Personal Data & GDPR
TITLE II – PERSONAL DATA PROTECTION POLICY
Last updated: September 18
PURPOSE AND APPLICABLE LAW
This policy explains how BUSINESS LOGISTICS LIMITED collects, uses, shares, stores, and protects personal data processed by mijaygroup.com and its secure areas.
The primary reference text is the Personal Data (Privacy) Ordinance (Cap. 9000031) of Hong Kong and its data protection principles. The GDPR applies only when its territorial criteria are met. Other mandatory rules may apply to a particular operation depending on the country, service, or individual concerned.
2. RESPONSIBLE PARTY AND CONTACT
Responsible Party: Mijay Group BUSINESS LOGISTICS LIMITED
Address: Room 2502C, 25/F, 148 Electric Road, North Point, Hong Kong
Contact: contact@mijaygroup.com
Privacy Officer: Raoua Smaali
3. DATA LIKELY TO BE PROCESSED
Depending on the role and services used, Mijay Group may process:
- identity, contact details, country, language, company, job title, and professional information;
- Account registration, authentication, role, permission, and security information;
- Application information for an agent, distributor, supplier, or other partner;
- Briefs, products, potential suppliers, offers, orders, audits, complaints, and project information;
- Quotes, invoices, payments, credit notes, bank references, and transaction metadata;
- Logistics information, addresses, packages, customs documents, tracking, and proof of delivery, including the recipient's name, a signature or photograph, and, if the device allows, a GPS location;
- Training progress, assessments, and certificates;
- Messages, discussion groups, documents, photographs, videos, and translations;
- Activity logs, IP addresses, timestamps, session data, security events, and proof of acceptance or signature;
- Any other information provided voluntarily or required for a task.
Credit card data is collected from the payment provider. Mijay Group does not store the full card number or the security code.
4. SOURCES
The data comes primarily from the individual concerned, their company, an authorized user of the same file, an authorized agent or partner, service providers involved in the project, carriers and tracking services, as well as public professional sources used for sourcing or verification.
5. PURPOSES
The processing may be used to:
- create, secure, and administer accounts;
- review a request, prepare a quote, and execute a contract;
- manage sourcing, purchasing, production, quality, distribution, logistics, warehousing, and training;
- prepare commercial documents, receive and reconcile payments;
- To provide messaging, translation, document search, previews, OCR, or AI assistance when enabled;
- To manage applications, contracts, subscriptions, permissions, and partner relationships;
- To provide support, handle complaints, and prevent abuse, fraud, and circumvention;
- To maintain contractual records and comply with applicable legal, accounting, tax, customs, or judicial obligations;
- To measure and improve the platform's functionality, security, and usability using necessary or aggregated data.
Where the GDPR applies, processing is based, as applicable, on pre-contractual measures or the contract itself, a legal obligation, the legitimate interest in operating and securing a service (9000033), or consent when required. Under Hong Kong law, data is used for the purposes stated at the time of collection or for directly related purposes, unless a legal basis or consent permits another use.
6. RECIPIENTS AND ACCESS RESTRICTIONS
Data is accessible to authorized members of Mijay Group according to their roles. The platform applies access rights based on role, project, and conversation so that a client, agent, sourcer, supplier, or distributor only has access to the information necessary for their participation.
Within these limits, data may be transmitted:
- to suppliers, sourcers, agents, distributors, carriers, warehouses, freight forwarders, insurers, customs brokers, and other parties necessary for the task;
- to Hostinger and the technical service providers necessary for hosting and operation;
- to Stripe for online payments;
- When the corresponding functions are configured and used, to providers of translation, artificial intelligence, file analysis, conversion, package tracking, or email services;
- To advisors, auditors, accountants, insurers, and authorities when required by law, a valid request, or the defense of rights.
The integrations currently planned by the application may include Google Cloud Translation, a configured artificial intelligence provider, Cloudmersive, UPS, and 17TRACK. Their actual activation depends on the production configuration. Only the data necessary for the requested action should be transmitted to them.
Mijay Group does not sell personal data for advertising purposes.
7. INTERNATIONAL TRANSFERS
Mijay Group operates internationally. Data may be accessed or processed from Hong Kong, the client's country, the countries of those involved in a project, and the countries where technical service providers are located. When applicable law mandates a specific mechanism for a transfer, [9000005] implements the required safeguards or chooses another legally available basis.
[9000049] DATA RETENTION PERIOD
Data is retained for the period necessary for the stated purpose, the business relationship, the security of the service, and the establishment, exercise, or defense of legal rights. Contractual, accounting, tax, customs, and transaction records are retained for the period required by applicable law.
Retention periods may vary depending on the type of file, the country, and the existence of a dispute. Technical backups are subject to rotation. At the end of the relevant retention period, data is deleted, anonymized, or isolated when further retention is legally required.
9. SECURITY AND CONFIDENTIALITY
Mijay Group applies measures appropriate to the risk, including HTTPS encryption, access controls, strong authentication for sensitive accounts, server-side validation, CSRF protection, audit logs, private storage of sensitive documents, signed temporary links, backups, and deployment controls.
No system offers absolute security. Operational details are presented in Title IV without constituting a guarantee of results or a contractual level of service.
10. ARTIFICIAL INTELLIGENCE AND TRANSLATION
The assistance, summarization, and translation functions produce automated suggestions. They do not alone approve a supplier, a payment, a contract, or a binding decision. The user must verify the result, including figures, references, clauses, and regulatory information. The original is authoritative when indicated by the platform.
11. RIGHTS OF INDIVIDUALS
Hong Kong law recognizes, in particular, rights of access and rectification. Where other laws apply, they may also provide for erasure, restriction, objection, data portability, or withdrawal of consent, under their respective conditions and subject to retention obligations.
A request can be sent to contact@mijaygroup.com. Mijay Group may request the information reasonably necessary to verify identity and prevent the disclosure of data to an unauthorized person. The response will be provided within the time frame stipulated by applicable law.
12. COOKIES AND SIMILAR TECHNOLOGIES
The Site's normal operation uses strictly necessary cookies, including those for secure session management, protection against forged requests, and language selection. Their duration depends on their function and session configuration.
Stripe, Cloudflare Turnstile, or an external media provider may use their own technologies when a corresponding page or function is opened. Their policies apply to this processing.
As of the date of this version, the application does not declare any advertising devices or general audience measurement tools enabled by default. If non-essential cookies are added, the user's information and, where required by law, choice will be updated before their activation.
13. PROFESSIONAL USE AND MINORS
The platform is intended for professionals and is not designed for use by minors on their own behalf. Anyone who believes their data has been wrongly transmitted can contact Mijay Group.
14. DATA BREACH
All incidents are assessed based on their nature, the data involved, and the risk to individuals. Mijay Group takes containment measures and makes the required notifications to the relevant authorities or individuals within the timeframes stipulated by applicable law.
15. CHANGES
This policy may change to reflect applicable services, providers, or obligations. The update date is indicated at the top of the section. A substantial change will be communicated through an appropriate channel, including on the platform where relevant.