Legal
Privacy Policy
How Nassouri Gold Capital Holding Group Co., Limited handles personal data.
This Privacy Policy explains how Nassouri Gold Capital Holding Group Co., Limited (“the Company”, “we”, “us”) collects, uses, discloses and protects personal data in connection with this website and corporate correspondence. It is designed to meet the requirements of the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”), and, where applicable, the UK GDPR and Data Protection Act 2018, and the EU General Data Protection Regulation 2016/679 (“EU GDPR”).
1. Data controller
The data controller is Nassouri Gold Capital Holding Group Co., Limited, Suite 1405A, 14/F, The Belgian Bank Building, 721–725 Nathan Road, Mong Kok, Kowloon, Hong Kong SAR. For any privacy matter, contact info@nassourigoldcapital.com.
2. Personal data we collect
- Correspondence data you provide when you contact us — name, employer or counterparty, email address, telephone number, and the content of your message and attachments.
- Due-diligence data exchanged for account-opening, compliance, KYC/CDD or contractual purposes, where you choose to provide it.
- Technical data collected automatically by our hosting and content-delivery providers for security and delivery — IP address, browser type, device information, referring pages and access timestamps.
We do not knowingly collect special-category data or data relating to children through this website.
3. How we use personal data and our lawful bases
| Purpose | Lawful basis (UK/EU GDPR, where applicable) |
|---|---|
| Responding to enquiries and corporate correspondence | Legitimate interests (Art. 6(1)(f)); steps prior to a contract (Art. 6(1)(b)) |
| KYC/CDD, sanctions screening and anti-money-laundering checks | Legal obligation (Art. 6(1)(c)); legitimate interests |
| Maintaining business and statutory records | Legal obligation (Art. 6(1)(c)) |
| Website security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
Under the PDPO, personal data is collected for purposes directly related to the Company’s holding, advisory and corporate functions, and is not used for any new purpose without your consent unless permitted by law.
4. Disclosure of personal data
We may disclose personal data to: our professional advisers (legal, accounting, audit, tax); banks and financial institutions in connection with account-opening and ongoing due diligence; our hosting and content-delivery service providers acting as processors; and regulators, law-enforcement or other authorities where required or permitted by law. We do not sell personal data.
5. Cross-border transfers
The Company operates across Hong Kong, the United Kingdom, the United Arab Emirates and Malaysia, and our service providers may process data in jurisdictions outside your own. Where personal data protected by the UK or EU GDPR is transferred outside the UK/EEA, we rely on an adequacy decision or appropriate safeguards (such as the UK International Data Transfer Agreement / Addendum or EU Standard Contractual Clauses) where required.
6. Retention
Personal data is retained only as long as necessary for the purposes above or as required by applicable law (including statutory record-keeping and AML retention periods), after which it is securely deleted or anonymised.
7. Security
We apply reasonable technical and organisational measures to protect personal data against unauthorised access, loss or misuse. No transmission over the internet can be guaranteed fully secure.
8. Your rights
Subject to applicable law, you may have the right to: access your personal data and request a copy; request correction of inaccurate data; request erasure, restriction or object to processing; withdraw consent; and request data portability. Under the PDPO you have data-access and data-correction rights. To exercise any right, email info@nassourigoldcapital.com. We may need to verify your identity before responding.
9. UK / EU representative
Where the Company is required to appoint a representative under Article 27 of the UK or EU GDPR, the representative’s details will be published here. Until then, all data-protection enquiries should be addressed to the contact above.
10. Cookies
This website uses only strictly necessary cookies. See our Cookie Policy for details.
11. Complaints
You may complain to the relevant supervisory authority: in Hong Kong, the Office of the Privacy Commissioner for Personal Data (PCPD); in the United Kingdom, the Information Commissioner’s Office (ICO); or, in the EU, your local Data Protection Authority. We ask that you contact us first so we can try to resolve the matter.
12. Changes
We may update this Privacy Policy from time to time. The current version and its date appear at the top of this page.