Last updated: 29 September 2026
Who we are
Soft Force Limited (Company No. 3216288), Room 1205, 12/F, Beverly House, 93-107 Lockhart Road, Wanchai, Hong Kong (“we”, “us”) runs softforcehk.com and is the controller of the personal data described in this policy. Contact for any privacy question: office [at] softforcehk.com.
We are based in Hong Kong. We handle personal data under Hong Kong’s Personal Data (Privacy) Ordinance (Cap. 486). Because we offer our services to clients in the European Union, the EU General Data Protection Regulation (GDPR) also applies to data about people in the EU (Article 3(2) GDPR).
What we collect and why
| Data | Where it comes from | Why | Legal basis (GDPR) | Kept for |
|---|---|---|---|---|
| Name, email, company, message and anything else you write to us | Your email to us. The contact form on this site does not send anything itself: it opens your own email app with the message filled in, and you decide whether to send it. | Reply to your enquiry and provide our services | Steps before a contract / legitimate interest (Art. 6(1)(b), (f)) | 24 months after our last contact. If you become a client, for as long as Hong Kong law requires for business and accounting records (normally 7 years). |
| IP address, browser, date and time of each request | Server logs at our hosting provider | Keep the site secure and working | Legitimate interest (Art. 6(1)(f)) | Up to 30 days |
We don’t use analytics, advertising pixels or social media plug-ins on this site, and we don’t make decisions about you based solely on automated processing.
Giving us your details is voluntary. Without them we can’t reply to you.
Who receives it
Only service providers acting on our instructions: Hostinger (website hosting) and Microsoft 365 (email). Authorities, when the law requires it. We do not sell your personal data.
International transfers
We are in Hong Kong, which does not have an EU adequacy decision. When you email us from the EU, you send your data to us directly. Where our providers process data outside the EEA (for example Microsoft in the USA), we rely on an adequacy decision, including the EU-US Data Privacy Framework, or on the European Commission’s Standard Contractual Clauses.
Cookies and local storage
We don’t set any non-essential cookies, and no tracking cookies at all. That is why this site shows no cookie banner. Our fonts are served from our own server, so your visit is not shared with Google or any other font provider.
The only thing we store on your device is the choice you make with the Motion switch in the footer, and only if you use it:
| Name | Type | Provider | Purpose | Category | Duration |
|---|---|---|---|---|---|
| sf-reduce-motion | Local storage | softforcehk.com | Remembers that you switched animations on or off | Necessary (a setting you asked for) | Until you clear your browser data |
This value never leaves your browser and is not used to identify you. You can delete it at any time by clearing this site’s data in your browser settings. If we ever add cookies that need your consent, we will ask first, update this policy and add a cookie settings link in the footer.
Your rights
You can ask us to access, correct or delete your data, to restrict its use, or to receive it in a portable format, and you can object to processing based on legitimate interest. Write to office [at] softforcehk.com. We reply within one month.
People in the EU
You can complain to the data protection authority in the EU country where you live or work, or where you think the problem happened. A list of authorities is on the European Data Protection Board’s website (edpb.europa.eu).
Hong Kong
Under the Personal Data (Privacy) Ordinance you have the right to request access to and correction of your personal data. We may charge a reasonable fee for a data access request, as the Ordinance allows. You can complain to the Office of the Privacy Commissioner for Personal Data (www.pcpd.org.hk).
Children
This site and our services are for businesses. They aren’t directed at children under 16, and we don’t knowingly collect their data.
Security
We use HTTPS, restricted access and reputable providers. No system is perfectly secure. We will tell you and the regulator about a breach where the law requires it.
Changes
We update this policy when our practices change. The date at the top shows the current version. Our Terms & Conditions cover the services we provide.