This Privacy Policy explains how OTRA TECHNOLOGY collects, uses, stores, shares and protects personal information when you visit our website, contact our bench, or engage us for managed IT services and systems integration. The policy is written by the developer Otra Tech for the firm OTRA TECHNOLOGY, Rm 650 HENG ON EST HENG KONG HSE, Sha Tin, Hong Kong (HK), and it reflects the plain way we run the lab room: we gather only what a job needs, we keep it tidy, and we tell you what we do with it.
We ask that you read this policy before you send us a message or ask us to look after a system that holds the information of other people. By using this website or our services, you accept the practices described below. If you do not accept them, please do not send us personal information and please contact us so we can discuss an alternative arrangement.
CONTENTS
- Who We Are
- Scope of This Policy
- Information We Collect
- How We Collect Information
- Why We Use Information
- Lawful Bases for Processing
- Information Inside Client Systems
- Cookies and Local Storage
- Server Logs and Security Records
- When We Share Information
- Service Providers and Subcontractors
- International Transfers
- How Long We Keep Information
- How We Protect Information
- Your Rights and Choices
- Privacy for Children
- Direct Marketing and Notices
- Third Party Sites and Links
- Data Breach Response
- Changes to This Policy
- How to Contact Us
1. Who We Are
OTRA TECHNOLOGY is a computer systems design and related services firm operating in the professional, scientific and technical services sector. Our work covers managed network watch, backup and restore runs, helpdesk queue care, office system setup, server room tidy-ups and software rollout support. Our registered details are OTRA TECHNOLOGY, Rm 650 HENG ON EST HENG KONG HSE, Sha Tin, Hong Kong (HK). Our general contact address is hello@otratech.buzz and our telephone number is +15044297775.
For the purposes of applicable data protection law, OTRA TECHNOLOGY is the organization that decides how and why personal information is used when we provide our services, unless a written services agreement states otherwise. When we work inside the systems of a client firm, that client is usually the party responsible for the information stored in those systems, and we act on that client instruction. This distinction matters, and we explain it in the section on information inside client systems.
2. Scope of This Policy
This policy applies to the website at otratech.buzz and to the personal information we handle when you contact us, request a quotation, receive support, or use any service we provide. It does not apply to websites, applications or services operated by other organizations, even where we link to them or work alongside them.
The policy also does not cover information that has been fully anonymized so that it can no longer be linked to any individual. Where we create such anonymized statistics for planning, capacity or reporting purposes, those statistics fall outside this policy because they are no longer personal information.
3. Information We Collect
We keep collection narrow and predictable. The categories of personal information we may handle are set out below.
Contact and identity information
This includes names, job titles, employer names, work email addresses, work telephone numbers, office addresses and the details you choose to put in a support request. If you are an emergency contact for a client, we may hold your name and telephone number for the purpose of reaching the right person when a system needs attention.
Service and support information
This includes the tickets you raise, the messages you send to our bench, the devices and software involved, the symptoms you describe, and the notes our technicians write as they work. Support records can include system names, machine names, network addresses and the times at which faults occurred.
Technical and device information
When you visit the website, our hosting infrastructure may record the internet protocol address that reached us, the browser and device type, the pages viewed and the times of those views. When we are engaged to manage devices, we may process device identifiers, operating system versions, software inventory, patch state and similar technical details needed to keep those devices working.
Billing and administrative information
This includes invoice details, purchase order references, payment records, billing contacts and the correspondence needed to keep an account accurate. We do not store full payment card numbers in our own systems; where card payment is used, the number is handled by a payment provider.
Recruitment information
If you apply to work with us, we may hold the information in your application, such as your history, references and the notes taken during an interview. We use that information only to assess the application and to meet our legal duties.
4. How We Collect Information
Most of the information we hold comes directly from you or from the firm you work for. You provide it when you send a message through our contact form, email our bench, telephone us, sign an engagement letter or raise a support ticket. A colleague may provide it when they add you as a contact for a system or an account.
Some information is collected automatically. Website logs are generated by the hosting infrastructure as a normal part of serving pages. Managed systems generate event records, backup reports and alert messages as part of the routines we run. Where a client grants us access to a monitoring tool, that tool may report on device health and network performance on our behalf.
We may also receive information from third parties in limited situations. A payment provider may confirm that an invoice has been settled. A hardware supplier may pass us the contact details needed to arrange a warranty visit. A client may share a support record with us when they ask us to take over an existing arrangement.
5. Why We Use Information
We use personal information for clear and specific purposes. In broad terms, we use it to answer your enquiry, to provide and support the services we have agreed, to keep systems secure and available, to keep accurate records, to raise and settle invoices, to improve the way our bench works, and to comply with the legal and regulatory duties that apply to a firm operating in Hong Kong.
More specifically, we may use information to respond to a support ticket, to schedule a tidy-up or a setup visit, to verify a backup restore, to diagnose a fault, to keep an asset list current, to warn a client about a risk we have noticed, to prepare a service report, to defend a legal claim, and to protect the rights and safety of our clients, our staff and the public. We may also use aggregated, non identifying information to understand which services are most requested and where our routines could be sharper.
6. Lawful Bases for Processing
Where the law requires us to identify a lawful basis for processing, we rely on one or more of the following. We rely on the performance of a contract when the processing is needed to deliver a service that you or your employer has engaged us to provide. We rely on our legitimate interests when we monitor and secure our own systems, keep our records accurate, or improve our routines, provided those interests are not overridden by your rights.
We rely on legal obligation when we must keep a record for tax, accounting or regulatory reasons, or when we must respond to a lawful request from a competent authority. We rely on consent where we ask for it, for example before sending marketing messages where consent is the appropriate basis, and you may withdraw that consent at any time. Where we process special categories of information that the law treats as sensitive, we do so only where a lawful condition is met and where the processing is genuinely necessary.
7. Information Inside Client Systems
Our managed services often require us to work inside systems that hold the information of a client firm, its staff, its customers and its suppliers. In those situations, the client firm decides what information the system holds and why. OTRA TECHNOLOGY processes that information only on the documented instructions of the client, only as far as the service requires, and only under confidentiality duties that survive the end of the engagement.
We do not use information inside a client system for our own marketing, we do not sell it, and we do not read it for curiosity. When a task requires us to look at a file, a mailbox or a database, we do so to complete the task, and we record the action where the service calls for an audit trail. If a client asks us to do something with that information that would breach the law or our duties, we will say so and ask for a lawful instruction.
At the end of an engagement, client information is returned or deleted according to the terms we have agreed, except where the law requires us to keep a copy. Backup copies held inside a client system are handled under the same client instruction and are removed as the backup cycle turns over.
9. Server Logs and Security Records
When a page is requested, our hosting infrastructure writes a log entry that records the request and the technical details that came with it. These logs help us detect attacks, troubleshoot faults and understand how the site is used. The entries are kept for a limited period and are then discarded as part of our routine housekeeping.
We may keep security records for longer where they are needed to investigate an incident, to support a legal claim, or to demonstrate that we acted properly. Access to these records is restricted to the bench staff who need them, and we treat them as confidential.
11. Service Providers and Subcontractors
Like most small firms we rely on a handful of specialist providers. These include the company that hosts this website, the provider that carries our business email, the bank and payment services that settle invoices, and the accounting software that keeps our books. Each provider is chosen with care, and we review their security and privacy commitments before we rely on them.
Where a provider processes personal information on our behalf, we put a written agreement in place that requires confidentiality, appropriate security, and limits on onward use. We remain responsible for the information we share with them. If a provider cannot meet our expectations, we look for another provider or we bring the task back in house.
12. International Transfers
Our bench is in Hong Kong, and much of the information we handle stays in Hong Kong. Some service providers operate infrastructure in other regions, so information may be transferred to, stored in, or accessed from a location outside Hong Kong. Where that happens, we take reasonable steps to ensure the information receives a comparable level of protection, for example by using providers that offer standard contractual safeguards or that process information under a framework the law recognizes.
When we send information across a border, we send only what the task requires. We keep a note of the providers that receive personal information so we can answer your questions about where your information goes.
13. How Long We Keep Information
We keep personal information only for as long as it is needed for the purpose we collected it, for as long as the law requires, or for as long as a legitimate business need continues. Support tickets are kept long enough to resolve the issue and to spot patterns across the service. Billing records are kept for the period required by tax and accounting rules. Website logs are kept for a short period and then discarded.
When the retention period ends, we delete the information or render it non identifying. Where information sits inside a client system, the client decides the retention period, and we follow that decision. If you ask us to delete information that we hold as a controller, we will do so where the law allows, and we will tell you where a legal duty requires us to keep a copy.
14. How We Protect Information
Security is the craft we sell, so we apply it to our own bench first. We restrict access to personal information to the staff who need it for a specific task. We use strong authentication, we keep systems patched, and we separate our own records from client systems. We take encrypted backups and we test that they restore. Our office and our servers sit behind controlled access, and our equipment is protected against theft and loss.
We train the bench on the plain habits that prevent most incidents: checking before clicking, locking a screen, using unique passwords, and reporting anything unusual at once. We write down what happened when an incident occurs, we learn from it, and we change our routine where the incident shows a gap. No safeguard is perfect, but we treat the protection of personal information as a daily discipline rather than a one time task.
If you ever suspect that your information has been mishandled, contact us at hello@otratech.buzz or call +15044297775 so we can investigate quickly.
15. Your Rights and Choices
Subject to the law in your region, you may have the right to ask whether we hold personal information about you, to ask for a copy of that information, to ask us to correct anything that is wrong, and to ask us to delete information that we no longer need. You may also have the right to object to certain processing, to ask us to restrict what we do with your information, or to ask for a portable copy in a common format.
To make a request, write to hello@otratech.buzz or send a letter to OTRA TECHNOLOGY, Rm 650 HENG ON EST HENG KONG HSE, Sha Tin, Hong Kong (HK). Please describe what you want and give us enough detail to find the right records. We will respond within the time the law allows, and we may ask you to prove your identity so we do not release information to the wrong person. If we cannot meet a request, we will explain why. If you are not satisfied with our reply, you may complain to the data protection authority that covers your region.
16. Privacy for Children
Our services are aimed at offices, businesses and professional teams, and our website is not directed at children. We do not knowingly collect personal information from a child. If you believe that a child has sent us personal information, please contact us and we will remove it promptly once we are able to confirm the situation. Where a client system happens to contain information about a minor, that information is handled under the client instruction and the client is responsible for the lawful basis on which it is held.
17. Direct Marketing and Notices
We send service messages when we need to, for example to confirm a scheduled visit, to warn about a fault, or to tell you about a change that affects an engagement. These messages are part of the service and are not marketing. Where we would like to send you news about our services, we will do so only where the law permits and, where required, only with your agreement.
You can stop marketing messages at any time by using the unsubscribe option in the message or by writing to hello@otratech.buzz. We will honour the request quickly. Stopping marketing does not affect the service messages that keep an engagement running, unless you also end the engagement.
18. Third Party Sites and Links
Our website may link to resources operated by other organizations. Those organizations have their own privacy practices, and we are not responsible for them. We encourage you to read the privacy notice of any site you visit. A link from our site does not mean that we endorse the way another organization handles personal information.
Where we embed a tool from another provider, we keep the embed to the minimum needed and we prefer tools that respect privacy. If an embedded tool changes its practices in a way that concerns us, we remove the embed rather than keep an unknown risk on our own pages.
19. Data Breach Response
If we become aware of a breach that risks the personal information we hold, we act at once. The bench contains the breach, determines what happened and what information was affected, and assesses the risk to the people concerned. Where the law requires notification, we tell the affected individuals and the relevant authority without undue delay, and we explain in plain language what happened and what we are doing about it.
After the immediate response, we write a short internal report so the same fault cannot repeat. We fix the cause, we strengthen the routine that should have caught it, and we tell clients on a watch plan what changed. We would rather report an incident honestly than hide one, because trust at the bench is built on plain speaking.
20. Changes to This Policy
We may update this policy from time to time to reflect a change in the law, a change in our services, or a lesson learned at the bench. When we make a material change, we will update the date at the top of the page and, where the change is significant, we will make the notice prominent on the site or tell clients directly. We encourage you to review this page when you return to the site so you always know how we handle personal information.
21. How to Contact Us
If you have a question about this policy, a worry about your information, or a request to exercise a right, the bench is easy to reach. Write to hello@otratech.buzz, telephone +15044297775, or send a letter to OTRA TECHNOLOGY, Rm 650 HENG ON EST HENG KONG HSE, Sha Tin, Hong Kong (HK). We read every message and we will answer with a name and a clear next step.
If you are already a client, the fastest route is to raise a ticket with the helpdesk queue, because that puts your question in front of the technician who knows your systems. If the matter is a formal privacy request, please mark it clearly so it reaches the right hands without delay.