Cherry Technology SolutionFINANCIAL TECHNOLOGY ENGINEERING
ServicesIdentity verificationCompanyContact

Legal

Privacy Policy

Effective 17 September 2026 · Last updated 17 September 2026

1. Scope and roles2. Data and sources3. Purposes and bases4. Identity verification5. Verification outcomes6. Sharing7. Transfers8. Retention9. Security10. Your rights14. Contact
This Policy explains how Cherry Technology Solution Ltd handles personal data through this website and through technology services we provide for client platforms, including identity verification integrations. A service-specific notice may also apply.

1. Scope, responsible organisations, and roles

Cherry Technology Solution Ltd (“Cherry”, “we”, “us” or “our”) is a Hong Kong technology company. This Policy applies when we process personal data through this website, our communications, and systems or technical services operated by us.

Cherry

Acts as data user or controller for this website, business enquiries, and its own administration. For a client platform, Cherry generally acts as a technology service provider or processor under the client’s instructions.

Applicable client service

The business offering the relevant service generally decides why verification is required and makes the final onboarding or account decision.

Verification provider

An authorised third-party provider may supply identity verification technology and related checks under the applicable contractual and legal arrangements.

The precise roles depend on the service, contract, jurisdiction, and processing activity. The privacy notices presented by the applicable client service and verification provider should be read together with this Policy.

2. Personal data and sources

Depending on the service and verification requirements, we may process:

  • identity and profile data, including name, date of birth, nationality, gender, signature, and customer identifiers;
  • contact data, including residential address, email address, and telephone number;
  • government-issued identity document data and images;
  • selfie, video, facial geometry or other biometric data, liveness results, document authenticity results, and verification status, where permitted;
  • sanctions, politically exposed person, adverse media, fraud, duplicate-account, and other screening or risk results;
  • IP address, device and browser information, timestamps, session data, cookies, logs, and security events;
  • transactional or service data made available through the applicable client platform; and
  • communications, support enquiries, appeals, complaints, and related records.

We may receive data directly from you; from the applicable client platform; through an authorised identity verification provider; automatically from your device or browser; and from lawful public, regulatory, sanctions, fraud-prevention, or identity-validation sources.

3. Purposes and lawful bases

We process personal data only where there is an appropriate basis under applicable law. Depending on the context, this may include performance of a contract or steps requested before entering one, compliance with legal obligations, legitimate interests in secure and reliable operations, and consent where required, including for biometric data.

Purposes may include providing and securing technology services; verifying identity, age, address, and eligibility; supporting KYC, AML, sanctions, fraud-prevention, and risk-management processes; operating client-authorised account, card, payment, and transaction workflows; responding to requests; maintaining audit and security records; meeting legal and contractual duties; and establishing, exercising, or defending legal claims.

4. Identity verification

For certain client services, identity verification may be performed using an authorised third-party provider. Relevant data may be collected through the provider’s secure interface and made available to the provider, Cherry, the applicable client service, and authorised compliance or operational personnel according to their respective roles.

Before personal data is submitted for verification, the relevant flow will display the applicable privacy information and require a clear affirmative action where consent or acknowledgement is required. Records of that action may include the notice version, date and time, and an applicant or technical identifier. Withdrawal of consent does not affect processing already lawfully carried out and may prevent completion of a service where verification is necessary.

Provider notices: Before submitting information, applicants should review the privacy notice, acknowledgement or consent text, and any regional or biometric notice displayed by the authorised verification provider in the verification flow.

Submitting information required for verification is generally necessary to complete the applicable onboarding or compliance process. If it is not provided, the applicable client service may be unable to approve, open, or continue an account or service relationship.

5. Automated checks, human review, and decisions

Verification may involve automated document extraction and authenticity checks, facial comparison, liveness and anti-spoofing analysis, sanctions and watchlist screening, device analysis, duplicate detection, and risk indicators. Automated results may be reviewed by authorised personnel, particularly for exceptions, suspected fraud, support, appeals, or compliance requirements.

The verification provider may generate a verification result, alert, or risk label. The final decision whether to approve onboarding, maintain an account, or permit access to a client service is made by the applicable client service or its authorised decision-makers, and should not be based solely on an automated provider output where applicable law requires human involvement. You may contact the applicable client service, or Cherry at the address below, to request review or clarification.

6. Who we share data with

Where reasonably necessary and permitted, we may share personal data with the applicable client service; authorised identity verification, screening, fraud-prevention, hosting, infrastructure, communications, security, or technical providers; relevant card, payment, banking, or operational partners; professional advisers, auditors, insurers, and contractors; competent authorities; and a successor in a corporate transaction subject to appropriate safeguards.

We do not sell identity verification or biometric data for advertising, and we do not use it for website advertising.

7. International data transfers

Personal data may be processed outside Hong Kong where the applicable client, verification or infrastructure provider, payment partner, support team, or authorised recipient operates. Data protection laws in those locations may differ. Where required, transfers are protected through appropriate contractual, organisational, or technical measures and lawful transfer mechanisms.

8. Retention and deletion

Cherry retains personal data only for as long as reasonably necessary for the stated purpose, the documented instructions of the applicable client, legal or regulatory obligations, security, dispute resolution, and legal claims. The period depends on the data, service, jurisdiction, client retention schedule, contractual requirements, and risk. Where Cherry acts as processor, the applicable client generally determines the principal retention period.

An authorised verification provider may retain data in accordance with its contract, legal obligations, and the privacy notice presented in the verification flow. When data is no longer required, it is deleted, anonymised, returned, or otherwise disposed of in accordance with applicable procedures, subject to backup cycles and legal holds.

9. Security

We use reasonable administrative, technical, and organisational measures designed to protect personal data against unauthorised or accidental access, processing, erasure, loss, or use. Depending on the service, measures may include access controls, least-privilege permissions, logging, encryption in transit, environment separation, supplier controls, and incident-response procedures. No transmission or storage method is completely secure.

10. Your choices and rights

Subject to applicable law and our role, you may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review of a decision involving automated processing. You may also complain to the relevant data protection authority. In Hong Kong, information about privacy complaints is available from the Office of the Privacy Commissioner for Personal Data.

If Cherry processes data only for a client service, we may refer your request to that client or assist it in responding. Requests relating to processing for which a verification provider acts independently may be directed to that provider under its privacy notice. We may verify identity before acting on a request.

11. Cookies and website data

Our website may use essential technologies required for security and operation. If analytics or other non-essential cookies are introduced, we will provide information and controls where required.

12. Children

Our business services are not directed to children. A client service may impose age requirements. We do not knowingly collect children’s personal data through this website except where required and lawfully authorised for a specific service.

13. Changes to this Policy

We may update this Policy to reflect changes in services, providers, practices, or law. The revised version will be published here with an updated date. Material changes may also be communicated through the relevant client service.

14. Contact, requests, and complaints

Cherry Technology Solution Ltd
Email: cs@cherrytechnologysolution.com
Suite C, Level 7, World Trust Tower
50 Stanley Street, Central, Hong Kong

Please identify the relevant service and the nature of your request. Do not send identity documents by ordinary email unless specifically instructed through a secure process. We will acknowledge and handle requests in accordance with applicable law and our role in the relevant service.

Cherry Technology Solution Ltd
HomeIdentity VerificationPrivacy PolicyTerms of Use
© 2026 Cherry Technology Solution Ltd. All rights reserved.Central, Hong Kong