Audit Program 4.1
AP4.1 Privacy Policy
This Privacy Policy explains how EQC Advisory Limited handles personal data in connection with Audit Program 4.1 (AP4.1).
1. Scope and Acceptance
This Privacy Policy is issued by EQC Advisory Limited, trading as EQC Compliance Advisory (“EQC”, “we”, “us”, or “our”). It applies to the handling of data entered through Audit Program 4.1 (“AP4.1” or the “Program”) by its users, including CPA Practice Units registered in Hong Kong under the Accounting and Financial Reporting Council (“AFRC”).
By installing, accessing, or using AP4.1, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, you must not install or use AP4.1.
This Policy concerns the Program’s data-handling model. It should be read together with the End-User Licence Agreement, Data Processing Agreement where applicable, and Disclaimer of Liability and Losses.
2. Data Handling in AP4.1
2.1 Local Processing and No Routine EQC Retention
AP4.1 is designed to process data entered by users within the user’s local device or designated network environment. On the local-processing model described in this Policy, EQC does not routinely collect, store, retain, or access audit-client data entered into AP4.1, and that data is not routinely transmitted to or retained on EQC servers or third-party servers on EQC’s behalf.
2.2 User Control
Data entered into AP4.1 remains under the user’s direct control within its local environment. The user remains responsible for deciding what data is entered, stored, backed up, exported, amended, or deleted within that environment.
2.3 No Sale or Routine Disclosure
Because EQC does not routinely collect or retain data entered into AP4.1 under the local-processing model, EQC does not sell that data or routinely disclose it to third parties. Any exception must be supported by law or separately agreed in writing with the user.
2.4 Support and Other Exceptional Access
If a user requests technical support that requires EQC personnel to access a user environment or data, the scope, method, and any handling of personal data should be agreed with the user in advance. Any such access is separate from ordinary local operation of AP4.1 and should be limited to the support purpose requested.
3. PDPO Context and User Responsibilities
EQC recognises the importance of the data-protection principles in Hong Kong’s Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”). Users remain responsible for complying with the PDPO and other applicable data-protection laws when collecting, using, storing, disclosing, or otherwise handling personal data through their audit and professional activities.
- Purpose and notice: Users should ensure that personal data is collected and used for lawful, appropriate purposes and that required notices or authorisations are provided.
- Accuracy and retention: Users should keep information accurate where appropriate and apply their own retention and deletion controls.
- Use and disclosure: Users should not use or disclose personal data beyond authorised purposes.
- Security: Users should apply appropriate device, network, access-management, and backup controls to their own environments.
- Access and correction: Users remain responsible for responding to data-subject requests concerning information held in their own local environments.
Where EQC processes personal data for a user under a separately agreed support, hosted, or other service arrangement, the applicable written data-processing terms should govern that processing.
4. Security and Program Design
4.1 Local Environment Security
AP4.1 is intended to operate within the user’s local environment. The user is responsible for implementing appropriate safeguards for that environment, including access management, endpoint and network security, backup and recovery arrangements, and protection of credentials and devices.
4.2 No Assumption of Internet Transmission
Nothing in this Policy creates an expectation that audit-client data will be transmitted to EQC or an external server as part of ordinary local operation. If a future AP4.1 feature, support arrangement, or service changes this model, EQC should provide an appropriate updated notice and, where relevant, updated contractual data-processing terms before that processing begins.
4.3 Business-Contact Information
EQC may separately receive business-contact information when users contact EQC, request support, purchase or subscribe to services, or otherwise communicate with EQC. The details, purposes, retention periods, and any recipients for such information should be described in a current EQC website or customer-contact privacy notice before publication of an updated version of this Policy.
5. Policy Availability, Requests, and Updates
5.1 Availability
This Privacy Policy is intended to be displayed on EQC’s official website and made available as part of the AP4.1 installation process and, where implemented, within AP4.1 settings or help materials.
5.2 Data-Access and Correction Requests
Questions about EQC’s own handling of personal data, or requests concerning personal data that EQC actually holds, may be directed to the contact details below. A request concerning audit-client data held only in a user’s local AP4.1 environment should be directed to the relevant user or CPA Practice Unit.
5.3 Changes to this Policy
EQC may update this Privacy Policy from time to time. The current version will show its “Last Updated” date. Where a material change affects the way EQC handles personal data, EQC should provide notice in a manner appropriate to the relevant users before or when the updated policy takes effect.
6. Contact, Governing Law, and Acknowledgment
EQC Advisory Limited
Unit 811, 8/F., New Tech Plaza, 34 Tai Yau Street, San Po Kong, Kowloon, Hong Kong
Email: services@eqcadvisory.com
Telephone: +852 9543 3218
This Privacy Policy is governed by and construed in accordance with the laws of the Hong Kong Special Administrative Region. By installing or using AP4.1, the CPA Practice Unit confirms that it has read and understood this Privacy Policy and the related AP4.1 terms.
Publication note: The factual statements in this Policy—particularly the local-processing architecture, support access, business-contact processing, retention, and security controls—should be confirmed by EQC and reviewed by qualified Hong Kong legal counsel before publication.