Privacy Policy
Last updated: 5 October 2026
This Privacy Policy explains how JP.Milton Limited (“JP.Milton”, “we”, “us” or “our”) collects, uses and protects personal data. It covers data collected through this website and in our business relationships, and it explains the rights you have over that data. It is our Privacy Policy Statement under the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (the “PDPO”). Where they apply, it is also our privacy notice under the EU General Data Protection Regulation (the “EU GDPR”) and under the UK General Data Protection Regulation read with the Data Protection Act 2018 (the “UK GDPR”).
1. Who we are and how to contact us
For the personal data described in this policy, JP.Milton Limited is the data user under the PDPO and the controller under the EU GDPR and the UK GDPR.
- Company: JP.Milton Limited, a private company limited by shares incorporated in Hong Kong (Company No. 80980535; Business Registration Certificate No. 80980535-000-08-26-1)
- Registered office: Suite C, Level 7, World Trust Tower, 50 Stanley Street, Central, Hong Kong
- Privacy requests: by email to admin@jpmilton.com with “Privacy request” in the subject line, through the contact form on this website (subject “Privacy request”), or by post to our registered office, addressed to the Data Privacy Contact
We have not appointed a data protection officer under Article 37 of the EU GDPR or the UK GDPR, because the processing described in this policy does not require one. Our Data Privacy Contact handles all questions and requests about personal data.
2. What this policy covers
This policy applies to personal data about:
- visitors to this website;
- people who contact us by email, through the contact form or by post; and
- the representatives of our suppliers, sourcing agent, logistics partners, service providers, banks and payment providers, and the creators and affiliates who work with our brands.
It does not apply to purchases made on our brand stores. Each store publishes its own privacy notice, which explains how order, payment, delivery, customer-service and marketing data are handled. Please read it before buying. This policy does not apply to third-party websites linked from this website either.
3. Personal Information Collection Statement (contact form)
We give this statement under Data Protection Principle 1 of the PDPO and Article 13 of the EU GDPR and the UK GDPR, at the point where you send us an enquiry.
- Data collected: your name, email address, organisation, the subject of your enquiry and your message.
- Purpose: to read and answer your enquiry and to keep a record of our exchange. If your enquiry concerns a business relationship, we also use the data to assess and manage that relationship.
- Obligatory or voluntary: your name, email address and message are obligatory; without them we cannot reply to you. The other fields are voluntary.
- Classes of transferees: our website host and form provider (Netlify, Inc., United States); our email and IT service providers; our professional advisers where your enquiry requires it; and courts, regulators and law-enforcement authorities where the law requires it.
- Direct marketing: we will not use your personal data for direct marketing.
- Access and correction: you may ask for access to, or correction of, your personal data by writing to the Data Privacy Contact at admin@jpmilton.com, through the contact form or at our registered office.
4. Personal data we process
| Category | Examples | Source |
|---|---|---|
| Contact details | Name, email address, telephone number, organisation, job title | You or your organisation |
| Correspondence | The content of your messages and any attachments | You |
| Business relationship data | Business contact details of partner representatives. For creators, affiliates and sole traders, the payment details and identity or tax information we need to pay them and to meet our legal obligations | You or your organisation |
| Verification data | Results of checks on business partners and their representatives against public company registers and sanctions lists | Public sources |
| Technical data | IP address, browser type, pages requested, and the date and time of each request, recorded in server logs | Our website host |
We do not ask for sensitive personal data, such as information about health, religious beliefs or political opinions, and we do not ask for payment card details. Please do not send them to us. We collect an individual's bank details only where we need to pay that person, for example as a creator or affiliate.
5. Purposes and legal bases
Under the PDPO, we use personal data only for the purposes for which it was collected or for a directly related purpose. We will not use it for a new purpose unless you give your express and voluntary consent.
For individuals in the European Economic Area and the United Kingdom, we rely on the following legal bases:
| Purpose | Legal basis (EU GDPR / UK GDPR) |
|---|---|
| Answering your enquiry | Our legitimate interest in responding to people who contact us (Art. 6(1)(f)), or steps taken at your request before entering into a contract (Art. 6(1)(b)) |
| Setting up and managing relationships with suppliers, logistics partners, creators, affiliates and service providers; placing orders; making and receiving payments | Performance of a contract with you (Art. 6(1)(b)). Where the contract is with your organisation, our legitimate interest in managing our business relationships (Art. 6(1)(f)) |
| Verifying the identity of business partners, screening them against sanctions lists and preventing fraud | A legal obligation under EU or UK law where one applies (Art. 6(1)(c)). Otherwise, our legitimate interest in complying with the laws that apply to us, including Hong Kong law, and in preventing fraud (Art. 6(1)(f)) |
| Keeping accounting and business records | Our legitimate interest in complying with the record-keeping obligations of Hong Kong law, including the Companies Ordinance (Cap. 622) and the Inland Revenue Ordinance (Cap. 112) (Art. 6(1)(f)). A legal obligation under EU or UK law where one applies (Art. 6(1)(c)) |
| Operating this website and keeping it secure | Our legitimate interest in providing a website that is available and protected against misuse (Art. 6(1)(f)) |
| Establishing, exercising or defending legal claims, and responding to lawful requests from authorities | Our legitimate interest in protecting our rights and complying with the law (Art. 6(1)(f)). A legal obligation under EU or UK law where one applies (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You may ask us for details of that assessment, and you may object at any time (see section 11). We do not make decisions about you based solely on automated processing, including profiling.
6. Direct marketing
We do not use personal data collected through this website or our business correspondence for direct marketing, and we do not provide it to anyone else for their direct marketing. If we ever wish to do so, we will first obtain your consent, as required by Part 6A of the PDPO. Where they apply, we will also follow the EU GDPR, the UK GDPR and electronic-marketing rules.
7. Who we share personal data with
- Netlify, Inc. (United States), which hosts this website and receives contact-form submissions on our behalf;
- email, office-software and file-storage providers, which store our correspondence and records;
- professional advisers, such as our accountants, auditors, company secretary and lawyers, who are bound by duties of confidentiality;
- banks and payment providers, where this is needed to make or receive a payment or to answer their due-diligence questions about a business relationship;
- business partners, limited to the contact details needed to coordinate a specific order, shipment or collaboration;
- courts, regulators and law-enforcement authorities, where the law requires it or where this is needed to protect our rights; and
- a successor business, if all or part of our business is reorganised or transferred, under protections equivalent to this policy.
Service providers that process personal data for us do so under written terms. These terms require them to act only on our instructions, keep the data secure, and return or delete it when the service ends, in line with Data Protection Principles 2(3) and 4(2) of the PDPO and Article 28 of the EU GDPR and the UK GDPR. We do not sell personal data, and we do not share it for targeted or cross-context behavioural advertising.
8. International transfers
We are based in Hong Kong, and our website host is based in the United States. Other service providers may store data in the European Union or elsewhere. Some personal data protected by the EU GDPR or the UK GDPR may be transferred to a country without an adequacy decision. In that case, we rely on a recognised safeguard: the EU–US Data Privacy Framework and its UK Extension where the recipient is certified, or the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum. You may ask the Data Privacy Contact for a copy of the relevant safeguards.
For every transfer out of Hong Kong, we take all practicable steps, including contractual obligations on our providers, so that your personal data is protected to a standard comparable to that of the PDPO.
9. How long we keep personal data
- Enquiries that do not lead to a business relationship: up to 24 months after our last exchange, then deleted.
- Business records (contracts, orders, invoices, payment records and related correspondence): seven years after the end of the financial year to which they relate, as required by the Companies Ordinance (Cap. 622) and the Inland Revenue Ordinance (Cap. 112), then deleted.
- Partner verification and sanctions-screening records: for the duration of the relationship and seven years after it ends, then deleted.
- Server logs: for the limited period set by our website host for security and operation.
We keep data for longer only where the law requires it or where it is needed to establish, exercise or defend a legal claim.
10. Security
This website is served over an encrypted (HTTPS) connection. Only the people who need access to personal data, and to the accounts we use to run our business, are given it. Our service providers are bound by written security and confidentiality obligations. No method of transmission or storage is completely secure. If a personal data breach occurs, we will contain it and assess the risk. Where the law requires, we will notify the people affected and the competent authorities.
11. Your rights
Under the PDPO, you may ask whether we hold personal data about you, obtain a copy of it (a data access request) and ask us to correct it. We will respond to a data access request within 40 days. We may charge a fee for providing a copy; any fee will not be excessive.
Under the EU GDPR and the UK GDPR, where they apply, you have the following rights:
- to access your personal data and receive a copy of it;
- to have inaccurate data corrected;
- to have your data erased, or its use restricted, in certain circumstances;
- to object to processing based on our legitimate interests;
- to receive the data you gave us in a portable format, where processing is based on a contract or on consent; and
- to withdraw any consent at any time, without affecting processing carried out before the withdrawal.
We will reply within one month. For complex requests, this may be extended by two further months, in which case we will tell you why. These requests are free of charge unless they are manifestly unfounded or excessive.
Residents of the United States may have rights under the law of their state, such as the right to know about, access, correct or delete personal information. We will honour such requests for personal data collected through this website.
To exercise any of these rights, write to the Data Privacy Contact at admin@jpmilton.com, through the contact form or at our registered office. We may ask you to confirm your identity before acting on a request.
12. Complaints
If you have a concern about how we handle your personal data, please contact us first. We will acknowledge your complaint within 30 days and respond to it without undue delay.
You may also complain to a supervisory authority:
- Hong Kong: the Office of the Privacy Commissioner for Personal Data (www.pcpd.org.hk);
- European Union: the data protection authority of the member state where you live or work, or where the alleged infringement took place;
- United Kingdom: the Information Commissioner's Office (ico.org.uk).
13. Representatives in the European Union and the United Kingdom
This website presents the company and does not offer goods or services. Where JP.Milton's brand stores process the personal data of customers in the European Union or the United Kingdom, Article 27 of the EU GDPR and of the UK GDPR requires it to designate a representative there. JP.Milton is appointing these representatives, and their names and contact details will be published in this section and in the privacy notice of each store concerned.
14. Cookies and similar technologies
This website does not use analytics, advertising or social-media cookies, tracking pixels or similar technologies, and it loads no third-party tracking scripts. Its fonts are served from our own hosting, so your browser does not contact a third-party font service. The website relies only on the technical means strictly necessary to deliver the pages you request and to protect the contact form against spam. For this reason, it does not display a cookie consent banner. If we decide to introduce analytics or any other non-essential technology, we will update this policy and ask for your consent before activating it.
15. Do Not Track and information for California residents
We do not track visitors over time or across third-party websites, and we do not allow third parties to do so through this website. The website therefore works in the same way whether or not your browser sends a “Do Not Track” or Global Privacy Control signal.
The California Online Privacy Protection Act asks us to state the following:
- the categories of personal information we collect are described in section 4;
- the categories of third parties with whom we may share it are listed in section 7;
- you can review and request changes to your personal information as described in section 11; and
- changes to this policy are notified as described in section 17.
We do not sell or share personal information, as those terms are defined under California law.
16. Children
This website is intended for businesses and adults. It is not directed at children, and we do not knowingly collect personal data from anyone under the age of 16.
17. Changes to this policy
We may update this policy to reflect changes in our activity or in the law. The date at the top of this page shows the latest version. If a change is material, we will also display a notice on this website for at least 30 days.
18. Language
This policy is written in English. If it is translated, the English version prevails to the extent permitted by law.
19. Contact
You can reach the Data Privacy Contact by email at admin@jpmilton.com, through the contact form on this website, or by post at JP.Milton Limited, Suite C, Level 7, World Trust Tower, 50 Stanley Street, Central, Hong Kong.