All legal documents

Privacy Policy

Last updated August 2, 2026


1. GENERAL PROVISIONS

  1. This Personal Data Processing Policy has been prepared in accordance with the requirements of the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (the "PDPO") and defines the procedure for processing personal data and the measures taken to ensure the security of personal data undertaken by RE:JOIN LIMITED (hereinafter – the Operator).
  2. This Personal Data Processing Policy:
    1. Establishes the rules for the processing by the Operator of personal data provided by persons who use the Website https://rejoin.network, including subdomains and their pages, in order to obtain services (hereinafter – the Customers, Users, Website).
    2. Determines the purposes, legal bases, procedure and scope of the personal data processed.
    3. Determines the procedure for interaction with data subjects when requests are received from them.
  3. This Policy defines the Operator's policy regarding the processing of personal data. All matters relating to the processing of personal data that are not regulated by this Personal Data Processing Policy shall be resolved in accordance with the applicable data-protection laws of the Hong Kong Special Administrative Region.
  4. This Operator's policy regarding the processing of personal data applies to all information that the Operator may obtain about visitors to the Website https://rejoin.network, including subdomains and their pages.
  5. Key terms used in the Personal Data Processing Policy:
    1. Operator – RE:JOIN LIMITED, independently or jointly with other persons organising and (or) carrying out the processing of personal data, as well as determining the purposes of processing personal data, the composition of the personal data to be processed, and the actions (operations) performed with personal data.
    2. Processing of personal data – any action or set of actions performed with or without the use of automation tools with personal data, including collection, recording, systematisation, accumulation, storage, clarification (updating, modification), extraction, use, transfer (distribution, provision, access), anonymisation, blocking, deletion, and destruction of personal data.
    3. Automated processing of personal data – the processing of personal data using computing equipment.
    4. Website – a set of graphic and information materials, as well as computer programs and databases, ensuring their availability on the internet at the network address https://rejoin.network, including subdomains and their pages.
    5. Personal data – any information relating directly or indirectly to a specified or identifiable User of the Website https://rejoin.network, including subdomains and their pages.
    6. User – any visitor to the Website https://rejoin.network, including subdomains and their pages.
    7. Blocking of personal data – the temporary cessation of the processing of personal data (except in cases where processing is necessary to clarify personal data).
    8. Provision of personal data – actions aimed at disclosing personal data to a specified person or a specified group of persons.
    9. Destruction of personal data – any actions as a result of which personal data are irrevocably destroyed with the impossibility of further recovery of the content of the personal data.
    10. Distribution of personal data – actions aimed at disclosing personal data to an indefinite group of persons.
    11. Anonymisation of personal data – actions as a result of which it becomes impossible, without the use of additional information, to determine the belonging of personal data to a specific data subject.
    12. Personal data information system – a set of personal data contained in databases and the information technologies and technical means that ensure their processing.
  6. The Operator processes the following categories of personal data:
    1. Surname, first name, patronymic (full name);
    2. Telephone number / messenger;
    3. Email address.
    4. User data (location information; type and version of the OS; type and version of the Browser; device type and its screen resolution; the source from which the user came to the Website; the language of the OS and Browser; which pages the user opens and which buttons the user clicks; IP address).
  7. The categories of subjects whose personal data are processed belong to natural persons who submit requests on the Operator's website and are in civil-law relations with the Operator; the processing of requests from natural persons for the provision of Services, clarification of order details, and coordination of the time and format of the provision of Services.
  8. The Website also collects and processes anonymised data about visitors (including "cookie" files) using internet statistics services (Google Analytics, PostHog, and others).

2. PURPOSES OF PROCESSING PERSONAL DATA

  1. Ensuring the protection of human and civil rights and freedoms in the processing of personal data, including the protection of the rights to privacy, personal and family confidentiality.
  2. Conclusion, performance and termination of civil-law contracts; provision of access for the User to the services, information and/or materials contained on the Website https://rejoin.network, including subdomains and their pages, and clarification of order details.
  3. When processing personal data, the Operator applies legal, organisational and technical measures to ensure the security of personal data in accordance with the requirements of the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486).
  4. The Operator has the right to send the User notifications about new products and services, special offers and various events.
  5. The anonymised data of Users collected using internet statistics services serve to collect information about Users' actions on the Website, and to improve the quality of the Website and its content.

3. PRINCIPLES OF PROCESSING PERSONAL DATA

  1. The processing of personal data is organised by the Operator on the principles of:
  2. Lawfulness of the purposes and methods of processing personal data, good faith and fairness in the activities of the Operator.
  3. Accuracy of personal data, their sufficiency for the purposes of processing, and the inadmissibility of processing personal data that are excessive in relation to the purposes stated at the time of collection of personal data.
  4. Processing only of those personal data that meet the purposes of their processing.
  5. Ensuring the accuracy of personal data, their sufficiency and, where necessary, their currency in relation to the purposes of processing personal data. The Operator takes the necessary measures, or ensures that they are taken, to delete or clarify incomplete or inaccurate data.
  6. Storage of personal data in a form that allows the data subject to be identified for no longer than the purposes of processing personal data require.
  7. The processing of personal data is carried out in compliance with the principles and rules provided for by the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) and this Policy.

4. RECEIPT, PROCESSING AND STORAGE OF PERSONAL DATA

  1. The Operator establishes the following procedure for obtaining personal data upon registration and ordering of services on the Operator's Website: the data subject provides their full name, telephone, email, messengers and other information necessary to identify the data subject and to provide services to them.
  2. When applying for the Operator's services, the Customer provides the data specified by the relevant forms.
  3. The Operator does not obtain or process a client's personal data concerning their racial origin, political views, religious and philosophical beliefs, state of health, or intimate life, unless otherwise provided by law.
  4. In the event that the Customer accepts the offer posted on the Operator's Website, or concludes another agreement with the Operator, the processing of the Customer's personal data is carried out for the performance of the relevant agreement that has entered into force as a result of the Customer's acceptance of the terms of the offer, or the conclusion of another agreement, respectively. The offer and its acceptance operate in accordance with the general principles of offer and acceptance under the common law.
  5. The Operator has the right to process the personal data of Customers and natural persons who have contacted the Operator only with their consent to the use of personal data.
  6. The Customer's consent to the processing of personal data is not required in the following cases:
    1. The personal data are publicly available.
    2. The processing of personal data is carried out on the basis of a law establishing its purpose, the conditions for obtaining personal data, the group of subjects whose personal data are to be processed, and the defined powers of the Operator.
    3. At the request of authorised state bodies – in the cases provided for by law.
    4. Processing of personal data for the purpose of performing an agreement concluded with the Operator.
    5. The processing of personal data is carried out for statistical or other scientific purposes, provided that the personal data are compulsorily anonymised.
    6. The processing of personal data is necessary to protect the life, health or other vital interests of the Customer, if obtaining their consent is impossible.
  7. The Operator ensures the secure storage of personal data, including:
    1. The storage, collation, recording and use of documents containing personal data is organised in the form of a separate archive of the Operator.
    2. The storage of personal data must be carried out in a form that allows the data subject to be identified for no longer than the purposes of processing personal data require, unless the period of storage of personal data is established by law or by an agreement to which the data subject is a party, beneficiary or guarantor. Processed personal data are subject to destruction or anonymisation upon achievement of the purposes of processing, or in the event of the loss of the need to achieve those purposes, unless otherwise provided by law.
  8. A condition for the termination of the processing of personal data may be the achievement of the purposes of processing personal data, the expiry of the term of consent or the withdrawal of the data subject's consent to the processing of their personal data, as well as the identification of unlawful processing of personal data.
  9. The security of personal data processed by the Operator is ensured through the implementation of legal, organisational and technical measures necessary to fully comply with the requirements of the applicable legislation in the field of personal data protection.
  10. The Operator ensures the safety of personal data and takes all possible measures to exclude access to personal data by unauthorised persons.
  11. If inaccuracies are identified in the personal data, the User may update them independently by sending the Operator a notification to the Operator's email address marked "Updating of personal data".
  12. The period for processing personal data is unlimited until the cessation of activities or the liquidation of the organisation; alternatively, the User may at any time withdraw their consent to the processing of personal data by sending the Operator a notification via email to the Operator's email address marked "Withdrawal of consent to the processing of personal data".

5. MEASURES TO ENSURE THE SECURITY OF PERSONAL DATA

  1. The Operator takes the following measures to ensure the security of personal data as required under the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486):
    1. Internal control is carried out over the compliance of the processing of personal data with the PDPO and the regulatory legal acts adopted in accordance with it, and with the requirements for the protection of personal data;
    2. On the Operator's website on the internet, through which the direct provision of services is carried out, a document defining the policy regarding the processing of personal data, together with information on the implemented requirements for the protection of personal data, has been published and posted;
    3. Organisational and technical measures are applied to ensure the security of personal data during their processing in information systems, as necessary to meet the requirements for the protection of personal data, the performance of which ensures the established levels of protection of personal data:
      1. appointment of officials responsible for organising the processing and protection of personal data;
      2. limiting the composition of persons authorised to process personal data;
      3. familiarising subjects with the requirements of the applicable legislation and the Operator's regulatory documents on the processing and protection of personal data;
      4. organising the recording, storage and handling of media containing personal data;
      5. identifying threats to the security of personal data during their processing, and forming threat models on their basis;
      6. developing, on the basis of the threat model, a system for the protection of personal data;
      7. checking the readiness and effectiveness of the use of information protection tools;
      8. differentiating user access to information resources and hardware and software means of processing information;
      9. registering and recording the actions of users of personal data information systems;
      10. using antivirus tools and tools for restoring the personal data protection system;
      11. applying, where necessary, firewalling, intrusion detection, security analysis, and cryptographic information protection tools.
    4. Rules for access to personal data processed in the information system have been established, as well as the registration and recording of all actions performed with personal data in the Operator's information system;
    5. Control is exercised over the measures taken to ensure the security of personal data and the level of protection of the Operator's information systems.
    6. The possibility of uncontrolled entry or presence of unauthorised persons in the premises where work with personal data is carried out is excluded. The safety of personal data media and information protection tools is ensured. In the event of processing personal data on physical media, separate storage of personal data (physical media) processed for different purposes is ensured.
    7. In order to protect personal data, the Operator has provided for the following measures: the use of antivirus software; the use of an electronic digital signature; passwords on computers on which personal data are processed; backup; and restriction of access to premises in which personal data are processed.

6. TRANSFER OF PERSONAL DATA

  1. Personal data are transferred to the Operator in compliance with the following requirements:
    1. It is prohibited to disclose personal data to a third party without the Customer's written consent, except in cases where this is necessary in order to prevent a threat to the life or health of the Customer, as well as in other cases provided for by law.
    2. Not to disclose personal data for commercial purposes without the written consent of the subject of such data.
    3. To warn persons receiving personal data that these data may be used only for the purposes for which they are provided, and to require these persons to confirm that this rule has been complied with.
    4. To allow access to personal data only to specially authorised persons, and such persons must have the right to receive only those personal data that are necessary for the performance of specific functions.
    5. Not to request information about the state of health of the Customer, except for such information as relates to the question of the Customer's ability to fulfil obligations under the agreement with the Operator.
    6. To transfer the Customer's personal data to their representatives in the manner established by the applicable data-protection legislation.
    7. Processing of personal data may be carried out by mixed processing, with transfer over the Operator's internal network and with transfer over the internet, and by automated processing without transfer over the Operator's internal network but with transfer over the internet.
    8. The Operator does not carry out cross-border transfer of personal data.
    9. Encryption (cryptographic) tools: not used.

7. LEGAL BASES FOR PROCESSING PERSONAL DATA

  1. The legal basis for the processing of personal data is the set of legal acts in pursuance of and in accordance with which the Operator processes personal data on the basis of: the applicable legislation, agreements between the Operator and the data subject, and consent to the processing of personal data (in cases not expressly provided for by the applicable legislation but consistent with the powers of the Operator).
  2. The Operator processes the User's personal data only if they are filled in and/or submitted by the User independently through the special forms located on the Website https://rejoin.network, including subdomains and their pages. By filling in the relevant forms and/or submitting their personal data to the Operator, the Customer/User expresses their consent to this Policy.
  3. The Operator processes anonymised data about the User if this is permitted in the User's browser settings (the saving of "cookie" files and the use of JavaScript technology are enabled).

8. FINAL PROVISIONS

  1. The User may obtain any clarifications on questions of interest concerning the processing of their personal data by contacting the Operator using the Operator's email address indicated on the Website as contact details.
  2. Upon achievement of the purposes of processing personal data, as well as in the event of the withdrawal by the data subject of consent to their processing, personal data are subject to destruction if:
    1. Not otherwise provided by an agreement to which the data subject is a party, beneficiary or guarantor;
    2. The Operator is not entitled to carry out processing without the consent of the data subject on the grounds provided for by the applicable data-protection legislation;
    3. Not otherwise provided by another agreement between the Operator and the data subject.
  3. The Operator reserves the right to make changes to this Policy at its discretion, including in cases where this is caused by changes in legislation or in the Terms of Use of the Website's services. Notices of changes to the Personal Data Processing Policy may be displayed on the Website (for example, in the Personal Account, via a pop-up window or banner) before such changes take effect, or may be sent by email. The User is obliged, each time they use the Website, to familiarise themselves with the text of the Personal Data Processing Policy.
  4. The Operator is obliged to provide the data subject or their representative with information about the processing of such subject's personal data upon request, which may be sent to the Operator's email address.
  5. The new version of the Personal Data Processing Policy enters into force from the moment of its posting in the relevant section of the Operator's Website. In the event of disagreement with the terms of this Policy, the User must immediately cease using the Website and its services.

9. Information about the Operator:

RE:JOIN LIMITED, a company incorporated in the Hong Kong Special Administrative Region.

Registered office: RM 68, 7/F, Woon Lee Commercial Building, 7 Austin Avenue, Tsim Sha Tsui, Hong Kong.

Website: https://rejoin.network

Email address (general): hello@rejoin.network

Email address (legal / privacy requests): legal@rejoin.network

Any complaints regarding the handling of personal data may also be addressed to the Office of the Privacy Commissioner for Personal Data (PCPD), Hong Kong.

Approved on behalf of RE:JOIN LIMITED.