CityTrust

Privacy Policy

In case of any inconsistency, the Traditional Chinese version of this document shall prevail.

Last updated: July 2026

1. Introduction and Scope

CITYTRUST LIMITED (the "Company") takes the protection of personal data seriously. This Privacy Policy (the "Policy") explains how the Company collects, uses, stores, discloses and protects your personal data.

The Policy applies to all personal data collected through the Company's website (www.citytrust.com), mobile applications and other service channels. The Company complies with the six data-protection principles of the Personal Data (Privacy) Ordinance (Cap. 486, "PDPO") of Hong Kong and has regard to the best practices of the EU General Data Protection Regulation (GDPR).

2. Categories of Personal Data Collected

Subject to business needs and regulatory requirements, the Company may collect the following categories of personal data:

Basic identity data

  • name, date of birth, nationality, identity-card/passport numbers and copies;
  • contact address, email address, telephone number;
  • tax identification number (TIN) and tax residency.

Financial data

  • Source of Funds (SOF) and Source of Wealth (SOW) declarations and supporting documents;
  • bank account details and transaction records;
  • credit assessment and risk-tolerance information.

Technical data

  • IP address, browser type and version, device information;
  • data collected through cookies and similar technologies (see the Company's Cookie Policy).

3. Purposes and Legal Basis

The Company collects and processes your personal data for purposes including, without limitation:

  • performing customer due diligence (KYC) and anti-money-laundering (AML) obligations;
  • establishing and administering your account and providing the requested trust and related services;
  • processing transaction instructions and settlement with third-party service providers;
  • complying with applicable laws, regulations and regulatory requirements;
  • internal risk management, audit and compliance monitoring;
  • improving service quality and user experience.

4. Sharing and Disclosure

The Company does not sell your personal data. The Company may however disclose your data to third parties in the following circumstances:

  • Third-party execution institutions: to execute your transaction instructions, necessary data may be provided to external brokers, banks or card issuers;
  • Government and regulators: to discharge statutory reporting obligations under the CRS and FATCA, or upon lawful request by law-enforcement agencies;
  • Professional advisers: including lawyers, auditors and insurers, for legal advice, audit or claims handling;
  • Service providers: providers of IT, cloud storage, email delivery, customer support and other operational support to the Company (some located outside Hong Kong), which the Company requires to observe confidentiality and to process the entrusted personal data only on the Company's instructions.

5. Data Retention

Under Hong Kong anti-money-laundering requirements, the Company will retain customer due-diligence records and transaction records for at least 5 to 7 years after the end of the business relationship or closure of the account. During this mandatory retention period you may not require complete deletion of the relevant records.

After the statutory retention period, the Company will securely destroy or anonymise your personal data.

6. Data Security

The Company adopts reasonable technical and organisational measures to protect your personal data, including without limitation:

  • encryption of data in transit (TLS/SSL);
  • authentication and access controls;
  • regular security audits and staff training.

7. Your Rights

Under the PDPO you have the right to:

  • ascertain whether the Company holds your personal data and obtain a copy;
  • request correction of inaccurate personal data;
  • object to the use of your data for direct marketing.

The Company may charge a reasonable fee for processing a data-access request. Certain data may not be deletable owing to legal obligations (such as AML retention requirements).

8. Cross-border Data Transfers

To provide the Services and discharge statutory obligations, your personal data may be transferred to jurisdictions outside Hong Kong. The Company will ensure that any cross-border transfer complies with the PDPO and is protected by appropriate safeguards.

9. Use of Cookies

This Website uses cookies and similar technologies to maintain site functionality and improve user experience. For details, please refer to the Cookie Policy.

10. Changes to this Policy

The Company reserves the right to revise this Policy at any time. Material changes will be notified through this Website or by email. The revised Policy takes effect immediately upon publication.

11. Contacting the Data Protection Officer

If you have any questions about this Policy or wish to exercise your rights, please contact the Company's Data Protection Officer:

  • Email: ops@citytrust.com
  • Telephone: (852) 2518-8888
  • Address: Room 1905, 19/F, Harbour Centre, 25 Harbour Road, Wan Chai, Hong Kong