WILLSON GROUP LIMITED

Privacy Policy

Effective date: 1 January 2026 · Last updated: 1 January 2026

Return to the Home Station
This Privacy Policy explains how WILLSON GROUP LIMITED, a computer integrated systems design practice, collects, uses, stores, shares and protects personal data. It applies to this website and to the professional services we provide. The policy was prepared with the assistance of our developer Willson Group and is reviewed at least once each year. We describe our practices in plain language and we do not use quotation marks in this document because we prefer direct statements. If anything here is unclear, please write to us at service@buildingwell.mom and we will explain it.

Company WILLSON GROUP LIMITED

Address Rm A2 19 MAX SHARE CTR, 367-373 KINGS RD, North Point, Hong Kong (HK)

Email service@buildingwell.mom

Phone +13209234969

Contents

  1. Scope of This Policy
  2. Who We Are and How to Reach Us
  3. Personal Data We Collect
  4. How We Collect Personal Data
  5. Why We Use Personal Data
  6. Our Lawful Bases for Processing
  7. Cookies and Similar Technologies
  8. When We Share Personal Data
  9. Service Providers and Processors
  10. International Transfers of Data
  11. How Long We Keep Personal Data
  12. How We Protect Personal Data
  13. Your Rights and Choices
  14. Making an Access or Correction Request
  15. Data We Process on Behalf of Clients
  16. Marketing Communications
  17. Privacy for Children
  18. Third Party Sites and Links
  19. Automated Decisions and Profiling
  20. Data Breaches and Incident Response
  21. Changes to This Policy
  22. Complaints and Dispute Resolution
  23. Governing Law and Language
  24. Contacting the Station

1. Scope of This Policy

This Privacy Policy governs the personal data that WILLSON GROUP LIMITED collects and processes when you visit this website, contact us, request a survey, engage our services, or otherwise interact with our station in North Point. It also describes the commitments we make when we handle personal data on behalf of a client as part of an engineering engagement.

The policy applies to all visitors, prospective clients, clients, suppliers, partners and applicants who provide personal data to us. It does not apply to the practices of other companies, including those whose websites or services may be linked from this site. Those organisations maintain their own privacy notices, and we encourage you to read them.

Where we process personal data on instructions from a client, that client is normally responsible for the original collection and for the lawful basis of the processing. In those situations this policy describes our role as a service provider, and the client privacy notice governs the relationship with the individual concerned.

2. Who We Are and How to Reach Us

WILLSON GROUP LIMITED is a company established in Hong Kong that provides computer integrated systems design and related professional services. Our registered and operational address is Rm A2 19 MAX SHARE CTR, 367-373 KINGS RD, North Point, Hong Kong (HK). Our teams design, integrate, secure and support the systems that our clients depend on.

For the purposes of applicable data protection law, WILLSON GROUP LIMITED is the controller of the personal data described in this policy, except where we act as a processor on behalf of a client. Questions about this policy, or about the way we handle personal data, may be sent to service@buildingwell.mom or raised by telephone on +13209234969.

We have a designated privacy contact within our operations team who coordinates responses to privacy enquiries and access requests. This person works with our engineering leads to ensure that any technical change affecting personal data is reviewed before it is deployed.

3. Personal Data We Collect

We collect only the personal data that we need for the purposes described in this policy. The categories we may collect include the following.

  • Identity and contact data, such as your name, employer, job title, email address, telephone number and postal address.
  • Enquiry and correspondence data, including the content of messages you send through our contact form, by email or by telephone, and a record of our replies.
  • Contract and billing data, such as company registration details, purchase order references, invoicing contacts and payment records.
  • Service and technical data, such as system information that you share with us during a survey, including configuration details that may incidentally contain personal data.
  • Website usage data, such as pages viewed, approximate location derived from network information, browser type, device type and timestamps.
  • Recruitment data, where you apply for a role with us, including your application, references and eligibility to work information.

We do not seek to collect sensitive categories of personal data, such as health information, political opinions or religious beliefs, through this website. If such information is ever required for a specific engagement, we will request it separately, explain why it is needed and obtain any consent that the law requires.

We do not collect payment card numbers through this website. Where billing requires such details, they are handled through agreed commercial channels between the contracting parties.

4. How We Collect Personal Data

We collect personal data in several ways. You provide much of it directly when you complete our contact form, send an email, call the station, sign a proposal, return a supplier form or apply for a position. When you provide data about another person, you confirm that you have the right to do so and that the person understands how the data will be used.

We also collect data automatically when you use this website. Our hosting infrastructure records standard technical information such as the requested page, the time of the request and the browser identification string. These records support security, capacity planning and fault diagnosis.

We may receive data from third parties, including clients who introduce their staff to us, partners who refer an opportunity, and public sources that help us verify business details. Where we receive personal data indirectly, we handle it in the same way as data we collect ourselves, and we do not use it for any purpose beyond those stated in this policy.

5. Why We Use Personal Data

We use personal data for the following purposes. Each purpose is tied to the operation of our business and to the services our clients engage us to provide.

  • To respond to enquiries and provide information about our services and availability.
  • To prepare proposals, surveys, conditions reports and statements of work.
  • To deliver, manage and support the systems we design and integrate.
  • To maintain accurate business records, issue invoices and manage payments.
  • To operate, secure and improve this website and our internal systems.
  • To meet legal, regulatory, tax and audit obligations that apply to us in Hong Kong.
  • To protect our rights and the rights of our clients, including in the investigation of misuse, fraud or security incidents.
  • To assess applications and manage relationships with suppliers, partners and contractors.

We do not sell personal data. We do not rent contact lists. We do not use personal data collected through this website for unrelated purposes, and we do not allow third parties to use it for their own marketing.

6. Our Lawful Bases for Processing

Depending on the circumstances, we rely on one or more lawful bases for processing personal data. Where you have entered into a contract with us, or where we are taking steps at your request before entering a contract, we process the data needed to perform that contract, including contact, delivery and billing information.

Where we have a legitimate interest, we process personal data to run and protect our business, provided that the interest is not overridden by your rights and freedoms. Examples include responding to business enquiries, preventing fraud and securing our infrastructure. Where we require your consent, for example to send certain marketing messages, we ask for it clearly and you may withdraw it at any time.

We also process personal data to comply with legal obligations, such as maintaining accounting records and responding to lawful requests from public authorities. Where we process personal data on behalf of a client, the client is responsible for ensuring that a lawful basis exists for the underlying processing.

7. Cookies and Similar Technologies

This website is designed to work with minimal tracking. We do not operate advertising networks, and we do not place profiling cookies for commercial purposes. The infrastructure that serves these pages may set a small number of technical cookies or use similar storage to keep the site functioning, to balance load and to protect against abuse.

If we introduce analytics that use cookies or comparable identifiers, we will update this policy, provide any notice that the law requires and offer a clear way to decline where consent is the applicable basis. Your browser settings allow you to block or delete cookies, and the site will continue to display its content if you do so.

We treat aggregate measurement data as non personal where it cannot reasonably be linked to an individual. Where such data can be linked, we handle it as personal data and apply the same safeguards described in this policy.

8. When We Share Personal Data

We share personal data only where there is a clear need and an appropriate safeguard. The categories of recipient are limited and are listed in this section. We do not disclose personal data to unrelated third parties for their own purposes.

  • Service providers who support our operations, such as hosting, email, accounting and professional advisory providers, acting under written instructions.
  • Subcontractors and engineering partners who work on a client engagement, to the extent needed to deliver the agreed services.
  • Professional advisers, including lawyers, auditors and insurers, where advice or protection is required.
  • Public authorities, courts and regulators, where disclosure is required by law or necessary to protect legal rights.
  • A successor entity, in the event of a merger, acquisition, reorganisation or transfer of business assets, subject to equivalent protections.

Where required, we put written agreements in place that require recipients to protect personal data and to process it only for the agreed purpose. We do not authorise any recipient to use personal data for their own independent marketing.

9. Service Providers and Processors

We rely on a small number of service providers for hosting, email delivery, document storage and accounting. These providers act as processors on our instructions and are selected with attention to their security posture and their ability to meet confidentiality obligations.

Before engaging a processor, we assess the nature of the data involved, the sensitivity of the processing and the risk to individuals. The written agreement with each processor addresses the subject matter of the processing, its duration, the type of data, the categories of data subject, and the obligations of the processor, including confidentiality, security, assistance with individual rights and deletion at the end of the engagement.

Where a processor wishes to engage a further subcontractor, we require prior authorisation and a flow down of the same obligations. We review our processor relationships periodically, and we end relationships where the required standard of protection is not maintained.

10. International Transfers of Data

WILLSON GROUP LIMITED is based in Hong Kong, and our primary data handling takes place there. Some of our service providers operate infrastructure in other jurisdictions, which means personal data may be transferred outside Hong Kong in the course of ordinary business operations.

Where we transfer personal data internationally, we take steps to ensure that the data continues to receive an appropriate level of protection. These steps may include contractual commitments that impose confidentiality, security and use limitations on the recipient, together with technical measures such as encryption in transit and access control.

We keep a record of the main international transfers associated with our operations and review them when providers or architectures change. If you would like more detail about the safeguards applied to a specific transfer, please contact our privacy contact using the details in this policy.

11. How Long We Keep Personal Data

We retain personal data only for as long as it is needed for the purpose for which it was collected, or for as long as the law, a contract or a legitimate business need requires. Retention periods are set with reference to the type of data, the sensitivity of the information and the risk of harm from unauthorised use.

As a general guide, enquiry correspondence is kept for the period needed to resolve the matter and for a reasonable follow up window. Contract, billing and tax records are kept for the period required by applicable Hong Kong law and accounting practice. Recruitment records are kept for the duration of the process and for a limited period afterwards, after which they are deleted unless you ask us to keep them longer.

When a retention period ends, we delete or anonymise the data in a controlled manner. Where deletion is not immediately possible because data resides in backups, we isolate the affected backups and delete the data when the backup cycle next completes.

12. How We Protect Personal Data

Security engineering is part of our professional discipline. We apply technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure and destruction. These measures are proportionate to the risk and are reviewed as threats and technologies evolve.

  • Access control based on role and least privilege, with review of accounts and permissions.
  • Encryption of data in transit, and encryption at rest where the platform supports it.
  • Segregated environments for development, testing and production.
  • Logging and monitoring of administrative activity, retained for investigation purposes.
  • Secure configuration baselines, patch management and vulnerability assessment.
  • Written operational procedures, including backup verification and recovery testing.
  • Confidentiality obligations for staff, contractors and partners who handle personal data.

No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. We continuously improve our controls and we act promptly when an issue is identified. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the affected parties and the relevant authority as required by law.

13. Your Rights and Choices

Subject to applicable law, you may have rights in relation to the personal data we hold about you. These rights are not absolute, and they may be limited by legal obligations or by the rights of others. Where you make a request, we will tell you what we can do and explain any limitation that applies.

  • The right to be informed about how your personal data is collected and used.
  • The right of access to the personal data we hold about you.
  • The right to request correction of data that is inaccurate or incomplete.
  • The right to request deletion of data that we no longer have a lawful reason to keep.
  • The right to object to certain processing, including processing based on legitimate interests.
  • The right to withdraw consent where processing is based on consent.
  • The right to request restriction of processing in certain circumstances.
  • The right to lodge a complaint with a supervisory authority.

You can exercise these rights by writing to service@buildingwell.mom or by post to Rm A2 19 MAX SHARE CTR, 367-373 KINGS RD, North Point, Hong Kong (HK). We will verify your identity before acting on a request, and we will respond within the period allowed by applicable law.

14. Making an Access or Correction Request

To make an access or correction request, please contact us using the details in this policy and describe the data you are asking about. If you write on behalf of another person, we may ask for evidence of your authority. This helps us protect personal data from being disclosed to someone who is not entitled to receive it.

There is normally no charge for handling a request, although we may apply a reasonable fee where the law permits and where a request is manifestly unfounded or excessive. If we need more information to locate the relevant data, we will tell you promptly and explain why it is needed.

We keep a record of requests received and of the outcome, so that we can demonstrate compliance and improve our handling over time. If we refuse a request, we will give our reasons and explain how you can challenge the decision. Nothing in this section limits any right you may have under applicable law.

15. Data We Process on Behalf of Clients

When we design, integrate or support systems for a client, we may process personal data that belongs to that client estate. In these situations we act as a service provider or processor, and the client determines the purposes and the lawful basis of the processing.

We process such data only on documented instructions from the client, and only for the purposes of delivering the agreed services. We apply the same security discipline described in this policy, and we do not use client data for our own purposes. Our staff and contractors who handle client data are bound by confidentiality obligations.

Where a client asks us to assist with a request from an individual, we will do so within the scope of the engagement and the applicable agreement. At the end of an engagement, we return or delete client data according to the contract and our retention obligations, and we provide evidence of deletion where the client requires it.

16. Marketing Communications

We send marketing messages only where we have a lawful basis to do so, and we keep them relevant and infrequent. You may receive occasional updates about our services, our quarterly systems review programme or changes that may affect clients. We do not send bulk marketing to individuals who have asked us to stop.

Every marketing message includes a way to opt out, and you may also write to service@buildingwell.mom at any time to change your preferences or to be removed from our list. Opting out of marketing does not affect service messages, such as those relating to a contract, an incident or a security notice that affects you.

We do not share contact details with third parties for their own marketing, and we do not purchase contact lists for cold outreach. Where we work with a partner on a joint activity, we identify the sender clearly and apply the preferences you have expressed to us.

17. Privacy for Children

Our website and services are directed at businesses and professional audiences. We do not knowingly collect personal data from children, and we do not design our services for use by children. If you believe that a child has provided personal data to us, please contact us so that we can investigate and, where appropriate, delete the data.

Where a client system that we support may be used by or about children, we handle that data strictly on the client instructions and apply additional care to minimise collection and access. Any such engagement is documented in the relevant agreement, including the safeguards that apply.

Because our services are not intended for children, we do not use personal data of children for marketing and we do not build profiles of children. Privacy for Children is a principle we take seriously, and we review it whenever our service scope changes.

18. Third Party Sites and Links

This website may contain links to other websites, including those of partners, providers, public bodies and professional resources. We are not responsible for the privacy practices or the content of those sites. When you follow a link, we encourage you to read the privacy notice of the destination site before providing any personal data.

We do not control the cookies, tracking technologies or data handling of third party sites, even where a link appears on our pages. The presence of a link does not imply that we endorse the practices of the destination, and it does not extend our commitments to that destination.

If you reach our website through a link from another site, the referring site may have collected information about your visit. We do not receive that information unless the referring site shares it with us, and we handle anything we do receive in accordance with this policy.

19. Automated Decisions and Profiling

We do not use personal data collected through this website to make automated decisions that produce legal effects or similarly significant effects on individuals. We do not build behavioural advertising profiles, and we do not sell inference data about visitors or clients.

Our engineering work may include automation that routes requests, classifies system events or prioritises alerts. Where such automation touches personal data, we design it to support human review rather than to replace it, and we document the logic so that its behaviour can be explained and corrected.

If a future service ever requires automated decision making that affects an individual, we will provide clear information in advance, offer a route to human review and obtain any consent that the law requires. We will update this policy before any such change takes effect.

20. Data Breaches and Incident Response

We maintain an incident response procedure that covers the detection, containment, assessment and notification of personal data breaches. The procedure names the roles responsible, sets out the evidence we preserve and defines the timescales for internal escalation.

When a breach is confirmed, we assess the likelihood and severity of the risk to affected individuals. Where the risk is significant, we notify the relevant supervisory authority without undue delay and, where required, we inform affected individuals directly with a clear description of what happened and what they can do.

After an incident we conduct a review, record the lessons learned and implement corrective measures. We share relevant findings with affected clients where the incident relates to a system we support, because transparency is part of keeping the watch and it improves the safety of the wider estate.

21. Changes to This Policy

We review this policy at least once each year and whenever our practices, our services or the law change in a material way. When we make a change, we update the effective date at the top of the page and, where the change is significant, we provide a prominent notice on the website or contact affected parties directly.

We keep previous versions of this policy so that we can show how our commitments have evolved. If you would like a copy of an earlier version, please contact us and we will provide it where we are able to do so.

Your continued use of this website after a change takes effect indicates that you have had the opportunity to read the updated policy. We encourage you to check this page periodically, particularly before providing new personal data.

22. Complaints and Dispute Resolution

If you are unhappy with the way we have handled your personal data, please tell us first so that we can investigate and, where appropriate, put things right. You can reach our privacy contact at service@buildingwell.mom or by telephone on +13209234969. We aim to acknowledge complaints promptly and to provide a substantive response within a reasonable period.

Where a complaint relates to a service we provide on behalf of a client, we may refer the matter to that client, because the client is normally the party responsible for the original processing. We will tell you if we do this and we will cooperate fully with the client response.

If you remain dissatisfied, you may have the right to complain to the relevant supervisory authority in your jurisdiction or in Hong Kong. We will provide reasonable information to help you exercise that right. Nothing in this policy prevents you from pursuing any remedy that the law makes available to you.

23. Governing Law and Language

This policy is governed by the laws of the Hong Kong Special Administrative Region, without regard to conflict of law principles, except where a mandatory provision of the law of your own jurisdiction gives you a stronger protection that cannot be waived. Where a dispute arises, the courts of Hong Kong have jurisdiction unless the applicable law requires otherwise.

This policy is written in English. Where a translation is provided for convenience, the English version prevails to the extent permitted by law. We keep the language direct and free of quotation marks so that readers can follow the meaning without ambiguity.

If any provision of this policy is found to be invalid or unenforceable, the remaining provisions continue in full force. The invalid provision is replaced by a valid provision that most closely reflects the original intention, and the overall level of protection for individuals is preserved.

24. Contacting the Station

We welcome questions about this policy and about the way WILLSON GROUP LIMITED handles personal data. Please write to service@buildingwell.mom, call +13209234969, or send post to WILLSON GROUP LIMITED, Rm A2 19 MAX SHARE CTR, 367-373 KINGS RD, North Point, Hong Kong (HK). Our team will direct your message to the right engineer or administrator and will respond within the timescales described in this policy.

If you are a client and your question concerns data held inside a system we support, please include the system name and a contact reference so that we can locate the relevant records quickly. If you are a visitor with a question about this website, a note of the page you were using helps us answer precisely.

We value the trust that clients and visitors place in us. Reading conditions accurately is our discipline, and handling personal data with care is part of the same practice. Thank you for taking the time to read this Privacy Policy, and for your interest in WILLSON GROUP LIMITED.

WILLSON GROUP LIMITED · Rm A2 19 MAX SHARE CTR, 367-373 KINGS RD, North Point, Hong Kong (HK)

Email service@buildingwell.mom · Phone +13209234969 · Copyright 2026 WILLSON GROUP LIMITED. All rights reserved.

Home Services Contact Privacy Policy Terms of Service