1. About This Policy
Hong Kong Insurance Brokers Directory("we", "us", "our") is committed to protecting personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong ("PDPO"). This Privacy Policy explains how we collect, use, store, and protect your personal data.
2. Personal Information Collection Statement (PICS)
When you register for an account, we collect the following personal data:
- Broker firms: IA licence number, admin email address, company registration certificate
- Technical representatives: IA licence number, email address, and a copy of your HKID document (image or PDF) uploaded for one-time identity verification by our site administrator
- Contact information (optional): Mobile number, WhatsApp number, WeChat ID — only if voluntarily provided and opted in for public display
- CPD records: Course certificates, course details, hours completed
3. Purpose of Collection
- Account verification and identity confirmation
- Managing your public directory listing (firm portfolio page)
- CPD compliance tracking and reporting
- Communication regarding your account
4. Use and Disclosure of Data
Your personal data may be shared with:
- Public directory:Only data you explicitly opt in to display (contact info with "Public" toggle enabled)
- Your appointing firm: Firm administrators can view your CPD records for compliance oversight
- AI processing: CPD certificates may be sent to an external AI service (OpenRouter) for automated extraction of course details. This constitutes a cross-border data transfer.
We will not use your data for marketing without your separate consent.
5. Data Retention
- HKID document: Stored in an encrypted, access-controlled storage bucket (private, never publicly accessible) solely for identity verification. Retained while your account remains active so we can re-verify identity if a dispute arises; deleted on account closure or on written request once verification is no longer required
- Rejected registration requests: Purged after 90 days
- CPD certificates: Retained for the assessment period plus 1 year
- Account data: Retained for the duration of your account; deleted upon account deletion request
- Audit logs: Retained for 2 years, then automatically purged
6. Data Security
We implement appropriate technical measures to protect your data, including encrypted storage, row-level security policies, signed URLs for private files, and access controls that limit data visibility to authorised users only.
7. Your Rights (DPP6)
Under the PDPO, you have the right to:
- Request access to your personal data held by us
- Request correction of any inaccurate personal data
- Delete your account and all associated personal data
You can manage your data directly through your admin portal or contact us at support@hongkonginsurancebrokers.com.