- Your rights and choices in relation to the personal data we hold and process
- Data retention
- How we keep your personal data safe
- Personal data we receive from you about other people
- Transfers of personal data abroad
- How long we retain your personal data
- Your rights regarding your personal data
- Correcting and updating your personal data
- Who decides why and how we process your personal data?
- Regulation of services
- Changes to this policy
For the purposes of this statement, Information includes:
- all the details we hold about you and the matters (if any) upon which we are instructed; and
- all personal data, if any, about you and your officers, employees, associates and, where applicable, family members.
Information we collect
We collect different types of personal data for different reasons – this may include:
Contact information: Information such as your name, job title, postal address, home address where you provide this to us, business address, telephone number, mobile number, fax number and email address.
Business details: Business information which we necessarily process as part of our instructions or projects we are involved in or otherwise provided by you voluntarily.
Payment data: Data necessary for us to process payments and implement fraud prevention measures, including bank details and other such relevant billing details.
Compliance details: Information we are legally required to collect for compliance purposes, such as ‘know your client’ (KYC) information, details relevant to international sanctions and restrictive measures, which may impact our ability to provide services.
Preferences: Information about your preferences, where it is relevant to the services we provide, such as the jurisdictions of relevance to the services provided to our clients.
Publicly available information: Information collected from publicly available resources, including but not limited to information collected from databases we use to carry out compliance checks, the corporate website of the organisation you are working for, or your LinkedIn profile.
Statutory Register Information: Information about you on account of an interest or office you may hold in, or certain relationships you may have with, a corporate entity, partnership, trust or other vehicle to which we provide services (each such entity, a Related Entity).
Details for events: In some cases, we may collect information about you, which may include sensitive information in relation to your health, for the purpose of tailoring our events to your needs. The processing of such data is based entirely on your consent – in the event that you do not want us to maintain such data, we may not be able to take the necessary precautions.
How we collect your Information
We may collect personal data about you in various cases, such as for example:
- when you or your organisation seek our services;
- when you or your organisation make an enquiry through our website, in person, over email or over the telephone;
- when you attend a Marbury seminar or other events we may organise, or sign up to receive communications from us, including training;
- when you meet and pass your details to a Marbury representative at a related industry event;
- when a Related Entity engages us to provide services and you hold an office or an interest in or have certain relationships with that Related Entity; or
- when you or your organisation provide services to us, or otherwise offer to do so.
In some circumstances, we may collect personal data about you from third parties – for example, we may collect personal data from your organisation, other organisations with whom you have dealings including Related Entities, government agencies, a credit reporting agency, an information or service provider or from a publicly available record.
How we use your Information
We use your personal data for the following purposes (Permitted Purposes):
- to provide services or things you may have requested, including online services or solutions (such as our client bookkeeping service), as instructed or requested by you or your organisation;
- to manage and administer your or your organisation's business relationship with us, including processing payments, accounting, auditing, billing and collection or support services;
- for compliance with our legal obligations (such as record keeping obligations), compliance screening or recording obligations (such as under antitrust laws, export controls, trade sanction and embargo laws, for anti-money laundering, financial and credit check and fraud and crime prevention and detection purposes), which may include automated checks of your contact data or other information you provide about your identity against applicable sanctioned-party lists and contacting you to confirm your identity in case of a potential match or recording interaction with you which may be relevant for compliance purposes;
- to provide updates, reminders, requests and directions relevant to the role or capacity in which you are interested in a Related Entity;
- to analyse and improve our services and communications to you;
- to protect the security of and managing access to our premises, IT and communication systems, online platforms, websites and other systems, preventing and to detect security threats, fraud or other criminal or malicious activities;
- for insurance purposes;
- to monitor and assess compliance with our policies and standards;
- to identify persons authorised to trade on behalf of our clients, customers, suppliers and/or service providers;
- to comply with our legal and regulatory obligations and requests anywhere in the world, including reporting to and/or being audited by local and foreign regulatory, law enforcement and tax reporting bodies;
- on instruction or request from your organisation or a relevant Related Entity;
- to communicate with you through the channels you have approved to keep you up to date on the latest legal developments, announcements, and other information about our services, products and technologies – including client briefings, newsletters and other information – as well as events and projects we may organise;
- to comply with court orders and exercises and/or defend our legal rights; and
- for any purpose related and/or ancillary to any of the above or any other purpose for which your personal data was provided to us.
Where you have expressly given us your consent, we may process your personal data also for the following purposes:
- for customer surveys, marketing campaigns, market analysis, contests or other promotional activities or events; or
- to collect information about your preferences to create a user profile to personalise and foster the quality of our communication and interaction with you (for example, by way of newsletter tracking or website analytics).
With regard to newsletters, legal updates and other general communications, we will - where legally required - only provide you with such information if you have opted in. You have the opportunity to opt out of receiving such communications at any time. We will not use your personal data for taking any automated decisions affecting you or creating profiles other than described above.
Depending on for which of the above Permitted Purposes we use your personal data, we may process your personal data on one or more of the following legal grounds:
- because processing is necessary for the performance of a client instruction or other contract with you or your organisation or a Related Entity;
- to comply with our legal obligations (eg to keep pension records or records for tax purposes); or
- because processing is necessary for purposes of our legitimate interest or those of any third party recipients that receive your personal data, provided that such interests are not overridden by your interests or fundamental rights and freedoms.
We may also process your data based on your consent where you have expressly given that to us.
How we share your Information
We may share your personal data in the following circumstances:
- We may share your personal data on a confidential basis where this is required for the purpose of providing our products and services, as well as for administrative, billing and other business purposes.
- If you are a Marbury client, or you are otherwise contracted by, are an agent of, or otherwise represent a Marbury client, we may disclose your personal data to:
- Legal specialists, consultants or experts engaged in your matter; or
- Foreign law firms for the purpose of obtaining foreign legal advice, as may be relevant.
- If we have collected your personal data in the course of providing services to any of our clients, we may disclose it to that client, and where permitted by law to others for the purpose of providing those services.
- We may share your personal data with companies providing services for money laundering checks, credit risk reduction and other fraud and crime prevention purposes and companies providing similar services, including financial institutions, credit reference agencies and regulatory bodies with whom such personal data is shared.
- We may share your personal data with any third party to whom we assign or novate any of our rights or obligations.
- We may also instruct service providers, domestically or abroad, eg shared service centres, to process personal data for the Permitted Purposes on our behalf and in accordance with our instructions only. Marbury will retain control over and will remain fully responsible for your personal data and will use appropriate safeguards as required by applicable law to ensure the integrity and security of your personal data when engaging such service providers.
- We may also use aggregated personal data and statistics for the purpose of monitoring website usage in order to help us develop our website and our services. (See ‘Cookies’ below.)
We will otherwise only disclose your personal data when you direct us or give us permission to do so, when we are required by applicable law or regulations or judicial or official request to do so, or as required by law enforcement authorities to investigate actual or suspected fraudulent or criminal activities.
Your rights and choices in relation to the personal data we hold and process
In general, we receive your personal data where you provide this on a voluntary basis, and there will typically be no detrimental effect for you if you wish not to provide this or otherwise withhold your consent for it to be processed. However, there are certain cases where we will unfortunately be unable to act without receiving such data, for example where we need to carry out legally required compliance screening or require such data to process your instructions or orders, or otherwise to provide you with our online services or communications.
Where it is not possible for us to provide you with what you request without the relevant personal data, we will let you know accordingly.
How we keep your personal data safe
We take appropriate technical and organisational measures to keep your personal data confidential and secure, in accordance with our internal policies and procedures regarding storage of, access to and disclosure of personal data. We may keep your personal data in our electronic systems, in the systems of our contractors, or in paper files.
Personal data we receive from you about other people
Transfers of personal data abroad
Marbury provides international services – this means that we may transfer your personal data abroad if required to do so for the Permitted Purposes. In certain cases, this may include transferring data to countries which do not offer the same level of protection as the laws of your country (such as for example the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486)).
When making such transfers, we will ensure that they are subject to appropriate safeguards in accordance with the General Data Protection Regulation (Regulation 2016/679) or other relevant data protection legislation. This may include entering into the EU Commission’s Standard Contractual Clauses. Please get in touch at email@example.com if you wish to obtain further information on the appropriate safeguards to which we are adhering.
Marbury will ensure an adequate level of protection for your personal data at all times.
How long we retain your personal data
We delete your personal data once it is no longer reasonably necessary for us to keep it for the Permitted Purposes, or, where we have relied on your consent to keep your personal data, once you withdraw your consent for us to do so, and we are not otherwise legally permitted or required to keep the data. Importantly, Marbury will keep your personal data as necessary for the purposes of defending or making legal claims until the end of the period during which we may retain the data and otherwise until the settlement of any such claims, as relevant.
Your rights regarding your personal data
Subject to certain conditions under applicable legislation, you have the right to:
- request a copy of the personal data which we hold about you;
- have any inaccurate data we hold about you corrected;
- object or restrict our use of your personal data; and
- submit a complaint if you have concerns about the way in which we are handling your data.
To do any of the above, please contact us at firstname.lastname@example.org. To enable us to process your request, we may require that you provide us with proof of your identity, such as by providing us with a copy of a valid form of identification – this is to ensure that we appropriately protect the personal data we hold from unauthorised access requests and comply with our security obligations.
We may charge you a reasonable administrative fee for any unreasonable or excessive requests we may receive, and for any additional copies of the data you may request.
In relation to complaints, we will promptly respond to your requests and complaints. In the event that you are unhappy with our response, you may submit a complaint to the relevant privacy regulator.
Correcting and updating your personal data
Where any personal data you have provided us with has changed, or where you believe the personal data we hold is inaccurate, please contact your Marbury relationship manager. In addition, please note that if you hold an office or are interested in or have certain relationships with a Related Entity to which we provide services, you and/or the Related Entity may have a contractual or legal obligation to notify us of any change within a prescribed time period. We cannot be responsible for any loss that may arise due to us having any inaccurate, incomplete, inauthentic or otherwise deficient personal data which you or a Related Entity have provided to us. Please also let us know if you wish to withdraw any request.
Who decides why and how we process your personal data?
Marbury determines why and how we process your personal data. Marbury consists of Marbury Corporate Advisory Services Limited (together with its respective affiliates, Marbury Entities). In each case, your personal data will be controlled by the Marbury Entity which you have given instructions to, or with which you are otherwise dealing with or receiving communications from or the Marbury Entity which provides services to a third party which you are associated with, for example a company of which you are a director or shareholder.
Regulation of services
Marbury is a licensed trust or company service provider in Hong Kong subject to the legal and supervisory requirements of authorised institutions regulated by the Hong Kong Monetary Authority. Services offered in the Cayman Islands are regulated by the Cayman Islands Monetary Authority, the Financial Services Commission in the British Virgin Islands, and the Bermuda Monetary Authority in Bermuda.