1. Introduction
Welcome to the Privacy Policy of Garb Digital, a computer systems design and integration practice operated by SAM CHEUNG INTERNATIONAL CO., LIMITED, a Hong Kong registered company located at 21/F, Cityplaza 3, 14 Taikoo Wan Road, Quarry Bay, Hong Kong (HK). At Garb Digital, we are committed to protecting the privacy and security of every individual who interacts with our website, services, and team. This Privacy Policy explains in clear and comprehensive terms how we collect, use, disclose, retain, and safeguard your personal information.
Our industry is Computer Systems Design and Related Services, operating within the broader Professional, Scientific, and Technical Services sector. In the course of delivering integrated systems solutions, we may process various categories of data. We comply with applicable data protection laws and regulations, including those of Hong Kong, the European Union (GDPR), the United Kingdom, the United States, and other jurisdictions where our clients and users reside. By accessing https://www.garbdigital.buzz or engaging with our services, you acknowledge that you have read and understood this Privacy Policy.
We encourage you to read this document in full. It is designed to be transparent about our data practices and to empower you with the knowledge needed to make informed decisions about your personal information. Should you have questions after reading, our contact details are provided at the end of this policy.
2. Information We Collect
We collect several types of information from and about users of our services. The categories of personal data we may collect include the following.
Personal Identification Information: When you fill out a contact form on our website, send us an email, or otherwise communicate with us, we may collect your full name, email address, telephone number, company name, job title, and any other details you voluntarily provide in your message. This information is necessary for us to respond to your inquiry and understand your project requirements.
Technical and Usage Data: As you navigate our website, we automatically collect certain technical information. This includes your Internet Protocol (IP) address, browser type and version, operating system, device type, referring URLs, pages visited, time spent on pages, click patterns, and the date and time of your visit. This data helps us understand how our website is used and identify opportunities for improvement.
Communication Records: When you correspond with us by email, telephone, or through our contact form, we retain records of those communications, including the content, date, and metadata associated with each interaction. This enables us to maintain context across conversations and deliver consistent service.
Business Information: For clients and prospective clients, we may collect information about your organization, including business requirements, technical specifications, project scope documents, and other data relevant to the systems design and integration services you seek. This information is treated with the same level of confidentiality as personal data.
Payment Information: In the event that payment processing becomes necessary for our services, we may collect billing details such as bank account numbers, wire transfer instructions, or invoicing information. Please note that we do not store full credit card numbers on our own servers; any card-based payment processing is handled through PCI-compliant third-party payment processors.
3. How We Collect Information
Information is collected through several methods and channels, each designed to be transparent and purposeful.
Direct Collection: The primary method of collection is direct interaction with you. When you submit a contact form on our website at https://www.garbdigital.buzz, send an email to feedback@garbdigital.buzz, call us at +1 941 559 3564, or engage with our team in person or at industry events, you voluntarily provide information to us. You always have the choice about what information to share, although certain data may be necessary for us to respond effectively.
Automated Collection: As described above, technical data is collected automatically through standard web server logs and analytics tools when you visit our website. This collection occurs regardless of whether you actively submit any form. We use this data in aggregate form to analyze trends, administer the site, and gather demographic information.
Third-Party Sources: On occasion, we may receive information about you from third parties, such as business partners, referral sources, or publicly available databases. In such cases, we take steps to ensure that the third party has lawfully obtained and is permitted to share that information with us.
Cookies and Similar Technologies: Our website uses cookies, web beacons, and similar tracking technologies to collect technical data. Details about our use of cookies are provided in Section 11 of this policy.
4. Use of Information
We use the information we collect for a variety of business and operational purposes. Each use is grounded in a legitimate business interest, contractual necessity, legal obligation, or your explicit consent.
Service Delivery: We use your information to provide the computer systems design, integration, and consulting services you request. This includes preparing proposals, drafting technical specifications, designing architecture blueprints, coordinating project teams, and delivering final solutions. Without access to this information, we would be unable to fulfill our contractual obligations effectively.
Communication: We use your contact details to respond to inquiries, provide project updates, share relevant technical documentation, and maintain an ongoing dialogue throughout the engagement lifecycle. We may also send administrative messages related to your account or our services.
Website Improvement: Technical and usage data informs our decisions about website design, content organization, and feature development. By understanding how visitors interact with our site, we can prioritize enhancements that improve the user experience and make our information more accessible.
Marketing and Business Development: With your consent where required by law, we may use your contact information to send you newsletters, case studies, white papers, event invitations, and information about new services that may be relevant to your business. You may opt out of marketing communications at any time.
Legal Compliance: We process information as necessary to comply with applicable laws, regulations, and legal processes, including tax obligations, regulatory reporting, and responding to lawful requests from government authorities.
Security and Fraud Prevention: We use data to monitor for and protect against security threats, unauthorized access, fraud, and abuse of our website and services. This includes analyzing traffic patterns and implementing safeguards to protect the integrity of our systems.
5. Sharing and Disclosure of Information
We do not sell, rent, or lease your personal information to third parties for their own commercial purposes. We may share your information only in the following limited circumstances.
Service Providers: We may engage trusted third-party service providers to perform functions on our behalf, such as website hosting, data analytics, email delivery, payment processing, and customer relationship management. These providers are contractually bound to process data only in accordance with our instructions and to implement appropriate security measures to protect your information.
Business Transfers: In the event of a merger, acquisition, reorganization, sale of assets, or other business transfer, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.
Legal Obligations: We may disclose your information if required to do so by law, regulation, court order, or other legal process, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of SAM CHEUNG INTERNATIONAL CO., LIMITED, our clients, or the public.
With Your Consent: We may share your information for purposes not described in this policy when we have obtained your prior consent to do so.
6. Data Retention
We retain personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable law. The specific retention period depends on the nature of the information and the context in which it was collected.
Contact form submissions and related correspondence are typically retained for the duration of the client relationship plus an additional period of up to five years to support ongoing business needs, resolve disputes, and maintain records of past engagement. Technical and usage data is retained in aggregate form for analytical purposes for up to 26 months. Server logs are retained for a period of 12 months for security and diagnostic purposes.
When the retention period expires, we securely delete or anonymize the data so that it can no longer be associated with any individual. We periodically review our data stores to identify and securely dispose of information that is no longer needed.
7. Data Security
The security of your personal information is a fundamental priority for Garb Digital and SAM CHEUNG INTERNATIONAL CO., LIMITED. We have implemented administrative, technical, and physical safeguards designed to protect your data against unauthorized access, alteration, disclosure, or destruction.
Our security measures include encryption of data in transit using Transport Layer Security (TLS) protocols, encryption of data at rest where appropriate, network firewalls and intrusion detection systems, regular vulnerability assessments and penetration testing, access controls with role-based permissions and multi-factor authentication, secure development practices including code review and dependency scanning, and ongoing security awareness training for our personnel.
While we strive to protect your information, no method of electronic storage or transmission over the Internet is 100% secure. We cannot guarantee absolute security, but we continuously monitor and improve our defenses to address evolving threats. In the event of a security breach involving your personal information, we will notify you as described in Section 17.
8. International Data Transfers
SAM CHEUNG INTERNATIONAL CO., LIMITED is headquartered in Hong Kong, and our data processing activities are primarily conducted in Hong Kong. However, because we serve a global clientele and utilize cloud infrastructure that may span multiple regions, your personal information may be transferred to and processed in countries other than your country of residence.
When we transfer personal data across international borders, we implement appropriate safeguards in accordance with applicable data protection laws. For transfers from the European Economic Area (EEA) or the United Kingdom to countries not recognized as providing an adequate level of data protection, we rely on standard contractual clauses approved by the relevant authorities, binding corporate rules, or other legally recognized transfer mechanisms. By using our services and providing your information, you consent to such transfers and processing in accordance with this policy.
9. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights regarding your personal information. These rights may include the following.
Right of Access: You may request a copy of the personal information we hold about you, along with details about how we process it. We will provide this information within the timeframe required by applicable law, typically within 30 days.
Right of Rectification: If you believe that the personal information we hold about you is inaccurate or incomplete, you may request that we correct or supplement it. We will promptly investigate and, where appropriate, make the necessary corrections.
Right of Erasure: In certain circumstances, you may request that we delete your personal information. We will comply unless there is a compelling legitimate reason for retaining the data, such as a legal obligation or an ongoing contractual relationship.
Right to Restrict Processing: You may request that we limit the processing of your personal information under specific conditions, such as when you contest the accuracy of the data or object to our processing.
Right to Data Portability: Where technically feasible and legally required, you may request that we provide your personal information to you or to another controller in a structured, commonly used, and machine-readable format.
Right to Object: You may object to our processing of your personal information based on legitimate interests or for direct marketing purposes. We will cease processing for the objected purpose unless we demonstrate compelling legitimate grounds that override your interests.
Right to Withdraw Consent: Where our processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, please contact us at feedback@garbdigital.buzz or write to the company address provided in Section 15. We will respond to your request in accordance with applicable legal timelines and may need to verify your identity before processing the request.
10. Privacy for Children
Our website and services are not directed at, intended for, or knowingly targeted to individuals under the age of 18. Garb Digital and SAM CHEUNG INTERNATIONAL CO., LIMITED do not knowingly collect, use, or disclose personal information from children under the age of 18.
If we become aware that we have inadvertently collected personal information from a child under the age of 18 without verified parental consent, we will take immediate steps to delete that information from our records. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at feedback@garbdigital.buzz so that we can take appropriate action.
We encourage parents and guardians to monitor the online activities of their children and to instruct them never to provide personal information through websites or online forms without permission.
11. Cookies and Tracking Technologies
Our website at https://www.garbdigital.buzz uses cookies and similar technologies to enhance your browsing experience, analyze website traffic, and understand where our visitors come from. This section explains what cookies are, how we use them, and how you can manage your cookie preferences.
What Are Cookies: Cookies are small text files that a website places on your device when you visit. They are widely used to make websites work more efficiently and to provide information to the site owners. Cookies may be session cookies, which are deleted when you close your browser, or persistent cookies, which remain on your device for a set period.
Types of Cookies We Use: We use essential cookies necessary for the operation of our website, such as those that enable navigation and access to secure areas. We also use analytics cookies to collect information about how visitors use our site, including which pages are most frequently visited and whether users encounter errors. This helps us improve the performance and relevance of our content.
Managing Cookies: Most web browsers allow you to control cookies through the browser settings. You can typically configure your browser to block cookies, delete existing cookies, or alert you when a website attempts to place a cookie on your device. Please note that disabling cookies may affect the functionality of our website and your ability to access certain features.
Do Not Track: Some browsers offer a Do Not Track signal. Our website does not currently respond to Do Not Track signals. We continue to monitor developments in this area and may adjust our practices accordingly.
12. Third-Party Services
Our website may contain links to third-party websites, services, or content that are not owned or controlled by Garb Digital or SAM CHEUNG INTERNATIONAL CO., LIMITED. This Privacy Policy does not apply to any third-party websites or services. We encourage you to review the privacy policies of every third-party service you interact with.
We may use third-party analytics tools, such as Google Analytics, to understand how visitors use our website. These tools may set their own cookies and collect information in accordance with their own privacy policies. We do not share your personal identification information with analytics providers in a way that allows them to identify you individually.
If we integrate third-party platforms, such as customer relationship management systems, email delivery services, or cloud infrastructure providers, into our operations, we require those providers to adhere to privacy and security standards consistent with this policy. However, their primary processing of data is governed by their own terms and policies.
13. Legal Basis for Processing
For individuals located in the European Economic Area (EEA), the United Kingdom, and other jurisdictions that require a specific legal basis for processing personal data, we rely on the following legal grounds.
Contractual Necessity: Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract. This includes providing the services you request, preparing proposals, and managing the client relationship.
Legitimate Interests: Processing is necessary for our legitimate business interests or those of a third party, provided those interests are not overridden by your data protection rights. Our legitimate interests include operating and improving our website, communicating with current and prospective clients, ensuring the security of our systems, and developing our service offerings.
Legal Obligation: Processing is necessary for compliance with a legal obligation to which we are subject, such as tax reporting, regulatory compliance, or responding to lawful government requests.
Consent: Where required by law, we obtain your explicit consent before processing your personal information for specific purposes, such as sending marketing communications. You have the right to withdraw consent at any time.
14. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or business operations. When we update this policy, we will revise the Last Updated date at the top of this page and post the updated version on our website.
For material changes that significantly affect how we handle your personal information, we will make reasonable efforts to notify you through a prominent notice on our website or via direct communication where we have your contact information and where required by law. We encourage you to review this Privacy Policy periodically to stay informed about our data practices.
Your continued use of our website and services after any changes to this policy constitutes your acknowledgment of the updated terms. If you do not agree with the revised policy, you should discontinue use of our website and services and, where applicable, exercise your rights as described in Section 9.
15. How to Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information below. We take all privacy inquiries seriously and will respond promptly.
Company Name: SAM CHEUNG INTERNATIONAL CO., LIMITED (operating as Garb Digital)
Registered Address: 21/F, Cityplaza 3, 14 Taikoo Wan Road, Quarry Bay, Hong Kong (HK)
Email: feedback@garbdigital.buzz
Phone: +1 941 559 3564
Website: https://www.garbdigital.buzz
If you are located in the EEA or the UK and believe that we have not adequately addressed your concerns, you have the right to lodge a complaint with the supervisory authority in your country of residence.
16. Additional Disclosures
Various jurisdictions impose specific disclosure obligations on businesses that handle personal information. This section addresses requirements applicable in certain regions.
Hong Kong: In compliance with the Personal Data (Privacy) Ordinance (PDPO), we confirm that personal data is collected for lawful purposes directly related to our functions and activities, and that all practicable steps are taken to ensure data accuracy, security, and limited retention. Data subjects in Hong Kong have the right to request access to and correction of their personal data held by us.
European Union and United Kingdom: In compliance with the General Data Protection Regulation (GDPR) and the UK GDPR, we act as a data controller for the personal information described in this policy. Our processing activities, purposes, legal bases, and data subject rights are comprehensively described throughout this document.
Australia: In compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, we take reasonable steps to protect personal information from misuse, interference, loss, unauthorized access, modification, or disclosure. Australian data subjects may request access to and correction of their personal information.
Canada: In compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA), we obtain consent for the collection, use, and disclosure of personal information, except where otherwise permitted by law. Canadian data subjects have the right to access their personal information and challenge its accuracy and completeness.
17. Data Breach Notification
Despite our robust security measures, the possibility of a data breach cannot be entirely eliminated. In the event of a security incident that compromises the confidentiality, integrity, or availability of your personal information, SAM CHEUNG INTERNATIONAL CO., LIMITED will follow an incident response protocol that includes the following steps.
We will promptly investigate the breach to determine its scope, cause, and impact. We will take immediate remedial action to contain the breach, prevent further unauthorized access, and restore the integrity of our systems. If the breach poses a risk to your rights and freedoms, we will notify you and any relevant regulatory authorities within the timeframe required by applicable law, describing the nature of the breach, the categories of data affected, the likely consequences, and the measures we have taken or propose to take to address it.
We maintain a breach response plan that is tested and updated regularly to ensure our readiness in the face of evolving cybersecurity threats.
18. California Privacy Rights
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), California residents have specific rights regarding their personal information. This section describes those rights and how California residents may exercise them.
Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you in the preceding 12 months, the categories of sources from which the information was collected, the business or commercial purpose for collection, and the categories of third parties with whom we share personal information.
Right to Delete: You have the right to request that we delete personal information we have collected from you, subject to certain exceptions such as completing a transaction, detecting security incidents, or complying with a legal obligation.
Right to Opt Out of Sale: Garb Digital and SAM CHEUNG INTERNATIONAL CO., LIMITED do not sell personal information as that term is defined under the CCPA. We do not share personal information for cross-context behavioral advertising.
Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights. This means we will not deny you services, charge you different prices, or provide a different level or quality of services because you exercised your privacy rights.
To exercise your California privacy rights, please contact us at feedback@garbdigital.buzz or call +1 941 559 3564. We will verify your identity before processing your request and will respond within the timeframe required by law.