Legal
Privacy Policy
GEHT International Limited
1. About this policy
GEHT International Limited (“GEHT”, “we”, “us”, “our”) is an industrial sourcing and agency company supplying advanced semiconductor lasers, optical amplifiers, fiber components, optical fibers, laser drivers and photonics test and probe systems to industrial, telecommunications, medical, defence and research customers worldwide.
This policy explains how we collect, use, share and protect personal data when you:
- visit www.gehtinternational.com (the “Site”);
- submit an enquiry, quotation request or callback request through the Site;
- correspond with us by email, telephone or messaging;
- interact with us as a customer, supplier, principal, agent or business partner contact;
- subscribe to our news or technical updates; or
- meet us at a trade fair, exhibition or industry event.
Because we operate from Hong Kong with European operations in Helsinki, Finland, this policy is written to meet both:
- Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) together with the Finnish Data Protection Act (1050/2018) and the Finnish Act on Electronic Communications Services (917/2014); and
- the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (the “PDPO”) and its six Data Protection Principles.
Where the two regimes differ, we apply the standard that gives you the greater protection.
This policy does not cover the GEHT Marketplace platform at www.gehtmarketplace.com, which is a separate platform governed by its own privacy notice, or third-party websites we link to.
2. Who is responsible for your data
| Data controller | GEHT International Limited, a limited company incorporated in Hong Kong, Companies Registry number 62528517 |
|---|---|
| Registered office | Rooms 2702–3, 27/F, Bank of East Asia Harbour View Centre, 56 Gloucester Road, Wan Chai, Hong Kong SAR, People’s Republic of China |
| European customer contact | Helsinki, Finland (EU) — European customer relationships and institutional accounts. Visits by prior appointment. |
| Privacy contact | [email protected] |
| European enquiries | [email protected] — we answer enquiries from the EU and EEA in English |
“Controller” means the party that decides why and how your personal data is processed. Under the PDPO the equivalent concept is “data user”.
3. Personal data we collect
We deal principally with businesses. The personal data we hold is almost always business contact data about individuals acting in a professional capacity — not consumer data, and not special category data.
3.1 Data you give us
| Category | Examples | Where it comes from |
|---|---|---|
| Identity and contact data | Name, job title, company name, business email address, business telephone number | Site enquiry form, email, telephone, business cards, meetings |
| Enquiry data | Enquiry type (quotation, callback, other), the content of your message, product and specification interest, application and volume information | Site enquiry form, subsequent correspondence |
| Commercial relationship data | Order and quotation history, delivery and shipping contact details, invoicing and payment contacts, contractual correspondence | Direct dealings with you or your employer |
| Correspondence data | Emails, meeting notes, call records and the records of any support or complaint handling | Ongoing communications |
| Marketing preference data | Subscription status, consent records, opt-out records | Your elections; our records |
We do not ask you for special category data (Article 9 GDPR) or criminal offence data, and we ask that you do not include such information in free-text enquiry fields.
3.2 Data we collect automatically
| Category | Examples |
|---|---|
| Technical data | IP address, browser type and version, operating system, device type, screen resolution, language and time-zone settings |
| Usage data | Pages viewed, time on page, referring and exit pages, links clicked, approximate location derived from IP address |
| Cookie and identifier data | Cookie identifiers and similar technologies — see section 8 |
| Consent data | A record of the cookie choices you make, the categories accepted or refused, the date and time, and a truncated identifier — collected through our consent management platform, CookieYes |
Analytics data is collected through Google Analytics 4, deployed via Google Site Kit. We have configured Google Analytics with IP address handling as described in section 8. Consent records are kept as evidence that consent was validly obtained, as Article 7(1) GDPR requires.
3.3 Data we obtain from third parties
- Publicly available business sources: your employer’s website, corporate directories, industry databases and professional networks such as LinkedIn.
- Referrals and introductions from principals, manufacturers, agents and mutual business contacts.
- Service providers listed in section 6 who process data on our behalf.
Where we obtain your data indirectly, we provide the information required by Article 14 GDPR at the point of first contact or within one month, whichever is earlier.
3.4 Is it compulsory to give us your data?
No. Supplying your personal data to us is entirely voluntary.
You are not required to complete our enquiry form, subscribe to our updates, or give us any personal data at all. However, if you choose not to supply the information marked as required on a form, or the information we need to process an order:
- we will not be able to respond to your enquiry, prepare a quotation or arrange a call;
- we will not be able to accept, process, ship or invoice an order; and
- we will not be able to send you the technical updates you have asked for.
You have the right to request access to, and correction of, the personal data we hold about you. Requests should be sent to [email protected], or by post to GEHT International Limited, Rooms 2702–3, 27/F, Bank of East Asia Harbour View Centre, 56 Gloucester Road, Wan Chai, Hong Kong SAR. Section 11 explains how this works in full.
This statement is given for the purposes of Data Protection Principle 1(3) of the PDPO and Articles 13 and 14 of the GDPR.
3.5 Children
The Site is directed at business users. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact us and we will delete it.
4. Why we use your data, and our legal basis
Under the GDPR we must have a lawful basis for each processing purpose. Under the PDPO, DPP1 requires that data be collected for a lawful purpose directly related to our functions and be adequate but not excessive. The table below covers both.
| Purpose | Data used | GDPR lawful basis | PDPO position |
|---|---|---|---|
| Responding to your enquiry, preparing quotations, arranging calls | Identity, contact, enquiry | Art. 6(1)(b) — steps at your request prior to entering a contract; or Art. 6(1)(f) legitimate interests where you enquire on behalf of your employer | DPP1 — collection directly related to our sourcing and agency activity |
| Supplying products and services; managing orders, shipping, invoicing and after-sales support | Identity, contact, commercial relationship, correspondence | Art. 6(1)(b) — performance of a contract; or Art. 6(1)(f) where the contract is with your employer | DPP1, DPP3 — use consistent with the purpose of collection |
| Managing supplier, principal and agency relationships | Identity, contact, commercial relationship | Art. 6(1)(b) / Art. 6(1)(f) — managing our supply chain | DPP1, DPP3 |
| Sending technical updates, product news and marketing to business contacts | Identity, contact, marketing preference | Art. 6(1)(f) — legitimate interest in marketing to existing business customers; Art. 6(1)(a) consent where required by the ePrivacy rules | PDPO Part 6A — we notify you and obtain your consent or non-objection before using your data in direct marketing, and provide an opt-out in every message |
| Operating, securing and improving the Site; measuring audience and page performance | Technical, usage, cookie | Art. 6(1)(a) consent for non-essential cookies; Art. 6(1)(f) legitimate interest in the security and integrity of the Site | DPP1, DPP4 |
| Complying with legal, tax, accounting, customs and trade-compliance obligations | Identity, contact, commercial relationship | Art. 6(1)(c) — legal obligation; Art. 6(1)(f) where the obligation arises under non-EU law | DPP3 — permitted use; statutory exemptions under Part 8 PDPO |
| Export control, sanctions and end-user screening | Identity, contact, commercial relationship | Art. 6(1)(c) — legal obligation; Art. 6(1)(f) where the obligation arises under non-EU law or a principal’s compliance requirement | DPP1, DPP3; see section 4a |
| Establishing, exercising or defending legal claims; preventing fraud | All categories as relevant | Art. 6(1)(f) — legitimate interest in protecting our legal position | DPP3; Part 8 exemptions |
| Corporate transactions (merger, acquisition, financing or asset sale) | Identity, contact, commercial relationship | Art. 6(1)(f) — legitimate interest in conducting corporate activity | DPP3, with notice where required |
Legitimate interests. Where we rely on Article 6(1)(f), we have carried out a balancing assessment weighing our interest against your rights and freedoms. Because the data is business contact data used in a professional context and processed in ways you would reasonably expect, we consider the balance is met. You may request a summary of the relevant assessment using the contact details in section 12.
Change of purpose. We will only use your personal data for a new purpose where that purpose is compatible with the original one, or where we are required or permitted by law, or where you have consented. Under the PDPO, that consent must be prescribed consent within the meaning of section 2(3) — express, given voluntarily, and not withdrawn.
4a. Trade compliance and end-user screening
The products we supply — including high-power semiconductor lasers, LiDAR components and photonics test systems — are subject to export control and dual-use regulations in several jurisdictions.
As a Hong Kong company, our primary obligations arise under the Import and Export Ordinance (Cap. 60) and the Import and Export (Strategic Commodities) Regulations (Cap. 60G), administered by the Trade and Industry Department of the Hong Kong SAR Government. Hong Kong’s Strategic Commodities Control List mirrors the control lists of the Wassenaar Arrangement and the other international export control regimes, and no listed article may be imported or exported except under a licence issued by the Director-General of Trade and Industry. Depending on the origin of the goods and the destination, the export control and sanctions regimes of other jurisdictions may also apply.
As a matter of routine practice on orders, we screen the names of customer, end-user, consignee and intermediary contacts against sanctions and denied-party lists, and we retain records of that screening.
- Legal basis: Article 6(1)(c) GDPR where the obligation arises under applicable law, and Article 6(1)(f) where it arises under non-EU law or a contractual compliance requirement, our legitimate interest being lawful and licensable trade.
- Retention: screening records are kept for 10 years, reflecting the record-keeping periods commonly imposed by export control authorities.
- No automated decisions: screening does not involve automated decision-making producing legal or similarly significant effects. Any potential match is reviewed by a member of our staff before any action is taken, and you may contest the outcome using the contact details in section 12.
- Disclosure: where an export licence, end-user statement or customs declaration requires it, we disclose the relevant contact details to the competent authority, to the manufacturer or principal, and to our customs and freight agents.
5. Direct marketing
We market only to business contacts, and only about products and services relevant to their professional role. Our newsletters and technical updates are sent using Smaily, an email marketing platform operated by Sendsmaily OÜ (Estonia, EU), acting as our processor.
- If you are in the EEA: we send electronic marketing on the basis of consent, or on the “soft opt-in” where you are an existing customer contact and we are marketing similar products. Every message contains a one-click unsubscribe.
- If you are in Hong Kong: we do not currently send direct marketing to contacts in Hong Kong. Should that change, we will first comply with Part 6A of the PDPO — informing you of our intention to use your data in direct marketing, the kinds of data to be used and the classes of goods and services to be marketed, stating expressly that we will not use your data unless you consent, and giving you a channel through which to respond without charge. On any first use we would also inform you of your right to require us to stop at no cost.
In all cases: we do not provide, transfer or sell your personal data to any third party for that party’s own direct marketing purposes. You may require us to stop using your data for direct marketing at any time, free of charge, and we will comply without delay.
To opt out at any time, use the unsubscribe link in any message or write to [email protected].
6. Who we share your data with
We do not sell your personal data. We share it only as set out below.
| Recipient category | Purpose | Basis |
|---|---|---|
| Manufacturers, principals and suppliers whose products you enquire about | To obtain pricing, technical clarification and lead times, and — once an order is placed — to manufacture, pack and despatch it. Many of our manufacturing partners are located in mainland China and elsewhere in Asia | Necessary to respond to your enquiry or to perform the contract |
| Shipping and delivery contacts passed to manufacturers | Where goods ship directly from the manufacturer, we pass the delivery contact details needed to complete the shipment: first name, last name, company name, delivery address and telephone number. Nothing further is passed | Necessary to perform the contract |
| Logistics, freight forwarding and customs brokerage providers | Shipping, export documentation and customs clearance | Contract performance and legal obligation |
| IT and hosting providers, including our website host, email provider and CRM | Operating our systems | Processors acting on our documented instructions |
| Analytics providers — Google Ireland Limited / Google LLC | Website analytics | Your cookie consent |
| Consent management — CookieYes Limited (United Kingdom) | Presenting our cookie banner and recording your cookie choices | Processor; Art. 7(1) record of consent |
| Email marketing — Sendsmaily OÜ (“Smaily”, Estonia, EU) | Sending newsletters and technical updates, and managing subscriptions | Processor acting on our documented instructions |
| Professional advisers — auditors, accountants, lawyers, insurers, banks | Professional services and financing | Legitimate interests; legal obligation |
| Public authorities and regulators | Tax, customs, export control, court orders and lawful requests | Legal obligation |
| A purchaser or prospective purchaser of our business or assets, and their advisers | Corporate transactions | Legitimate interests, subject to confidentiality undertakings |
Where a recipient acts as a processor, we have a written contract in place meeting Article 28 GDPR and a comparable engagement under DPP2(3) and DPP4 of the PDPO.
Where a recipient acts as an independent controller — for example a manufacturer that receives your enquiry and contacts you directly — that party’s own privacy notice applies to its use of your data.
7. International transfers
GEHT is established in Hong Kong and works with suppliers, manufacturers and service providers in Asia, Europe and North America. Your personal data will therefore be transferred outside your own country, and outside the EEA.
Hong Kong has not been the subject of an adequacy decision by the European Commission. Transfers of personal data from the EEA to GEHT in Hong Kong, and onward to other non-adequate countries, are made under one or more of the following:
- an adequacy decision where one applies to the destination country. Our email marketing provider is established in Estonia, within the EEA, so no transfer arises. Our consent management provider is established in the United Kingdom, which benefits from a European Commission adequacy decision renewed in December 2025;
- the derogations in Article 49 GDPR — in particular Article 49(1)(b) and (c), where a transfer is necessary to perform a contract, and Article 49(1)(e) for the establishment, exercise or defence of legal claims. In practice this covers the majority of our transfers, because the data we transfer is the business contact data needed to supply and ship the products you have ordered;
Mainland China. Several of our manufacturing partners are located in mainland China, which is not the subject of an adequacy decision. Where goods ship directly from a manufacturer, we pass the delivery contact details needed to complete that shipment — first name, last name, company name, delivery address and telephone number — to the manufacturer and to the carriers and customs agents handling it. We do not pass enquiry or quotation data to manufacturers in mainland China for marketing or profiling purposes, and we do not pass more data than the shipment requires. These transfers are made under Article 49 GDPR pending completion of the Standard Contractual Clauses work described below;
- Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), supported by a transfer impact assessment and, where that assessment indicates it is required, supplementary technical and organisational measures such as encryption in transit and at rest. We are in the process of putting Standard Contractual Clauses in place across our EEA-facing counterparties and will update this section as that work completes.
In every case we transfer the minimum data needed, and we require recipients to keep it confidential and to use it only for the purpose we transferred it for.
In relation to Hong Kong law, section 33 of the PDPO, which regulates transfers of personal data outside Hong Kong, has been enacted but is not yet in force. The Privacy Commissioner has published recommended model contractual clauses for cross-border transfers, which are guidance rather than a legal requirement. We are working towards adopting those clauses alongside the Standard Contractual Clauses described above, and will update this section as that work completes. In the meantime, Data Protection Principles 2(3) and 4 continue to apply, and we use contractual and practical means to prevent recipients from keeping or using your data beyond the purpose we transferred it for.
You may request a copy of the safeguards we rely on — with commercially confidential terms redacted — by writing to [email protected].
8. Cookies and similar technologies
A cookie is a small text file placed on your device. We use cookies and similar technologies as set out below.
Our cookie banner and preference centre are provided by CookieYes Limited (3 Warren Yard, Warren Park, Wolverton Mill, Milton Keynes MK12 5NW, United Kingdom), acting as our processor. CookieYes presents your choices, blocks non-essential scripts until you consent, and stores a record of what you chose.
8.1 Consent
We set strictly necessary cookies without consent, because they are required to deliver the Site you have requested. We set all other cookies only after you have given consent through our cookie banner. Consent is:
- opt-in — no non-essential cookie is set before you act;
- granular — you may accept some categories and refuse others;
- as easy to refuse as to accept — “Reject all” appears alongside “Accept all” on the first screen of the banner, in the same size and position, and requires no additional steps; and
- withdrawable at any time — through the cookie settings button displayed on every page.
This reflects Article 5(3) of the ePrivacy Directive as implemented by section 205 of the Finnish Act on Electronic Communications Services (917/2014), and Articles 4(11) and 7 GDPR.
8.2 Categories we use
The category names below are those shown in our cookie banner and preference centre.
| Category | Purpose | Consent required | Typical retention |
|---|---|---|---|
| Necessary | Site security, and the CookieYes cookie that records your consent choices | No | Up to 12 months |
| Analytics | Google Analytics 4 — visitor counts, pages viewed, session duration, traffic sources, aggregated device and approximate location data | Yes | Up to 14 months |
We do not currently use functional, performance or advertising cookies, and we do not embed third-party content that sets cookies. If that changes, this policy and the cookie register will be updated before those cookies are set.
A current, itemised register listing each cookie name, provider, purpose and duration is maintained at /cookie-policy. It is generated from a scheduled scan of the Site and reviewed whenever we change the tools we use.
8.3 Google Analytics
Google Analytics 4 is provided by Google Ireland Limited for users in the EEA and by Google LLC elsewhere. Google processes the data as our processor for analytics purposes. GA4 does not log or store full IP addresses; IP addresses are used transiently to derive coarse geolocation and are then discarded. Data may be transferred to the United States under Google’s contractual and certification arrangements. You can also install Google’s browser opt-out add-on at tools.google.com/dlpage/gaoptout.
8.4 Browser controls and Do Not Track
You can block or delete cookies through your browser settings, or browse in private mode. Blocking strictly necessary cookies may prevent parts of the Site from working. The Site does not currently respond to “Do Not Track” browser signals, as no common standard for these has been agreed.
9. How long we keep your data
We keep personal data only as long as necessary for the purposes it was collected for, and to meet legal, accounting, tax and export-compliance requirements. Our standard periods are:
| Data | Retention period |
|---|---|
| Enquiries that do not lead to a business relationship | 24 months from last contact, then deleted |
| Customer, supplier and partner contact records | Duration of the relationship plus 7 years from the end of the last transaction |
| Contracts, orders, invoices and shipping documents | 7 years from the end of the relevant financial year, or longer where trade, customs or export-control law requires |
| Business correspondence | 7 years from the date of the correspondence |
| Export control and sanctions screening records | 10 years — see section 4a |
| Marketing subscription and consent records | Until you unsubscribe, plus 3 years to evidence the consent or opt-out |
| Suppression list (people who have opted out) | Retained indefinitely, minimally, solely so we do not contact you again |
| Website analytics data | Up to 14 months at event level; aggregated reporting thereafter |
| Cookie consent records | 12 months, as configured in CookieYes, after which you are asked again |
Where data no longer needs to be identifiable, we anonymise it rather than delete it, and may continue to use anonymised data indefinitely. Where deletion is not immediately possible — for example in backups — we isolate the data and delete it on the next scheduled backup cycle.
These periods give effect to section 26 of the PDPO, which requires us to erase personal data that is no longer required for the purpose it was used for, unless erasure is prohibited by law or it is in the public interest not to erase, and to Data Protection Principle 2(2). Under the GDPR they give effect to the storage limitation principle in Article 5(1)(e).
10. How we protect your data
We maintain technical and organisational measures appropriate to the risk, in line with Article 32 GDPR and DPP4 of the PDPO. These include:
- encryption of the Site in transit (TLS) and encryption of data at rest on our systems;
- access control on a need-to-know basis, with individual accounts and multi-factor authentication on business-critical systems;
- vetting of processors, and written data processing terms with each of them;
- backup, patching and malware controls;
- staff confidentiality obligations and periodic data protection awareness training;
- an incident response procedure covering detection, containment, assessment and notification.
Breach notification. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, in accordance with Article 33 GDPR, and will notify you directly where the risk is high (Article 34).
No transmission over the internet can be guaranteed completely secure. While we apply the measures above, any transmission you make to us is at your own risk.
11. Your rights
11.1 If the GDPR applies to you
You have the right to:
| Right | What it means |
|---|---|
| Access (Art. 15) | Obtain confirmation of whether we process your data and receive a copy of it |
| Rectification (Art. 16) | Have inaccurate data corrected and incomplete data completed |
| Erasure (Art. 17) | Have your data deleted where there is no continuing lawful ground to keep it |
| Restriction (Art. 18) | Have processing suspended in defined circumstances |
| Portability (Art. 20) | Receive data you provided to us in a structured, machine-readable format, where processing is based on consent or contract and is automated |
| Object (Art. 21) | Object to processing based on legitimate interests. You have an absolute right to object to direct marketing at any time, and we will stop |
| Withdraw consent (Art. 7(3)) | Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal |
| Not be subject to automated decision-making (Art. 22) | We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile you for such purposes |
We respond within one month, extendable by two further months for complex or numerous requests, in which case we will tell you within the first month. There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse it, giving reasons.
Complaints. You may lodge a complaint with a supervisory authority — in Finland, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Lintulahdenkuja 4, 00530 Helsinki, tietosuoja.fi — or with the authority in your country of residence or workplace. We would appreciate the chance to address your concern first.
11.2 If the PDPO applies to you
Under sections 18 and 22 of the PDPO you may make a data access request for a copy of your personal data, and a data correction request to correct data that is inaccurate.
- Time limit. We will comply within 40 days (section 19(1)). If we are unable to comply within that period, we will tell you so in writing within the 40 days, explain why, and then comply as soon as practicable (section 19(2)).
- Refusal. In the limited circumstances set out in section 20 we may or must refuse a request. If we refuse, we will tell you in writing and give our reasons, and we will keep a log of the refusal.
- Fees. The PDPO permits us to charge a fee for complying with a data access request. Any fee will not be excessive. We will charge only those costs directly related to and necessary for complying with your request — staff time actually spent and actual out-of-pocket costs. We will not recover general overheads and we make no profit on it. We will tell you the amount before we do the work, and you may withdraw your request at that point at no cost. No fee is charged for a data correction request, and none for requiring us to stop direct marketing.
- Direct marketing. You may require us at any time, free of charge, to cease using your data in direct marketing.
Complaints. You may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong, at pcpd.org.hk.
11.3 How to exercise your rights
Write to [email protected] or to the registered office in section 2. We may ask you for information to verify your identity — this is a security measure to ensure data is not disclosed to the wrong person.
Why the fee position differs. Sections 11.1 and 11.2 treat fees differently because the two statutes do. The GDPR prohibits charging for a subject access request; the PDPO expressly permits a cost-based fee. We apply whichever rule governs your request. If both could apply to you, we will not charge.
12. Contact
| General privacy enquiries | [email protected] |
|---|---|
| Post | GEHT International Limited, Rooms 2702–3, 27/F, Bank of East Asia Harbour View Centre, 56 Gloucester Road, Wan Chai, Hong Kong SAR |
| European enquiries | [email protected] — we answer enquiries from the EU and EEA in English |
| Data protection officer | We are not required to appoint a data protection officer under Article 37 GDPR. Privacy matters are handled by our Co-founder / Director, reachable at the address above. |
13. Third-party links
The Site contains links to third-party websites, including manufacturer and principal websites, LinkedIn and GEHT Marketplace. Following a link takes you to a site governed by that operator’s own privacy policy. We do not control those sites and accept no responsibility for their content or data practices. Please review their notices before submitting personal data.
14. Changes to this policy
We review this policy at least annually and update it whenever our processing changes materially. The current version and its effective date always appear at the top of this page. Where a change materially affects how we use your personal data, we will give you prominent notice — and, where the law requires it, obtain your consent — before the change takes effect. Previous versions are available on request.
15. Status of this policy and governing law
This policy is a notice explaining how we handle personal data. It is not a contract, and it does not form part of any contract between you and us or create contractual rights.
This policy and any dispute arising out of it are governed by the laws of the Hong Kong Special Administrative Region, and the courts of Hong Kong have jurisdiction. This does not affect any mandatory right you have under the GDPR or other applicable data protection law, including your right to bring a complaint before a supervisory authority in your own country or to bring proceedings in the courts of your own country where the law allows.
If any provision of this policy is held to be invalid or unenforceable, the remaining provisions continue in effect.
This privacy policy is a standalone document. Our website terms of use are published separately at /terms.
