Privacy Policy

Last Updated: 15 January 2026
Effective Date: 15 January 2026

1. Introduction

Cipherwise is committed to protecting the privacy and security of personal data we collect in connection with our legal services. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in accordance with Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486) and our professional obligations as legal practitioners.

As a law firm, we handle personal data with particular care, recognizing both our legal obligations under data protection law and our professional duties of confidentiality to clients. This policy applies to all personal data we process through our website, client engagements, and business operations.

For questions about this Privacy Policy or our data handling practices, please contact us at [email protected].

2. Data Controller Information

The data controller responsible for your personal data is:

Cipherwise
Unit 1905, Tower 1, The Gateway
25 Canton Road, Tsim Sha Tsui
Hong Kong
Email: [email protected]
Phone: +852 3156 8247

3. Personal Data We Collect

We collect personal data necessary to provide legal services and operate our business. The types of information we collect include:

3.1 Client Information

When you engage our services, we collect contact details (name, email address, phone number, business address), organizational information (company name, position, business registration details), matter-specific information relevant to the legal services requested, and identification documents as required for client verification and legal compliance.

3.2 Website Visitors

When you visit our website, we may collect technical information (IP address, browser type, device information), usage data (pages visited, time spent, navigation patterns), and information you provide through contact forms or inquiry submissions.

3.3 Correspondent and Third-Party Information

In providing legal services, we may collect personal data about opposing parties, witnesses, or other individuals relevant to matters we handle, as necessary for representing client interests and fulfilling professional obligations.

4. How We Collect Personal Data

We collect personal data through direct provision by individuals when engaging our services or contacting us, website interactions through contact forms and inquiry submissions, client communications via email, phone, video conference, or in-person meetings, documents and materials provided in connection with legal matters, and public sources when necessary for legal research or matter-related inquiries.

5. Legal Basis and Purposes for Processing

We process personal data on the following legal bases and for the following purposes:

5.1 Contractual Necessity

Processing necessary to provide legal services pursuant to engagement agreements, including matter management, legal advice provision, documentation preparation, and communication with clients and relevant parties.

5.2 Legal Obligations

Processing required to comply with legal and regulatory requirements, including client identification and verification, anti-money laundering obligations, professional conduct rules, and court or regulatory authority requirements.

5.3 Legitimate Interests

Processing necessary for our legitimate business interests, including practice administration, billing and accounting, professional indemnity insurance arrangements, dispute resolution, and business development (subject to appropriate safeguards and your rights).

6. Data Sharing and Disclosure

We may share personal data with the following categories of recipients where necessary:

Service providers who support our operations (IT services, document management, practice management software, professional advisers), courts and regulatory authorities as required by law or professional obligations, other parties involved in legal matters (opposing counsel, mediators, experts) with appropriate confidentiality protections, professional indemnity insurers in connection with coverage requirements, and third parties with your consent or as directed in connection with specific matters.

All third-party service providers are required to implement appropriate security measures and process personal data only as instructed by us.

7. International Data Transfers

Some of our service providers may be located outside Hong Kong, which may involve transferring personal data to jurisdictions with different data protection frameworks. Where we transfer personal data internationally, we implement appropriate safeguards, which may include standard contractual clauses, adequacy determinations by relevant authorities, or other legally recognized transfer mechanisms.

For cross-border matters involving client representation, we may need to transfer personal data to relevant jurisdictions as necessary to provide legal services, subject to appropriate confidentiality and data protection measures.

8. Data Retention

We retain personal data for as long as necessary to fulfill the purposes outlined in this Privacy Policy and to comply with legal and professional obligations. Specific retention periods include:

Client matter files are retained for a minimum of six years following matter conclusion, in accordance with Law Society guidelines and professional indemnity insurance requirements. Financial records are maintained for seven years as required by applicable laws. General correspondence and inquiries are retained for three years unless related to active or concluded matters. Website analytics data is retained for two years.

Upon expiry of retention periods, we securely delete or anonymize personal data unless continued retention is required by law or for legitimate legal purposes such as defending claims.

9. Data Security

We implement technical and organizational security measures appropriate to the sensitivity of personal data we handle, including encrypted communications for client matters, secure document management systems with access controls, regular security assessments and updates, staff training on data protection and confidentiality, physical security measures for office premises, and secure backup and disaster recovery procedures.

While we take reasonable precautions to protect personal data, no method of transmission or storage is completely secure. We cannot guarantee absolute security but maintain industry-standard protections appropriate for a legal practice handling confidential information.

10. Your Rights

Subject to applicable law and professional obligations, you have the following rights regarding your personal data:

Right of access to request information about personal data we hold concerning you and obtain a copy of such data. Right to correction of inaccurate or incomplete personal data. Right to erasure in certain circumstances, though this may be limited by legal retention requirements or professional obligations. Right to restrict processing in specific situations. Right to data portability for data provided under contract or consent. Right to object to processing based on legitimate interests, subject to our compelling legal grounds or professional obligations. Right to lodge a complaint with the Privacy Commissioner for Personal Data if you believe your data protection rights have been violated.

To exercise these rights, please contact us at [email protected]. We will respond to requests within the timeframes required by applicable law. Note that certain rights may be limited by legal privilege, professional obligations, or other legal requirements applicable to legal practice.

11. Cookies and Website Technologies

Our website uses cookies and similar technologies. For detailed information about our cookie practices, please see our Cookie Policy. Essential cookies necessary for website functionality are used, while optional analytics or preference cookies require your consent.

12. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices of external sites. We encourage you to review the privacy policies of any third-party sites you visit.

13. Children's Privacy

Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from minors. If you become aware that a minor has provided us with personal data, please contact us so we can take appropriate action.

14. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or operational needs. Material changes will be communicated through our website or directly to clients as appropriate. The "Last Updated" date at the top of this policy indicates when it was most recently revised.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect personal data.

15. Contact Us

For questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact:

Privacy Officer
Cipherwise
Email: [email protected]
Phone: +852 3156 8247
Address: Unit 1905, Tower 1, The Gateway, 25 Canton Road, Tsim Sha Tsui, Hong Kong

We will respond to privacy inquiries within a reasonable timeframe and work to address your concerns promptly.