Privacy Policy for Oli Digital Limited

Last Updated: March 2026

This Privacy Policy describes how Oli Digital Limited ("Oli Digital", "we", "us", or "our") collects, uses, processes, and protects your personal data when you visit our website at www.oli-digital.com, use our STAR Platform (the “Platform”), or otherwise interact with us.

At Oli Digital Limited, we are committed to protecting your privacy and handling your personal data in an open and transparent manner. We adhere to the principles of the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong ("PDPO"), the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) (“AMLO”), and the ethical guideline issued by the PCPD regarding the use of Artificial Intelligence.

1. Important Information and Who We Are

To ensure clarity in our data processing activities, we operate in two capacities:

  • As a Data User (Controller): We collect and manage the personal data of our prospective clients, Licensee representatives, and website visitors for our own business purposes (e.g., account management, billing, and marketing).

  • As a Data Processor: Through the STAR Platform, we process data uploaded by our Licensees (e.g., accounting firms, legal firms) to perform name screening against global watchlists. In this capacity, our Licensees are the Data Users, and we process data strictly according to their instructions and our Licensing Agreement.

2. The Data We Collect About You

Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store, and transfer different kinds of data about you which we have grouped together as follows:

  • Identity Data: includes first name, last name, username or similar identifier, marital status, title, date of birth, gender, Identity Card number or other identification document details.

  • Contact Data: includes address, email address, and telephone numbers.

  • Financial & Transaction Data: includes bank account details for licensing fee payments, and details of products or services acquired from us, or through our facilitation.

  • Technical Data: includes internet protocol (IP) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this website.

  • Usage Data: includes information about how you use our website, products, and services, including interaction logs within the STAR Platform.

  • Marketing and Communications Data: includes your preferences in receiving marketing from us and our third parties, and your communication preferences.

  • Compliance Data: includes information necessary for us to fulfill our legal obligations and assist Licensees in theirs, particularly those related to AML/CFT laws (e.g., Know Your Customer (KYC) information, screening results, and audit logs).

  • AI-Generated Insights: Risk scores and "fuzzy match" strength indicators generated by our proprietary algorithms during the screening process.

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this Privacy Policy.

We do not collect any Special Categories of Personal Data (race, religion, etc.) unless required for your screening purposes (e.g., data from official sanctions and PEP lists), in which case it will be handled with the highest level of security and in accordance with legal requirements as a Data Processor.

3. Artificial Intelligence and Automated Processing

The STAR Platform may utilize Artificial Intelligence (AI) and machine learning to enhance the accuracy of our screening services.

  • How We Use AI: We may employ algorithms for "Fuzzy Matching" to identify potential matches despite variations in spelling, transliteration, or naming conventions across languages, and to assist in False Positive Reduction. AI may also be used to provide a "confidence score" regarding the likelihood of a data match.

  • Human-in-the-Loop: The STAR Platform is a technological tool designed to assist professional judgment. Our AI (if used) does not make final, legally binding decisions regarding the onboarding or rejection of clients. All "Screening Results" provided by the platform require human review and validation by the Licensee.

  • AI Ethics: We may use anonymized or aggregated usage data to improve our AI models. We do not use identifiable "Licensee Data" to train global AI models in a way that would allow the reconstruction of sensitive client information.

4. Licensee Responsibilities and Warranties

When a Licensee (our client) uses the STAR Platform to process personal data of their own customers or counterparties, the Licensee acknowledges the following:

  • Duty of Notification: Under the PDPO, the Licensee is responsible for ensuring that their own customers (the Data Subjects) are properly informed through a Personal Information Collection Statement (PICS) or Privacy Policy that their data may be shared with third-party service providers (such as Oli Digital) for the purposes of AML/CTF screening and regulatory compliance.

  • Legal Basis for Processing: The Licensee warrants that they have a valid legal basis (such as legal obligation or explicit consent) to collect, process, and transfer the data to the Platform.

  • Data Accuracy: The Licensee is responsible for the accuracy of the data they input. Oli Digital acts as a neutral processor and does not verify the original source or accuracy of the data provided by the Licensee.

5. How is Your Personal Data Collected?

We use different methods to collect data from and about you, including through:

  • Direct interactions: You may give us your Identity, Contact, Financial, Transaction, and Compliance Data by filling in forms or by corresponding with us by visit, post, phone, email, instant messengers or otherwise. This includes personal data you provide when you:

    • Apply for our services;

    • Create an account;

    • Engage/interact with us for services;

    • Subscribe to our publications;

    • Request marketing to be sent to you;

    • Give us feedback or contact us.

  • Automated technologies or interactions: As you interact with our website/portal, we may automatically collect Technical and Usage Data about your equipment, browsing actions, and patterns. We collect this personal data by using cookies, server logs, and other similar technologies.

  • Third parties or publicly available sources: We may receive personal data about you from various third parties and public sources, including analytics providers (e.g., Google Analytics), data brokers, and global risk intelligence providers or publicly accessible registers (e.g., UN, OFAC, HK Gazette) to facilitate our screening engines or for AML/CFT purposes.

6. How We Use Your Personal Data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data where we need to perform the contract we are about to enter into or have entered into with you, where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests, where we need to comply with a legal or regulatory obligation, or where you have given your explicit consent.

We process your personal data primarily to fulfill our contractual obligations, which includes registering you as a new client and ensuring the seamless delivery of the STAR Platform's screening and monitoring services. Beyond basic service provision, we use collected data to support our legitimate interests in refining our products and enhancing our AI algorithms, thereby providing more accurate risk intelligence to our users. This includes analyzing usage patterns to optimize platform performance and develop sophisticated tools that meet the evolving needs of the professional services sector in Hong Kong.

Furthermore, we utilize personal data to ensure full compliance with our legal and regulatory duties, particularly when responding to lawful requests from Hong Kong authorities. A critical component of our platform is the "Reporting" pillar, where we process data to generate the necessary timestamped audit trails and comprehensive reports that professional firms require for their internal compliance and regulatory inspections. By processing this data, we enable our Licensees to maintain a defensible and transparent compliance program in alignment with the AMLO.

7. Disclosures of Your Personal Data

We may share your personal data with the parties set out below for the purposes stated in Section 6 above:

  • Internal Third Parties: Other companies within the Oli Digital Limited group.

  • Google Cloud Infrastructure: The STAR Platform is hosted on Google Cloud’s world-class infrastructure. We leverage Google’s advanced security protocols, encrypted storage, and global redundancy to ensure your data is protected by multi-layered defense-in-depth systems.

  • External Third Parties:

    • Service providers acting as processors who provide IT and system administration services, identity verification, and data analytics services.

    • Professional advisers including lawyers, bankers and auditors who provide consultancy, banking, legal, and accounting services.

    • Regulators and other authorities when legally required.

  • Business Transfers: Third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this Privacy Policy.

8. Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

9. Data Retention

We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process your personal data, and applicable legal requirements. While our Licensees may have specific statutory retention periods (such as 5 years under the AMLO), Oli Digital retains Licensee Data for the duration of the active subscription period or as otherwise specified in the Licensing Agreement. Following the termination of services, data will be securely deleted or anonymized in accordance with our internal data destruction policies.

10. Your Legal Rights

As a data user under the PDPO, we are committed to upholding the personal data privacy rights of individuals. Your key rights concerning the personal data we hold about you include:

  • Right to Access: Request access to the personal data we hold about you.

  • Right to Correction: Request the correction of any inaccurate or incomplete personal data.

  • Right to Object to Processing: Object to processing for direct marketing purposes.

  • Right to Restriction of Processing: Request temporary suspension of processing while data accuracy is being verified.

  • Right to Erasure (Right to be Forgotten): Request the deletion or removal of your personal data where there is no legitimate reason for us to continue processing it, subject to our legal and regulatory obligations.

  • Right to Data Portability: Request a transfer of your data in a structured, machine-readable format.

  • Right to Withdraw Consent: Withdraw your consent at any time where we are relying on consent to process your personal data. Note that this will not affect the lawfulness of processing conducted before such withdrawal.

The exercise of these rights is subject to certain legal conditions, exemptions, and our operational requirements under the PDPO. We may need to request specific information from you to confirm your identity and ensure your right to exercise these rights. We will endeavor to respond to all legitimate requests within the timeframes prescribed by law. Please note that fulfilling certain requests may impact our ability to provide services to you, and we will advise you if this is the case.

To exercise these rights, please contact us at info@oli-digital.com.

11. Cookies and Third-Party Links

Our website uses cookies to distinguish you from other users. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site.

This website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements.

12. Changes to This Privacy Policy

We keep our Privacy Policy under regular review to reflect changes in the STAR Platform or Hong Kong Law. Any changes we may make to our Privacy Policy in the future will be posted on this page. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data.