Privacy
Privacy Policy
Last updated: 15 August 2026 · Personal Data (Privacy) Ordinance (Cap. 486)
1. Data user
Captain Legal LLC is the data user responsible for the personal data processed to provide the Captain.Legal service, within the meaning of the Personal Data (Privacy) Ordinance (Cap. 486) (the “PDPO”). This policy explains how we comply with the six Data Protection Principles (DPPs) in Schedule 1 to the PDPO. For any request, use our contact form.
2. Personal data we collect (DPP1)
In accordance with DPP1, we collect personal data by lawful and fair means, only where it is necessary for the service and not excessive for that purpose:
- Identification and contact data: email address, first name, last name.
- Data entered in the questionnaires: information needed to generate a document, which may relate to third parties under your responsibility.
- Order and billing data: documents purchased, amount, date, history.
- Payment data: processed directly by PayPal and Stripe; we never access your full card details.
- Technical and connection data: IP address, access logs and information used to prevent fraud.
3. Purposes of use (DPP3)
In accordance with DPP3, we use personal data only for the purpose for which it was collected or a directly related purpose, unless we obtain your prescribed consent for a new purpose:
- Creating, delivering and storing the documents you order.
- Managing your account, orders, invoices and support requests.
- Protecting the service and preventing fraudulent use.
- Measuring audience and sending communications only where a valid basis or your consent exists.
4. Accuracy and retention (DPP2)
In accordance with DPP2, we take practicable steps to ensure that personal data is accurate and is not kept longer than necessary for the purpose for which it is used. Each category of data is retained for the time needed to provide the service, meet accounting obligations and handle complaints, after which it is erased or anonymised.
5. Service providers and transfers
Personal data may be processed by providers of hosting, email delivery, support, analytics and payment services, bound by confidentiality and data-protection obligations. Where data is transferred outside Hong Kong, we take practicable steps — including contractual safeguards — to ensure it receives a level of protection consistent with the PDPO. Your data is never sold.
6. Security (DPP4)
In accordance with DPP4, we take practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss or use: TLS encryption, access controls, operation logging, secure hosting and backup measures.
7. Transparency and your rights (DPP5 & DPP6)
In accordance with DPP5, we make our policies and practices on personal data openly available through this policy. Under DPP6 and Part 5 of the PDPO, you may make a data access request to obtain a copy of your personal data and a data correction request to have inaccurate data corrected. Submit your request through the contact form, stating your identity and the data concerned; we will respond within the statutory time limit. If you are not satisfied with our response, you may complain to the Privacy Commissioner for Personal Data (PCPD), the independent authority responsible for enforcing the PDPO in Hong Kong.
8. Direct marketing (Part 6A)
In accordance with Part 6A of the PDPO, we use your personal data in direct marketing only after informing you and obtaining your indication of no objection or consent, and every message includes a way to opt out. You may require us, at any time and free of charge, to stop using your personal data for direct marketing through the unsubscribe link or the contact form.
9. Cookies and changes
Necessary cookies keep the site working. Analytics and advertising cookies follow the choice you make in the consent banner; you can change it at any time via “Manage cookies” or read the Cookie Policy. Any material change to this policy will be published on this page with a new update date.