Hong Kong PDPO and GDPR where applicable
Privacy Notice
This notice explains how Cat & Mouse Software Limited processes personal data in connection with this website and its B2B SaaS services, including Tender Intelligence Platform.
It addresses the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (PDPO) and, where applicable to a processing activity, the EU General Data Protection Regulation (GDPR).
Data User and Controller
Cat & Mouse Software Limited
Unit 2A, 17/F
Glenealy Tower
No. 1 Glenealy
Hong Kong
Email: office@catandmouse.com.hk
Further company details are available in the Imprint.
Data Protection Roles
- For this website and our own business operations, Cat & Mouse Software Limited is the data user under the PDPO and, where the GDPR applies, the controller.
- When we process personal data in the SaaS on a customer’s documented instructions, we generally act as the customer’s data processor and, where the GDPR applies, its processor.
- Where required, the customer agreement includes a data processing agreement appropriate to the parties’ roles and applicable law.
Categories of Data Subjects and Personal Data
This notice may apply to:
- visitors to this website,
- contacts at prospects, customers, suppliers, and partners, and
- authorized users of our B2B SaaS services.
Depending on how you interact with us, we may process:
- identity and business contact data, such as name, employer, role, email address, and telephone number,
- communication data, such as email content and related metadata,
- website usage and log data, such as IP address, timestamp, requested URL, referrer, device, and browser information,
- authentication and access data, such as user ID, business email address, roles, sign-in events, and IP address,
- contract, transaction, and billing data, and
- customer-provided content processed through the SaaS.
Purposes, Justifications, and Retention
| Processing activity | Purpose | Data categories | Justification where GDPR applies | Retention |
|---|---|---|---|---|
| Website delivery and security logs | Delivering the website, maintaining stability, preventing abuse, and troubleshooting | IP address, URL, timestamp, user agent, referrer | Legitimate interests under Art. 6(1)(f) GDPR | Normally short-term; longer where needed to investigate security or reliability incidents |
Language preference (NEXT_LOCALE) | Remembering the language selected by the visitor | Language code and technical cookie data | Requested functionality and Art. 6(1)(f) GDPR | Up to 12 months or until removed through browser controls |
| Website analytics | Understanding aggregate website use and improving content and performance | Technical usage and page-view information | Legitimate interests under Art. 6(1)(f) GDPR | According to the analytics configuration and only for as long as needed for the stated purpose |
| Email and business communication | Responding to enquiries and managing pre-contractual, customer, supplier, and partner relations | Contact data, message content, and metadata | Art. 6(1)(b) or Art. 6(1)(f) GDPR, depending on context | Until the enquiry or relationship ends, then as required for legal or contractual obligations |
| User authentication and access control | Secure login, identity verification, authorization, and protection against unauthorized access | Business account data, identifiers, email address, roles, sign-in metadata, and IP address | Art. 6(1)(b) or Art. 6(1)(f) GDPR, depending on context | During active account use, then according to contract, security, and legal requirements |
| B2B SaaS delivery | Providing the contracted SaaS functions | Account, usage, configuration, and customer-provided content | Art. 6(1)(b) or Art. 6(1)(f) GDPR, depending on context | During the contract, then deletion or return under the contract and data processing agreement |
| Compliance, accounting, and legal claims | Meeting legal obligations and establishing, exercising, or defending legal claims | Contract, transaction, billing, and communication data | Art. 6(1)(c) or Art. 6(1)(f) GDPR, depending on context | For the period required by applicable law or while a relevant claim may be brought or defended |
Under the PDPO, we collect personal data for lawful purposes directly related to our functions and activities, limit collection to data that is necessary and not excessive, and do not use it for a new purpose without the prescribed consent or another lawful basis.
Cookies
This website may set the functional NEXT_LOCALE cookie to remember a visitor’s language preference. We do not use advertising or cross-site profiling cookies on this website.
Our SaaS services may use cookies or similar storage that is necessary for authentication, session continuity, security, and abuse prevention. Where applicable law requires consent for any additional technology, we request it before use.
Service Providers and Recipients
We use service providers to host and operate our website and SaaS services, manage authentication, deliver communications, and administer domains and related infrastructure. Depending on the service configuration, these providers may process the categories described below.
| Provider | Purpose | Data categories | Role | Processing location | Transfer safeguard where GDPR applies |
|---|---|---|---|---|---|
| Hetzner | Infrastructure hosting services | Usage and log data | Processor | EU, mainly Germany or Finland | No transfer outside the EEA initiated through this service where configured in the EEA |
| Convex | Cloud platform services | Account, usage, and content data | Processor | EU and additional regions depending on project configuration | Appropriate Chapter V safeguard where required |
| Microsoft Azure | Cloud platform services | Account, usage, and content data | Processor | EU and additional regions depending on configuration | Appropriate Chapter V safeguard where required |
| Microsoft Entra ID | Identity and access management | Business account data, identifiers, email address, roles, sign-in metadata, and IP address | Processor | EU and additional regions depending on configuration | Appropriate Chapter V safeguard where required |
| Amazon Web Services | Cloud and communication services | Communication data, usage data, and related metadata | Processor | EU and additional regions depending on configuration | Appropriate Chapter V safeguard where required |
| Vercel | Website hosting, delivery, and analytics | Request, log, and technical website usage data | Processor | EU and additional regions depending on delivery setup | Appropriate Chapter V safeguard where required |
| bunny.net | DNS and edge delivery services | DNS requests and technical metadata | Processor | EU and global edge locations depending on routing | Appropriate Chapter V safeguard where required |
| netcup | Infrastructure hosting and domain services | Usage or log data, domain administration data, and billing-related data | Processor or independent data user/controller, depending on the activity | EU, mainly Germany | Appropriate Chapter V safeguard where required |
| Migadu | Email services | Email content and metadata and contact data | Processor | Switzerland and possible additional locations through subprocessors | Adequacy for Switzerland or another Chapter V safeguard where required |
We may also disclose personal data where necessary to perform an agreement, comply with law, protect legal rights or security, complete a corporate transaction, or act with the data subject’s consent. We do not sell personal data.
International Processing and Transfers
Cat & Mouse Software Limited is based in Hong Kong. Corporate administration and authorized support may therefore involve processing or access from Hong Kong.
Service providers may process data in the locations described above. Where the GDPR applies to a transfer from the European Economic Area to a country without an adequacy decision, the transfer is handled using an applicable safeguard under Chapter V GDPR, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where required.
Subprocessors
When we act as a processor for a customer, subprocessors, notice of material changes, and any objection mechanism are governed by the applicable data processing agreement. Current provider subprocessors are also identified on their official privacy or subprocessor pages.
Retention and Deletion
We retain personal data only for as long as necessary for the purposes described in this notice. We then delete or anonymize it unless applicable law, a contract, or a legal claim requires longer retention.
Retention periods may differ by data type, service configuration, customer instructions, and the laws applicable to Cat & Mouse Software Limited or the customer.
Security
We use reasonable and appropriate technical and organizational measures intended to protect personal data against unauthorized or accidental access, processing, erasure, loss, or use. No system can be guaranteed completely secure.
Your Rights
Under the PDPO, you may request access to and correction of personal data that we hold about you, subject to applicable conditions and exceptions.
Where the GDPR applies, you may also have rights to:
- access,
- rectification,
- erasure,
- restriction of processing,
- data portability,
- object to processing based on legitimate interests, and
- withdraw consent for future processing where consent is the basis used.
To exercise a right, contact office@catandmouse.com.hk. We may request information reasonably necessary to verify your identity and locate the relevant data.
Complaints
You may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD):
Unit 1303, 13/F, Dah Sing Financial Centre
248 Queen’s Road East
Wanchai, Hong Kong
Website: https://www.pcpd.org.hk/
Complaint email: complaints@pcpd.org.hk
Where the GDPR applies, you may also lodge a complaint with the supervisory authority in the EEA country where you live or work or where you believe an infringement occurred.
Changes to This Notice
We update this notice when our processing, service providers, or legal obligations materially change. The date shown on this page identifies the latest revision.
Last updated: August 3, 2026