Europe and the UK
General Data Protection Regulation Statement (“GDPR Statement”)
This GDPR Statement applies to individuals in the European Economic Area (“EEA”) and the United Kingdom (“UK”) whose personal data is collected, used or otherwise processed by Majestica Enterprises Limited (“Majestica”, “we”, “us” or “our”).
This GDPR Statement forms part of and should be read together with Majestica’s
Privacy Policy
.
To the extent of any inconsistency between this GDPR Statement and the
Privacy Policy
,
the GDPR Statement will prevail as to individuals located in the EEA and the UK.
1. Controller of Personal Information
1.1 Majestica Enterprises Limited is the controller of the personal information we collect.
1.2 Please contact us at
dpo@majesticaenterprises.com
for information relating to your rights regarding our processing of your personal data or if you have any questions regarding this GDPR Statement.
2. Purposes of Processing and Legal Basis
2.1 The categories of personal data we may collect are set out in our
Privacy Policy
and
Cookie Policy
.
2.2 We process personal data only where we have a lawful basis to do so.
2.3 Pursuant to GDPR, we may process your personal data for the following purposes:
| Purpose of Data | Legal Basis |
|---|---|
| (a) To respond to enquiries, process orders, purchase/supply products and manage customer/supplier relationships | Where we need to perform the contract we are about to enter into or have entered into with you, and compliance with legal obligations. |
| (b) To improve our Website, products and services | Where it is necessary for our legitimate interests to maintain our Website, detect fraud and protect our business, and compliance with legal obligations. |
| (c) Communication |
Where it is necessary for our legitimate interests to communicate with you and your interests and fundamental rights do not override those interests.
Where we need your consent for the information use, we will seek your prior consent. |
| (d) Legal, regulatory, accounting and reporting compliance | Where it is necessary to meet our legal obligations. |
3. Legitimate Interests
3.1 Where we rely on legitimate interests as a legal basis for processing, we have considered and balanced the potential impact on your rights and freedoms against our business interests and do not process personal data where those interests are overridden by your rights and freedoms.
4. Your Rights
4.1 Subject to applicable law, you have certain rights regarding your personal data that we may collect. These rights include the following:
- (a) The right to request access to your personal data. This enables you to receive a copy of the personal data we hold about you.
- (b) The right to request correction of your personal data if it is inaccurate. You may also supplement any incomplete personal data we have, taking into account the purposes of the processing.
- (c) The right to request deletion of your personal data if:
- your personal data is no longer necessary for the purposes for which we collected or processed them;
- you withdraw your consent if the processing of your personal data is based on consent and no other legal ground exists;
- you object to the processing of your personal data and we do not have an overriding legitimate ground for processing;
- your personal data is unlawfully processed; or
- your personal data must be deleted for compliance with a legal obligation.
- (d) The right to object to the processing of your personal data. We will comply with your request, unless we have a compelling overriding legitimate interest for processing or we need to continue processing your personal data to establish, exercise, or defend a legal claim.
- (e) The right to restrict the processing of personal data, if:
- the accuracy of your personal data is contested by you, for the period in which we have to verify the accuracy of the personal data;
- the processing is unlawful, and you oppose the deletion of your personal data and request restriction;
- we no longer need your personal data for the purposes of processing, but your personal data is required by you for legal claims; or
- you have objected to the processing for the period in which we have to verify overriding legitimate grounds.
- (f) The right to data portability. You may request that we send your personal data to a third party, where feasible. You only have this right if it relates to personal data you have provided to us where the processing is based on consent or necessity for the performance of a contract between you and us, and the processing is conducted by automated means.
- (g) You also have the right to lodge a complaint before your national data protection authority.
4.2 You will not usually have to pay a fee to access your personal data (or to exercise any of the other rights described in this GDPR Statement). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
4.3 We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). To the extent you use a third party to submit a data request on your behalf, we may need to take reasonable steps to verify the authenticity of the request. These are security measures to ensure that personal data is not disclosed to any person who has no right to receive it. In an effort to speed up our response, we may also contact you to ask you for further information in relation to your request. To exercise your rights, please contact us at
dpo@majesticaenterprises.com
.
5. International Transfers
5.1 Majestica is based in Hong Kong and personal data may be processed in Hong Kong and other jurisdictions where our service providers operate.
5.2 Where personal data is transferred outside the EEA or the UK, we take reasonable steps to ensure that appropriate safeguards are implemented in accordance with applicable law. Such safeguards may include:
- (a) adequacy regulations or adequacy decisions recognised by applicable law;
- (b) Standard Contractual Clauses approved by the European Commission;
- (c) the UK International Data Transfer Addendum or other recognised transfer mechanisms; and/or
- (d) contractual, organisational and technical safeguards designed to provide an equivalent level of protection.
6. Updates & Contact Us
6.1 We may amend this GDPR Statement from time to time. Any updates will be published on this page and will take effect from the “Last Updated” date stated below.
6.2 If you have any questions regarding this GDPR Statement or how we process your personal data, please contact us at
dpo@majesticaenterprises.com
.
Last Updated: 1 August 2026
Majestica Enterprises Limited
Majestica Enterprises Limited