1. Introduction
Green Stream Capital Limited, operating under the development name GreenStreams, is committed to protecting your privacy and safeguarding your personal data. This Privacy Policy explains in clear and comprehensive terms how we collect, use, store, share, and protect information obtained from visitors to our website at https://www.greenstream.buzz, as well as from clients and prospective clients who engage with our computer systems design and professional technical services. We encourage you to read this document thoroughly so that you understand our practices regarding your personal information and how we treat it.
Our company, Green Stream Capital Limited, is a Hong Kong-based technology services provider specializing in computer integrated systems design, systems architecture, cloud infrastructure, cybersecurity, and related professional services within the Professional, Scientific, and Technical Services sector. Our registered office is located at Rm 308 3/F Chevalier House, 45-51 Chatham Road South, Tsim Sha Tsui, Hong Kong (HK). Throughout this policy, references to the Company, we, us, or our refer to Green Stream Capital Limited and its affiliated operations.
By accessing or using our website, engaging our services, or otherwise providing information to us, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein. If you do not agree with any part of this policy, you should discontinue use of our website and services immediately.
We recognize that privacy is a fundamental right and take our responsibilities as a data controller seriously. This policy has been designed to comply with applicable data protection laws including but not limited to the Personal Data (Privacy) Ordinance of Hong Kong, the General Data Protection Regulation (GDPR) where applicable, and other relevant privacy frameworks that govern the jurisdictions in which we operate or serve clients.
2. Information We Collect
In the course of operating our business and providing our technology consulting and systems design services, we may collect and process several categories of information. The types of data we collect depend on the nature of your interaction with us, whether you are a website visitor, a prospective client making an inquiry, an active client engaged in an ongoing project, or a vendor or partner organization.
Personal identification information includes data that can be used to identify you directly or indirectly. This may encompass your full name, email address, telephone number, postal address, company name, job title, and any other contact details you voluntarily provide when you fill out a contact form on our website, subscribe to communications from us, request a consultation, or enter into a service agreement with our firm.
Technical and usage data is automatically collected when you visit our website. This includes your Internet Protocol (IP) address, browser type and version, operating system, device type, referring URL, pages visited, time and date of your visit, time spent on each page, and other diagnostic data. We collect this information through server logs, analytics tools, and similar technologies to understand how visitors interact with our site and to improve its functionality and user experience.
Communication data includes the content of any messages you send to us via email, contact forms, telephone calls, or other communication channels. We retain records of correspondence to manage client relationships, respond to inquiries, improve our services, and maintain a record of our interactions for quality assurance and legal compliance purposes. Project-related data may also include technical specifications, system architecture documents, infrastructure diagrams, and other proprietary information shared in the course of a consulting engagement, all of which are treated with strict confidentiality.
3. How We Use Your Information
The information we collect serves several legitimate business purposes that enable us to deliver our services effectively and maintain the high standards of professionalism expected in the computer systems design industry. We use your personal data only for the purposes described in this policy and do not process it in ways that are incompatible with those purposes without first notifying you and, where required, obtaining your consent.
Service delivery and client engagement is the primary purpose for which we collect and process personal data. We use your contact information to communicate with you about your projects, deliver consulting services, prepare proposals, technical assessments, and system architecture recommendations, provide ongoing support and maintenance services, issue invoices and process payments, and manage our contractual relationship with you throughout the engagement lifecycle.
Website operation and improvement is another important use of the data we collect. Technical and usage data helps us monitor the performance and security of our website, identify and resolve technical issues, analyze trends in how visitors navigate our content, optimize page layouts and user flows, and develop new features that enhance the overall experience for our audience.
Marketing and business development communications may be sent to individuals who have expressed interest in our services or who we believe would benefit from learning about our capabilities. These communications include newsletters, service updates, industry insights, event invitations, and promotional materials. You may opt out of marketing communications at any time by using the unsubscribe link provided in each message or by contacting us directly at help@greenstream.buzz. We will process your opt-out request promptly and will not send further marketing materials following receipt of such a request.
Legal compliance and protection of rights is a necessary basis for processing certain categories of data. We may use and disclose information as required by applicable laws, regulations, legal processes, or governmental requests, to enforce our terms of service and other agreements, to protect the rights, property, or safety of our company, our clients, or others, and to detect, prevent, or address fraud, security breaches, or other illegal activities.
4. Legal Basis for Processing
Under applicable data protection laws, including the GDPR where it applies to our processing activities, we rely on one or more lawful bases to process your personal data. The specific basis depends on the nature of the data and the purpose for which it is processed. We are transparent about these bases and ensure that they are properly documented in our data processing records.
Contractual necessity applies when the processing of your personal data is required for us to perform a contract with you or to take steps at your request before entering into a contract. For example, when you engage us for a systems architecture consultation, we need your contact and project details to deliver the agreed services, manage the engagement, and fulfill our contractual obligations to you.
Legitimate interests form the basis for processing activities that are reasonably necessary for our business operations and do not override your fundamental rights and freedoms. These interests include improving our website and services, responding to inquiries, sending relevant marketing communications to individuals who have shown interest in our services, ensuring the security of our systems, and preventing fraud. We conduct legitimate interest assessments to balance our interests against any potential impact on your privacy rights.
Consent is the basis for processing in situations where you have given clear and affirmative permission for a specific purpose, such as subscribing to a newsletter, agreeing to the use of certain cookies, or providing information through an optional form. You have the right to withdraw your consent at any time, and we will cease the relevant processing activities upon receiving your withdrawal. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Legal obligation requires us to process certain data to comply with applicable laws, including tax regulations, anti-money laundering requirements, and obligations to cooperate with regulatory authorities. In such cases, the scope and duration of processing are limited to what is strictly necessary to fulfill the legal requirement.
5. Data Sharing and Disclosure
Green Stream Capital Limited does not sell, rent, or trade your personal data to third parties for their own marketing purposes. We share information only in the limited circumstances described below and always under appropriate safeguards designed to protect your privacy and ensure compliance with applicable data protection laws.
Service providers and business partners may receive access to certain personal data where necessary to assist us in operating our business and delivering services to you. These providers include cloud hosting and infrastructure services, email communication platforms, analytics services, payment processing partners, and professional advisors such as legal counsel and accountants. We carefully vet all service providers, require them to commit to data protection standards at least as stringent as our own through written agreements, and restrict their use of your data to the specific purposes for which we engage them.
Legal and regulatory disclosures may occur when we believe in good faith that disclosure is necessary to comply with a legal obligation, protect our rights or property, prevent or investigate possible wrongdoing, protect the personal safety of our users or the public, or defend against legal claims. We will, where legally permissible, notify you of any such disclosure before it occurs and provide information about the nature and scope of the disclosure.
International transfers of personal data may take place in connection with the services and infrastructure we use. Your data may be transferred to and processed in countries other than the country in which you reside. We take appropriate safeguards to ensure that such transfers comply with applicable data protection laws and that your data remains protected to the standard described in this policy, including through the use of standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms.
7. Data Retention
We retain personal data only for as long as is necessary to fulfill the purposes for which it was collected, including to satisfy any legal, regulatory, accounting, or reporting requirements. The specific retention period varies depending on the type of data, the purpose of processing, and applicable legal obligations. We have established a data retention schedule that documents these periods and ensures that data is not kept longer than necessary.
Client project data is retained for the duration of the active engagement and for a reasonable period thereafter to address any post-project questions, warranty claims, or follow-up support needs. Typically, we retain client records for a period of seven years following the conclusion of the engagement to comply with tax and business record-keeping requirements. After this period, client data is securely deleted or anonymized unless a longer retention period is required by law or agreed to in writing.
Website usage data is retained in an aggregated and anonymized form for analytical purposes for up to twenty-six months. Individual session data and IP addresses are anonymized or deleted after a shorter period, typically within fourteen months of collection. Marketing contact data is retained until you unsubscribe or request deletion, after which your details are removed from our marketing lists, though a record of your opt-out preference is maintained to ensure we respect your wishes in future.
When personal data is no longer needed for the original purpose, we take steps to securely delete, destroy, or anonymize it in accordance with industry best practices. This includes the secure erasure of digital records, shredding of physical documents, and ensuring that backups and archives are also purged in due course according to our retention schedule.
8. Data Security
Protecting your personal data from unauthorized access, alteration, disclosure, or destruction is a priority for us. We implement and maintain a comprehensive set of technical, administrative, and physical security measures designed to safeguard the information we collect and process. These measures are regularly reviewed and updated to address evolving threats and to align with current industry standards for information security.
Technical safeguards include the use of encryption for data in transit using Transport Layer Security protocols, encryption of sensitive data at rest using industry-standard algorithms, network firewalls and intrusion detection systems, regular vulnerability scanning and penetration testing, secure authentication mechanisms including multi-factor authentication where supported, and comprehensive access logging and monitoring.
Administrative safeguards include our internal data protection policies and procedures, regular staff training on privacy and data security practices, role-based access controls that limit data access to personnel who require it for their job functions, confidentiality agreements with all employees and contractors, and a designated data protection officer responsible for overseeing our privacy compliance program.
Physical safeguards include secured access to our office premises at Rm 308 3/F Chevalier House, 45-51 Chatham Road South, Tsim Sha Tsui, Hong Kong, locked server rooms and storage areas, visitor access controls, and proper disposal procedures for physical documents containing personal data. While we strive to use commercially acceptable means to protect your data, no method of transmission over the Internet or electronic storage is one hundred percent secure. We cannot guarantee absolute security, but we are committed to responding promptly to any security incidents and notifying affected individuals and relevant authorities as required by applicable law.
9. International Data Transfers
As a Hong Kong-based company serving a global clientele, your personal data may be transferred to, stored, and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from those in your jurisdiction. We take steps to ensure that any international transfer of personal data is carried out in compliance with applicable data protection laws and that your data receives an adequate level of protection regardless of where it is processed.
For transfers of personal data from the European Economic Area (EEA) or the United Kingdom to countries that have not been deemed to provide an adequate level of data protection, we implement appropriate safeguards as required by the GDPR. These safeguards may include the European Commission approved standard contractual clauses, binding corporate rules where applicable, or reliance on specific derogations provided under the GDPR for particular situations.
Hong Kong maintains its own robust data protection framework under the Personal Data (Privacy) Ordinance, which governs our core operations. When we transfer data out of Hong Kong, we ensure compliance with the requirements of the Ordinance, including any relevant cross-border data transfer guidance issued by the Office of the Privacy Commissioner for Personal Data. We are transparent about the locations where your data may be processed and are happy to provide additional information about the safeguards we have in place upon request.
10. Your Data Protection Rights
Depending on your jurisdiction, you may have certain rights regarding your personal data. We respect these rights and have established procedures to enable you to exercise them efficiently. The following is a summary of the rights that may be available to you under applicable data protection laws.
The right of access entitles you to request a copy of the personal data we hold about you and to obtain confirmation about whether and how we process your data. We will provide this information within the timeframe required by applicable law, typically within one month of receiving your request. The first copy is provided free of charge, though we may charge a reasonable fee for additional copies or for requests that are manifestly unfounded or excessive.
The right of rectification allows you to request the correction of inaccurate or incomplete personal data we hold about you. We will promptly update our records upon verifying the accuracy of the new information you provide. You also have the right to have incomplete data completed, including by providing a supplementary statement.
The right of erasure, also known as the right to be forgotten, permits you to request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, when you withdraw consent on which the processing is based, or when the data has been unlawfully processed. This right is not absolute and may be subject to exceptions, such as when we need to retain data to comply with a legal obligation or to establish, exercise, or defend legal claims.
The right to restrict processing enables you to request that we limit the processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to the processing. During the period of restriction, we will store your data but not otherwise process it without your consent or for limited purposes such as legal claims.
The right to data portability allows you to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another data controller without hindrance from us, where the processing is based on consent or a contract and is carried out by automated means.
The right to object permits you to object to the processing of your personal data in certain circumstances, including where processing is based on our legitimate interests or for direct marketing purposes. If you object to processing for direct marketing, we will cease such processing immediately. For objections based on other grounds, we will assess whether our legitimate grounds override your interests and inform you of our decision.
11. California Privacy Rights
If you are a resident of California, United States, you may have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). This section describes those rights and explains how California residents can exercise them in relation to our data processing activities.
Under California law, you have the right to know what personal information we collect, use, disclose, and sell or share. You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which the information was collected, the business or commercial purpose for collecting or sharing the information, and the categories of third parties with whom we share personal information.
You have the right to request deletion of personal information we have collected from you, subject to certain exceptions provided by law. You also have the right to correct inaccurate personal information that we hold about you. Additionally, you have the right to opt out of the sale or sharing of your personal information, although we confirm that we do not sell or share personal information as those terms are defined under California law.
We will not discriminate against you for exercising any of your California privacy rights. This means we will not deny you services, charge you different prices, provide a different level or quality of services, or suggest that you may receive a different price or rate for services as a result of your exercise of privacy rights. To exercise your California privacy rights, please contact us using the information provided in the Contact Information section below. We will verify your identity before processing your request, which may require you to provide sufficient information to confirm you are the person about whom we collected personal data.
12. Privacy for Children
Our website and services are not directed toward individuals under the age of eighteen. We do not knowingly collect, solicit, or process personal data from anyone under that age. The computer systems design and professional technical services we provide are intended for businesses and adult professionals, and our marketing and content are tailored accordingly.
If we become aware that we have inadvertently collected personal data from a minor without verified parental consent, we will take prompt and reasonable steps to delete such information from our records. If you are a parent or legal guardian and believe your child has provided us with personal data without your consent, please contact us immediately at help@greenstream.buzz so that we can take appropriate action. We encourage parents and guardians to monitor their childrens online activities and to educate them about the importance of protecting their personal information.
We do not have actual knowledge that we sell or share the personal information of consumers under sixteen years of age. Our data collection practices are designed with adult users in mind, and our contact forms and other data input mechanisms are structured for professional business communications rather than for general consumer interaction.
13. Third-Party Links
Our website may contain links to external websites, platforms, or services that are not operated or controlled by Green Stream Capital Limited. These links are provided for your convenience and informational purposes. We do not endorse and are not responsible for the content, privacy practices, or security of any third-party website you may visit through a link on our site.
This Privacy Policy applies solely to information collected by us through our website and direct interactions with you. When you navigate to a third-party website, you become subject to the privacy policy and terms of service of that external site. We strongly recommend that you review the privacy policies of every website you visit, especially before providing any personal information. We cannot be held liable for any loss or damage arising from your interaction with third-party websites, even if you access them through links on our website.
If we include links to partner services, tools, or resources that we integrate with our own systems design work, we will clearly indicate when you are leaving our site and entering a third-party environment. We select our partners and the resources we reference carefully, but our ability to control their data practices is limited, and your engagement with those third parties is at your own risk.
14. Business Transfers
In the course of our business operations, Green Stream Capital Limited may be involved in corporate transactions such as mergers, acquisitions, reorganizations, asset sales, or transfers of business units. In such circumstances, personal data that we hold may be among the assets transferred to the acquiring or surviving entity as part of the transaction.
We will take reasonable steps to ensure that any entity to which we transfer personal data in connection with a business transaction agrees to treat your data in a manner consistent with this Privacy Policy and applicable data protection laws. If a transfer results in a material change to the way your personal data is processed, we will notify you and, where required by law, provide you with an opportunity to opt out or exercise your data protection rights before the change takes effect.
In the event of our insolvency, bankruptcy, or receivership, personal data may be transferred to a successor entity or liquidator. We will, to the extent permitted by applicable law, make reasonable efforts to ensure that any such successor treats your data in accordance with this policy and gives you notice before your information is transferred or becomes subject to a different privacy policy.
15. Do Not Track Signals
Do Not Track (DNT) is a privacy preference that users can set in their web browsers to indicate that they do not want their online activities to be tracked across websites. At present, there is no widely accepted industry or legal standard for how websites should respond to DNT signals. As a result, our website does not currently alter its data collection and use practices in response to a Do Not Track signal from your browser.
We continue to monitor developments in DNT technology and the regulatory landscape surrounding online tracking. If a uniform standard is established and adopted, we will evaluate our practices and update this policy accordingly to provide you with meaningful choices regarding the collection of information about your online activities over time and across third-party websites or online services. In the meantime, you can manage your tracking preferences through your browser settings and by using the cookie controls described earlier in this policy.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal obligations, or the services we offer. When we make changes, we will update the Last Updated date at the top of this page and post the revised policy on our website. The updated policy will become effective as of the date it is posted unless a different effective date is specified.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data. If we make material changes to this policy, we will take reasonable steps to notify you, such as by posting a prominent notice on our website, sending an email to the address you have provided, or using other appropriate communication channels. Your continued use of our website or services after the effective date of a revised policy constitutes your acceptance of the updated terms.
Where changes to this policy require your consent under applicable data protection law, we will obtain such consent before implementing any changes that materially affect the way we process your personal data. If you do not agree with the changes, you should discontinue using our website and services and exercise your data protection rights as described in this policy.
17. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, or if you wish to exercise any of your data protection rights, you can reach us using the contact details provided below. We are committed to addressing your inquiries promptly and resolving any concerns you may have about the handling of your personal data.
Green Stream Capital Limited
Rm 308 3/F Chevalier House
45-51 Chatham Road South
Tsim Sha Tsui
Hong Kong (HK)
Email: help@greenstream.buzz
Phone: +1 (870) 470-7970
Website: https://www.greenstream.buzz
We will acknowledge receipt of your inquiry and respond within the timeframe required by applicable data protection law, typically within thirty calendar days. If your request is complex or we receive a high volume of requests, we may extend this period by up to an additional two months, in which case we will inform you of the extension and the reasons for the delay within the initial thirty-day period.
18. Complaints and Supervisory Authority
If you believe that we have not adequately addressed your privacy concerns or that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with the relevant data protection supervisory authority. In Hong Kong, the supervisory authority is the Office of the Privacy Commissioner for Personal Data (PCPD). Residents of other jurisdictions may contact their local data protection authority.
While you have the right to contact a supervisory authority at any time, we encourage you to reach out to us first so that we have an opportunity to understand your concerns and work toward a satisfactory resolution. Many privacy issues can be resolved through direct communication, and we are committed to addressing all complaints fairly, transparently, and in a timely manner. Our goal is to maintain the trust and confidence of every individual whose data we process, and we view every concern as an opportunity to improve our practices.
For individuals in the European Economic Area or the United Kingdom, you may lodge a complaint with the data protection authority in your country of residence, place of work, or the place of the alleged infringement. A list of EU data protection authorities is available on the European Data Protection Board website. For UK residents, the Information Commissioner Office (ICO) is the relevant supervisory authority.