FYDUS Logo
FYDUS

Privacy Policy

How the FYDUS Group handles personal data submitted through this website.

Effective date: 27 July 2026

1. Introduction

This Privacy Policy explains how the FYDUS Group handles personal data.

“FYDUS Group” means, collectively:

  1. FYDUS Limited, a trust or company service provider licensed in Hong Kong;
  2. FYDUS (M.E) Limited, a corporate services provider licensed in the Dubai International Financial Centre; and
  3. FYDUS S.EA Limited, a managed trust company licensed in Labuan, Malaysia.

Each FYDUS Group member is a separate legal entity. The FYDUS Group member responsible for a particular service, relationship or processing activity will depend on the circumstances, the relevant engagement and applicable law.

Our Network — FYDUS consists of a collection of companies operating in various jurisdictions. FYDUS is a member of a global professional network, which includes the international legal group M.B. KEMP and their affiliated businesses. For information about the regulatory status of the entity you are dealing with, please contact [email protected].

This Privacy Policy applies to the FYDUS Group’s website at www.fydus.one and to personal data submitted through the website’s contact form.

2. Personal data collected through the website

The website is primarily informational. However, visitors may submit personal data through the website’s contact form. The information collected may include:

  • name;
  • email address;
  • telephone number, if provided or requested;
  • company name, job title or other business details;
  • the content of the visitor’s enquiry;
  • any other information voluntarily included in the enquiry; and
  • technical and security information associated with the submission, such as IP address, date and time of submission, browser details and information used to detect spam or abusive submissions.

Visitors should not submit passports, identity documents, financial information, confidential client information, information concerning beneficial ownership or other sensitive information through the contact form unless the relevant FYDUS Group member has specifically requested it and has provided an appropriate secure method of transmission.

3. How we obtain personal data

We obtain personal data:

  • directly from visitors who complete and submit the contact form;
  • from persons who correspond with us by email or other means following a website enquiry;
  • from an individual’s employer, organisation or professional adviser where they submit an enquiry on another person’s behalf; and
  • automatically through technical, hosting, security and anti-spam systems used to operate the website and contact form.

Visitors should ensure that any personal data they provide concerning another person has been provided lawfully and that the relevant person has been informed, where required.

4. Purposes of processing

We may use personal data submitted through the contact form to:

  • receive, record and respond to enquiries;
  • identify the enquirer and understand the nature of the enquiry;
  • assess whether a FYDUS Group member, or a member of the M.B. KEMP group, may be able to provide requested services;
  • communicate with the enquirer about a potential or existing business relationship;
  • arrange meetings or further communications;
  • carry out preliminary conflict of interest, risk, regulatory or compliance checks (including network-wide checks across the FYDUS and M.B. KEMP groups);
  • facilitate integrated service delivery and network administration;
  • prevent spam, fraud, misuse and security incidents;
  • maintain records of communications and enquiries;
  • improve the website and our enquiry-handling processes; and
  • establish, exercise or defend legal rights.

We will not use contact-form information for unrelated purposes unless permitted or required by applicable law.

5. Legal and regulatory basis

The applicable legal basis depends on the relevant jurisdiction and the circumstances. We may process contact-form personal data where processing is:

  • necessary to respond to an enquiry or take steps at the individual’s request before entering into a contract;
  • necessary for our legitimate interests in administering enquiries, developing business relationships, conducting network-wide conflict checks, maintaining records and protecting our systems;
  • necessary to comply with a legal or regulatory obligation;
  • necessary to establish, exercise or defend legal claims; or
  • based on consent, where consent is required (for example, if we request your consent to share your details with the M.B. KEMP group for cross-marketing purposes).

Submitting an enquiry does not, by itself, guarantee that a FYDUS Group member or an M.B. KEMP group member will accept the enquirer as a client or provide any service. Further personal data and verification information may be required before a business relationship can be established.

6. Disclosure of personal data

We may disclose contact-form personal data, where appropriate and permitted by law, to:

  • the relevant FYDUS Group member and other FYDUS Group companies;
  • members of the international legal group M.B. KEMP and their affiliated businesses, for the purposes of conflict checking, integrated service delivery, network administration, or where you have requested services that they provide;
  • employees, officers and authorised personnel who need the information to handle the enquiry;
  • professional advisers and service providers;
  • website hosting, email, customer-relationship-management and contact-form providers;
  • spam-filtering, fraud-prevention and information-security providers;
  • technology and cloud-service providers supporting the website or our business;
  • regulators, licensing bodies, governmental authorities and law-enforcement bodies where required or permitted by law; and
  • courts, tribunals, arbitrators and other dispute-resolution bodies where necessary.

We do not sell personal data. Third-party providers and network affiliates may process personal data on our behalf or in connection with the services provided. We will take reasonable steps to ensure that relevant recipients are subject to appropriate confidentiality, security and data-processing obligations.

7. Contact-form providers and email

Contact-form submissions may be transmitted to and stored by:

  • the website hosting provider;
  • the provider of the website form or content-management system;
  • the email provider used by the relevant FYDUS Group member; and
  • security or anti-spam providers.

Those providers may process personal data in jurisdictions outside the jurisdiction in which the visitor is located.

8. International transfers

The FYDUS Group operates across Hong Kong, the DIFC and Labuan. Furthermore, the M.B. KEMP group operates internationally. Personal data may therefore be transferred between those jurisdictions.

Personal data may also be transferred to service providers located in other jurisdictions, including jurisdictions in which website hosting, email, cloud, security or customer-relationship-management services are provided.

Where required by applicable law, we will implement appropriate safeguards for international transfers. These may include contractual protections (such as intra-group data sharing agreements), approved transfer mechanisms, adequacy arrangements, regulatory permissions, consent or another lawful transfer mechanism.

9. Retention of contact-form information

We retain contact-form information only for as long as reasonably necessary for the purposes described in this Privacy Policy. Typically, we may retain an enquiry:

  • for as long as necessary to respond to and manage the enquiry;
  • for a reasonable period after the last communication where the enquiry may result in a business relationship;
  • for longer where required for legal, regulatory, compliance, accounting, tax, professional or dispute-resolution purposes; or
  • for the period required by the applicable FYDUS Group member’s retention policy.

If the enquiry does not result in a business relationship, we will normally delete or securely archive the information when it is no longer reasonably required, subject to applicable legal and regulatory retention obligations.

10. Cookies and similar technologies

At the date of this Privacy Policy, www.fydus.one does not intentionally use optional analytics, advertising, social-media or behavioural-tracking cookies.

The website or contact form may use strictly necessary technical technologies for purposes such as:

  • maintaining the security and functionality of the form;
  • preventing automated or abusive submissions;
  • preserving form-session information;
  • routing a submission to the relevant email account; and
  • monitoring technical failures.

Website hosting, security and infrastructure providers may also maintain technical logs, which may include IP addresses and access information. These technologies are not used by FYDUS Group for advertising or behavioural profiling. If the website later introduces analytics, marketing, advertising or other non-essential technologies, the website will be updated and an appropriate consent or preference mechanism will be implemented where required.

11. Security

We use reasonable technical and organisational measures designed to protect personal data against unauthorised or unlawful access, use, alteration, disclosure, loss or destruction. These measures may include access controls, secure email and hosting arrangements, anti-spam protections, malware controls, backups and staff confidentiality obligations.

No online submission method is entirely secure. Visitors should not include confidential, sensitive or identity-document information in the contact form.

12. Regulated and client-related information

The contact form is intended for general enquiries. It is not intended to collect the detailed information required for onboarding, customer due diligence, beneficial-ownership verification, trust administration or regulated services.

If a potential client wishes to proceed, the relevant FYDUS Group member (or M.B. KEMP group member) may request further information through a separate and more secure process. That information may include identity, ownership, financial, tax, source-of-funds, source-of-wealth and other compliance information.

The processing of such information will also be subject to applicable legal, regulatory and professional obligations, including customer due diligence, anti-money laundering, counter-terrorist financing and sanctions requirements.

13. Data-subject rights

Subject to applicable law and relevant exemptions, an individual may have rights to:

  • request access to personal data;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to particular processing;
  • withdraw consent where processing is based on consent;
  • request data portability where applicable; and
  • complain to the relevant data-protection authority.

These rights are not absolute. They may be limited where the FYDUS Group is required or permitted to retain or process information for legal, regulatory, anti-money laundering, sanctions, fraud-prevention, litigation or other legitimate purposes.

14. Complaints and contact

For privacy enquiries, requests or complaints, please contact the Privacy Contact at FYDUS Group:

A request should contain sufficient information to identify the relevant individual and explain the nature of the request. We may need to verify the requester’s identity before responding. Where a request concerns a particular service or relationship, the relevant FYDUS Group member will handle it in accordance with the applicable law and regulatory requirements.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, website functionality, technology, legal obligations or data-protection practices. The current version will be published on www.fydus.one with the applicable effective date.

16. Separate legal entities

Nothing in this Privacy Policy makes the FYDUS Group members or the M.B. KEMP group members a single legal entity or creates joint liability between them.

The entity responsible for a particular service or processing activity will be determined by the relevant engagement, service terms, applicable law and regulatory requirements.

Get in Touch