CloudsEscort Hong Kong escort directory Back to directory

Personal data should be limited to a defined directory purpose

The directory may receive technical data, profile material, reviews, reports and correspondence. It should collect only what is relevant, use it for stated purposes, protect it and avoid keeping it longer than necessary.

This policy covers personal data handled for the Directory

It applies when CloudsEscort receives personal data through browsing, profile publication, reviews, reports, correction/removal requests or direct correspondence. Personal data means information relating to a living individual who can be identified from it, alone or with other practicably accessible data.

The party determining why and how Directory data is handled is referred to here as the “Directory Operator”. Approved operator particulars and an active privacy contact remain required before production release. Where Hong Kong's Personal Data (Privacy) Ordinance (PDPO) applies, that party acts as the relevant data user.

The data depends on how a person uses the site

Data categories and typical sources
Category Examples Source
Technical requests IP address, time, requested URL, browser/device and security logs Browser, server and security infrastructure
Browser preferences Age choice, favourites and interface/session preferences Cookies or local browser storage
Profile material Nickname, media, declared facts, contacts and review evidence Advertiser or authorised submitter
Reviews and reports Ratings, review text, URLs, concern details and moderation signals Reviewer, reporter or affected person
Correspondence Email address, message content, evidence and response history Person contacting the Directory

Do not send identity documents, banking credentials, intimate evidence or unrelated third-party data unless a specific, proportionate request explains why it is needed.

Personal data should serve a defined and disclosed purpose

  • Deliver pages, remember requested browser state and maintain security.
  • Assess, publish, maintain or remove directory profiles and reviews.
  • Respond to support, privacy, rights, safety and legal requests.
  • Detect spam, manipulation, abuse, unauthorised access and repeat violations.
  • Keep proportionate decision evidence and comply with lawful obligations.
  • Measure technical performance and site use where configured.

Data should not be used for an unrelated new purpose without an appropriate basis and, where required, express and voluntary consent. Direct marketing requires the notices and choices applicable to that use; silence is not treated as consent.

Access should be limited to people and services that need it

Data may be handled by hosting, delivery, security, communications, storage, moderation or professional advisers supporting the Directory. Those providers should receive only what is needed for their role and be subject to appropriate contractual or other safeguards.

Information may also be disclosed where required by law, court order or a valid authority request; to protect a person from serious harm; or to establish, exercise or defend legal rights. An exemption is considered for the specific situation and is not treated as a routine reason to disregard privacy.

Public profile and approved review content is, by purpose, available to website visitors. Publishing a field can also make it discoverable by search engines or copied by third parties outside the Directory's control.

Keep data only while its purpose or a lawful need remains

Retention depends on the data: public material may remain while the relevant profile or review is eligible; correspondence may remain while a request is handled; decision and security records may remain longer where needed to prevent repeat abuse, resolve a dispute or meet a lawful obligation. Data that is no longer needed should be erased or anonymised where practicable.

Practical safeguards should address access control, secure transmission, backups, software updates, least-privilege access and response to unauthorised or accidental access, loss, processing or disclosure. No internet system can promise absolute security.

People can ask what is held and seek correction

  • Request access to personal data about you, subject to applicable requirements and exemptions.
  • Request correction of inaccurate personal data and reasons where a request is refused.
  • Withdraw consent for a consent-based use, without changing earlier lawful handling.
  • Request restriction or erasure where the data is no longer needed or publication lacks authority.
  • Opt out of direct marketing if it is introduced.
  • Clear local browser data or adjust browser cookie/storage settings, understanding that some functions may reset.

A request may require proportionate information to locate the data and establish that it concerns the requester. The removal and correction guide explains how to minimise unnecessary evidence.

Use the privacy channel first when it is active

The Contact page shows whether a privacy channel is active. Include the relevant URL, the data involved and the right or correction requested; do not send an unredacted identity archive without a specific need.

The Office of the Privacy Commissioner for Personal Data explains the PDPO's principles, access/correction rights and complaint process. Contacting the Directory does not remove a person's right to use an applicable regulator or official remedy.

Draft reviewed for internal consistency: 29 July 2026.