Skip to main content

Privacy Policy

Last updated: 2026-07-28

Important notice

This policy explains how Aries CPA & Co. handles personal data under Hong Kong privacy law and, where applicable, GDPR. Collection-specific notices may also appear on forms and secure upload links.

1. Introduction

Aries CPA & Co. respects your privacy and is committed to protecting personal data. This policy is prepared with reference to the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) and, where applicable, the European Union General Data Protection Regulation (GDPR).

2. Scope of this Policy

This policy applies to personal data collected through our website, contact channels, client communications, service engagements, and secure invitation-only links used for KYC, onboarding, or document upload workflows. Additional collection notices shown at the point of collection should be read together with this policy.

3. Types of Personal Data We May Collect

Depending on your relationship with us and the services requested, we may collect the following categories of personal data:

  • Identity and contact data, such as name, email address, telephone number, address, and contact person details.
  • Client and engagement data, such as company name, relationship to a client, service history, enquiry details, and internal client references.
  • KYC and verification data provided through secure invitation-only links, such as identity documents, passport or identification numbers, address proof, source of funds, source of wealth, birth place, and related declarations.
  • Company formation and onboarding data, such as director, shareholder, company secretary, registered office, correspondence address, business activity, shareholding, signature, and confirmation details.
  • Financial and transaction data, such as payment records, bank details, invoices, receipts, accounting records, and billing information.
  • Professional service records, such as accounting, audit, tax, company secretarial, compliance, due diligence, and supporting documents.
  • Communications data, such as messages submitted through forms, emails, phone notes, meeting records, and correspondence history.
  • Technical and security data, such as IP address, user agent, browser and device information, cookie preferences, log records, timestamps, and security verification results.
  • Uploaded file metadata, such as file names, file sizes, file types, upload status, storage references, and submission dates.
  • Any other personal data you choose to provide to us or that is necessary for the requested service.

4. How We Collect Personal Data

We collect personal data only by lawful and fair means, including:

  • Directly from you or an authorised representative when you contact us, submit a form, send us documents, or communicate by email, phone, messaging, or in person.
  • Through secure invitation-only links issued to specific clients or authorised contacts for KYC, onboarding, or document upload purposes.
  • Automatically when you use our website, including through necessary cookies, server logs, security tools, and similar technologies.
  • From third parties where relevant to our services or legal obligations, such as professional advisers, service providers, public registers, banks, regulators, government bodies, or client-authorised parties.

5. How We Use Personal Data

We use personal data for purposes directly related to our functions and services, including:

  • Responding to enquiries and managing client communications.
  • Providing accounting, audit, tax, company secretarial, compliance, advisory, onboarding, KYC, and related professional services.
  • Verifying identity, conducting due diligence, reviewing source of funds or source of wealth, and meeting anti-money laundering, sanctions, tax, audit, or professional obligations.
  • Preparing, reviewing, filing, or retaining service records, statutory records, tax records, company formation documents, engagement records, and supporting documents.
  • Administering payments, billing, client accounts, internal records, and service quality controls.
  • Operating, securing, troubleshooting, and improving our website, secure upload flows, systems, and communications.
  • Complying with laws, regulations, professional standards, court orders, regulator requests, government requests, or lawful reporting obligations.
  • Establishing, exercising, or defending legal rights and protecting the legitimate interests, safety, and security of Aries CPA & Co., our clients, and others.

6. GDPR Lawful Bases Where Applicable

Where GDPR applies, we rely on one or more lawful bases depending on the context of the processing:

  • Performance of a contract or steps taken before entering into a contract.
  • Compliance with legal or regulatory obligations.
  • Our legitimate interests in providing, managing, improving, and securing professional services, where not overridden by your rights and interests.
  • Consent, where consent is required or appropriate, such as certain optional communications or cookies.
  • Establishing, exercising, or defending legal claims, and processing special-category data only where a valid GDPR condition applies.

7. Disclosure and Transfer of Personal Data

We may disclose or transfer personal data only where relevant to the purposes above or where permitted or required by law, including to:

  • Authorised partners, principals, employees, contractors, and representatives of Aries CPA & Co. who need the information for their work.
  • Cloud hosting, secure storage, email, IT, cybersecurity, analytics, payment, and workflow service providers acting for us.
  • Professional advisers, including auditors, accountants, lawyers, insurers, consultants, company secretarial providers, and other advisers.
  • Banks, payment processors, financial institutions, company registries, tax authorities, regulators, government departments, courts, law enforcement bodies, and other public authorities where relevant.
  • Clients, authorised client representatives, beneficial owners, directors, shareholders, officers, or other parties involved in the relevant engagement.
  • Third parties involved in business continuity, risk management, professional indemnity, dispute handling, or enforcement of our rights.
  • Other parties with your consent, at your direction, or as otherwise permitted by applicable law.

8. Direct Marketing and Cookies

We do not use your personal data for direct marketing unless we have given any notice required by law and obtained your consent or indication of no objection where required. You may opt out at any time. Our website may use necessary cookies and, where enabled, analytics or preference cookies.

9. Cross-border Processing

Some service providers, systems, or authorised recipients may process or store personal data outside Hong Kong or outside your place of residence. Where this occurs, we take practicable steps and use contractual, technical, and organisational measures to protect the data and to meet applicable Hong Kong PDPO and GDPR requirements where relevant.

10. Data Security

We take practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss, or use. Measures may include access controls, confidentiality obligations, secure transmission and storage, server-side encryption for KYC uploads, file validation, staff access on a need-to-know basis, and appropriate service-provider controls.

11. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected or used, including legal, tax, accounting, audit, anti-money laundering, professional, dispute-resolution, and record-keeping requirements. When data is no longer required, we take practicable steps to erase or anonymise it unless retention is required or permitted by law or is in the public interest.

12. Your Rights

Under the Hong Kong PDPO, you have rights to request access to and correction of your personal data. Where GDPR applies, you may also have additional rights, subject to applicable limits and exemptions:

  • Request access to personal data we hold about you.
  • Request correction of inaccurate or incomplete personal data.
  • Request erasure of personal data where applicable.
  • Object to processing where applicable.
  • Request restriction of processing where applicable.
  • Request data portability where applicable.
  • Withdraw consent where processing is based on consent.
  • Opt out of direct marketing communications.
  • Lodge a complaint with the relevant privacy or data protection authority where applicable.

To exercise your rights, please contact our Privacy Officer. We may need to verify your identity and may charge a non-excessive fee for data access requests where permitted by law.

13. Third-party Links

Our website may include links, maps, plug-ins, security widgets, or other third-party services. Those third parties may handle personal data under their own policies. We do not control third-party websites and encourage you to review their privacy notices.

14. Updates to this Policy

We may update this policy from time to time. The updated version will be posted on this page. Where appropriate, we may notify affected clients or users through other reasonable channels.

15. Contact Information

Privacy Officer, Aries CPA & Co., Unit 744, 7/F, Star House, 3 Salisbury Road, Tsim Sha Tsui, Kowloon, Hong Kong. Email: info@ariescpa.com. Please mark privacy requests clearly so they can be handled promptly.

Personal Information Collection Statements

The following summary explains the notices presented at key online collection points:

  • Contact form: providing the requested fields is voluntary. We use them to respond to your enquiry and may disclose them to authorised personnel and email, cloud, security, or professional service providers.
  • Secure KYC and document-upload workflows: required fields and documents are mandatory for onboarding, client due diligence, anti-money laundering compliance, statutory records, and the requested services.
  • If required KYC or formation information is not provided, we may be unable to onboard you, complete the requested service, make required filings, or comply with legal and professional obligations.
  • Each collection notice identifies the collection purpose, whether provision is mandatory or voluntary, the consequences of not providing required data, possible transferee classes, and how to request data access or correction.