Legal

Privacy policy

We audit websites for a living, so we take the handling of personal data seriously. This page explains, in plain language, what we collect, why, how long we keep it and what you can ask us to do.

This policy is written to align with the Hong Kong Personal Data (Privacy) Ordinance, Cap. 486.

Who we are

neurabase provides passive website security audits and security services to businesses in Hong Kong. For any question about this policy or your data, write to hello@neurabase.pro.

What we collect

When you ask us for a report or a quote. Your name, email address, phone number if you give one, your company or website, and whatever you write in the message. We collect this because you asked us to get in touch.

When we audit a website. Our scan reads only what the website already publishes to any visitor: DNS records, the public WHOIS register, TLS certificate details, HTTP headers, and the pages the site serves openly. If a domain's public WHOIS entry contains a person's name, address, phone or email, that information is already public, and our report shows it precisely so the owner can decide whether it should be.

When you visit this website. Standard server request information such as IP address, browser type and the pages requested, kept for security and troubleshooting.

What we never do

  • We never log in to a website, never attempt to bypass any control, and never exploit a weakness. Every check is passive and read only.
  • We never sell or rent personal data.
  • We never share a report with anyone other than the business it concerns, unless the law requires it.
  • We do not use tracking or advertising cookies on this website.

How we use it

To prepare and send your report, to answer your enquiry, to provide services you engage us for, and to keep our own systems secure. We also produce aggregate statistics about the state of Hong Kong website security. Those figures are counts and percentages only. No business or person is identifiable from them.

Direct marketing

If we contact you about our services, we will always say who we are, tell you what we would use your details for, and give you a free and simple way to refuse. If you tell us to stop, we stop, and we keep a record of that so it does not happen again. Under Part 6A of the Ordinance, ignoring an opt out is a criminal offence, and we treat it that way.

How long we keep it

  • Report links expire 30 days after the report is created, after which the report is no longer reachable.
  • Enquiry and quote records are kept for up to 24 months so we can answer follow up questions, then deleted.
  • Opt out records are kept indefinitely, because that is the only way to guarantee we do not contact you again.

Where it is held and how it is protected

Data is held on servers we control, in a database that is not reachable from the public internet. Access requires individual authentication. Traffic to our sites is encrypted in transit. Report links use long random tokens, are marked so search engines do not index them, and expire.

Your rights

Under the Ordinance you may ask us for a copy of the personal data we hold about you, ask us to correct it if it is wrong, and ask us to stop using it for direct marketing. Write to hello@neurabase.pro. We will respond within 40 days, as the Ordinance requires. There is no charge for a reasonable request.

Changes

If we change this policy we will update the date below. Material changes will be highlighted on this page.

Last updated: February 2026.