Skip to main content
HainanInc

Data Protection Policy

Our obligations when we process personal data on a client's behalf while delivering an engagement.

Version 1.0 · Last updated August 16, 2026

Purpose and scope

This policy governs personal data that HainanInc Advisory Group processes on behalf of a client in the course of delivering services. In that relationship the client determines why and how the data is processed and acts as controller; we act on the client's documented instructions and act as processor.

It applies to every engagement under which we handle personal data belonging to a client's employees, officers, beneficial owners, contractors or customers — including entity administration, statutory filings, payroll, employer-of-record services and immigration support.

Personal data we process in our own right is not covered here. That is dealt with in our Privacy Policy.

This policy forms part of the engagement terms agreed with each client. Where an engagement requires additional terms — because of the jurisdiction involved, the category of data, or the client's own regulatory position — those are agreed in a schedule to the engagement letter and take precedence over this policy to the extent of any conflict.

1. Processing on instructions

We process personal data only on the client's documented instructions, including in relation to transfers to another country, unless we are required to do otherwise by a law we are subject to. Where a law requires it, we will tell the client before processing unless that law prohibits us from doing so.

If we consider an instruction to conflict with applicable data protection law, we will say so before acting on it. We will not silently proceed and we will not silently refuse.

2. What we process

The categories of data subject, categories of personal data, purposes and duration for each engagement are recorded in the engagement documentation rather than fixed here, because they differ by service. Typical categories are set out below for orientation.

  • Identification and contact details of employees, officers, shareholders and beneficial owners
  • Employment and remuneration data, where we provide payroll or employer-of-record services
  • Identity documentation, immigration status and dependant details, where we provide immigration support
  • Corporate records, signatory information and authorisations, where we provide entity administration

Consents and notices

Where the applicable law requires a notice to be given to, or a consent obtained from, the individuals whose data we process, the client is responsible for giving that notice or obtaining that consent before the data is passed to us. We will assist, but we are not in a position to do it in the client's place.

3. Subprocessing

We engage subprocessors where they are necessary to deliver a service — infrastructure and software providers, and in some jurisdictions a local specialist firm. The client's agreement to our engagement terms constitutes general authorisation for us to do so.

Every subprocessor is engaged under written terms imposing obligations no less protective than those in this policy, and we remain fully liable to the client for a subprocessor's performance.

We will tell the client in advance of any intended addition or replacement of a subprocessor and allow a reasonable period to object. If the client objects on reasonable data protection grounds, we will work with them to find an alternative; if none is available, either party may terminate the affected service without penalty.

4. Confidentiality and security

We treat client personal data as confidential. Access is limited to personnel who need it to deliver the engagement, each of whom is bound by a written confidentiality obligation that survives the end of their engagement with us.

We implement technical and organisational measures appropriate to the risk, taking account of the state of the art, the cost of implementation, and the nature and severity of the risk to the individuals concerned.

  • Encryption of personal data in transit, and at rest where the storage medium supports it
  • Access control on a least-privilege basis, with access reviewed when a person's role changes and revoked when they leave
  • Segregation of one client's data from another's
  • Logging of access to systems holding client personal data
  • Backup and restoration procedures, tested rather than assumed
  • A defined route for reporting a suspected incident internally, without waiting for certainty

5. Assisting the client

We assist the client with the obligations that fall on them as controller, taking into account the nature of our processing and the information available to us.

Requests from individuals

If an individual contacts us directly to exercise a right in relation to data we hold as processor, we will not respond substantively ourselves. We will pass the request to the client without undue delay and assist them in responding.

Impact assessments and consultation

Where the client is required to carry out a data protection impact assessment, or to consult a supervisory authority, in relation to processing we perform, we will provide the information reasonably necessary for them to do so.

Audit

We will make available the information reasonably necessary to demonstrate our compliance with this policy, and will allow for and contribute to an audit conducted by the client or a mandated auditor on reasonable notice and during business hours.

An audit may not require us to disclose another client's information, our internal pricing, or internal audit material. One audit per twelve-month period is at our cost; a further audit within the same period is at the client's cost unless it follows an incident we caused.

6. Personal data breaches

We will notify the client without undue delay after becoming aware of a personal data breach affecting their data, and in any event in time to allow the client to meet their own notification deadlines.

Our notification will describe what we know at the time — the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed. We will not delay an initial notification in order to complete an investigation, and we will update the client as more becomes known.

We will cooperate with the client and take the steps they reasonably direct to investigate, contain and remediate the breach. Where the breach is attributable to us, we bear the reasonable cost of doing so.

7. International transfers

Engagements connected to the Hainan Free Trade Port frequently involve a party outside the People's Republic of China, so a transfer of personal data across a border may be necessary to deliver the service the client has asked for.

We will make such a transfer only where a lawful mechanism exists for that route under the law applying to the transfer, and where the recipient is bound to protections no weaker than those in this policy. Where the applicable law requires the controller to complete a formality — an assessment, a filing, or a notice to the individuals concerned — the client remains responsible for it and we will provide the information they need.

8. Return and deletion

At the end of an engagement we will, at the client's choice, return their personal data or delete it, together with existing copies.

We will retain data beyond that point only where a law we are subject to requires us to, and only for as long as that requirement lasts. Where we do, it remains subject to this policy and we will not process it for any other purpose.

9. Allocation of responsibility

The client warrants that the personal data they provide has been collected lawfully, that any notice or consent the applicable law requires has been given or obtained, and that our processing of it on their instructions will not put them in breach of their own obligations.

We are responsible for the consequences of processing that fails to meet the obligations this policy places on us as processor, or that departs from the client's lawful instructions. We are not responsible for the consequences of an instruction that was itself unlawful, where we had no reasonable means of knowing.

Contact

Data protection questions relating to a live engagement should go to your usual contact, who will involve the right people. Anything else may be sent to enquiries@hainaninc.com.