Skip to content

Privacy Policy

Last updated: 

This policy explains how Nebula Iris Limited handles personal data when you visit nebulairis.com or write to us. The site is addressed to companies; the personal data we handle is that of the people who contact us on their behalf.

1. Who is responsible

The data user under Hong Kong law is Nebula Iris Limited. To the extent that we handle personal data of people in the European Union or the European Economic Area and the GDPR applies to that handling, the company is also the controller.

Company name
Nebula Iris Limited
Legal form
Private company limited by shares. Incorporated in Hong Kong under the Companies Ordinance (Cap. 622)
Company No. / Business Registration No.
81086788
Date of incorporation
21 August 2026
Registered office
Unit G15, Tin Hau Apple SOLO, 14 Kings Road, Tin Hau, Hong Kong

For any question about personal data, write to info@nebulairis.com; requests from any country are accepted directly at this address.

2. What we collect

  • Contact requests: your name, work e-mail address, company name and the text of your message, when you send the form or write to us by e-mail. A request sent through the form also records the language version and page it was sent from and the date and time of sending.
  • Spam check data: when you reach the contact form, the Cloudflare Turnstile check runs in your browser. It processes your IP address and information about your browser and device to tell people from automated programs. We receive only the result of the check, not this information.
  • Technical data: the IP address, date and time of the request, the page requested and browser type. Cloudflare receives this data when it delivers a page; our server does not keep a log of page requests, and its application and system logs are kept as set out in section 5.
  • Your cookie choice: a record, kept in your own browser, of the choice you made in the cookie notice. It is not sent to us.

We do not ask for special categories of data, and we ask you not to include them in a message. The site has no user accounts, no analytics and no advertising trackers.

3. Why we use it and on what basis

  • Purpose
    Replying to your business enquiry and the correspondence that follows
    Data
    Contact request data
    Legal basis (GDPR)
    Article 6(1)(f): our legitimate interest in answering business enquiries addressed to us
  • Purpose
    Protecting the contact form from spam and automated abuse
    Data
    Spam check data; your IP address, used to limit how many requests can be sent in a short time
    Legal basis (GDPR)
    Article 6(1)(f): our legitimate interest in receiving genuine requests and keeping the form usable
  • Purpose
    Keeping the site available and secure, finding faults and abuse
    Data
    Technical data
    Legal basis (GDPR)
    Article 6(1)(f): our legitimate interest in a working and secure site
  • Purpose
    Remembering your cookie choice
    Data
    Record of the choice in your browser
    Legal basis (GDPR)
    Strictly necessary storage; no consent is required

Under the Personal Data (Privacy) Ordinance (Cap. 486) we collect data only for these purposes, which are directly related to our business, and we do not use it for a new purpose without your consent. We do not use your data for direct marketing and do not sell it.

4. Who receives it

Your data is handled by the company and by the service providers below, which the company uses to run the site and its e-mail. We disclose data to authorities only where the law requires it.

  • Cloudflare, Inc. (United States): delivers this site through its network, working as a CDN and proxy in front of the server and handling the encrypted HTTPS connection, and runs the Turnstile spam check on the contact form. It processes your IP address and information about your browser and device. Cloudflare states that it also uses Turnstile signals to improve its bot detection and that for this purpose it acts as a controller under its own privacy policy (cloudflare.com/privacypolicy).
  • Google LLC (United States): requests sent through the form are passed as e-mail through Google's Gmail mail service to our mailbox. A copy of each message is kept in the sent mail of the Google account used for sending.
  • Proton AG (Switzerland): hosts the company's mailboxes at nebulairis.com, including contact@nebulairis.com, where requests from the form arrive, and info@nebulairis.com.
  • HOSTKEY B.V. (the Netherlands): provides the virtual server in Germany (European Union) on which the site runs, and receives the technical data described in section 2.

Through these providers your data may be processed outside the country you send it from, in particular in the European Union (Germany, where the site's server is located), the United States and Switzerland. Each provider handles it under its own terms and data protection policies. Where the GDPR applies: the European Commission has found that Switzerland ensures an adequate level of protection; for transfers to the United States, Cloudflare and Google state that they rely on the EU-U.S. Data Privacy Framework and the European Commission's standard contractual clauses.

When you send a request, you send your data directly to the company. Data sent from another country is therefore handled by the company, which is established in Hong Kong. Hong Kong is not covered by a European Commission adequacy decision.

5. How long we keep it

  • Contact requests that do not lead to a business relationship: while the correspondence continues and until the questions raised in it are settled, after which they are deleted.
  • Contact requests that lead to a business relationship: the correspondence is kept with the company's business records for the period for which Hong Kong law requires business records to be kept.
  • Spam check data: we do not store it. Cloudflare keeps it for the periods set out in its own policies.
  • Technical data: the web server keeps no access logs. Application and system logs on the server are kept for 14 days and then deleted automatically; entries needed to investigate a specific fault or security incident are kept until that investigation is finished. Cloudflare keeps its own logs for the periods set out in its policies.
  • IP addresses used to limit how many requests can be sent: kept only in the server's memory, for about 10 minutes.
  • Cookie choice: in your browser until you change it, clear the browser's site data, or we update the Cookie Policy.

6. Your rights

Under the Personal Data (Privacy) Ordinance you may ask whether we hold your personal data, request a copy and ask us to correct it. We reply to a data access or correction request within 40 days of receiving it.

Where the GDPR applies, we reply within one month of receiving the request. If a request is complex, this may be extended by up to two further months; we will tell you so, with the reasons, within the first month.

Where the GDPR applies to you, you may also ask us to erase your data, to restrict its use, to hand it over in a portable form, and you may object to use based on our legitimate interest. Where use is based on consent, you may withdraw it at any time.

Data access and correction requests may be addressed to Nebula Iris Limited, Unit G15, Tin Hau Apple SOLO, 14 Kings Road, Tin Hau, Hong Kong; e-mail info@nebulairis.com.

To use any of these rights, write to info@nebulairis.com. We may ask for information needed to confirm who you are. We do not charge for a reply, except that Hong Kong law allows a fee that is not excessive for complying with a data access request.

7. Complaints

If you think we have handled your data wrongly, please tell us first. You may also complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (pcpd.org.hk) or, if you are in the European Economic Area, to the data protection authority of the country where you live or work.

8. Whether you must provide data

You can read the site without giving us any data. The fields of the contact form are required only so that we can reply; without them we cannot answer a request. The form cannot be sent without the spam check; if you prefer not to use it, write to us by e-mail instead. We make no decisions by automated means alone and do no profiling.

9. Security

The site is available only over HTTPS: the connection between your browser and Cloudflare, which delivers the site, is encrypted, and the site sends security headers that limit what a browser may load. Requests from the form are sent from the site to our mail service over an encrypted connection; between mail services, encryption is used where both sides support it. Access to requests is limited to what is needed to reply.

10. Changes and language

When this policy changes, we publish the new text here with a new date. The policy exists in English and Traditional Chinese; if the two differ, the English text prevails.

Back to the home page