1. Who we are and scope
This Privacy Policy explains how Power and Grace Co Limited (“Power & Grace”, “we”, “us” or “our”) handles personal data in connection with the Power & Grace Partner Hub, related websites, partner applications, account administration and support.
It applies to business contacts, applicants, approved partners, website visitors and other individuals whose personal data we process through the Hub. It does not govern third-party websites or services with their own privacy notices.
2. Personal data we collect
Information you provide
- Identity and professional details, such as full name, job title and employer.
- Business contact details, such as work email, company telephone, mobile or WhatsApp number, country or region and company website.
- Partner profile information, such as business type, products of interest, application status, approved access level and communications.
- Account and support information, such as login identifier, password stored in protected form, verification status, enquiries and support records.
- Transaction or service information made available through the Hub, where applicable.
Information collected automatically
When you use the Hub, we may collect device and usage data such as IP address, browser type, device identifiers, pages viewed, dates and times, referring pages, session activity, security events and cookie identifiers.
Information from other sources
We may receive business contact information from your employer, our sales teams, authorised distributors, event or enquiry records, publicly available business sources, and service providers supporting identity, compliance or security checks.
3. How we use personal data
We use personal data to:
- create, verify, review and administer Partner Hub accounts;
- assess partner applications and assign appropriate access, pricing or service levels;
- provide product information, quotations, order support, technical resources and after-sales services;
- communicate about applications, accounts, enquiries, security and service updates;
- personalise relevant Hub content and maintain business relationships;
- protect users, investigate misuse, prevent fraud and secure our systems;
- keep records, analyse and improve operations, and comply with legal obligations;
- send business marketing where permitted and according to your choices.
We will not use personal data for a new incompatible purpose without providing appropriate notice or obtaining consent where required.
4. Legal bases where applicable
Depending on your location and the activity, we may rely on one or more of the following legal bases:
- Contract: to take requested steps or provide services under an agreement.
- Legitimate interests: to operate a secure B2B partner platform, manage relationships, improve services and protect our business, balanced against your rights.
- Consent: for optional communications, cookies or other processing where consent is required. You may withdraw consent at any time.
- Legal obligation: to meet applicable accounting, tax, compliance, regulatory or law-enforcement duties.
6. International data transfers
Because we work with partners and service providers internationally, personal data may be accessed or processed outside your country or region. Privacy laws in those locations may differ.
Where required, we use recognised transfer mechanisms or contractual and organisational safeguards designed to protect personal data. Contact us for information about safeguards relevant to your data, subject to lawful confidentiality restrictions.
7. How long we keep personal data
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including account administration, an active or prospective business relationship, security, dispute resolution and legal recordkeeping.
Retention depends on the type of record, its sensitivity, operational need and applicable limitation or regulatory periods. When data is no longer required, we delete or anonymise it, unless continued retention is required or permitted by law.
8. Security
We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. Measures may include access controls, authentication, encryption in transit, logging, backups, staff confidentiality and service-provider review.
No internet service is completely secure. You are responsible for protecting your account credentials and should notify us promptly if you believe your account has been compromised.
10. Your privacy rights
Depending on applicable law, you may have the right to request access to personal data, correction of inaccurate data, deletion, restriction or objection to processing, withdrawal of consent, or a portable copy. You may also have the right to complain to a competent privacy regulator.
To exercise a right, use the Contact us button below. We may need to verify your identity and authority. Rights may be subject to lawful exceptions. We will respond within the period required by applicable law.
Hong Kong: individuals have rights of access and correction under the Personal Data (Privacy) Ordinance. Other rights may apply based on the law governing the relevant processing.
11. Direct marketing and communications
Where permitted, we may use your business contact details to send information about products, services, training, events or partner opportunities that may be relevant to your role. We will obtain consent where required.
You may opt out of marketing at any time using the unsubscribe method in the message or by contacting us. We may still send non-promotional communications necessary for your account, transactions, security or support.
12. Changes to this Policy
We may update this Privacy Policy to reflect changes in our services, systems or legal obligations. We will post the revised Policy with a new effective date and provide additional notice for material changes where appropriate.