Data Processing Agreement — Hong Kong
The terms under which Cerrax processes your customers' personal data as your data processor.
This agreement forms part of the Terms of Service and applies whenever Cerrax processes personal data on your behalf. It uses the meanings given in the Personal Data (Privacy) Ordinance (Cap. 486) (the "Ordinance"), and it is the contract the Ordinance expects you, as a data user, to have with a data processor to keep your customers’ personal data secure and no longer than necessary. Where this agreement and the Terms conflict on data protection, this agreement governs.
1. Which of us is which
You are the data user of your customers’ personal data: you decide why and how it is collected and used. We are your data processor of it: we process it on your behalf and use it for our own purposes only in the ways section 3 lists. That covers personal data about your customers, the people who enquire with you, your other contacts, and your staff and crew in their working role. For your own account data — your name, your login, your firm’s settings and billing — we are a data user in our own right, and our Privacy Policy covers that.
One exception, which is your customer's choice, not yours. When your customer sends a video or photographs of their home, they may tick a separate box allowing Cerrax to keep them to train software that recognises furniture and rooms. For that use alone, Cerrax is not your data processor: it is a data user in its own right, on the customer's express consent, and our Privacy Policy(§3) covers it: identifying details are blurred before it is ever used for training, nothing uses it today, and the customer can withdraw at any time, after which the video and photographs are deleted under the ordinary ninety-day rule. Everything else in this agreement applies to them as it does to the rest of your customers’ data.
2. What we process, and for how long
- Subject matter and purpose: running your removals business on Cerrax — receiving and organising your enquiries, keeping your customer records (contacts), pricing, quoting and following up quotes, booking and running jobs, and sending the messages you set up — on your instructions.
- What we do with it: collecting, storing, organising, reading (including with AI, to suggest details for a person at your firm to confirm), pricing, sending messages on your behalf, de-identifying (section 9), exporting and deleting.
- Duration: for as long as your account is open, and afterwards only as section 8 allows.
- Type of personal data: names, addresses and districts, contact details, move dates, and details of the property and its contents that you or your customer enter; where your crew use Cerrax on the day of the move, photographs of the property, its access and any damage found, together with the name and drawn signature of whoever signs the inventory off; and, where you invite it and your customer chooses to send one, a video of their home. Where you use them: your contacts (names, email addresses, phone numbers, company, preferred language, addresses used, the choices they gave you about your messages and when, where they came from, and your notes); enquiries, including the text of enquiry emails sent to your Cerrax lead address; the messages you send through Cerrax and whether they were delivered; follow-up tasks and their notes; whether a payment has been made (never card details); and reviews and ratings your customers give you.
- People it is about: people who enquire with you (whether or not they become customers); your customers; the people at the properties you move between; other people you keep as contacts; people named in notes, messages, photographs or video; and your staff and crew in their working role.
We do not ask for and do not want sensitive personal data. Please do not enter Hong Kong Identity Card numbers, health, financial-account or similar information into free-text fields. If it arrives anyway — in an enquiry or a note — we hold it only as part of that record, never use it for pricing or learning, and keep it out of section 9.
A signature captured against an inventory is held as evidence that your customer agreed what was moved and in what condition. Nothing measures, compares or matches it, and nothing recognises a face in a photograph or video (where faces are blurred, software finds them only to blur them and keeps no measurement of them) — so we do not collect biometric data. Collecting signatures is optional: if you would rather your crew did not, simply do not use it.
3. We act on your instructions
We process your customers’ personal data only on your documented instructions — which include your use of the product and this agreement — unless the law requires otherwise, in which case we will tell you first unless the law forbids that. If we think an instruction breaches the Ordinance, we will tell you promptly and may pause carrying it out until you confirm or change it. We will not use or disclose the data for any purpose other than the one in section 2 — except the de-identified use in section 9 — and we will not sell it or use it in direct marketing.
Our own uses, and only these: the de-identification in section 9; keeping descriptions of a job's items and rooms, with any email address, phone number or address removed, for 30 days to improve how Cerrax recognises items (we keep no other text sent to our AI sub-processor); keeping the service secure and preventing abuse; and meeting our own legal obligations.
Your instructions include these, when you use the features concerned: receiving emails sent to your Cerrax lead address and reading them — using our AI sub-processor where an email has no labelled layout — to suggest details you confirm; keeping contact records and the choices your customers make about your messages; and sending the messages you switch on, in your name, identifying you and with your postal address, honouring every request to stop at once and for all of those messages from you to that person. We keep a record of each choice and each stop, and a scrambled record of a stop for as long as it must be honoured.
Also on your instructions, when you use the features concerned: sending your customers the messages about a job that you set up (by WhatsApp where you have connected it, otherwise by email), including a review request and the private rating and comment a customer may give you; creating links you choose to share — a job sheet for your crew, or evidence (the customer's name, photographs, video and signatures, never their contact details) for your insurer, broker or claims handler; publishing your jobs to calendar subscriptions you create; and keeping follow-up tasks and their notes.
4. Confidentiality
Everyone we allow to access your customers’ personal data is bound by a written duty of confidentiality that continues after they leave, and only sees what their role requires. Access inside the product is governed by roles and individual permissions, checked on the server for every request.
5. Security
We take all practicable steps to protect the data against unauthorised or accidental access, processing, erasure, loss or use, appropriate to its nature and the harm that could follow. The measures are described in our security overview — encryption in transit and at rest, role-based access control, an audit trail of consequential actions, point-in-time recovery and separate daily backups. That page states plainly what we do not yet have.
We will not materially reduce the overall level of security described there while this agreement lasts.
6. Sub-processors
You authorise us to use sub-processors. The current list is in section 8 of our Privacy Policy and is kept current there. We bind each of them by written contract to obligations no less protective than these, and we remain fully responsible to you for their performance. We will email your account owner at least 30 days before a new sub-processor starts handling your customers’ personal data (sooner only in an emergency, such as a provider failing, and then we tell you as soon as we can). You may object within that time on reasonable data protection grounds; if we cannot resolve it, you may end the affected service or your subscription and we will refund any fees paid in advance for the unused period. Services you connect yourself under your own account with them — your own Stripe, WhatsApp Business or Xero account — act on your instruction under your agreement with them, and are not our sub-processors.
If you subscribe your own calendar to your Cerrax calendar link, your calendar provider fetches your jobs under your own agreement with it; it is not our sub-processor.
7. Helping you meet your own obligations
Taking into account the nature of the processing, we will help you respond to data access and data correction requests — promptly enough for you to answer within the Ordinance’s 40 days — and to requests to stop using data in direct marketing. If a person contacts us directly about data we hold for you, we will refer them to you rather than answer for you. If we become aware of a breach affecting your customers’ personal data, we will tell you without undue delay, and in any event within 48 hours, with what we know of what happened, the data and people affected, and what we have done to contain it — so that you can decide whether to notify the Privacy Commissioner for Personal Data and the people affected, as the Commissioner’s guidance recommends.
You can find, export, correct and delete a contact or a job yourself in the product; for anything the product cannot do, we will act within 10 working days of your written instruction.
8. Deletion and return
Your instruction on how long we keep it. Unless you tell us otherwise, you instruct us to keep each job record — the quote, its booking and outcome, the crew's sheets and the photographs attached to them — for six years after the move (or after the quote, if the job did not go ahead), or for longer while a claim or dispute about that job is open, and then to delete it. A video, and any photographs your customer sends with it, are deleted 90 days after the job's last date unless your customer has separately agreed to their longer use. You can change this instruction by telling us.
Beyond that, we keep your customers’ personal data no longer than is necessary for the purpose in section 2. At the end of the agreement you can export your data for 30 days. We then delete your customers’ personal data within 90 days, and it leaves our backups as they expire (within 98 days), except where the law requires us to keep it or you ask us to keep specific records, such as evidence in an open claim. Committed pricing records are never silently altered — personal identifiers within them are removed, which is how deletion is honoured without falsifying a record of what was quoted. Section 9 records are not your customers’ personal data and are not affected.
Unless you tell us otherwise, you also instruct us to delete: an enquiry that was never priced or sent, 12 months after its last activity; a quote that was sent but never accepted, 24 months after it was sent; and a contact record 12 months after the last job record linked to it is deleted (or 12 months after it was made, if it was never linked to a job). A record of a person's consent is kept while their contact record is kept and for six years after; a scrambled record of a request to stop messages is kept for as long as it must be honoured.
Two records keep their own periods: email delivery records (recipient, subject and whether it was delivered), 90 days; and the audit trail of actions in your account, up to six years after your account closes, with a customer's details removed when that customer is erased.
9. De-identified job data
(a) You instruct us to make de-identified records from the jobs we hold for you. (b) A de-identified record holds only the shape and economics of a job — volume, a distance band, access features, crew, vans, hours, price and cost, whether the quote was won and why not, the month of the move, and an area no finer than the first two letters of a district's name — and never a name, contact detail, full address, map position, free text, photograph, video, signature, your firm's identity, or any reference that links it back to the job. (c) We treat a record as de-identified only when no one could reasonably identify a person from it, taking account of other information we or you hold. Data that can be linked back — for example by a job reference, or while we still hold the original job — is not de-identified and stays under this agreement until the original is deleted. (d) We will not try to re-identify anyone from these records, and require anyone we share them with to make the same commitment. (e) Once a record meets this standard it is not your customers’ personal data; it is ours, and we may keep and use it to improve and provide Cerrax, including after the underlying records are deleted and after this agreement ends. (f) We never show another firm, or anyone else, your individual prices or anything that identifies your firm.
10. Learning across firms
We use de-identified records under section 9, and statistics made from them, from across all firms using Cerrax, in every region we serve, to improve the pricing engine for everyone, including you. This is stated here rather than assumed, because it is how the product gets better and we would rather you knew than found out.
11. Your numbers stay yours
Your rates, your margins, your customers and your prices are never visible to another firm, and never shown to the people you are quoting. The learning in section 10 runs on aggregated, de-identified signal — not on access to any one firm’s data by anybody else.
12. Audit
We will make available the information you reasonably need to show we are meeting these obligations — first by written answers and our security documentation — and will allow and contribute to a reasonable assessment by you or an independent assessor you appoint where those are not enough or a regulator requires it: at your cost, on 30 days' notice, under confidentiality, without access to other firms' data, and no more than once a year unless a regulator or a breach requires otherwise.
13. International transfers
We hold your customers’ personal data in the United Kingdom, in London, so it is transferred outside Hong Kong, and you authorise that. Section 33 of the Ordinance, which would restrict such transfers, has not been brought into force. We apply safeguards anyway: the data is used only for the purpose in section 2; it is protected as section 5 describes wherever it is held; every sub-processor that handles it — including those that may process it outside the United Kingdom, such as the AI provider in the United States and the mapping and website-hosting providers named in our Privacy Policy — is bound by a written contract no less protective than this agreement; and in London the UK GDPR also applies to it. Where your data is stored on any given day is a question you can ask us at any time, and we will answer it for the day you ask.
Liability. Section 11 of the Terms of Service (limitation of liability) applies to this agreement.
14. Contact
Data protection questions, data access and correction requests, and breach notifications: hello@cerrax.io.
15. The Ordinance’s terms, in one place
For your own records, this agreement gives you the contractual means the Ordinance expects a data user to have with a data processor: keeping personal data no longer than necessary, and deleting or returning it at the end (sections 2 and 8); preventing unauthorised or accidental access, processing, erasure, loss or use (sections 4 and 5); using it only for your purpose and on your instructions (section 3); sub-processors bound by written contract (section 6); help with access and correction requests and prompt notice of a breach (section 7); information and audits to show compliance (section 12); and safeguards for transfers outside Hong Kong (section 13).