Legal · Effective 11 September 2026
Privacy and data handling policy
This policy explains data handling by this static website and our professional enquiry process. It distinguishes browser-local functionality from information actually sent to us.

Controller contact: Digital Buzz Tech, 728 King's Road, Quarry Bay, Hong Kong. Email: [email protected].
1. Scope and status
This policy covers visits to digitalbuzztech.com, direct enquiries and information handled while assessing a prospective engagement. It does not govern a client system we operate under a separate contract; that contract will identify the parties’ roles and instructions.
2. Information you provide
When you email us, we may receive your name, work contact details, organisation, project brief, attachments and correspondence. Please do not send production credentials, unrestricted personal datasets, student records or other sensitive material in an initial enquiry.
3. Browser-local forms and drafts
The contact form in this static build saves a draft under dbt_contact_draft_v1 in your browser. The project-fit plan, planning signal and capability shortlist use separate local-storage keys. Unless an endpoint is later configured and disclosed, form confirmation is local only and no message is delivered to us. You can clear these records through the interface or browser controls.
4. Event queue and analytics choices
The site exposes a browser event layer for quality assurance. It records page views, scroll milestones and interaction labels in a bounded queue of the last 250 events under dbt_event_queue_v1. Event payloads must not include raw newsletter or contact email addresses. Consent choice is stored under dbt_consent_v1. No external analytics collector is configured in this build.
5. Purposes and legal bases
We use information actually received to answer enquiries, assess fit, prepare proposals, administer contracts, protect systems and meet legal obligations. Depending on context, processing is based on steps requested before a contract, performance of a contract, consent, legal obligation or legitimate interests such as secure business administration.
6. Sharing and processors
We may use proportionate hosting, communication, document, accounting and professional-adviser services. Access is limited to a business purpose and appropriate contractual or confidentiality controls. We do not sell personal data. A project proposal may identify additional processors or cross-border services relevant to that scope.
7. International transfers
Hong Kong information may be processed through service providers in other locations. Where applicable law requires transfer safeguards, we assess the destination and use an appropriate contractual mechanism. Clients should raise localisation requirements before sharing data.
8. Retention and security
Unsuccessful enquiry correspondence is generally reviewed for deletion within 24 months, subject to legal, dispute and security needs. Contract and accounting records may be kept for the applicable statutory period. Local browser records remain until you clear them. We use access control, account protection, patching and proportionate backup practices, but no transmission or storage method is risk-free.
9. Rights under the PDPO and GDPR where applicable
Under Hong Kong’s Personal Data (Privacy) Ordinance, you may request access to and correction of personal data subject to legal conditions. Where the GDPR or similar law applies, rights may also include erasure, restriction, objection, portability and withdrawal of consent. We may verify identity and retain information where an exemption or legal duty applies.
10. Requests, complaints and changes
Send privacy requests to [email protected]. Explain the context without sending unnecessary identity documents initially. You may also complain to the Office of the Privacy Commissioner for Personal Data in Hong Kong or an applicable supervisory authority. Material updates will change the effective date and, where appropriate, receive prominent notice.