1. Introduction and Scope
MAVERICK 360 LIMITED, a company duly incorporated in Hong Kong with its registered address at Rm 8 13/F Multifield Plaza, 3 Prat Avenue, Tsim Sha Tsui, Hong Kong, is committed to protecting the privacy and personal data of every individual who interacts with our website, services, and digital platforms. This Privacy Policy document describes in comprehensive detail the types of information we may collect, the methods and purposes for which we process that information, the third parties with whom data may be shared under specific circumstances, and the technical, administrative, and organizational safeguards we have implemented to protect your privacy rights.
Maverick 360 operates as a computer systems design and integration firm serving enterprise clients across Asia-Pacific, North America, and Europe. In the course of our operations, we may process personal data relating to client representatives, website visitors, job applicants, subcontractors, and other business contacts. This policy applies to all personal data processed through our website at https://www.maverick360.mom, any subdomains, mobile applications, API endpoints, and any other digital service that links to this policy.
By accessing our website or engaging our professional services, you acknowledge that you have read and understood the practices described in this Privacy Policy. If you do not agree with any part of this policy, you should discontinue use of our website and refrain from submitting personal information through our contact forms or other data collection channels.
2. Data Controller Identity
For the purposes of the Hong Kong Personal Data Privacy Ordinance (Cap. 486) and to the extent applicable, the European Union General Data Protection Regulation (GDPR) and other international data protection instruments, the data controller responsible for your personal information is:
MAVERICK 360 LIMITED
Registered Office: Rm 8 13/F Multifield Plaza, 3 Prat Avenue, Tsim Sha Tsui, Hong Kong
Email: team@maverick360.mom
Phone: +1 406 831 8026
Website: https://www.maverick360.mom
Maverick 360 takes its obligations as a data controller seriously. We have appointed internal data protection personnel who oversee compliance with this policy and applicable data protection legislation. Any questions, concerns, or requests regarding personal data handling should be directed to the contact details provided above.
3. Information We Collect
3.1 Information You Provide Voluntarily
When you interact with Maverick 360 through our website contact forms, email communications, service inquiries, consultation booking systems, or direct correspondence with our engineering team, we collect the following categories of personal information that you voluntarily submit:
- Identity Information: First name, last name, job title, and professional designation.
- Contact Information: Business email address, company name, telephone number, and mailing address.
- Professional Information: Details about your organization, including company size, industry sector, current technology stack, and infrastructure environment.
- Project Information: Descriptions of your systems challenges, technical requirements, budget parameters, timeline expectations, and any documents or architectural diagrams you upload or reference during pre-engagement discussions.
- Communication Records: The content of email exchanges, meeting notes, support tickets, and any other correspondence between you and Maverick 360 personnel.
3.2 Information Collected Automatically
When you visit our website, certain technical information is collected automatically through server logs, analytics tools, and browser interactions. This category includes:
- Device and Browser Data: Internet Protocol (IP) address, browser type and version, operating system, device type and manufacturer, screen resolution, and language preferences.
- Usage Data: Pages visited, time spent on each page, referring and exit URLs, click patterns, scroll depth, form interaction data, and search terms used to reach our website.
- Network Information: Internet service provider details, network type, approximate geographic location derived from IP address (city and country level only), and connection speed indicators.
- Session Data: Session identifiers, timestamps, and interaction event logs that help us understand how visitors navigate our digital properties.
This automatically collected information is processed in aggregated and anonymized form wherever possible. We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.
3.3 Cookies and Similar Technologies
Our website uses first-party cookies and similar tracking technologies for essential functionality, performance monitoring, and security purposes. The cookies we deploy fall into the following categories:
- Essential Cookies: These are strictly necessary for the operation of our website. They enable core functionality such as page navigation, secure form submissions, and load balancing. The website cannot function properly without these cookies.
- Performance Cookies: These collect anonymized information about how visitors use our website, including which pages are most frequently accessed and whether users encounter error messages. We use this data exclusively to improve website performance and user experience.
- Security Cookies: These support our security infrastructure by helping to detect and prevent malicious activity, including cross-site request forgery attacks and automated bot traffic.
We do not deploy advertising cookies, third-party tracking cookies for marketing purposes, or social media pixels. Maverick 360 does not sell, rent, or trade cookie-derived data to any external parties. You may configure your browser to refuse all cookies or to alert you when cookies are being sent. Please note that disabling essential cookies may impair the functionality of certain website features.
4. Legal Basis and Purposes of Processing
Maverick 360 processes personal data on the following legal bases, as appropriate under applicable data protection legislation:
4.1 Legitimate Business Interests
A significant portion of our data processing activities is grounded in the legitimate interests of Maverick 360 to operate and grow our computer systems design business. These legitimate interests include:
- Responding to inquiries submitted through our website contact forms and providing prospective clients with information about our services, capabilities, and engagement models.
- Evaluating whether a prospective engagement falls within our technical expertise and operational capacity, and determining the appropriate engineering resources to allocate.
- Maintaining business records of communications, proposals, and project documentation for internal reference, quality assurance, and continuity planning.
- Improving our website content, navigation structure, and technical performance based on aggregated usage analytics.
- Protecting our network infrastructure, digital assets, and client data against unauthorized access, cyber threats, and security incidents through monitoring and logging.
- Sending occasional service-related communications about updates to our capabilities, technology partnerships, or relevant industry developments to existing clients and active prospects who have expressed interest.
We have conducted and documented legitimate interest assessments to ensure that our data processing does not override the fundamental rights and freedoms of the individuals whose data we process. You have the right to object to processing based on legitimate interests at any time, as described in Section 8 below.
4.2 Contractual Necessity
Where you engage Maverick 360 for professional services, we process personal data as necessary for the performance of the contractual agreement between our organizations. This includes processing contact details for project communication, invoicing and payment processing, deliverable distribution, and support arrangements throughout the engagement lifecycle.
4.3 Legal Obligations
Maverick 360 may process personal data as required to comply with applicable laws and regulations, including but not limited to Hong Kong company law, tax and accounting obligations, anti-money laundering requirements, and any lawful requests from regulatory authorities or law enforcement agencies with competent jurisdiction.
4.4 Consent
In specific circumstances where neither legitimate interests, contractual necessity, nor legal obligation applies, Maverick 360 will request your explicit consent before processing personal data. Consent may be withdrawn at any time by contacting us using the details in Section 11. Withdrawal of consent does not affect the lawfulness of processing conducted prior to the withdrawal.
5. Data Sharing and Third-Party Disclosures
Maverick 360 does not sell, rent, trade, or otherwise monetize personal data. We share personal information only in the following limited circumstances and always under appropriate contractual safeguards:
5.1 Service Providers and Infrastructure Partners
We engage carefully vetted third-party service providers to support our business operations. These providers act as data processors and are bound by contractual agreements that mandate compliance with our data protection standards. Categories of service providers include:
- Cloud hosting and infrastructure providers that host our website, email systems, and internal collaboration platforms.
- Email delivery services used for business correspondence and service-related communications.
- Analytics platforms that provide aggregated and anonymized website usage statistics.
- Professional services automation platforms used for project management and client communications.
5.2 Legal and Regulatory Disclosures
We may disclose personal data when such disclosure is reasonably necessary to comply with a legal obligation, respond to lawful requests from public authorities, enforce our contractual terms, protect the rights and safety of Maverick 360 and its personnel, or investigate and defend against legal claims or allegations of wrongdoing.
5.3 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or a portion of Maverick 360 business assets, personal data held by us may be transferred to the acquiring entity as part of the transaction. You will be notified via email and a prominent notice on our website of any change in ownership or control of your personal data, as well as any choices you may have regarding your information.
5.4 International Data Transfers
As a Hong Kong-based organization serving clients globally, Maverick 360 may transfer personal data to countries outside the data subjects jurisdiction of origin. When we transfer data internationally, we implement appropriate safeguards in accordance with applicable data protection laws, including but not limited to standard contractual clauses, adequacy decisions, and binding corporate rules where applicable. Our primary data hosting infrastructure is located in facilities that maintain internationally recognized security certifications.
6. Data Retention
Maverick 360 retains personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our retention periods are determined by the following criteria:
- Inquiry Data: Information submitted through contact forms from prospects who do not proceed to engagement is retained for a maximum of twenty-four months from the date of last communication, after which it is securely deleted or anonymized.
- Client Engagement Data: Personal data related to active and completed client engagements is retained for a period of seven years following the conclusion of the engagement to comply with Hong Kong tax and accounting obligations, and to maintain business continuity records.
- Website Analytics Data: Aggregated and anonymized usage data may be retained indefinitely for trend analysis and performance benchmarking. Individual session logs containing IP addresses are retained for a maximum of ninety days.
- Communication Records: Business correspondence is retained in accordance with our document retention policy, generally for a period of five years from the date of the communication.
Upon expiry of the applicable retention period, personal data is either irreversibly anonymized or securely deleted using industry-standard data destruction methods. We periodically review our data holdings to identify and purge information that is no longer required.
7. Data Security
Maverick 360 implements and maintains a comprehensive suite of technical, administrative, and physical security measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. Our security program includes the following controls:
- Transport Layer Security (TLS) encryption for all data transmitted between your browser and our servers, enforced through HTTPS with current-generation certificate authorities.
- Encryption at rest for stored personal data using AES-256 or equivalent encryption standards on all production storage volumes and backup media.
- Logical access controls including role-based access management, multi-factor authentication, and the principle of least privilege applied to all systems that process personal data.
- Network security controls including next-generation firewalls, intrusion detection and prevention systems, distributed denial-of-service mitigation, and continuous network traffic monitoring.
- Regular vulnerability assessments and penetration testing conducted by qualified security professionals on an annual basis and following any significant infrastructure change.
- Security awareness training for all Maverick 360 personnel covering data protection obligations, phishing recognition, secure coding practices, and incident reporting procedures.
- Business continuity and disaster recovery plans with defined Recovery Time Objectives and Recovery Point Objectives, tested on a semi-annual basis.
- Strict vendor security assessment process requiring all third-party service providers to demonstrate compliance with our security requirements before being granted access to any systems or data.
While we implement robust security measures, no method of electronic storage or transmission over the Internet is absolutely secure. Maverick 360 cannot guarantee the absolute security of personal data. In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals and relevant supervisory authorities in accordance with applicable breach notification laws.
8. Your Data Protection Rights
Depending on your jurisdiction of residence and the applicable data protection framework, you may exercise the following rights with respect to the personal data held by Maverick 360:
8.1 Right of Access
You have the right to request confirmation of whether Maverick 360 processes personal data relating to you, and to receive a copy of that data along with information about the purposes of processing, categories of data, recipients, retention periods, and the source of the data if it was not collected directly from you.
8.2 Right of Rectification
You may request the correction of inaccurate or incomplete personal data that we hold about you. We will promptly update our records upon verification of the corrected information.
8.3 Right of Erasure
Under certain circumstances, you may request the deletion of your personal data. This right is not absolute and may be limited by our legal obligations to retain certain records, or by the necessity of the data for the establishment, exercise, or defense of legal claims.
8.4 Right to Restriction of Processing
You may request that we restrict the processing of your personal data in specific situations, such as when you contest the accuracy of the data or object to the processing, for a period enabling us to verify the basis for continued processing.
8.5 Right to Data Portability
Where processing is based on consent or contractual necessity and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another data controller without hindrance.
8.6 Right to Object
You have the right to object at any time to the processing of your personal data where the processing is based on legitimate interests. Upon receiving a valid objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where the processing is necessary for legal claims.
8.7 Rights Regarding Automated Decision-Making
Maverick 360 does not engage in automated individual decision-making, including profiling, that produces legal effects or similarly significant effects on natural persons. Should this practice change in the future, we will update this policy and provide mechanisms for human intervention.
8.8 How to Exercise Your Rights
To exercise any of the rights described above, please contact us at team@maverick360.mom with the subject line Data Protection Request. We will acknowledge receipt of your request within five business days and provide a substantive response within thirty calendar days. Where the request is complex or numerous, we may extend the response period by an additional sixty days, in which case we will inform you of the extension and the reasons for the delay within the initial thirty-day period.
We may request proof of identity before processing certain requests to ensure that personal data is not disclosed to unauthorized parties. Maverick 360 does not charge a fee for exercising data protection rights unless the request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or decline to act on the request.
9. Childrens Privacy
The Maverick 360 website and services are designed exclusively for business-to-business engagement and are not intended for use by individuals under the age of eighteen. We do not knowingly collect, solicit, or process personal data from children. If we become aware that personal data from a child has been inadvertently collected, we will take immediate steps to delete that information from our systems. Parents or legal guardians who believe their child has provided personal data to Maverick 360 should contact us promptly using the details in Section 11.
10. Third-Party Websites and Services
Our website may contain hyperlinks to external websites, platforms, and resources operated by third parties that are not under the control of Maverick 360. This Privacy Policy applies solely to information processed through Maverick 360-owned digital properties. We are not responsible for the privacy practices, content, or security of any third-party websites. We encourage you to review the privacy policies of every website you visit, particularly before submitting any personal information. The inclusion of a hyperlink does not imply endorsement by Maverick 360 of the linked website or its operators.
11. Contact, Complaints, and Supervisory Authority
If you have any questions, concerns, or complaints regarding this Privacy Policy or the data protection practices of Maverick 360, please contact us through any of the following channels:
Email: team@maverick360.mom
Phone: +1 406 831 8026
Postal Address: MAVERICK 360 LIMITED, Rm 8 13/F Multifield Plaza, 3 Prat Avenue, Tsim Sha Tsui, Hong Kong
We take all privacy complaints seriously and will investigate each matter thoroughly. Our data protection team will acknowledge your complaint within five business days and provide a detailed response within thirty calendar days.
If you are dissatisfied with our response or believe that your data protection rights have been infringed, you have the right to lodge a complaint with a relevant supervisory authority. In Hong Kong, the competent authority is the Office of the Privacy Commissioner for Personal Data (PCPD). For individuals located in the European Economic Area or the United Kingdom, you may lodge a complaint with the data protection authority in your Member State or with the UK Information Commissioners Office (ICO), respectively.
12. Policy Updates and Version History
Maverick 360 reserves the right to modify or update this Privacy Policy at any time to reflect changes in our data processing practices, legal obligations, or operational requirements. When we make material changes to this policy, we will:
- Post the revised policy on this page with an updated effective date.
- Display a prominent notice on the Maverick 360 website homepage for a period of at least thirty days following the change.
- For clients with active engagements, provide direct email notification of material changes that affect their data processing arrangements.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal information. Continued use of the Maverick 360 website following the posting of changes constitutes acceptance of the revised policy. If you do not agree with the updated terms, you should discontinue use of our website and services.
This Privacy Policy was last revised and published on July 20, 2026. This version supersedes all prior versions of the Maverick 360 Privacy Policy.
Maverick 360 is a trade name of MAVERICK 360 LIMITED, a company registered in Hong Kong. All references to Maverick 360 in this policy shall be construed as references to MAVERICK 360 LIMITED, including its officers, employees, agents, and authorized subcontractors, where the context so permits.