Asiacom Group Privacy Policy cover
DOCUMENT STRUCTURE

Table of Contents

SectionTitle
11. Purpose and Scope
22. Responsible Group Entity
33. Personal Information We May Collect
44. Purpose of Use
55. Contact Forms and Business Enquiries
66. AI-Assisted Processing
77. Cookies, Access Logs and Website Technology
88. Sharing and Service Providers
99. International and Group Data Transfers
1010. Security and Retention
1111. Your Rights and Requests
1212. Policy Updates and Contact
Document TitleAsiacom Group Privacy Policy
PurposePublic Website Policy for the Handling of Personal Information
Review StatusDraft for Final Content Review
Publication StatusDraft / Not Yet Published

Core Privacy Principles. Data Protection · Clear Purpose · No Unauthorised Sharing · Your Rights Matter

This document is designed for public website publication and should be read together with other relevant governance materials of Asiacom Group where applicable.

ASIACOM GROUP | PRIVACY POLICY
SECTION 01

1. Purpose and Scope

1.1Purpose of this Privacy Policy

Asiacom Group respects the privacy of individuals who visit its public websites or communicate with its Group companies through online channels. This Privacy Policy explains the general principles governing the collection, use, storage, protection and sharing of personal information obtained through public websites and related business communications.

1.2Scope of Application

This Policy applies primarily to information collected through corporate websites, contact forms, enquiry channels, email communications initiated through the websites, and related website operation and security functions.

1.3Business Context

Asiacom Group operates international trading and related business activities. Information obtained through the websites may therefore be used to respond to enquiries, provide corporate or business information, review potential business relationships and support legitimate business administration.

1.4Outside the Main Scope

This public Policy is not intended to disclose every internal handling process for employee records, transaction due diligence, banking records, internal security information or other specialised non-public information. Such information may be governed by separate internal rules or legal obligations.

1.5Relationship with Other Group Documents

This Privacy Policy should be read alongside the Trade Governance & Compliance Framework and the AI Governance & Responsible Use Framework. Those documents address trade controls and AI governance respectively, while this document focuses on personal information connected with public websites and related communications.

ASIACOM GROUP | PRIVACY POLICY
SECTION 02

2. Responsible Group Entity

2.1Entity-Specific Responsibility

Asiacom Group consists of separate legal entities. The responsible entity for personal information generally depends on the website, enquiry, communication or business relationship through which the information is collected or used.

2.2Japan

For matters relating to the Japan website or Japan business operations, the relevant entity is Asiacommunication Co., Ltd., Japan.

2.3Hong Kong

For matters relating to the Hong Kong website or Hong Kong business operations, the relevant entity is Asiacom Global Trading Limited, Hong Kong.

2.4Group Support

Group companies may support one another where reasonably necessary for routing enquiries, translation, internal coordination, management review or technical support. Such support does not automatically change which legal entity is responsible for the relevant website or business relationship.

2.5Need-to-Know Access

Access to personal information should be limited according to business purpose, role, responsibility and operational need.

ASIACOM GROUP | PRIVACY POLICY
SECTION 03

3. Personal Information We May Collect

3.1Basic Principle

Asiacom Group seeks to collect only personal information reasonably necessary for legitimate business and website purposes.

3.2Contact Information

We may receive your name, company or organisation name, department or position, email address, telephone number and other contact details you choose to provide.

3.3Enquiry Information

We may collect information contained in your enquiry, including the subject of the enquiry, message content, business topic, requested information and documents or information voluntarily provided.

3.4Business Information

Where relevant to a legitimate business enquiry, we may receive information about your organisation, your business role, the nature of a proposed relationship and products or services of interest.

3.5Technical Information

Website systems may generate limited technical information such as IP address, browser or device information, date and time of access, requested page or resource and security-related log information.

3.6Voluntary Submission

Providing information through a general enquiry form is generally voluntary. However, where necessary information is not provided, we may be unable to review or respond properly.

ASIACOM GROUP | PRIVACY POLICY
SECTION 04

4. Purpose of Use

4.1Basic Principle

Asiacom Group uses personal information for legitimate and identifiable business purposes connected with website operation, communication, security and business review.

4.2Responding to Enquiries

Information may be used to receive, review, route and respond to enquiries, provide requested information, request clarification and conduct reasonable follow-up communication.

4.3Business Communication

Personal information may be used to communicate with customers, potential customers, suppliers, business partners, advisers and other legitimate business contacts.

4.4Business Relationship Review

Where an enquiry concerns a potential business relationship, the information may be used to understand the business purpose, identify the appropriate office or function and support reasonable internal review.

4.5Website Operation and Security

Technical information may be used for website operation, troubleshooting, security monitoring, prevention of misuse and service reliability.

4.6Records and Compliance

Relevant information may be retained as appropriate for record keeping, security, dispute resolution or legitimate legal, regulatory and institutional requirements.

ASIACOM GROUP | PRIVACY POLICY
SECTION 05

5. Contact Forms and Business Enquiries

5.1Purpose of Contact Forms

Online contact forms and related channels are provided to receive legitimate corporate and business enquiries. Information submitted through a form is used primarily to review, route and respond to the enquiry.

5.2Information Submitted by the User

Users may provide information such as name, company, department, email address, telephone number, subject of enquiry, message content and any other information voluntarily included in the enquiry.

5.3Internal Routing

An enquiry may be routed internally according to business area, responsible Group entity, region, language or technical subject so that it reaches the most appropriate office or responsible person.

5.4Follow-Up Communication

Information submitted through a contact form may be used to answer questions, request clarification, provide requested documents or arrange further discussion concerning the enquiry.

5.5No Automatic Business Relationship

Submitting an enquiry does not itself create a contract, transaction approval, agency relationship or other binding business relationship. Any subsequent arrangement remains subject to separate review and confirmation.

ASIACOM GROUP | PRIVACY POLICY
SECTION 06

6. AI-Assisted Processing

6.1Basic Principle

Asiacom Group may use approved AI-supported tools to assist with limited business and administrative functions. AI is used to support employees and operations, not to remove human responsibility for important decisions.

6.2Permitted Support Functions

AI-supported tools may assist with translation, classification of enquiries, routing, summarisation, information organisation, preparation of draft responses and other limited support functions.

6.3Minimum Necessary Information

Where personal information is processed through AI-supported tools, Asiacom Group seeks to use only the information reasonably necessary for the relevant purpose.

6.4Human Responsibility

AI-generated classifications, summaries, translations or draft responses do not automatically become final company decisions or official responses. Important communications and material actions remain subject to appropriate human review or approval.

6.5Relationship with AI Governance

AI-assisted processing remains subject to the principles described in the Asiacom Group AI Governance & Responsible Use Framework, including Human Decision, Information Governance and controlled use of external AI services.

ASIACOM GROUP | PRIVACY POLICY
SECTION 07

7. Cookies, Access Logs and Website Technology

7.1Basic Principle

Asiacom Group may use limited website technologies necessary to operate, secure and maintain its public websites.

7.2Server and Security Logs

Hosting, network or security systems may automatically generate technical records such as IP address, date and time of access, browser or device information and requested pages or resources. These may be used for website operation, troubleshooting and security monitoring.

7.3Cookies

Where cookies or similar technologies are used, they may support necessary website operation, security, session management, user preferences or other disclosed website functions.

7.4Analytics and Technology Review

If analytics or other third-party website technologies are used, Asiacom Group may update this Policy to describe the type of service used, the information collected and the applicable purpose. Statements about website technology should be checked against the actual website configuration before publication.

ASIACOM GROUP | PRIVACY POLICY
SECTION 08

8. Sharing and Service Providers

8.1Basic Principle

Asiacom Group does not disclose personal information to unrelated third parties without an appropriate business, legal or operational reason.

8.2Group Companies

Information may be shared within Asiacom Group where reasonably necessary to route an enquiry, prepare a response, coordinate business activity, provide translation or support legitimate management review.

8.3Service Providers

Asiacom Group may use service providers supporting functions such as website hosting, cybersecurity, email, cloud infrastructure, communication services, approved AI-supported processing and technical maintenance.

8.4Controlled Access

Service providers should receive access only to the information reasonably necessary for the authorised service and should be subject to appropriate contractual, organisational or technical controls.

8.5Legal and Institutional Requests

Personal information may be disclosed where reasonably necessary to comply with applicable legal obligations, lawful requests from competent authorities or the protection of legal rights and security.

8.6No Sale of Personal Information

Asiacom Group does not sell personal information collected through its public corporate websites.

ASIACOM GROUP | PRIVACY POLICY
SECTION 09

9. International and Group Data Transfers

9.1Basic Principle

Because Asiacom Group operates across more than one jurisdiction, personal information may be accessed, transferred or processed outside the country or region in which it was originally submitted where reasonably necessary for legitimate operations.

9.2Group Transfers

Information may be shared between authorised Group entities for purposes such as responding to enquiries, routing communication, translation, business coordination, management review or technical support.

9.3External Service Providers

Some authorised service providers may operate infrastructure or services from locations outside the jurisdiction in which the information was collected.

9.4Appropriate Safeguards

Where cross-border handling is subject to applicable requirements, Asiacom Group seeks to use appropriate organisational, contractual or technical safeguards relevant to the type of information, sensitivity, purpose and receiving party.

9.5Data Minimisation

Cross-border processing remains subject to the principle of minimum necessary information. A Group relationship or international technology service does not justify unrestricted access to personal information.

ASIACOM GROUP | PRIVACY POLICY
SECTION 10

10. Security and Retention

10.1Security Principle

Asiacom Group seeks to take reasonable and appropriate organisational and technical measures to protect personal information against unauthorised access, loss, misuse, inappropriate disclosure, alteration or destruction.

10.2Organisational and Technical Controls

Measures may include access control, responsibility allocation, internal procedures, confidentiality controls, incident response, website security, authentication, network protection, monitoring, logging and backup.

10.3Access Limitation

Access to personal information should be limited to persons, functions or authorised service providers that reasonably require the information for an approved purpose.

10.4Retention Principle

Personal information should be retained only for as long as reasonably necessary for enquiry handling, business relationship management, record keeping, security, dispute resolution or applicable legal and institutional requirements.

10.5Review and Deletion

Where information is no longer reasonably required, Asiacom Group may delete it, securely dispose of it, archive it where retention remains necessary or otherwise restrict continued use as appropriate.

10.6Security Incidents

Where a material information-security or privacy incident is identified, Asiacom Group may take steps to contain the issue, review what occurred, protect affected information, correct the relevant problem and respond to applicable requirements.

ASIACOM GROUP | PRIVACY POLICY
SECTION 11

11. Your Rights and Requests

11.1Basic Principle

Individuals may have rights concerning personal information held about them depending on applicable law, the responsible Group entity and the circumstances. Asiacom Group seeks to respond appropriately to legitimate privacy-related requests.

11.2Types of Requests

Depending on the circumstances, a person may be able to request confirmation, access, correction, updating, deletion where applicable, restriction of certain uses or information concerning how personal information is handled.

11.3Identity Confirmation

Before responding to a request involving personal information, Asiacom Group may take reasonable steps to confirm the identity of the requester and whether the requester is authorised to act for another person.

11.4Scope of Response

A request may be subject to limitations where disclosure or other action would be inappropriate or restricted under applicable requirements, including cases involving another person’s information or confidential business information.

11.5Deletion and Cessation of Use

A request for deletion does not necessarily require immediate deletion in every circumstance. Information may need to be retained for legitimate reasons such as legal, regulatory, accounting, contractual or security requirements.

ASIACOM GROUP | PRIVACY POLICY
SECTION 12

12. Policy Updates and Contact

12.1Policy Status and Updates

This Privacy Policy is a public website document explaining Asiacom Group’s general approach to personal information associated with public websites and related communications. It may be reviewed and updated where there is a material change in website functionality, business operations, service providers, AI-supported processing or information-handling practices.

12.2Version Information

The published Privacy Policy should identify the document title, publication status, version and last updated date.

12.3Group Privacy Contact Information

For privacy-related enquiries, requests or other communications concerning this Privacy Policy, please contact the appropriate Asiacom Group entity below.

Hong Kong Privacy Enquiries

Asiacom Global Trading Limited

Unit 1101, 11/F, Tower 1, Cheung Sha Wan Plaza,
833 Cheung Sha Wan Road, Lai Chi Kok, Kowloon, Hong Kong

Email: info@asiacomgroup.com.hk

Japan Privacy Enquiries

Asiacommunication Co., Ltd.

Ginza Otake Building 2F,
1-22-11 Ginza, Chuo-ku, Tokyo 104-0061, Japan

Email: info@asiacomgroup.co.jp

General Group Note. Where a person is uncertain which Asiacom Group entity is responsible, a general enquiry may be routed internally to the appropriate Group company for proper response and handling.

Closing Principle. Asiacom Group seeks to collect only what is reasonably necessary, use information for identifiable purposes, limit access and protect information, and retain information only as long as reasonably necessary.

ASIACOM GROUP | PRIVACY POLICY
Asiacom Group Privacy Policy back cover