Privacy Policy

Last Updated: January 15, 2026

Introduction

Spotlight Legal is committed to protecting your personal information and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the Personal Data Privacy Ordinance (Cap. 486) of Hong Kong.

By using our website or engaging our legal services, you consent to the collection and use of your personal data as described in this policy.

Data Controller Information

Spotlight Legal is the data controller responsible for your personal information. For questions about this Privacy Policy or our data practices, you may contact us at:

Email: [email protected]

Address: Level 22, Lee Garden One, 33 Hysan Avenue, Causeway Bay, Hong Kong

Phone: +852 2847 3165

Information We Collect

Personal Information You Provide

We collect personal information that you voluntarily provide when you:

  • Contact us through our website contact form
  • Request legal services or consultation
  • Engage us as your legal counsel
  • Subscribe to our updates or communications

This information may include your name, email address, phone number, professional details, and information about your legal matter.

Information Collected Automatically

When you visit our website, we may automatically collect:

  • Browser type and version
  • IP address and geographic location
  • Pages visited and time spent on our website
  • Referring website addresses
  • Device information

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to improve user experience and analyze website usage. Please see our Cookie Policy for detailed information about our use of cookies.

How We Use Your Information

We use your personal information for the following purposes:

Legal Service Delivery

  • Providing legal advice and representation
  • Communicating about your legal matters
  • Preparing legal documents and agreements
  • Managing client relationships

Communication and Marketing

  • Responding to your inquiries and requests
  • Sending service updates and legal developments (with consent)
  • Providing information about our services

Website Improvement

  • Analyzing website usage to improve functionality
  • Understanding user preferences and behavior
  • Enhancing user experience

Legal and Compliance

  • Complying with legal obligations and professional conduct rules
  • Establishing, exercising, or defending legal claims
  • Preventing fraud and protecting our rights

Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Consent: Where you have given clear consent for us to process your personal data for specific purposes
  • Contract: Where processing is necessary for performing our legal services contract with you
  • Legal Obligation: Where we must process your data to comply with Hong Kong legal requirements or Law Society obligations
  • Legitimate Interests: Where processing serves our legitimate business interests while respecting your rights and interests

Data Sharing and Disclosure

We maintain strict confidentiality regarding client matters. We may share your personal information only in the following circumstances:

Service Providers

We may share information with trusted third-party service providers who assist in operating our business, such as cloud storage providers, IT support, and professional advisors. These providers are contractually obligated to protect your information and use it only for specified purposes.

Legal Requirements

We may disclose your information when required by law, court order, or legal process, or when necessary to protect our rights, property, or safety.

With Your Consent

We may share your information with third parties when you have given explicit consent for such disclosure.

Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit and at rest
  • Secure servers and network infrastructure
  • Access controls limiting data access to authorized personnel
  • Regular security assessments and updates
  • Staff training on data protection practices

However, no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee absolute security.

Data Retention

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including:

  • Client data: Retained for the duration of our professional relationship plus a minimum of seven years after the conclusion of the matter, in accordance with Law Society of Hong Kong guidelines
  • Website analytics data: Typically retained for 26 months
  • Marketing communications: Until you withdraw consent or request deletion

When personal data is no longer needed, we securely delete or anonymize it in accordance with our data retention policy.

Your Rights

Under Hong Kong's Personal Data Privacy Ordinance, you have the following rights regarding your personal data:

Right to Access

You have the right to request access to the personal data we hold about you and receive information about how we process it.

Right to Correction

You may request correction of inaccurate or incomplete personal data we hold about you.

Right to Data Portability

You may request to receive your personal data in a structured, commonly used, and machine-readable format.

Right to Erasure

In certain circumstances, you may request deletion of your personal data, subject to legal and professional retention requirements.

Right to Object

You have the right to object to processing of your personal data for direct marketing purposes.

Right to Lodge a Complaint

You have the right to lodge a complaint with the Office of the Privacy Commissioner for Personal Data in Hong Kong if you believe we have not handled your personal data appropriately.

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 40 days as required by Hong Kong law.

International Data Transfers

Your personal data is primarily stored and processed in Hong Kong. If we transfer your data outside of Hong Kong, we ensure appropriate safeguards are in place to protect your information in accordance with applicable data protection laws.

Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will notify you by:

  • Updating the "Last Updated" date at the top of this policy
  • Posting a notice on our website
  • Sending an email notification to registered users (where appropriate)

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Protection Officer: Spotlight Legal

Email: [email protected]

Phone: +852 2847 3165

Address: Level 22, Lee Garden One, 33 Hysan Avenue, Causeway Bay, Hong Kong