Privacy Policy

Personal Information Collection Statement — BackDoor Security Limited

1. General

1.1 This privacy policy (the “Policy”) is issued by BackDoor Security Limited, a company incorporated in Hong Kong (Business Registration No. 80651887) (the “Operator”, “we”), and describes how we collect, hold, process and use personal data in connection with the provision of access to the computer program BackDoor (the “Software”, “Platform”).

1.2 This Policy is prepared in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of the Laws of Hong Kong (the “PDPO”) and the six Data Protection Principles set out in Schedule 1 to the PDPO, and serves as our Personal Information Collection Statement.

1.3 This Policy is a public document and is published on the Operator's website in freely accessible form. It applies to all information about data subjects that the Operator may obtain in connection with the provision of access to the Software. The Software is intended for persons aged 18 or over.

1.4 By using the Software and the Website, you acknowledge that you have read this Policy. Where the PDPO or applicable law requires consent for a particular processing activity, we obtain that consent separately.

2. The Operator

Operator: BackDoor Security Limited

Business Registration No.: 80651887

Registered office: Room 76, Unit 3, 2/F, Lai Cheong Fty. Building, 479 Castle Peak Road, Cheung Sha Wan, Hong Kong

Website: https://backdoor.tech

Data protection contact (email): [email protected]

3. Categories of Data Subjects

3.1 The Operator processes the personal data of the following categories of data subjects:

  • individuals who are users of the Software (Licensees);
  • individuals acting on behalf of sole proprietors and legal entities that have entered into a licence agreement with the Operator: representatives, contact persons and authorised employees;
  • individuals who are visitors to the Operator's website and who complete feedback forms, submit demo requests or subscribe to mailings;
  • job applicants;
  • other individuals in a relationship with the Operator that requires the processing of their personal data.

3.2 This Policy does not apply to the processing of personal data of the Operator's own employees.

4. Categories and Content of Personal Data Processed

4.1 The Operator processes personal data to the minimum extent necessary to achieve the purposes set out in Clause 5. The Operator does not collect any data that is excessive in relation to those purposes. The Operator does not process biometric data or, save where volunteered by a data subject, any data of a sensitive nature.

4.2. Content of data processed, by category of subject:

4.2.1. Licensees who are individuals:

  • name;
  • email address;
  • telephone number (where voluntarily provided);
  • information for processing payments, without storage of payment-card details;
  • order and payment history.

4.2.2. Representatives of Licensees that are sole proprietors and legal entities:

  • name of the representative;
  • position;
  • email address;
  • telephone number.

4.2.3. Technical data generated automatically:

  • device IP address;
  • information about the browser and operating system (User-Agent);
  • cookies and other user identifiers;
  • logs of actions in the Personal Account (timestamps, operations performed);
  • session identifiers.

4.2.4. Data generated during operation of the Software:

  • domain names and sub-domains specified by the Licensee as Target Resources;
  • Scan results and Reports generated by the Software;
  • technical metadata of a Scan (duration, volume of checks, configuration).

4.2.5 Information incidentally discovered by the Software when scanning a Target Resource (for example, email addresses, tokens or access keys found in the public responses of the Licensee's web application), where such information relates to third parties, is recorded solely in the Report as evidence of a vulnerability and does not form a separate filing system of personal data held by the Operator. The Operator does not use such information for any other purpose and does not store it separately from the Report.

5. Purposes of Processing

5.1 The Operator processes personal data solely for the following purposes:

  • conclusion and performance of the licence agreement with the Licensee, including provision of access to the Software and support of the Personal Account;
  • identification and authentication of the user in the Software;
  • processing of payments and generation of primary accounting documents;
  • sending the Licensee service notices (about the progress of a Scan, completion of a Report, changes to the terms of use of the Software and so on);
  • handling requests from data subjects, including in relation to the exercise of their rights;
  • sending the Licensee informational and marketing messages, subject to Clause 5.2;
  • ensuring the information security of the Software and detecting and preventing fraudulent activity;
  • compliance with the Operator's obligations under applicable law;
  • protection of the rights and lawful interests of the Operator, including in the preparation and conduct of legal proceedings;
  • improvement of the Software through analysis of anonymised and aggregated data without identifying individual subjects.

5.2. Direct marketing

5.2.1 In accordance with Part VIA of the PDPO, the Operator will not use your personal data in direct marketing without your consent. Before using your personal data for direct marketing, we will inform you of the kinds of personal data to be used and the classes of marketing subjects (for example, the Operator's products, events and offers), and we will obtain your consent (opt-in).

5.2.2 You may at any time, and free of charge, require the Operator to cease using your personal data in direct marketing. To do so, use the unsubscribe link in the relevant message or contact the Operator using the details in Clause 2. The Operator will comply with such a request without charge.

6. Basis and Fairness of Collection

6.1 The Operator collects personal data by lawful and fair means and for purposes directly related to its functions and activities as set out in Clause 5, in accordance with Data Protection Principle 1.

6.2 Personal data is used only for the purpose for which it was collected or for a directly related purpose, unless the data subject has given prescribed consent to a new purpose, in accordance with Data Protection Principle 3. Where processing is based on consent, the data subject may withdraw that consent as set out in Clause 12.

7. Manner of Processing

7.1 Personal data is processed both by automated means and without the use of automation.

7.2 Operations with personal data include: collection, recording, systematisation, accumulation, storage, updating and amendment, retrieval, use, transfer (provision, access), anonymisation, blocking, deletion and destruction.

7.3 The Operator processes personal data by: collecting personal data directly from the subject on registration in the Software, completion of forms on the website and contact with support; automatically obtaining technical data (IP address, cookies and so on) when the subject interacts with the website and the Software; storing data in the Operator's secured information systems; and transferring data to third parties in the cases and manner set out in Clause 9.

8. Retention Periods and Destruction

8.1. The Operator retains personal data for no longer than is necessary to fulfil the purpose for which it is used, in accordance with Data Protection Principle 2.

8.2. Upon expiry of the retention periods, or upon achievement of the purposes of processing or loss of the need to achieve them, personal data is destroyed or anonymised.

8.3 Destruction of personal data processed electronically is carried out by deleting it from the information system in a manner that precludes its recovery. Paper media are destroyed by means that preclude recovery (shredding).

9. Transfer of Personal Data to Third Parties

9.1. The Operator transfers personal data to third parties only in the following cases:

  • to persons engaged, on the Operator's instructions, to provide the technical operation of the Software (hosting providers, cloud-infrastructure providers, email and SMS notification providers, messaging providers, payment service providers, including 3S Money), subject to agreements ensuring the confidentiality and security of the data;
  • to tax, law-enforcement and other governmental authorities, on the basis of their lawful requests, in the manner and to the extent provided by applicable law;
  • to the Operator's professional advisers (lawyers, auditors, tax advisers) acting under obligations of confidentiality;
  • to successors of the Operator, in the event of reorganisation, sale of the business or transfer of rights in the Software.

9.2 Where the Operator engages a data processor, it adopts contractual or other means to ensure that the processor does not keep the personal data for longer than is necessary and does not use or disclose it other than for the purpose for which it was provided, and to prevent unauthorised or accidental access, in accordance with Data Protection Principle 4.

10. Cross-border Transfer and Storage of Data

10.1 The Software operates on a cloud model. Personal data may be stored and processed on servers located outside Hong Kong, in jurisdictions that ensure the protection of personal data.

10.2 Where required, the Operator obtains the data subject's consent to the transfer of personal data outside Hong Kong. By accepting the licence agreement and this Policy, and by providing your data through the Software, you consent to such transfer for the purposes set out in Clause 5.

11. Data Security Measures

11.1 The Operator takes all practicable legal, organisational and technical measures to protect personal data against unauthorised or accidental access, processing, erasure, loss or use, and against other unlawful acts.

11.2 The measures taken by the Operator include, in particular:

  • adoption of internal policies establishing procedures for the processing and protection of personal data;
  • use of information-protection means and controls appropriate to the risk;
  • internal control and/or audit of compliance of data processing with legal requirements;
  • assessment of the harm that may be caused to data subjects in the event of a breach;
  • familiarising staff who process personal data with the applicable law and internal policies;
  • identification of threats to the security of personal data during processing in information systems;
  • encryption of personal data at rest and in transit over public networks;
  • access control for staff to personal data;
  • logging of the actions of users and administrators of information systems;
  • regular data backup;
  • detection of, and prompt response to, information-security incidents.

12. Rights of Data Subjects

12.1 In accordance with the PDPO, a data subject has the right to:

  • ascertain whether the Operator holds personal data about the subject, and to be provided with a copy of such data (a data access request under Data Protection Principle 6 and section 18 of the PDPO);
  • request correction of personal data that is inaccurate, incomplete or out of date (a data correction request);
  • require the Operator to cease using the subject's personal data for direct marketing (regardless of any consent previously given);
  • withdraw consent to processing, where processing is based on consent;
  • make a complaint to the Privacy Commissioner for Personal Data (PCPD) or seek compensation by civil action for damage (including injury to feelings) suffered as a result of a contravention of the PDPO.

12.2. Manner of exercising rights

A request by a data subject is submitted to the Operator in writing by one of the following means:

  • by email to the address specified on the Website, with the subject line “Data Subject Request”;
  • by post to the Operator's registered office set out in Clause 2;
  • through the feedback form on the Website.

A request must contain information sufficient to identify the subject (name, contact details) and information confirming that the Operator processes the subject's personal data (the email address of the account, the Licensee identifier and so on).

The Operator will respond to a request within 40 (forty) calendar days. The Operator may charge a reasonable fee for complying with a data access request. Where the Operator is unable to respond within 40 days, it will notify the subject in writing within that period and respond as soon as practicable thereafter.

12.3. Withdrawal of consent

12.3.1 Consent to the processing of personal data may be withdrawn at any time by sending the Operator a notice by the means set out in Clause 12.2.

12.3.2 Upon withdrawal of consent, the Operator ceases the processing of personal data and ensures its destruction within a period not exceeding 30 (thirty) days from receipt of the withdrawal, unless otherwise required by law or by an agreement to which the subject is a party.

12.3.3 The Operator may continue to process personal data without the subject's consent where there are grounds provided by law.

12.3.4 Withdrawal of consent to the processing of personal data processed in connection with Use of the Software may make further Use of the Software impossible and may result in termination of the licence agreement.

13. Cookies and Similar Technologies

13.1 The Operator's website and the web interface of the Software use cookies and similar technologies for:

  • ensuring the operation of the website and the Personal Account (technical cookies, without which the service does not work);
  • storing user settings (interface language and so on);
  • collecting statistics on the use of the website in anonymised form (analytical cookies);
  • improving the effectiveness of marketing communications (marketing cookies — only with the subject's consent).

13.2 The user may accept or reject non-essential cookies, and may disable the use of cookies in the browser settings or in the Personal Account.

14. Web-analytics Services

14.1 The Operator uses web-analytics services to collect anonymised statistics on the use of the Website. The Operator uses analytics solely to collect anonymised statistics and does not combine the data obtained from analytics services with the personal data of specific users of the Software. The Operator does not identify users on the basis of analytics data.

15. Amendments to this Policy

15.1 The Operator may amend this Policy from time to time. The current version is always published on the Website. Material changes will be notified through the Website or by email where appropriate.

15.2 This Policy is drawn up in the English language, which prevails in all respects.