Terms of Use

Privacy Policy

Effective Date: 5 Jun 2026

Vantis (“we,” “us,” or “our”) is committed to protecting the privacy, confidentiality, and security of the personal data we hold. We strictly comply with the requirements of the Personal Data (Privacy) Ordinance (Cap. 486) of the Laws of Hong Kong (“PDPO”).

This Privacy Policy explains how we collect, hold, process, use, and transfer personal data across our digital platforms, including our website (https://www.vantissol.com), mobile applications, and during the implementation, maintenance, and support of our corporate solutions (such as Enterprise Resource Planning (ERP), Human Resources (HR), and other business applications).

1. Scope of This Policy

This policy applies to all personal data collected or handled by Vantis in two distinct operational capacities:

  • Our Public Digital Platforms: Data collected from visitors to our websites, individuals inquiring about our services, and users of our public-facing mobile applications.
  • Our Enterprise Solution Implementations: Data processed during the evaluation, data migration, configuration, customization, system training, maintenance, and technical support of ERP, HR systems, and other solutions provided to our corporate clients.

2. Our Legal Capacity: Data User vs. Data Processor

Under the PDPO, our legal responsibilities depend on our relationship with the data:

  • Vantis as a Data User: When you browse our website, download our marketing applications, submit sales inquiries, or request product demos, Vantis controls the collection and use of that data. We act as the “Data User” and are directly responsible for ensuring compliance with the PDPO.
  • Vantis as a Data Processor: When we implement, host, or provide technical support for an ERP or HR solution on behalf of your organization, our corporate client is the Data User, and Vantis acts strictly as a Data Processor. In these instances, we process employee, financial, or operational data solely on behalf of our client, according to the terms of our service contracts, service level agreements (SLAs), and non-disclosure agreements (NDAs).

3. Categories of Personal Data We Collect

We only collect personal data that is necessary for, or directly related to, our legitimate business functionalities and services.

A. From Public Websites and Mobile Apps

  • Identity & Contact Information: Name, job title, company name, corporate email address, business telephone number, and communication preferences when you complete online contact forms or request information.
  • Technical & Usage Information: IP addresses, device identifiers, operating system types, browser characteristics, app utilization data, and interactions with our digital platforms.
  • Cookies: We use cookies to improve website functionality and track traffic patterns. You can choose to disable cookies via your browser settings, though some website features may become unavailable.

B. From Enterprise Solution Implementations (ERP, HR, and Others)

When deploying and servicing enterprise software, we may have access to data sets managed by our clients. This data is handled strictly within our scope as a Data Processor:

  • Migration & System Setup Data: Client-provided records used for system testing, data cleansing, and migration (e.g., historical accounting files, supplier registries, inventory logs).
  • HR & Payroll Parameters: Employee master lists, attendance logs, and compensation structures necessary to build and validate payroll and HR calculation rules.
  • Support & Maintenance Logs: Temporary database backups, system event logs, screen shares, or diagnostic profiles securely accessed by our technical support engineers during system troubleshooting or upgrades.

4. Purpose of Using Personal Data

We use the collected personal data for the following purposes:

  • Service Provision: To configure, deploy, maintain, troubleshoot, and optimize our ERP, HR, website, and mobile application environments.
  • Customer Support & Communication: To respond to your requests, provide software training, send critical system updates, and manage customer accounts.
  • Security & System Integrity: To monitor our environments, detect unauthorized system access, prevent data breaches, and defend against malicious cyber activities.
  • Legal & Regulatory Compliance: To fulfill statutory obligations, prevent fraud, and comply with legal requirements applicable in Hong Kong.

5. Direct Marketing

Vantis intends to use your name, company name, email address, and phone number to send you marketing materials regarding our enterprise software solutions, product updates, webinars, and corporate events.

  • Your Consent Matters: We will not use your personal data for direct marketing purposes unless we have received your explicit, free consent.
  • Opt-Out Right: You may opt out of receiving direct marketing communications from us at any time, free of charge, by clicking the “unsubscribe” link in our emails or by contacting us at inquiry@vantissol.com.

6. Disclosure and Transfer of Personal Data

We keep all personal data confidential. We do not sell, rent, or trade personal data to third parties. We will only disclose or transfer personal data to third parties under the following circumstances:

  • Authorized Data Processors: To trusted third-party service providers (such as secure cloud hosting companies, data centers, or technical partners) who assist us in operating our business and maintaining our solutions. These providers are bound by strict contractual obligations to ensure data security and prevent unauthorized use or retention.
  • Legal Requirements: When required by law, court order, or requested by statutory bodies or law enforcement agencies in Hong Kong.

7. Data Security and Retention

  • Security Safeguards: In compliance with Data Protection Principle 4 of the PDPO, we employ rigorous physical, electronic, and managerial security measures to protect personal data against unauthorized or accidental access, processing, erasure, loss, or use. This includes data encryption, firewall protections, strict access controls, and secure data handling protocols for our staff.
  • Retention Period: We will not keep personal data longer than is necessary to fulfill the purpose for which it was collected, or to satisfy legal, accounting, or regulatory requirements. Data processed on behalf of corporate clients in our ERP/HR systems is retained or deleted strictly according to the client’s contractual instructions.

8. Data Access and Correction Requests

Under the PDPO, you have the right to check whether Vantis holds your personal data, request a copy of that data, and request the correction of any inaccurate records.

  • How to Submit a Request: Data access or correction requests should be made in writing and sent to our team at inquiry@vantissol.com.
  • Administrative Fee: As permitted by Section 28 of the PDPO, we may charge a reasonable fee for processing data access requests to cover administrative costs.

Note: If your personal data was collected and uploaded into an ERP or HR system by your employer, Vantis acts as a Data Processor. In such cases, please submit your data access or correction requests directly to your employer’s internal system administrator.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect modifications in our software solutions, business operations, or legal updates under the PDPO. The revised policy will be posted on our website with an updated effective date.

Contact Us: For any questions, concerns, or data access requests regarding this policy, please contact our team at: Email: inquiry@vantissol.com