from you and from persons connected with your company as part of onboarding and ongoing compliance.

2.2 Verification and screening data: facial images and biometric data captured during electronic identity verification (including liveness detection and face matching), document authenticity results, and the results of screening against sanctions lists, politically exposed person lists, watchlists and adverse media.

2.3 Business and financial data: information about your company, its ownership and control, its activities and source of funds; accounting records and transactions where you take accounting services or connect your accounting software; and billing and payment information (we do not store full card numbers — payments are processed by our payment provider).

2.4 Platform and technical data: account details, communications with us, documents you upload, and technical information such as device, browser and usage data, including through cookies as described in our Cookie Policy.

3. Why we use it (purposes)

3.1 To provide our services: incorporation, company secretarial services, registered office and mail handling, accounting and tax filing support, and operation of the client platform.

3.2 To meet our legal and regulatory obligations, including customer due diligence, ongoing monitoring, screening, record-keeping and reporting under the AMLO and related laws and regulatory guidance.

3.3 To administer the relationship: billing, payment collection, service communications, notices and support.

3.4 To operate, secure and improve our website and platform, including audit logging, fraud and abuse prevention, and analytics.

3.5 For direct marketing only with your consent, as described in section 7.

3.6 The supply of data in sections 2.1–2.3 is obligatory to the extent needed for onboarding, compliance and service delivery; if it is not provided, we may be unable to act for you or to continue acting for you.

4. Biometric data

4.1 Identity verification includes the processing of facial images and derived biometric data for the purposes of confirming that an identity document is genuine and that the person presenting it is its holder. You will be asked to give explicit consent before any biometric processing begins, and you may choose not to proceed — in which case we may be unable to complete verification or provide services.

4.2 Biometric processing is carried out with the assistance of our specialist electronic identity verification provider acting on our instructions, and the results are retained as part of our compliance records described in section 8.

5. Who we share it with

5.1 Service providers acting for us, under contract and only as needed to deliver the purposes above: our electronic identity verification and screening provider, our payment processor, our cloud hosting, email and productivity providers, our accounting software provider where you take accounting services, and our professional advisers.

5.2 Government, regulatory and law-enforcement authorities, in or outside Hong Kong, where we are required or permitted by law to make disclosures — including the Companies Registry, the Inland Revenue Department and bodies concerned with anti-money laundering and counter-terrorist financing.

5.3 Third parties you ask us to deal with, such as your bank, auditors or incoming service providers on a handover; and a purchaser or successor in connection with a reorganisation or sale of our business, on terms that respect this policy.

5.4 Some of our providers store or process data outside Hong Kong. Where personal data is transferred outside Hong Kong we take reasonable steps, including contractual protections, to ensure it receives a level of protection comparable to this policy.

6. How we protect it

We apply technical and organisational measures appropriate to the nature of the data, including encryption of personal data in transit and at rest, access controls, audit logging and staff confidentiality obligations. No system is completely secure, and you should also keep your own credentials and devices safe.

7. Direct marketing

We will only use your name and contact details to send you news, product updates or offers about our services if you have given consent (for example, by ticking the optional marketing box), and we will not provide your personal data to any other person for their marketing. You may withdraw consent at any time, free of charge, by using the unsubscribe link in any message or by contacting us, and we will stop promptly.

8. How long we keep it

Customer due diligence and transaction records are kept for a minimum of six years after the end of the business relationship, in line with our legal obligations and internal policies. Accounting and tax records are kept for the periods required by law. Other personal data is kept no longer than is necessary for the purposes described in this policy, after which it is securely deleted or anonymised.

9. Your rights

9.1 Under the PDPO you may request access to, and correction of, your personal data. Requests can be made using the contact details in section 11; we may charge a reasonable fee for complying with a data access request as permitted by the PDPO. You may also withdraw marketing consent (section 7) and, where processing is based on consent, withdraw that consent for the future — noting that compliance records we are required to keep will be retained as described in section 8.

9.2 If you are unhappy with how we handle personal data, please contact us first so we can put it right. You also have the right to complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (pcpd.org.hk).

10. Changes to this policy

We may update this policy from time to time. Each version carries a version number and effective date, and material changes will be notified through the platform or by email.

11. Contact

Questions, access or correction requests, and marketing opt-outs can be sent to us through the client portal, by email to the contact address published on our website, or by post to our registered office as published on our website, marked for the attention of the Data Protection Officer.

Do you have questions?
Reach out to our team and start a discussion.
Contact us
Contact us