Privacy notice (version 2026-09-27)
How One IBC Limited (Offshore Company Corp) collects, uses, shares and protects personal data on our website and client portal, and how to use your rights.
In plain language
- One IBC Limited in Hong Kong (brand Offshore Company Corp) is responsible for your personal data. Write to privacy@offshorecompanycorp.com.
- We collect what you type into our website forms, checkout, chat and client portal, plus security data such as your sign-in devices.
- When you become a client, Hong Kong anti-money laundering law requires us to check who you are. You upload identity and ownership documents to our encrypted document vault in the portal.
- We keep client and KYC records for at least 5 years after our relationship ends, because the law requires it. We cannot delete them earlier.
- We never see or store your full card number. You enter card details on PayPal or GlobalPay hosted payment pages or fields.
- Our AI assistant, Ask OCC, is a computer program, not a person. It does not decide whether we accept you as a client.
- We send marketing emails only if you opt in. You can change this in the preference centre or with the unsubscribe link at any time.
- Our service providers are mainly in Singapore and the United States. You can ask to see, correct or delete your data.
This summary helps you read the document. If it differs from the full text below, the full text applies.
1. Who we are and what this notice covers
This website and client portal are run by One IBC Limited, a company in Hong Kong that trades as Offshore Company Corp (OCC). We hold Trust or Company Service Provider licence TC001305 from the Hong Kong Companies Registry. Our head office is Unit 1411, 14/F, COSCO Tower, 183 Queen's Road Central, Sheung Wan, Hong Kong.
One IBC Limited decides why and how your personal data is used. In data protection law that makes us the "data user" (Hong Kong), the "controller" (EU and UK), the "organisation" (Singapore) and the "personal data controller" (Vietnam).
One IBC Limited and One IBC Pte. Ltd (Singapore registration no. FA20180115) are sister companies in One IBC Group. Our Terms of Service name the company that carries out each part of a service (the "performing company"): One IBC Pte. Ltd in Singapore, One IBC USA, Inc. in the United States or Công ty TNHH One IBC Việt Nam (One IBC Vietnam Co., Ltd) in Vietnam. A performing company uses your data only to carry out that work, and may also be responsible for it under its own local law. One IBC Limited stays your contact for every privacy request.
This notice covers offshorecompanycorp.com and everything behind it: our forms, call booking, checkout, the Ask OCC assistant, the client portal at /portal (accounts, document vault, identity checks, company formation and company secretarial records), the emails we send, and cookies.
For any privacy question or request, email privacy@offshorecompanycorp.com or write to our office address above.
2. Personal data we collect
We collect only the data we need for the service you ask for. Fields marked optional are optional. The list depends on how far you go with us: a visitor who sends one question gives us much less than a client who forms a company.
- Enquiries (contact, quote, call booking, price list, shortlist, partner forms): your name, email, phone or WhatsApp number, country of residence, what you need, your message, and for calls the time slot, time zone and language. Partners also give firm details.
- Checkout and orders: proposed company names, business activity, your name as on your passport, email, phone, country of residence, payment method, order details, invoices and the time you accepted our terms.
- Payments: the payment status and a reference from our payment processor or bank. We do not receive or store full card numbers or card security codes.
- Client portal account: your name and email, sign-in links we email you, your two-step sign-in method (an authenticator app secret or a passkey's public key; we never receive your fingerprint or face data from a passkey), and your signed-in devices with browser type, approximate location from IP address and sign-in times.
- Team members: if your account lets several people work on the same company, the name, email and role of each person you invite, and who did what in the account.
- Identity and due diligence (KYC/CDD): passport or national ID, proof of address, date of birth, nationality, residential address, and the same details for directors, shareholders, beneficial owners (UBOs) and company secretaries. Also whether a person is a politically exposed person (PEP), the results of sanctions, PEP and adverse media screening, and our risk rating.
- Company records: statutory registers of directors, members, beneficial owners and secretaries, share details, company documents we prepare or you upload, and filings with registries.
- Emails: which service, security and marketing emails we sent you, whether they were delivered or bounced, your email preferences, and unsubscribe records.
- Account history: notes, calls, tasks and messages our staff record about your enquiry or account in our customer records system (CRM).
- Ask OCC assistant: the questions you type and the page you are on. See the Ask OCC section below.
- Your choices: whether you agreed to be contacted, your marketing choice, the version of this notice shown to you and the time.
- Campaign data (only where your cookie choice allows it): the advert or campaign that brought you to us, such as UTM tags, Google or Meta click IDs, the landing page and the referring website.
- Technical data: your IP address is used to limit abuse and protect your account. With website forms we store only a one-way hash of it. Our hosting provider also sees standard request data such as browser type in its logs.
3. Identity documents and sensitive data
As a licensed Trust or Company Service Provider, we must identify and verify our clients and their beneficial owners before we act for them, and keep checking them while we do. That is why we ask for identity documents and ownership details in the client portal. We do not ask for these on the public website pages.
Screening against sanctions, PEP and adverse media lists can show information about criminal allegations or convictions, or a person's public or political role. We use it only to meet our anti-money laundering duties and to decide whether we can act, and only trained staff can see it.
Identity checks with a face scan (liveness check) are used only if we switch on an outside identity verification provider. If we do, the provider compares a selfie or short video with your ID photo, which involves biometric data. We will ask for your explicit consent first and offer another way to verify you, such as a certified copy of your documents. Until a provider is switched on, our staff check your documents by hand.
We do not ask for health data, religious beliefs or sexual orientation. Please do not include this kind of information, or bank or card details, in forms, the chat or uploaded files unless we ask for a specific document. If you do, we will use it only to reply to you, or delete it.
4. Why we use your data and our legal basis
We use your data only for the purposes below. For people in the EU, EEA and UK, we also name the legal basis under Article 6 of the GDPR and UK GDPR. For people in Vietnam, see the Vietnam section.
- To answer your enquiry, prepare a quote or hold a call: steps you ask for before a contract (Art. 6(1)(b)). One follow-up on the same enquiry: our legitimate interest in completing it (Art. 6(1)(f)).
- To take your order, form and administer your company, keep its statutory registers, file with registries, invoice you and take payment: to perform our contract with you (Art. 6(1)(b)), and to meet company law duties in the place your company is registered.
- To run your portal account, sign you in safely, show you your devices and let your team members work together: to perform our contract (Art. 6(1)(b)) and our legitimate interest in keeping accounts secure (Art. 6(1)(f)).
- To verify identity, screen against sanctions and PEP lists, rate risk and monitor the relationship (KYC/CDD): our legal obligations under Hong Kong's Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615). For people in the EU, EEA and UK, where no EU or UK law requires this, we rely on our legitimate interest in meeting our Hong Kong legal duties and preventing financial crime (Art. 6(1)(f)), and on Art. 6(1)(c) where EU or UK law applies. We process data about criminal offences only as the law allows (Art. 10). Biometric data, if used, only with your explicit consent (Art. 9(2)(a)).
- To keep client, KYC, order and payment records after the relationship ends: our legal obligations under AMLO and tax law. See "Keeping records and deleting data".
- To send service and security emails (sign-in links, order updates, invoices, security alerts): to perform our contract (Art. 6(1)(b)) and our legitimate interest in account security (Art. 6(1)(f)). You cannot opt out of these while you have an account.
- To send marketing emails: your consent (Art. 6(1)(a)).
- To keep our customer records (CRM) accurate and plan follow-ups: our legitimate interest in running our business (Art. 6(1)(f)).
- To measure how the site is used and which adverts work: your consent where we ask for it first (Art. 6(1)(a)). See the cookie policy.
- To protect the site and portal from spam, bots, fraud and abuse: our legitimate interest in security (Art. 6(1)(f)).
- To answer questions in the Ask OCC assistant: steps you ask for before a contract (Art. 6(1)(b)) and our legitimate interest in quick, accurate answers (Art. 6(1)(f)).
- To handle privacy requests and complaints, and to defend legal claims: legal obligations (Art. 6(1)(c)) where EU or UK law applies, otherwise our legitimate interest (Art. 6(1)(f)).
5. Data about other people
When you order a company, you usually give us details of other people: directors, shareholders, beneficial owners, company secretaries and colleagues you invite to your account. Please give them a copy of this notice or a link to it before you do. We may contact them directly to verify their identity, as the law requires.
6. Marketing
We send marketing only if you tick the optional marketing box. The box is never ticked for you, and your request is handled the same way whether you tick it or not.
If you agree, we will use your name and email address to send you news, guides and offers about company formation, company secretarial and accounting services, bank-account introduction support, and related corporate services from Offshore Company Corp. We send marketing by email only.
You can withdraw your consent at any time, free of charge, with the unsubscribe link in every marketing email, in the email preference centre, or by writing to privacy@offshorecompanycorp.com. We then stop and keep your email on a suppression list so we do not contact you again by mistake.
We do not sell your personal data, and we do not give it to other companies for their own marketing.
Messages about your own request or order, such as a quote, a booking confirmation or an invoice, are service messages, not marketing. If you give us a Singapore phone number, we will not send you marketing calls or messages to it unless you have given clear consent or we have checked the Singapore Do Not Call Registry.
7. Ask OCC, our AI assistant
Ask OCC is an AI assistant, not a person. When it is switched on, it may use a large language model called Claude, provided by Anthropic. It answers from our published prices and facts, and it can make mistakes. Its answers are general information, not legal or tax advice.
When you use it, we send your messages in that conversation and basic page context (such as the jurisdiction or service you are viewing) to our server and, when the AI model is on, to Anthropic to produce an answer. We do not send your name or email to Anthropic unless you type them into the chat. Please do not type passport, bank or card details.
We do not store the chat on our servers when you only ask questions. Your browser keeps a random session ID for that tab so we can limit the number of messages per hour. If you rate an answer, we keep the rating with that session ID.
We keep a copy of the chat (up to the last 30 messages) only if you ask us to email you a summary or to save a quote. The copy is stored with that request and kept for the same period as other enquiries.
Ask OCC suggests jurisdictions, packages and prices. It does not make any decision that has a legal or similarly significant effect on you, such as accepting or refusing you as a client. Those decisions are made by our staff after our KYC checks. You can ask to talk to a person at any time.
10. Transfers outside your country
We are in Hong Kong, our database and our sister company are in Singapore, performing companies are in the United States and Vietnam, and several providers are in the United States. To form a company abroad we must also send details to the registry and agents in that country. Your data may therefore be processed outside the place where you live.
Where the law requires a safeguard, we use one of these: for the EU and EEA, the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), or the EU-US Data Privacy Framework (Decision (EU) 2023/1795) for US providers certified under it; for the UK, the International Data Transfer Agreement or UK Addendum, or the UK Extension to the Data Privacy Framework; for Singapore, contracts that give a comparable standard of protection; for Hong Kong, contract terms based on the Privacy Commissioner's recommended model clauses; for Vietnam, the cross-border transfer impact assessment the law requires, kept up to date.
When we send details to a registry or agent in the country where you asked us to form your company, and no other safeguard is available, the transfer is necessary to perform the contract you asked for (GDPR Art. 49(1)(b)).
You can ask us for more information about the safeguard used for a transfer, or a copy of it, at privacy@offshorecompanycorp.com.
11. How long we keep your data
We keep personal data only as long as we need it for the purpose we collected it for, or as long as the law requires. Then we delete it or remove the details that identify you.
- Enquiries, quote requests, call bookings, price lists and partner applications that do not lead to an order: 24 months after our last contact, then anonymised. Chat copies you asked us to email or save are kept with the enquiry.
- Saved carts and resume links: the link works for 30 days; we delete the cart 90 days after the link expires.
- Checkouts you start but do not submit: 12 months, then your contact details are removed.
- Client records, including KYC/CDD documents, screening results, risk ratings, orders, invoices and payments: at least 5 years after our business relationship ends, as Hong Kong anti-money laundering law requires. Longer only if a law, investigation or legal claim requires it.
- Access logs for the document vault: for as long as we keep the document they relate to.
- Statutory registers and company documents: while we act for the company, then for as long as the company law of the company's country requires.
- Biometric data from a liveness check (only if a provider is switched on): deleted by the provider after the check. We keep only the result.
- Portal account and device records: while your account is open. Sign-in and security logs: 12 months.
- Email delivery log (metadata only, such as the date, the type of email and whether it was delivered, not the content): 24 months. Unsubscribe and suppression records: for as long as we need to respect your choice.
- Privacy requests and complaints: 3 years after we close them.
- Cookies: see the cookie policy for each cookie.
12. Keeping records and deleting data
As a licensed Trust or Company Service Provider, we must keep customer due diligence and transaction records, including copies of identity documents and screening results, for at least 5 years after the business relationship ends (Anti-Money Laundering and Counter-Terrorist Financing Ordinance, Cap. 615, Schedule 2, section 20).
If you ask us to delete data we must keep under that duty, we will delete what we can and restrict the rest, so it is used only for the legal purpose. We will tell you what we kept and why. We delete or anonymise it when the retention period ends.
Some company records must be kept or filed under the company law of the place where your company is registered, and public registers are controlled by the registry, not by us.
If you never became a client, the AMLO duty does not apply, and we will delete your enquiry when you ask, unless we need it for a legal claim.
13. How we protect your data
We use technical and organisational measures that fit the risk. They include:
- Encrypted connections (HTTPS with HSTS) for every page, form and portal screen.
- Security headers that limit which outside scripts can run on our pages.
- Portal sign-in by one-time email links, with two-step sign-in by an authenticator app or a passkey. You can see your signed-in devices and sign them out.
- Each file in the document vault is encrypted on its own (AES-256-GCM with envelope encryption). Files are opened only through signed links that expire after a short time, and every access is logged.
- Access for our staff only through named accounts, with roles that limit what each person can see and change. Only staff who need identity documents for their work can open them.
- When we connect a sales or marketing system, only an approved list of fields is sent, never identity documents or screening results.
- Rate limits and a bot check on forms, sign-in and the chat. IP addresses from website forms stored only as a one-way hash with a secret key.
- No names, emails or phone numbers in our application logs.
- No card data on our systems: you enter card details on the hosted payment fields or pages of PayPal or GlobalPay Hong Kong, who are responsible for card security under the PCI DSS standard.
14. If something goes wrong
If a personal data breach happens, we act to contain it and assess the risk. Where the law requires, we tell the regulator and the people affected within the legal time limit. For example, the GDPR and UK GDPR require notice to the regulator within 72 hours where a breach is likely to risk people's rights, Vietnam requires notice to the Ministry of Public Security within 72 hours, and Singapore requires notice to the PDPC within 3 calendar days after we assess that a breach is notifiable. In Hong Kong we notify the Privacy Commissioner and affected people where there is a real risk of harm, following the Commissioner's guidance.
15. Your rights
Depending on where you live, you can ask us to:
- Tell you whether we hold data about you and give you a copy.
- Correct data that is wrong or incomplete.
- Delete your data, subject to the record-keeping duties above.
- Restrict how we use your data, or object to our use of it. You can always object to marketing, and we will stop.
- Give you the data you provided in a common machine-readable format, or send it to another organisation (EU, EEA and UK).
- Withdraw your consent at any time. This does not affect what we did before you withdrew it.
- Explain how a decision was made, and let a person review it. We do not make decisions about you by automated means alone that have legal or similarly significant effects. Screening tools flag possible matches, and our staff decide what to do.
- Complain to us or to a regulator (see below).
16. How to make a request or complaint
Email privacy@offshorecompanycorp.com, or use "Your privacy rights" in the site footer, which opens our contact form with a privacy request. Clients can also see and download their documents in the portal. Requests are free. We may ask for information to confirm your identity before we act, and we will use it only for that purpose.
We reply within the time your law allows. That is within 40 days for Hong Kong access and correction requests, within one month for the GDPR and UK GDPR (we may extend this by up to two further months for complex requests and will tell you why), and as soon as reasonably possible, normally within 30 days, for Singapore. For Vietnam, we acknowledge your request within 2 working days and then act within the limits in Decree 356/2025/ND-CP.
If you complain to us about how we use your data, we acknowledge the complaint within 2 business days and send you a full reply within 30 days. If you are not satisfied, you can go to a regulator.
Anti-money laundering law may stop us from telling you about some checks or reports, or from giving you some screening information. If so, we will give you everything else.
17. Regulators
You can complain to the data protection regulator where you live or work, or where you think the problem happened. For example:
- Hong Kong: Office of the Privacy Commissioner for Personal Data (pcpd.org.hk).
- EU and EEA: the supervisory authority in your country, listed by the European Data Protection Board (edpb.europa.eu).
- United Kingdom: Information Commissioner's Office (ico.org.uk).
- Singapore: Personal Data Protection Commission (pdpc.gov.sg).
- Vietnam: Ministry of Public Security, Department of Cybersecurity and High-Tech Crime Prevention (A05).
18. Extra information for people in Vietnam
Vietnam's Law on Personal Data Protection No. 91/2025/QH15 and Decree 356/2025/ND-CP apply to foreign organisations that process the personal data of people in Vietnam.
We ask for your consent in a clear, separate way for each purpose. Silence, inaction or a pre-ticked box is never consent. Sending a form or starting a chat is consent to use your data to answer that request. Marketing emails and analytics or advertising cookies each need their own consent.
Some data we process is sensitive personal data under Vietnamese law: images of ID cards, bank and financial data, information on criminal records from screening, biometric data (only if a liveness check is switched on) and online behaviour tracking such as advertising cookies. In the portal we ask for separate, explicit consent before we collect it, except where the law allows us to process it without consent. We use advertising cookies only if you accept marketing cookies.
Your data is transferred to Hong Kong, Singapore, the United States and the country where your company is formed, as described above. We keep a cross-border transfer impact assessment as the law requires.
If you withdraw consent or ask us to delete data, we may no longer be able to provide our service, and anti-money laundering law may require us to keep some records. We will tell you if that is the case.
Ask OCC uses artificial intelligence to answer questions. It suggests options only and does not make decisions about you.
19. Visitors in the United States
Based on our current size and activities, we do not believe US state consumer privacy laws such as California's CCPA apply to us. We do not sell personal data. If your browser sends a Global Privacy Control signal, we treat it as a refusal of advertising cookies. You can use the rights described in this notice wherever you live.
20. Children
Our services are for adults forming and running companies. The website is not aimed at anyone under 18, and we do not knowingly collect data from children. If you think a child has sent us data, contact us and we will delete it.
21. Contact for people in the EU and UK
If you are in the EU, EEA or UK, you can contact us directly about anything in this notice at privacy@offshorecompanycorp.com. We answer in English.
We have not appointed a representative in the EU or the UK under Article 27 of the GDPR and UK GDPR. We will review this before our client portal starts storing identity documents, and if we appoint representatives we will name them here.
22. Changes to this notice
We will update this notice when our services or the law change. The version and date are shown at the top. Forms record the version you saw. If we make an important change, we will say so on the website, and where the law requires, we will ask for your consent again.
Change log
What changed in version 2026-09-27 (29)
Who we are and what this notice covers: Controller changed from "One IBC Group" to the legal entity One IBC Limited with HK TCSP licence TC001305 and the full Hong Kong head office address. Scope now covers the client portal, document vault, CRM and emails.
Why: A notice must name the legal entity responsible and how to reach it.
Law: GDPR Art. 13(1)(a); PDPO Sch. 1 DPP1(3); PDPA s.20; Law 91/2025/QH15 Art. 9
Personal data we collect: Replaced generic categories with the actual data per stage: enquiries, checkout, portal account (sign-in links, TOTP or passkey, devices), team members, KYC/CDD, statutory registers, email records, CRM history, chat, campaign and technical data.
Why: The notice must match what the website, portal, document vault, email platform and CRM collect.
Law: GDPR Art. 13(1)(c)-(e), Art. 5(1)(a),(c); PDPO DPP1(1),(3)
Identity documents and sensitive data: New section: identity documents, PEP and screening data collected in the client portal under AMLO; criminal-offence data from screening; biometric liveness data only if a KYC vendor is switched on, with explicit consent and a manual alternative.
Why: The platform now stores KYC/CDD documents and screening results in its own document vault. The live text listed passports and risk data without a basis or safeguards.
Law: AMLO Cap. 615 Sch. 2; GDPR Art. 6(1)(c),(f), Art. 9(2)(a), Art. 10; Decree 356/2025/ND-CP Art. 4; Law 91/2025/QH15 Art. 9
Why we use your data and our legal basis: Each purpose now has a named legal basis. Removed "staff training" and blanket legitimate-interest marketing; marketing, analytics and advertising moved to consent.
Why: Marketing by email to individuals needs consent under PECR and PDPO Part 6A; cookie-based analytics and ads need consent under ePrivacy Art. 5(3).
Law: GDPR Art. 6(1), Art. 13(1)(c); Directive 2002/58/EC Art. 5(3); PECR reg. 6 and 22; Law 91/2025/QH15 Art. 9 and 19
Marketing: Rewritten: separate unticked opt-in, kinds of data and classes of marketing subjects stated, email only, free opt-out, no sale of data, Singapore DNC rule. Removed post, telephone and SMS marketing.
Why: PDPO requires the data user to inform the data subject of the kinds of data and classes of marketing subjects and obtain consent before direct marketing. Only email opt-in exists in the code.
Law: PDPO Part 6A, s.35C, s.35G; GDPR Art. 7, Art. 21(2)-(3); PECR reg. 22; PDPA Part 9 (Do Not Call); Law 91/2025/QH15 Art. 28
Ask OCC, our AI assistant: New section describing the AI assistant, the AI provider, what is sent, when chats are stored, and that no automated decisions with legal effect are made.
Why: Transparency for AI interaction and automated processing.
Law: Regulation (EU) 2024/1689 Art. 50(1); GDPR Art. 13(2)(f), Art. 22; Decree 356/2025/ND-CP Art. 10; Law 91/2025/QH15 Art. 30
Cookies and similar technologies: Removed Microsoft Clarity, Hotjar and web beacons, which the new site does not use. Linked to a cookie policy that lists actual cookies. Described the consent defaults.
Why: The notice must describe real processing. Clarity and Hotjar are not in the code.
Law: Directive 2002/58/EC Art. 5(3); PECR reg. 6; GDPR Art. 7(3)
Who we share your data with: Replaced "service providers" and "framing techniques" with named processor categories and providers, their countries, and other recipients.
Why: Recipients or categories of recipients must be given; naming them is clearer.
Law: GDPR Art. 13(1)(e), Art. 28; PDPO DPP1(3)(b)(i)(B)
Transfers outside your country: Replaced "appropriate safeguards" with the actual countries and the transfer tool used under each law.
Why: The notice must name the safeguards and how to get a copy.
Law: GDPR Art. 13(1)(f), Art. 44-49; Decision (EU) 2021/914; Decision (EU) 2023/1795; UK GDPR Art. 46; PDPA s.26; Law 91/2025/QH15 Art. 20
How long we keep your data: Replaced a single 5-year period for everything with periods per data type. Non-client enquiries are no longer kept 5 years.
Why: The AMLO 5-year duty covers clients' CDD and transaction records only. Keeping prospects' data for 5 years breaches the storage limitation principle.
Law: GDPR Art. 5(1)(e); PDPO DPP2(2) and s.26; AMLO Cap. 615 Sch. 2 s.20; Law 91/2025/QH15 Art. 14
Keeping records and deleting data: New section explaining how the AMLO retention duty limits erasure requests and how data is restricted meanwhile.
Why: Transparent limits on the right to erasure.
Law: GDPR Art. 17(3), Art. 18; AMLO Cap. 615 Sch. 2 s.20
How we protect your data: Replaced "SSL" with the measures the platform uses: HTTPS/HSTS, passkey or TOTP two-step sign-in, per-file AES-256-GCM envelope encryption, signed short-lived URLs, access logs, role-based staff access, CRM sync field allowlist, and card data handled by processors under PCI DSS.
Why: Security statements must be accurate; overstated claims create liability.
Law: GDPR Art. 32; PDPO DPP4; PDPA s.24
If something goes wrong: New section on breach notification with time limits per law.
Why: Not in the live text.
Law: GDPR Art. 33-34; PDPA s.26D; Law 91/2025/QH15 Art. 23; PCPD Guidance on Data Breach Handling
Your rights: Rights list completed (objection, restriction, withdrawal, automated decisions) and linked to how to exercise them.
Why: Live text omitted objection and withdrawal and had no process or deadlines.
Law: GDPR Art. 7(3), 15-22; PDPO s.18, s.22, DPP6; PDPA s.16, s.21, s.22; Law 91/2025/QH15 Art. 4
How to make a request or complaint: New: contact route, identity check, deadlines per law, and complaint handling.
Why: UK DUAA 2025 added a duty to handle data protection complaints, acknowledge within 30 days and respond without undue delay (in force for complaints received from 19 June 2026).
Law: GDPR Art. 12(3); PDPO s.19; PDPA s.21; Decree 356/2025/ND-CP Art. 5; DPA 2018 s.164A (inserted by DUAA 2025)
Regulators: New list of regulators.
Why: Right to lodge a complaint with a supervisory authority must be stated.
Law: GDPR Art. 13(2)(d), Art. 77
Extra information for people in Vietnam: New Vietnam section: consent rules, sensitive behavioural tracking data, transfer impact assessment, consequences of withdrawal, AI use.
Why: Law 91/2025/QH15 and Decree 356/2025/ND-CP apply from 1 January 2026 to foreign organisations processing Vietnamese people's data.
Law: Law 91/2025/QH15 Art. 4, 9, 20, 28, 30; Decree 356/2025/ND-CP Art. 2(3), 4, 5, 6, 10
Visitors in the United States: New short US section: state laws likely do not apply, no sale, GPC honoured.
Why: Avoids claiming CCPA rights processes that are not in place while honouring GPC.
Law: Cal. Civ. Code s.1798.140(d)
Children: New children section.
Why: Live text had no section on minors.
Law: GDPR Art. 8; Law 91/2025/QH15 Art. 24
Contact for people in the EU and UK: Section on EU and UK representatives.
Why: Non-EU/UK controller offering services to people in the EU and UK may need a representative.
Law: GDPR Art. 27; UK GDPR Art. 27
Data about other people: New section asking clients to pass the notice to directors, shareholders, UBOs, secretaries and invited colleagues.
Why: Data about these people is collected from the client, not from them, so they must be informed.
Law: GDPR Art. 14; PDPO DPP1(3)
Keeping records and deleting data: Retention duty now expressly covers identity documents and screening results held in the document vault, and company-law records.
Why: KYC records are now held inside the platform.
Law: AMLO Cap. 615 Sch. 2 s.20; GDPR Art. 17(3)(b),(e), Art. 18
Who we are and what this notice covers: Adds One IBC Group (One IBC Limited and its sister company One IBC Pte. Ltd, Singapore registration no. FA20180115) and the performing companies named in the Terms (One IBC USA, Inc.; One IBC Vietnam Co., Ltd). One IBC Limited stays the contact for all privacy requests.
Why: Owner decision of 27 September 2026: a One IBC Limited master agreement with service schedules naming the performing company. People must know which companies use their data.
Law: GDPR Art. 13(1)(a),(e); PDPO Sch. 1 DPP1(3); PDPA s.20
Who we share your data with: Names the actual providers: Amazon SES (ap-southeast-1) for email; PayPal and GlobalPay Hong Kong (Global Payments Asia-Pacific) for payments with hosted card entry. Removed Stripe, Resend, Postmark and Meta. Adds group and performing companies as recipients, with no intra-group marketing. Document storage described without naming the provider: files are encrypted before storage.
Why: Owner provider decisions of 27 September 2026. Recipients must be accurate.
Law: GDPR Art. 13(1)(e), Art. 28; PDPO DPP1(3)(b)(i)(B)
How long we keep your data: Completed the open periods: statutory registers for as long as the company law of the company's country requires; biometric data deleted by the provider after the check; sign-in and security logs 12 months; email delivery log 24 months (metadata only).
Why: Owner retention decisions of 27 September 2026. Each category needs a period or the criteria used to set it.
Law: GDPR Art. 13(2)(a); PDPO DPP2(2); Law 91/2025/QH15 Art. 14
Cookies and similar technologies: Optional cookies now need consent in every country, not only in opt-in regions.
Why: Owner decision of 27 September 2026 (consent everywhere).
Law: Directive 2002/58/EC Art. 5(3); PDPA; Decree 356/2025/ND-CP Art. 4
How to make a request or complaint: Complaints about data use: acknowledged within 2 business days, full reply within 30 days, the same times as our general complaints process.
Why: One complaints standard across the legal set (owner decision of 27 September 2026). Meets the UK duty to acknowledge within 30 days.
Law: DPA 2018 s.164A (inserted by DUAA 2025)
Contact for people in the EU and UK: Replaced the placeholder: people in the EU and UK can contact us directly at privacy@offshorecompanycorp.com. No representative is claimed; the need is reviewed before the client portal stores identity documents.
Why: A notice must not claim an appointment that has not been made.
Law: GDPR Art. 13(1)(a), Art. 27; UK GDPR Art. 27
Who we are and what this notice covers: Published: status, version and effective date 27 September 2026.
Why: Owner decision to publish the legal set on 27 September 2026.
Law: GDPR Art. 12(1) and 13; PDPO (Cap. 486) Sch. 1 DPP1(3)
Sources
- OCC Privacy Policy (live text, updated 29 Jun 2026), Offshore Company Corp (accessed Sep 2026) (opens in a new tab)
- Personal Data (Privacy) Ordinance (Cap. 486), Hong Kong e-Legislation (accessed Sep 2026) (opens in a new tab)
- Guidance on Direct Marketing, Office of the Privacy Commissioner for Personal Data, Hong Kong (accessed Sep 2026) (opens in a new tab)
- Guidance on Recommended Model Contractual Clauses for Cross-border Transfer of Personal Data, Office of the Privacy Commissioner for Personal Data, Hong Kong (accessed Sep 2026) (opens in a new tab)
- Data Breach Notification, Office of the Privacy Commissioner for Personal Data, Hong Kong (accessed Sep 2026) (opens in a new tab)
- Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615), Hong Kong e-Legislation (accessed Sep 2026) (opens in a new tab)
- Regulation (EU) 2016/679 (General Data Protection Regulation), EUR-Lex (accessed Sep 2026) (opens in a new tab)
- Commission Implementing Decision (EU) 2021/914 on standard contractual clauses, EUR-Lex (accessed Sep 2026) (opens in a new tab)
- Commission Implementing Decision (EU) 2023/1795 (EU-US Data Privacy Framework), EUR-Lex (accessed Sep 2026) (opens in a new tab)
- Directive 2002/58/EC (ePrivacy Directive), EUR-Lex (accessed Sep 2026) (opens in a new tab)
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex (accessed Sep 2026) (opens in a new tab)
- Data Protection Act 2018, legislation.gov.uk (accessed Sep 2026) (opens in a new tab)
- Data (Use and Access) Act 2025, legislation.gov.uk (accessed Sep 2026) (opens in a new tab)
- Privacy and Electronic Communications (EC Directive) Regulations 2003, legislation.gov.uk (accessed Sep 2026) (opens in a new tab)
- Data Protection (Adequacy) (United States of America) Regulations 2023, legislation.gov.uk (accessed Sep 2026) (opens in a new tab)
- How to deal with data protection complaints, Information Commissioner's Office (accessed Sep 2026) (opens in a new tab)
- The Data (Use and Access) Act 2025: what does it mean for organisations?, Information Commissioner's Office (accessed Sep 2026) (opens in a new tab)
- Personal Data Protection Act 2012, Singapore Statutes Online (accessed Sep 2026) (opens in a new tab)
- Personal Data Protection Act overview, Personal Data Protection Commission Singapore (accessed Sep 2026) (opens in a new tab)
- Luật Bảo vệ dữ liệu cá nhân số 91/2025/QH15, Cổng Thông tin điện tử Chính phủ (vanban.chinhphu.vn) (accessed Sep 2026) (opens in a new tab)
- Nghị định số 356/2025/NĐ-CP (31/12/2025) quy định chi tiết Luật Bảo vệ dữ liệu cá nhân, Cổng Thông tin điện tử Chính phủ (vanban.chinhphu.vn) (accessed Sep 2026) (opens in a new tab)
- California Consumer Privacy Act (Civil Code Title 1.81.5), California Legislative Information (accessed Sep 2026) (opens in a new tab)
- Organized and Serious Crimes Ordinance (Cap. 455), Hong Kong e-Legislation (accessed Sep 2026) (opens in a new tab)
Laws and regulator guidance this document follows. They explain our obligations; they are not legal advice for your situation.