Skip to content

Privacy Policy (Hong Kong)

Inocras Hong Kong Limited (BRN: 74908632) (“Inocras,” “we,” “us,” or “our”) is committed to protecting your privacy in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”). This Privacy Policy applies to your use of our Clinical Services (as defined herein) in Hong Kong. It describes how and why we collect, store, use, transfer or share personal data (as defined in the PDPO) within the scope of these services.

We will only process your personal data where we have a lawful basis to do so under the PDPO, including: (a) for the performance of a contract with you; (b) to comply with our legal obligations; (c) for our legitimate interests, provided they are not overridden by your interests or rights; (d) to protect the vital interests of you or another person; or (e) with your voluntary and explicit consent, where required by law.

We collect, store, use, transfer or share your personal data when you:

  • Access or use our website, platforms, or our Clinical Services;
  • Participate in our separate research initiatives, where applicable and only with your additional explicit consent;
  • Interact with us, including by transmitting data or information by email, telephone, social media, and in person; or
  • Otherwise communicate with us.

For the purposes of this Privacy Policy, “Clinical Services” refers to the testing services provided by Inocras in Hong Kong, which may include pathology testing (such as PDL1 28-8 diagnostic testing) and genetic testing (such as genetic sequencing, analysis and related molecular diagnostics).

This Privacy Policy will help you understand your rights and choices related to your personal data. Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our website or platform. If you still have any questions or concerns after reading this Privacy Policy, please contact us at the contact point as set out below.

Purpose of Processing Personal Data

Inocras collects and uses personal data for specified, explicit, and lawful purposes:

  • To provide Clinical Services to you, or to perform any contract that we will enter into or have entered into with you.
  • To process your registration on our websites or platforms.
  • To personalize your experience on our websites or digital platforms, including by using cookies and similar tracking technology to keep track of your preferences in reliance on your consent (please see the “Data Collection Through Technology” section below).
  • To communicate with you and respond to or carry out your requests, questions, and feedback.
  • To verify your identity.
  • To maintain the quality of, and improve, existing Clinical Services and develop new Clinical Services.
  • To enforce and improve our security measures.
  • To maintain compliance with laws and regulations that apply to us.

Activities Requiring Your Explicit Consent

For the following specific activities, we will only proceed after obtaining your prior voluntary and explicit consent, which you may withdraw at any time:

  • To provide you with direct marketing materials, including but not limited to information to participate in specific research initiatives or clinical trials. We will always provide a clear means for you to opt-out.
  • To de-identify your personal data and use the de-identified data for statistical compilation, scientific research, record-keeping for public interest purposes. [We will seek this consent separately via a dedicated consent form.]

Personal Data to be Collected and Processed

Personal Data We Collect

  1. Data You Provide to Us Directly:
    This includes contact details, professional registration numbers (for healthcare providers), payment information, and any testimonials you choose to submit.
  2. Data Collected for Clinical Services:
    To provide Clinical Services, we process data provided by you or your healthcare provider. This includes identification details, sensitive health-related information (including medical history and genetic data we generate from your sample), and associated payment information.
  3. Data Collected Automatically:
    When you use our website or platform, we automatically collect technical data such as your IP address, browser type, and information collected via cookies (see “Data Collection Through Technology” section below).
  4. Data concerning Minors:
    We may collect the personal data of a minor for Clinical Services. In such an event, Inocras will only process the personal data where it is necessary for the provision of those services and will obtain prior, verifiable consent from the holder of parental responsibility, in accordance with Hong Kong law and best practice.

Period of Retention and Use for Personal Data

We will retain your personal data for the period stated in the relevant consent form (if applicable), or otherwise for as long as necessary to fulfil the purposes outlined in this Privacy Policy or to comply with legal, regulatory or professional requirements.

In determining the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and applicable legal, regulatory, tax, accounting, or professional requirements.

We retain personal data, including health-related information, for as long as necessary to fulfil the purposes for which it was collected to comply with applicable legal, regulatory or professional requirement.

We may retain personal data for longer periods where necessary to comply with a legal obligation (e.g., a court order), for the establishment, exercise, or defence of legal claims, or for legitimate purposes such as fraud prevention and security incident investigation.

We retain personal data for the duration of our business relationship and for a reasonable period thereafter to manage account inquiries, comply with record-keeping obligations, and for reactivation purposes.

At the end of the applicable retention period, we will securely delete or anonymise your personal data so that it can no longer be used to identify you.

Sharing and Transfer of Personal Data to Third Parties

We may share your personal data with third parties only for the purposes specified in this Policy and in accordance with the PDPO:

Affiliates. We may share your personal data with our corporate parent, subsidiaries, and affiliates, for centralized administrative, technical, and security support, under binding intra-group agreements that uphold the standards of this Privacy Policy.

Healthcare Providers. We share personal data with your referring or treating healthcare provider(s) as necessary to provide Clinical Services to you, whether pathology or geneticic in nature, in line with the primary purpose of collection.

Service Providers. We engage trusted third parties (e.g., IT services, analytics services, etc.) to help us perform, provide, improve, protect, and promote our Clinical Services, and to perform functions on our behalf. These third parties process your personal data only per our instructions, under strict contractual obligations that impose data protection standards consistent with the PDPO and prohibit them from using your data for their own purposes.

International Data Transfers. As we share data with service providers and affiliates outside Hong Kong (e.g., in Taiwan), such transfers constitute cross-border data transfers under the PDPO. We take all practicable steps to ensure your data is protected, including by using contractual agreements that impose obligations comparable to those under the PDPO.

Other Applications and Third-party Links. The Sites may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy policies. When you leave our website or platform, we encourage you to read the privacy policies of every website you visit. Please remember that their use of your personal data will be governed by their privacy policies and terms.

The Public. We may make your testimonials public. If you gave us consent to use and share your testimonial but wish to update or delete it, please contact us at inquiry@​inocras.​com.

For Compliance, Fraud Prevention and Safety. We may share personal data for the compliance, fraud prevention, and safety purposes described above and to comply with legal requirements and processes.

Business Transfers. We may sell, transfer or otherwise share some or all of our business or assets, including personal data, in connection with a business transaction (or potential business transaction) such as a corporate divestiture, merger, consolidation, acquisition, reorganization or sale of assets, or in the event of bankruptcy or dissolution.

Legal Purposes. We may disclose your personal data when we think disclosure is necessary to comply with any applicable Hong Kong law, regulation or legal process; or protect the rights, property or assets of our users, the public or Inocras.

Professional Advisors. We may share data with our legal, financial, and audit advisors under duties of confidentiality.

Your Rights

As a data subject under the PDPO, you have the following rights regarding your personal data:

Right of Access. You have the right to request a copy of your personal data we hold and to be informed of the types of data held and its purposes. We will respond within 40 days. We may charge a reasonable fee for processing.

Right of Correction. You have the right to request correction of any inaccurate personal data. We will correct the data as soon as practicable. If we do not agree to a correction, you may request that we attach a statement of your proposed correction to the data.

Right to Withdraw Consent. Where our processing is based on your written consent (e.g., for direct marketing or research activities), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing of your data based on consent before its withdrawal.

How to Exercise Your Rights

To exercise any right, please submit a written request to us at the contact details provided in the “Contact Us” section available on our website or contacting us at inquiry@inocras.com.

We may need to verify your identity before processing your request. If you act on behalf of another person (e.g., as a legal guardian), proof of authority such as power of attorney or court order is required.

Limitations on Rights

Your rights are not absolute. We may be unable to comply where it would:

  • Reveal personal data about another individual;
  • Violate a legal or regulatory obligation or court order;
  • Involve legally privileged information;
  • Where the request is manifestly unfounded or excessive; or
  • Where the data is being processed for certain statutory exemptions under the PDPO.

If we cannot comply, we will inform you of the reasons in writing.

Destruction of Personal Data

Inocras will securely dispose of your personal data when your personal data becomes unnecessary for the fulfilment of the purposes for which it was collected, unless its retention is required or permitted by Hong Kong laws.

If Inocras needs to retain your personal data in order to comply with a legal or regulatory obligation or for establishment, exercise or defence of legal claims, Inocras will securely store your personal data with restricted access, and isolate it from our active processing system.

Our disposal methods are designed to prevent recovery and are appropriate to the sensitivity of the information. This includes the permanent erasure of electronic data using industry-standard methods and the secure destruction of physical records.

Safety Measures for Personal Data

Inocras has implemented all reasonably practicable technical and organizational security measures designated to protect your personal data against unauthorized or accidental access, processing, erasure, loss or use.

Our security measures are based on the nature, scope, and sensitivity of the data we process and include, but are not limited to:

  • administrative measures: establishment of internal data protection policies, regular privacy and security training for employees, and strict access controls on a need-to-know basis.
  • technical measures: encryption of personal data, secure network infrastructure, storage access records, protection against malicious software (malware), maintenance of access logs for security monitoring, and regular review of our information security practices.
  • physical measures: controls on physical access to our facilities and the locations where data is stored.

While we strive to use commercially acceptable means to protect your personal data, please be aware that no method of electronic transmission or storage is completely secure. We are committed to continuously evaluating and enhancing our security controls.

Data Collection Through Technology

Inocras uses ‘cookies’ to store and retrieve your usage information about your interaction with our websites and platforms from time to time. This helps us to provide secure, functional and individually customized services.

Cookies are a small amount of information sent to your electronic device, which are used to operate the website, etc., and stored in your electronic device. They help the site remember information about your visit.

Inocras uses cookies to enable basic functions like page navigation, secure log-in, and load balancing, in order to provide you with secure, optimized information by identifying the type of visit and use of each service and website you visit, popular search terms, remember your preferences, and whether you have a secure connection.

You can reject the storage of cookies by setting your web browser’s privacy and security options. You can usually set your browser to refuse cookies or to alert you when a cookie is being sent. Please note that by refusing to save cookies, you may experience difficulties in using customized services.

Contact Us About Privacy

Contact: inquiry@inocras.com

We are committed to addressing your privacy concerns promptly. We will acknowledge your inquiry or complaint without undue delay and work to provide a response within a reasonable period.

If you are not satisfied with our response, you may lodge a complaint with the Hong Kong supervisory authority, Office of the Privacy Commissioner for Personal Data (PCPD).

PCPD’s contact details are provided below:

Address: Unit 1303, 13/F, Dah Sing Financial Centre, 248 Queen’s Road East, Wanchai, Hong Kong.
Complaint Hotline / General Line: (+852) 2827 2827
Website: www.pcpd.org.hk

Updates to This Privacy Policy

Inocras may update this Privacy Policy from time to time to comply with legal and regulatory requirement including those under Hong Kong law or to reflect any changes in the provision of service, in which case Inocras will notify you of such amendment before the effective date of such amendment.

Your continued use of our Clinical Services after the effective date of a revised Privacy Policy constitutes your acknowledgment and acceptance of its terms.

The Privacy Policy shall take effect from 28 January 2026.