Privacy Policy
Last Updated: January 15, 2026
Introduction
Spotlight Legal is committed to protecting your personal information and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the Personal Data Privacy Ordinance (Cap. 486) of Hong Kong.
By using our website or engaging our legal services, you consent to the collection and use of your personal data as described in this policy.
Data Controller Information
Spotlight Legal is the data controller responsible for your personal information. For questions about this Privacy Policy or our data practices, you may contact us at:
Email: [email protected]
Address: Level 22, Lee Garden One, 33 Hysan Avenue, Causeway Bay, Hong Kong
Phone: +852 2847 3165
Information We Collect
Personal Information You Provide
We collect personal information that you voluntarily provide when you:
- Contact us through our website contact form
- Request legal services or consultation
- Engage us as your legal counsel
- Subscribe to our updates or communications
This information may include your name, email address, phone number, professional details, and information about your legal matter.
Information Collected Automatically
When you visit our website, we may automatically collect:
- Browser type and version
- IP address and geographic location
- Pages visited and time spent on our website
- Referring website addresses
- Device information
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to improve user experience and analyze website usage. Please see our Cookie Policy for detailed information about our use of cookies.
How We Use Your Information
We use your personal information for the following purposes:
Legal Service Delivery
- Providing legal advice and representation
- Communicating about your legal matters
- Preparing legal documents and agreements
- Managing client relationships
Communication and Marketing
- Responding to your inquiries and requests
- Sending service updates and legal developments (with consent)
- Providing information about our services
Website Improvement
- Analyzing website usage to improve functionality
- Understanding user preferences and behavior
- Enhancing user experience
Legal and Compliance
- Complying with legal obligations and professional conduct rules
- Establishing, exercising, or defending legal claims
- Preventing fraud and protecting our rights
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: Where you have given clear consent for us to process your personal data for specific purposes
- Contract: Where processing is necessary for performing our legal services contract with you
- Legal Obligation: Where we must process your data to comply with Hong Kong legal requirements or Law Society obligations
- Legitimate Interests: Where processing serves our legitimate business interests while respecting your rights and interests
Data Sharing and Disclosure
We maintain strict confidentiality regarding client matters. We may share your personal information only in the following circumstances:
Service Providers
We may share information with trusted third-party service providers who assist in operating our business, such as cloud storage providers, IT support, and professional advisors. These providers are contractually obligated to protect your information and use it only for specified purposes.
Legal Requirements
We may disclose your information when required by law, court order, or legal process, or when necessary to protect our rights, property, or safety.
With Your Consent
We may share your information with third parties when you have given explicit consent for such disclosure.
Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Secure servers and network infrastructure
- Access controls limiting data access to authorized personnel
- Regular security assessments and updates
- Staff training on data protection practices
However, no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee absolute security.
Data Retention
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including:
- Client data: Retained for the duration of our professional relationship plus a minimum of seven years after the conclusion of the matter, in accordance with Law Society of Hong Kong guidelines
- Website analytics data: Typically retained for 26 months
- Marketing communications: Until you withdraw consent or request deletion
When personal data is no longer needed, we securely delete or anonymize it in accordance with our data retention policy.
Your Rights
Under Hong Kong's Personal Data Privacy Ordinance, you have the following rights regarding your personal data:
Right to Access
You have the right to request access to the personal data we hold about you and receive information about how we process it.
Right to Correction
You may request correction of inaccurate or incomplete personal data we hold about you.
Right to Data Portability
You may request to receive your personal data in a structured, commonly used, and machine-readable format.
Right to Erasure
In certain circumstances, you may request deletion of your personal data, subject to legal and professional retention requirements.
Right to Object
You have the right to object to processing of your personal data for direct marketing purposes.
Right to Lodge a Complaint
You have the right to lodge a complaint with the Office of the Privacy Commissioner for Personal Data in Hong Kong if you believe we have not handled your personal data appropriately.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 40 days as required by Hong Kong law.
International Data Transfers
Your personal data is primarily stored and processed in Hong Kong. If we transfer your data outside of Hong Kong, we ensure appropriate safeguards are in place to protect your information in accordance with applicable data protection laws.
Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will notify you by:
- Updating the "Last Updated" date at the top of this policy
- Posting a notice on our website
- Sending an email notification to registered users (where appropriate)
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Officer: Spotlight Legal
Email: [email protected]
Phone: +852 2847 3165
Address: Level 22, Lee Garden One, 33 Hysan Avenue, Causeway Bay, Hong Kong