← Back to home

Privacy Policy

Last updated: 5 October 2026

This Privacy Policy explains how JP.Milton Limited (“JP.Milton”, “we”, “us” or “our”) collects, uses and protects personal data. It covers data collected through this website and in our business relationships, and it explains the rights you have over that data. It is our Privacy Policy Statement under the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (the “PDPO”). Where they apply, it is also our privacy notice under the EU General Data Protection Regulation (the “EU GDPR”) and under the UK General Data Protection Regulation read with the Data Protection Act 2018 (the “UK GDPR”).

1. Who we are and how to contact us

For the personal data described in this policy, JP.Milton Limited is the data user under the PDPO and the controller under the EU GDPR and the UK GDPR.

We have not appointed a data protection officer under Article 37 of the EU GDPR or the UK GDPR, because the processing described in this policy does not require one. Our Data Privacy Contact handles all questions and requests about personal data.

2. What this policy covers

This policy applies to personal data about:

It does not apply to purchases made on our brand stores. Each store publishes its own privacy notice, which explains how order, payment, delivery, customer-service and marketing data are handled. Please read it before buying. This policy does not apply to third-party websites linked from this website either.

3. Personal Information Collection Statement (contact form)

We give this statement under Data Protection Principle 1 of the PDPO and Article 13 of the EU GDPR and the UK GDPR, at the point where you send us an enquiry.

4. Personal data we process

CategoryExamplesSource
Contact detailsName, email address, telephone number, organisation, job titleYou or your organisation
CorrespondenceThe content of your messages and any attachmentsYou
Business relationship dataBusiness contact details of partner representatives. For creators, affiliates and sole traders, the payment details and identity or tax information we need to pay them and to meet our legal obligationsYou or your organisation
Verification dataResults of checks on business partners and their representatives against public company registers and sanctions listsPublic sources
Technical dataIP address, browser type, pages requested, and the date and time of each request, recorded in server logsOur website host

We do not ask for sensitive personal data, such as information about health, religious beliefs or political opinions, and we do not ask for payment card details. Please do not send them to us. We collect an individual's bank details only where we need to pay that person, for example as a creator or affiliate.

5. Purposes and legal bases

Under the PDPO, we use personal data only for the purposes for which it was collected or for a directly related purpose. We will not use it for a new purpose unless you give your express and voluntary consent.

For individuals in the European Economic Area and the United Kingdom, we rely on the following legal bases:

PurposeLegal basis (EU GDPR / UK GDPR)
Answering your enquiryOur legitimate interest in responding to people who contact us (Art. 6(1)(f)), or steps taken at your request before entering into a contract (Art. 6(1)(b))
Setting up and managing relationships with suppliers, logistics partners, creators, affiliates and service providers; placing orders; making and receiving paymentsPerformance of a contract with you (Art. 6(1)(b)). Where the contract is with your organisation, our legitimate interest in managing our business relationships (Art. 6(1)(f))
Verifying the identity of business partners, screening them against sanctions lists and preventing fraudA legal obligation under EU or UK law where one applies (Art. 6(1)(c)). Otherwise, our legitimate interest in complying with the laws that apply to us, including Hong Kong law, and in preventing fraud (Art. 6(1)(f))
Keeping accounting and business recordsOur legitimate interest in complying with the record-keeping obligations of Hong Kong law, including the Companies Ordinance (Cap. 622) and the Inland Revenue Ordinance (Cap. 112) (Art. 6(1)(f)). A legal obligation under EU or UK law where one applies (Art. 6(1)(c))
Operating this website and keeping it secureOur legitimate interest in providing a website that is available and protected against misuse (Art. 6(1)(f))
Establishing, exercising or defending legal claims, and responding to lawful requests from authoritiesOur legitimate interest in protecting our rights and complying with the law (Art. 6(1)(f)). A legal obligation under EU or UK law where one applies (Art. 6(1)(c))

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You may ask us for details of that assessment, and you may object at any time (see section 11). We do not make decisions about you based solely on automated processing, including profiling.

6. Direct marketing

We do not use personal data collected through this website or our business correspondence for direct marketing, and we do not provide it to anyone else for their direct marketing. If we ever wish to do so, we will first obtain your consent, as required by Part 6A of the PDPO. Where they apply, we will also follow the EU GDPR, the UK GDPR and electronic-marketing rules.

7. Who we share personal data with

Service providers that process personal data for us do so under written terms. These terms require them to act only on our instructions, keep the data secure, and return or delete it when the service ends, in line with Data Protection Principles 2(3) and 4(2) of the PDPO and Article 28 of the EU GDPR and the UK GDPR. We do not sell personal data, and we do not share it for targeted or cross-context behavioural advertising.

8. International transfers

We are based in Hong Kong, and our website host is based in the United States. Other service providers may store data in the European Union or elsewhere. Some personal data protected by the EU GDPR or the UK GDPR may be transferred to a country without an adequacy decision. In that case, we rely on a recognised safeguard: the EU–US Data Privacy Framework and its UK Extension where the recipient is certified, or the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum. You may ask the Data Privacy Contact for a copy of the relevant safeguards.

For every transfer out of Hong Kong, we take all practicable steps, including contractual obligations on our providers, so that your personal data is protected to a standard comparable to that of the PDPO.

9. How long we keep personal data

We keep data for longer only where the law requires it or where it is needed to establish, exercise or defend a legal claim.

10. Security

This website is served over an encrypted (HTTPS) connection. Only the people who need access to personal data, and to the accounts we use to run our business, are given it. Our service providers are bound by written security and confidentiality obligations. No method of transmission or storage is completely secure. If a personal data breach occurs, we will contain it and assess the risk. Where the law requires, we will notify the people affected and the competent authorities.

11. Your rights

Under the PDPO, you may ask whether we hold personal data about you, obtain a copy of it (a data access request) and ask us to correct it. We will respond to a data access request within 40 days. We may charge a fee for providing a copy; any fee will not be excessive.

Under the EU GDPR and the UK GDPR, where they apply, you have the following rights:

We will reply within one month. For complex requests, this may be extended by two further months, in which case we will tell you why. These requests are free of charge unless they are manifestly unfounded or excessive.

Residents of the United States may have rights under the law of their state, such as the right to know about, access, correct or delete personal information. We will honour such requests for personal data collected through this website.

To exercise any of these rights, write to the Data Privacy Contact at admin@jpmilton.com, through the contact form or at our registered office. We may ask you to confirm your identity before acting on a request.

12. Complaints

If you have a concern about how we handle your personal data, please contact us first. We will acknowledge your complaint within 30 days and respond to it without undue delay.

You may also complain to a supervisory authority:

13. Representatives in the European Union and the United Kingdom

This website presents the company and does not offer goods or services. Where JP.Milton's brand stores process the personal data of customers in the European Union or the United Kingdom, Article 27 of the EU GDPR and of the UK GDPR requires it to designate a representative there. JP.Milton is appointing these representatives, and their names and contact details will be published in this section and in the privacy notice of each store concerned.

14. Cookies and similar technologies

This website does not use analytics, advertising or social-media cookies, tracking pixels or similar technologies, and it loads no third-party tracking scripts. Its fonts are served from our own hosting, so your browser does not contact a third-party font service. The website relies only on the technical means strictly necessary to deliver the pages you request and to protect the contact form against spam. For this reason, it does not display a cookie consent banner. If we decide to introduce analytics or any other non-essential technology, we will update this policy and ask for your consent before activating it.

15. Do Not Track and information for California residents

We do not track visitors over time or across third-party websites, and we do not allow third parties to do so through this website. The website therefore works in the same way whether or not your browser sends a “Do Not Track” or Global Privacy Control signal.

The California Online Privacy Protection Act asks us to state the following:

We do not sell or share personal information, as those terms are defined under California law.

16. Children

This website is intended for businesses and adults. It is not directed at children, and we do not knowingly collect personal data from anyone under the age of 16.

17. Changes to this policy

We may update this policy to reflect changes in our activity or in the law. The date at the top of this page shows the latest version. If a change is material, we will also display a notice on this website for at least 30 days.

18. Language

This policy is written in English. If it is translated, the English version prevails to the extent permitted by law.

19. Contact

You can reach the Data Privacy Contact by email at admin@jpmilton.com, through the contact form on this website, or by post at JP.Milton Limited, Suite C, Level 7, World Trust Tower, 50 Stanley Street, Central, Hong Kong.