Coreway

Coreway Limited Privacy Policy

Welcome to the websites, platforms, applications, browser extensions, APIs, integrations, and any other related products that we make available from time to time (collectively, the "Services"), operated by Coreway Limited (Company No. 79650222), of 21/F, Cityplaza Three 14 Taikoo Wan Road, Taikoo Hong Kong (referred to in this Privacy Policy as "Coreway", "we", "us" or "our").

Your privacy matters to us. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal data when you use the Services, and the choices and rights you have regarding your own data.

If you do not agree with the practices described in this Privacy Policy, please do not use the Services.

This Privacy Policy should be read together with our applicable Terms of Service, Data Processing Addendum, and Cookie Policy. Capitalized terms not defined here have the meaning given in our Terms of Service. This Privacy Policy does not govern our relationship with our own employees, which is governed by our internal HR policies.


1. Scope of this Policy

This Privacy Policy applies to:

  • Customers who register an account directly with Coreway, and their authorized users;
  • End users who use the Services under an account created by another organization (e.g., their employer);
  • Visitors who browse our website or otherwise interact with us (e.g., submitting an inquiry, requesting a demo, subscribing to updates).

If you are an end user accessing the Services under an account owned by another organization, that organization is the data controller responsible for the account and the personal data processed within it. If you wish to access, update, or delete your personal data, we recommend you first contact that organization.

Coreway generally has no direct relationship with individuals whose personal data is submitted to the Services by our customers (for example, an employee whose HR records are entered by their employer). If you are a current or former employee (or other individual) of one of our customers and wish to access, correct, object to the processing of, or request deletion of your personal data held on the Services, please contact the customer organization that operates the relevant account, as they control that data and are best placed to action your request.


2. Information We Collect

Depending on how you use the Services, we may collect two broad categories of information:

2.1 Personally Identifiable Information

Information that identifies you or can be used to identify or contact you, such as:

  • Name, company name, job title;
  • Email address, phone number, mailing address;
  • Account login credentials (stored in encrypted form);
  • Billing and payment information (typically processed by a licensed third-party payment processor);
  • Data entered into the Services at a customer's direction, which may include employee or business-operational data (e.g., ID numbers, salary, employment records) — such data is controlled by the customer as data controller, and Coreway processes it as a data processor acting on the customer's instructions.

2.2 Non-Personally Identifiable Information

Information that, on its own, cannot identify you, such as:

  • Demographic information (industry, region, language preference);
  • Device data, IP address, browser type, operating system;
  • Aggregated statistics on how the Services are used.

Where non-personal information is combined with other data in a way that makes you identifiable (e.g., an IP address combined with account records), we treat the combined data as personal data.


3. How We Collect Information

3.1 Information you provide directly

  • When you register an account or complete forms on our website or in the Services;
  • When you contact our sales, customer service, or support teams;
  • When you request a demo, complete a survey, attend a webinar, or subscribe to our newsletter;
  • When you create content, applications, workflows, or forms within the Services;
  • When you or your organization enter data into the Services in the course of using them.

3.2 Information collected automatically

  • Service usage data: the features you use, the tasks/workflows/forms you view or create, the type and size of files you upload, frequently used search terms, and how you interact with collaborators;
  • Device and connection data: device type, operating system, browser type, IP address, referring/exit URLs, device identifiers, and crash reports. We may use your IP address to approximate your location to improve your experience;
  • Cookies and similar tracking technologies: see Section 8;
  • Log files: used to analyze trends and to operate, maintain, and monitor the Services.

3.3 Information we receive from other sources

  • Other users of the Services: e.g., a colleague mentions you in a task, or an administrator adds you as an authorized user and provides your contact details;
  • Third-party integrations: if you or your administrator connect a third-party app or service to the Services (e.g., calendar, storage, communication tools), we may receive related information, subject to the permissions and privacy policy of that third-party service;
  • Business and marketing partners: e.g., partners who assist with market research or advertising, where you have consented to the sharing of your information or the information is otherwise publicly available.

Where we receive and transfer information from Google APIs, we will comply with Google's API Services User Data Policy, including the Limited Use requirements.


4. Why We Need and How We Use Your Personal Data

We use the information we collect to:

(a) Provide, operate, maintain, and improve the Services;

(b) Process account registration and payments, and manage your account and subscription;

(c) Respond to your enquiries and provide customer support;

(d) Communicate with you about the Services (e.g., account notices, updates, or requested information) and carry out direct marketing (see Section 5);

(e) Analyze how the Services are used, and research and develop new features;

(f) Detect, prevent, and investigate fraud, security incidents, or misuse of the Services;

(g) Comply with applicable laws and regulatory requirements, and respond to legal proceedings or requests from public authorities;

(h) Purposes directly related or incidental to the above.

When you register for the Services, you will be asked to confirm your agreement to our processing of your personal data in line with this Policy. Where our processing relies on your consent, you may withdraw it at any time by contacting us using the details in Section 17, subject to applicable law.

If you withdraw your consent to our collection, use, or disclosure of your personal data, we may be unable to continue providing you with some or all of the Services, which may result in the termination of your agreement with Coreway. Withdrawing consent does not affect processing we carried out before the withdrawal, or our right to continue processing your personal data where this does not require consent under applicable law.


5. Direct Marketing

We may use your personal data (such as your name and email address, as described in Sections 2.1 and 3) to send you marketing communications about Coreway and its products, services, seminars, or events, via electronic message, email, or in-app notification.

We will only use your personal data for direct marketing with your consent (e.g., an opt-in checkbox at registration), and every marketing communication will include an unsubscribe option. You may also opt out at any time by emailing hello@coreway.com, and we will stop sending you marketing communications free of charge.

5.1 Text Messages (SMS/MMS)

We may send you text messages (SMS/MMS) in connection with the Services, including account verification, security alerts, and, where you have opted in, marketing or promotional communications. Message frequency may vary, and your mobile carrier's message and data rates may apply. Opt-in data and consent for text messaging will not be shared with third parties, other than aggregators and providers of the text messaging services used to deliver such messages. You may opt out of marketing text messages at any time by following the instructions provided in the message or by contacting us using the details in Section 17.


6. When We Disclose Information to Third Parties

Except as set out in this Policy, our Cookie Policy, an applicable Data Processing Addendum, or with your explicit authorization, we do not disclose your personal data to third parties outside the Coreway group.

6.1 Group companies and service providers

  • Our group companies, including our subsidiaries, holding company, and other companies under common ownership or control;
  • Third-party service providers, agents, advisers, auditors, and contractors who support our operations (e.g., cloud hosting, payment processing, fraud screening, email delivery). We require these providers to protect your personal data to a standard consistent with this Policy, and to use it only for the purpose we engaged them for or as required by law.

6.2 Legal and regulatory requirements

We may disclose your information (including personal data) if we believe in good faith that disclosure is required to comply with an applicable law, regulation, subpoena, search warrant, court or regulatory order, or other valid legal process; to identify, contact, or take legal action against someone violating our Terms of Service; to detect or prevent fraud; or to protect the safety or security of our users, the Services, or the public; or in response to a lawful request from a public authority.

6.3 Business transfers

If Coreway or any of its group companies undergoes a sale, merger, or other transfer of all or substantially all of its business or assets, or in the event of bankruptcy, reorganization, or a similar proceeding, we reserve the right to transfer information to the relevant third party, provided that party agrees to comply with the terms of this Policy.

6.4 Other

We may also disclose information to overseas offices, group companies, business partners, and counterparts on a need-to-know basis, subject to the terms of this Policy.


7. Data Retention

We retain your personal data only for as long as reasonably necessary for you to use the Services and/or for us to provide the Services, unless a longer period is required or permitted by law (e.g., for regulatory or accounting purposes). Once the purpose for retaining data has ended, we will delete or anonymize it where reasonably practicable, although residual copies may remain in backup systems for a period of time; such backup data will not be actively used.


8. Cookies and Tracking Technologies

Our website and applications use cookies and similar technologies to distinguish you from other users, improve your browsing experience, and improve our Services. A cookie is a small text file stored on your browser or device.

We (and our third-party analytics/advertising partners) use the following types of cookies:

  • Strictly necessary cookies: required for core website functionality (e.g., login, session management);
  • Analytical/performance cookies: help us understand how visitors use our website so we can improve it;
  • Functionality cookies: remember your preferences (e.g., language selection);
  • Targeting/advertising cookies: record your browsing activity to make advertising and content more relevant to you.

You can block cookies through your browser settings, though this may prevent you from using some parts of the website or applications. For more information, see our separate [Cookie Policy]. We currently do not respond to "Do Not Track" browser signals.


9. Data Security

We take reasonable physical, electronic, and managerial measures to safeguard your personal data against unauthorized access, disclosure, alteration, or loss:

  • All information you provide is stored on secure servers;
  • Payment-related transactions are encrypted using TLS/SSL technology;
  • Access to personal data is restricted to employees, service providers, and contractors on a need-to-know basis, and such persons are subject to confidentiality obligations;
  • We periodically review our data collection, storage, and processing practices.

No system or encryption method can guarantee absolute security, and data transmission over the internet carries inherent risk. In the event of a security incident affecting your personal data, we will take reasonable remedial and notification steps in accordance with applicable law.

9.1 Data Breach Notification

If we become aware of a security incident that may have resulted in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data, we will assess the incident without undue delay to determine its impact. Where our assessment confirms that the incident is one that requires notification, we will notify the relevant regulator or data protection authority within the timeframe required by applicable law. Where a data breach is likely to result in significant harm to the affected individuals, or is of significant scale, we will, without unreasonable delay, notify the affected customer(s) so that they can inform the individuals concerned.


10. International Data Transfers

Because Coreway and our service providers may operate outside Hong Kong (including cloud hosting and support functions), your personal data may be transferred to, stored in, and/or processed in locations outside Hong Kong, where data protection laws may differ from those in your jurisdiction.

By providing personal data to us, you consent to such data being transferred, stored, and processed outside Hong Kong as described in this Policy. We will take reasonable steps to ensure your data continues to be handled securely and in accordance with this Policy, and, where applicable, will use appropriate safeguards (such as standard contractual clauses) for cross-border transfers.


11. Children's Privacy

The Services are not designed for or directed at individuals under the age of 16. We do not knowingly collect personally identifiable information from anyone under 16. If we become aware that we have collected a child's personal data without appropriate parental or guardian consent, we will take steps to delete that data promptly.


12. Accuracy of Your Data

We take reasonable steps to ensure that the personal data we collect about you is accurate, complete, and not misleading, having regard to the purpose for which it is used. Where reasonably possible, we will verify the personal data you provide against generally accepted practices and guidelines. If we have an ongoing relationship with you (for example, an active subscription), you are responsible for promptly notifying us of any changes to your contact or business information so that our records remain accurate and up to date.


13. Your Rights

13.1 General rights under the Hong Kong PDPO

Under the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"), you have the right to:

(a) check whether we hold personal data about you;

(b) access the personal data we hold about you; and

(c) require us to correct any inaccurate or erroneous personal data we hold about you.

We may charge a reasonable administrative fee to cover the cost of processing such requests, except where a correction is required due to our own clerical or input error. We will endeavor to respond to access and/or correction requests within 30 days of receipt. If we are unable to do so within that time, we will notify you in writing within 30 days of the time by which we expect to be able to respond.

13.2 Additional rights that may apply under other applicable laws

This Policy is primarily governed by Hong Kong's PDPO. However, as Coreway's Services are used across multiple regions, where a data protection law applicable to you grants rights beyond those in Section 13.1 — such as the right to request erasure of your data, restrict or object to certain processing, receive your data in a portable format, or withdraw consent at any time — we will honor those rights as required. You may also have the right to lodge a complaint with the relevant supervisory or data protection authority in your jurisdiction.

We may need to verify your identity (e.g., using information associated with your account) before processing a request under this section, and, where permitted, you may designate an authorized agent to submit a request on your behalf.

To exercise any of these rights, please contact us using the details in Section 17.

13.3 Verifying your identity and updating your data

You can contact us to (1) update or correct your personal data, (2) change your communication preferences, or (3) request deletion of the personal data we hold about you, subject to Section 7 (Data Retention) and any applicable legal exceptions. To protect your privacy and security, we may take reasonable steps — such as verifying account credentials or requesting additional identifying information — before granting access to your data or making the requested changes. You are responsible for keeping your account password and login credentials confidential.

It is not always technically possible to remove every record of information from our systems immediately (for example, copies may remain in backup systems for a period of time). We will action requests in databases we actively use and other readily searchable systems as soon as reasonably practicable. Updates, corrections, or deletions will not affect information already lawfully shared with third parties prior to your request.


14. Third-Party Links and Services

The Services may contain links to other websites or third-party services (including third-party applications you or your administrator connect to the Services). We are not responsible for the privacy practices of any website or service other than our own, and we encourage you to review the privacy policy of any third-party service before using it. This Policy applies only to information we collect through the Services.


15. Sensitive Personal Data

We ask that you do not submit sensitive personal data (e.g., data relating to racial or ethnic origin, political opinions, religious beliefs, health, biometric or genetic characteristics, criminal records, or trade union membership) through the Services unless necessary. If you choose to submit such data as part of user-generated content, you consent to our processing it in accordance with this Policy; if you do not consent, please do not submit such content.


16. Changes to this Policy

We may revise this Privacy Policy from time to time. If a change results in a significant change to how we use or disclose your personal data, we will notify you by email or through a notice within the Services. Non-material changes may be made without individual notice, though we encourage you to review this page periodically.

Your continued use of the Services after an update to this Policy takes effect constitutes your acceptance of the revised Policy. If you do not agree with a revision, you should stop using the Services and contact us.


17. Contact Us

If you have any questions or comments about this Privacy Policy, or wish to exercise any of the rights described in Section 13, please contact our Privacy Officer:

Coreway Limited

Attn: Privacy Officer

Email: hello@coreway.com

Address: 21/F, Cityplaza Three 14 Taikoo Wan Road, Taikoo Hong Kong

We will respond to your request within a reasonable time and in accordance with applicable law.

Last updated: 15 Sep 2026

Mendorong Pertumbuhan Bisnis

Rasakan bagaimana platform manajemen AI HR × bisnis menghadirkan momentum pertumbuhan bagi perusahaan Anda