Back to Home

Hong Kong PDPO and GDPR where applicable

Privacy Notice

This notice explains how Cat & Mouse Software Limited processes personal data in connection with this website and its B2B SaaS services, including Tender Intelligence Platform.

It addresses the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (PDPO) and, where applicable to a processing activity, the EU General Data Protection Regulation (GDPR).

Data User and Controller

Cat & Mouse Software Limited

Unit 2A, 17/F

Glenealy Tower

No. 1 Glenealy

Hong Kong

Email: office@catandmouse.com.hk

Further company details are available in the Imprint.

Data Protection Roles

  • For this website and our own business operations, Cat & Mouse Software Limited is the data user under the PDPO and, where the GDPR applies, the controller.
  • When we process personal data in the SaaS on a customer’s documented instructions, we generally act as the customer’s data processor and, where the GDPR applies, its processor.
  • Where required, the customer agreement includes a data processing agreement appropriate to the parties’ roles and applicable law.

Categories of Data Subjects and Personal Data

This notice may apply to:

  • visitors to this website,
  • contacts at prospects, customers, suppliers, and partners, and
  • authorized users of our B2B SaaS services.

Depending on how you interact with us, we may process:

  • identity and business contact data, such as name, employer, role, email address, and telephone number,
  • communication data, such as email content and related metadata,
  • website usage and log data, such as IP address, timestamp, requested URL, referrer, device, and browser information,
  • authentication and access data, such as user ID, business email address, roles, sign-in events, and IP address,
  • contract, transaction, and billing data, and
  • customer-provided content processed through the SaaS.

Purposes, Justifications, and Retention

Processing activityPurposeData categoriesJustification where GDPR appliesRetention
Website delivery and security logsDelivering the website, maintaining stability, preventing abuse, and troubleshootingIP address, URL, timestamp, user agent, referrerLegitimate interests under Art. 6(1)(f) GDPRNormally short-term; longer where needed to investigate security or reliability incidents
Language preference (NEXT_LOCALE)Remembering the language selected by the visitorLanguage code and technical cookie dataRequested functionality and Art. 6(1)(f) GDPRUp to 12 months or until removed through browser controls
Website analyticsUnderstanding aggregate website use and improving content and performanceTechnical usage and page-view informationLegitimate interests under Art. 6(1)(f) GDPRAccording to the analytics configuration and only for as long as needed for the stated purpose
Email and business communicationResponding to enquiries and managing pre-contractual, customer, supplier, and partner relationsContact data, message content, and metadataArt. 6(1)(b) or Art. 6(1)(f) GDPR, depending on contextUntil the enquiry or relationship ends, then as required for legal or contractual obligations
User authentication and access controlSecure login, identity verification, authorization, and protection against unauthorized accessBusiness account data, identifiers, email address, roles, sign-in metadata, and IP addressArt. 6(1)(b) or Art. 6(1)(f) GDPR, depending on contextDuring active account use, then according to contract, security, and legal requirements
B2B SaaS deliveryProviding the contracted SaaS functionsAccount, usage, configuration, and customer-provided contentArt. 6(1)(b) or Art. 6(1)(f) GDPR, depending on contextDuring the contract, then deletion or return under the contract and data processing agreement
Compliance, accounting, and legal claimsMeeting legal obligations and establishing, exercising, or defending legal claimsContract, transaction, billing, and communication dataArt. 6(1)(c) or Art. 6(1)(f) GDPR, depending on contextFor the period required by applicable law or while a relevant claim may be brought or defended

Under the PDPO, we collect personal data for lawful purposes directly related to our functions and activities, limit collection to data that is necessary and not excessive, and do not use it for a new purpose without the prescribed consent or another lawful basis.

Cookies

This website may set the functional NEXT_LOCALE cookie to remember a visitor’s language preference. We do not use advertising or cross-site profiling cookies on this website.

Our SaaS services may use cookies or similar storage that is necessary for authentication, session continuity, security, and abuse prevention. Where applicable law requires consent for any additional technology, we request it before use.

Service Providers and Recipients

We use service providers to host and operate our website and SaaS services, manage authentication, deliver communications, and administer domains and related infrastructure. Depending on the service configuration, these providers may process the categories described below.

ProviderPurposeData categoriesRoleProcessing locationTransfer safeguard where GDPR applies
HetznerInfrastructure hosting servicesUsage and log dataProcessorEU, mainly Germany or FinlandNo transfer outside the EEA initiated through this service where configured in the EEA
ConvexCloud platform servicesAccount, usage, and content dataProcessorEU and additional regions depending on project configurationAppropriate Chapter V safeguard where required
Microsoft AzureCloud platform servicesAccount, usage, and content dataProcessorEU and additional regions depending on configurationAppropriate Chapter V safeguard where required
Microsoft Entra IDIdentity and access managementBusiness account data, identifiers, email address, roles, sign-in metadata, and IP addressProcessorEU and additional regions depending on configurationAppropriate Chapter V safeguard where required
Amazon Web ServicesCloud and communication servicesCommunication data, usage data, and related metadataProcessorEU and additional regions depending on configurationAppropriate Chapter V safeguard where required
VercelWebsite hosting, delivery, and analyticsRequest, log, and technical website usage dataProcessorEU and additional regions depending on delivery setupAppropriate Chapter V safeguard where required
bunny.netDNS and edge delivery servicesDNS requests and technical metadataProcessorEU and global edge locations depending on routingAppropriate Chapter V safeguard where required
netcupInfrastructure hosting and domain servicesUsage or log data, domain administration data, and billing-related dataProcessor or independent data user/controller, depending on the activityEU, mainly GermanyAppropriate Chapter V safeguard where required
MigaduEmail servicesEmail content and metadata and contact dataProcessorSwitzerland and possible additional locations through subprocessorsAdequacy for Switzerland or another Chapter V safeguard where required

We may also disclose personal data where necessary to perform an agreement, comply with law, protect legal rights or security, complete a corporate transaction, or act with the data subject’s consent. We do not sell personal data.

International Processing and Transfers

Cat & Mouse Software Limited is based in Hong Kong. Corporate administration and authorized support may therefore involve processing or access from Hong Kong.

Service providers may process data in the locations described above. Where the GDPR applies to a transfer from the European Economic Area to a country without an adequacy decision, the transfer is handled using an applicable safeguard under Chapter V GDPR, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where required.

Subprocessors

When we act as a processor for a customer, subprocessors, notice of material changes, and any objection mechanism are governed by the applicable data processing agreement. Current provider subprocessors are also identified on their official privacy or subprocessor pages.

Retention and Deletion

We retain personal data only for as long as necessary for the purposes described in this notice. We then delete or anonymize it unless applicable law, a contract, or a legal claim requires longer retention.

Retention periods may differ by data type, service configuration, customer instructions, and the laws applicable to Cat & Mouse Software Limited or the customer.

Security

We use reasonable and appropriate technical and organizational measures intended to protect personal data against unauthorized or accidental access, processing, erasure, loss, or use. No system can be guaranteed completely secure.

Your Rights

Under the PDPO, you may request access to and correction of personal data that we hold about you, subject to applicable conditions and exceptions.

Where the GDPR applies, you may also have rights to:

  • access,
  • rectification,
  • erasure,
  • restriction of processing,
  • data portability,
  • object to processing based on legitimate interests, and
  • withdraw consent for future processing where consent is the basis used.

To exercise a right, contact office@catandmouse.com.hk. We may request information reasonably necessary to verify your identity and locate the relevant data.

Complaints

You may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD):

Unit 1303, 13/F, Dah Sing Financial Centre

248 Queen’s Road East

Wanchai, Hong Kong

Website: https://www.pcpd.org.hk/

Complaint email: complaints@pcpd.org.hk

Where the GDPR applies, you may also lodge a complaint with the supervisory authority in the EEA country where you live or work or where you believe an infringement occurred.

Changes to This Notice

We update this notice when our processing, service providers, or legal obligations materially change. The date shown on this page identifies the latest revision.

Last updated: August 3, 2026