Privacy Policy
Last updated: 28 August 2026
This Privacy Policy explains how Lacomo Limited collects, uses, stores, and protects information when you visit the lacomo.lol website or use the systems design and integration services offered there. The website and all of the services described on it are developed and operated by the developer Lacomo, on behalf of Lacomo Limited, a company incorporated in Hong Kong with its registered office at Rm 1603 16/F THE L PLZ, 367-375 QUEENS RD C, Sheung Wan, Hong Kong (HK). We take the protection of information seriously, and we have written this Policy in plain language so that you can see clearly what we do. We encourage you to read this Policy in full before you use our website or engage us to do work.
1. Introduction
Lacomo Limited provides computer systems design and related services, including systems architecture design, software and platform integration, cloud and infrastructure engineering, security and compliance advisory, managed IT operations, and round-the-clock technical support. To deliver these services we handle information about the people who visit our website, the people who enquire about our services, and the clients and organisations whose systems we design, integrate, and operate. This Policy describes our approach to that information in a single document, so that you can understand what we collect, why we collect it, and what you can do about it.
This Policy applies to everyone who interacts with Lacomo Limited, whether you are browsing our website, submitting an enquiry, signing a proposal, or receiving managed services under a service agreement. Where a separate service agreement or data processing agreement contains terms about information handling, those terms apply to the engagement they cover, and this Policy applies everywhere else. If you have any question that this Policy does not answer clearly, please contact us using the details in the Contact Us section and we will explain the position to you directly.
By using our website or engaging our services, you acknowledge that you have read and understood this Policy. If you do not agree with any part of this Policy, please do not use our website or our services. We review this Policy regularly and we will revise it whenever our practices change, as described in the Changes to This Policy section below.
2. Information We Collect
We collect information in two broad categories: information that you give us directly, and information that we observe when you use our website or services. We collect only the information that is reasonably necessary for the purposes described in this Policy, and we do not deliberately collect information that goes beyond what the website or the services require.
The first category is information you provide to us directly. This includes your name, your email address, your telephone number, your company name, your job title, and any details you choose to include in a contact form, an email, a telephone call, or a project brief. When you become a client, we may also collect billing details, the addresses of systems we manage under an agreement, and the contact details of the people we work with at your organisation.
The second category is technical information that we observe automatically. This includes your IP address, the type of browser you use, your operating system, the pages you view on our website, the date and time of each visit, the address of the page that referred you, and similar diagnostic information collected through standard server logs and analytics tools. This technical information helps us keep the website secure and helps us understand how visitors use it.
3. Information from Managed Systems
When we provide managed IT operations or integration services, we are given access to systems, platforms, and data that belong to our clients. This is a different category of information from the personal information described above, because it is collected for the purpose of operating the client environment under an agreement.
This information includes system configuration, access credentials granted for the purpose of the engagement, logs generated by the client systems, data held in client databases, and records of the support requests raised under the agreement. We treat this information as strictly confidential and we use it only to deliver the services described in the applicable agreement, to keep the client systems secure, and to respond to incidents.
We keep the managed data of one client separate from the managed data of any other client, and we never mix client environments or use one client data to improve or test the systems of another client. The client remains the owner and controller of its data, and we act as a processor on its instructions. Our obligations in relation to managed data are set out in the service agreement and in these Terms, and this Policy should be read alongside those documents.
4. How We Use Information
We use the information we collect to operate, improve, and secure our website and services. In practice this means we use your contact details to respond to enquiries, to prepare proposals, to send you information you have requested, and to manage our relationship with you as a client. We do not send unsolicited marketing to people who have only visited the website, and we never sell or rent contact details to third parties.
We use technical configuration data and access credentials to design, build, integrate, monitor, and maintain the systems we manage on your behalf, and to provide the support and incident response described in our service standards. We use billing details to issue invoices and to process payments. We use website analytics data to understand how visitors move through our site, to diagnose technical faults, and to improve the structure and usefulness of our content.
We may also use information to meet legal obligations, to enforce our agreements, to prevent fraud or abuse, to protect the rights and safety of Lacomo Limited, our clients, and the public, and to exercise or defend legal claims. Whenever we use information for a purpose not described here, we will first confirm that the use is compatible with the purpose for which the information was collected, and we will update this Policy if the practice becomes a regular one.
5. Legal Bases for Processing
Where applicable law requires a lawful basis for processing personal information, we rely on one or more of the following bases, chosen according to the circumstances and the type of information involved.
Performance of a contract: we process the information necessary to deliver the services you have engaged us to provide, including integration, engineering, security, and support work. Without this information we could not perform the engagement. Legitimate interests: we process website analytics, maintain the security of our systems, improve our services, and communicate with prospective clients in ways that are proportionate and that respect your rights. We weigh our legitimate interests against your interests and fundamental rights before relying on this basis.
Consent: where we ask for your consent for a specific use, such as a marketing newsletter, you are free to withdraw that consent at any time by contacting us at the details below, and we will stop the use without penalty. Legal obligation: we process information where we are required to do so by law, by regulation, or by a competent authority. If you have questions about the basis on which we process your information, contact us and we will explain the specific basis that applies to your situation.
7. Data Retention
We keep personal information only for as long as it is needed for the purposes described in this Policy, or for as long as the law requires us to keep it. When information is no longer needed, we delete it or make it unidentifiable in a secure manner, and we document the deletion so that we can demonstrate compliance.
Contact and proposal information is retained while an enquiry is active and for a reasonable period afterwards, so that we can respond to follow-up questions and so that a proposal can be reissued if you return to it. Client project records, including technical configuration and support history, are retained for the duration of the agreement and for a period afterwards that is reasonable to support warranty obligations, audits, and continuity of service.
Billing and financial records are retained for the period required by applicable tax and accounting law in Hong Kong. Website logs are retained for a limited period and then deleted or anonymised so that they no longer identify individual visitors. You may request deletion of your personal information at any time, subject to any legal obligation that requires us to keep it, and we will honour a valid request promptly.
8. International Transfers
Lacomo Limited operates primarily from Hong Kong, and our registered office is at Rm 1603 16/F THE L PLZ, 367-375 QUEENS RD C, Sheung Wan, Hong Kong (HK). Depending on the services you use, information may be processed by trusted providers located in other jurisdictions, including providers of cloud infrastructure, monitoring, and support tools that we have engaged under contract.
Where we transfer personal information across borders, we take reasonable steps to ensure that it is protected to a standard consistent with this Policy and with applicable law. We rely on recognised transfer mechanisms where they are required, such as standard contractual clauses, and we review the security practices of our providers before we engage them and on a regular basis afterwards.
The protection of your information is not diminished by the fact that a server is located in another country. Our contracts bind our providers to the standards in this Policy regardless of where they operate, and we verify compliance through the access and audit rights in those contracts. If you have questions about where your information is stored or how it is protected in transit, please contact us and we will give you a clear answer.
9. Data Security
We apply technical and organisational measures to protect personal information against unauthorised access, loss, alteration, and disclosure. These measures are reviewed regularly and strengthened whenever our risk assessment identifies a need.
Our measures include access controls based on the principle of least privilege, so that every person who works on your account can reach only what their role requires; encryption of data in transit using secure protocols; encryption of sensitive data at rest; continuous monitoring of our own infrastructure; regular review of our security configurations; and training for our staff on the handling of information.
We follow a defence in depth model across every system we manage for our clients, and we test our controls regularly through vulnerability scanning and configuration review. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work continuously to keep our safeguards strong and current. If you believe your information is at risk, contact us immediately at the details below and we will act to contain and resolve the issue without delay.
10. Your Privacy Rights
You have rights in relation to your personal information, subject to the law that applies in your jurisdiction. These rights may include the right to access the information we hold about you, the right to request correction of information that is inaccurate, the right to request deletion of your information, the right to restrict or object to certain processing, and the right to data portability where it applies.
To exercise any of these rights, send a written request to the contact details in the Contact Us section of this Policy. We will respond to your request within the period required by applicable law, and we will explain any reason why a request cannot be honoured in full.
We may ask you to verify your identity before we act on a request, so that we can be sure we are releasing information only to the person entitled to it. We will not discriminate against you for exercising your privacy rights, and we do not charge a fee for reasonable requests. If you are not satisfied with our response, you also have the right to complain to the data protection authority in your jurisdiction, and we will cooperate fully with any such authority.
12. Marketing Communications
We send marketing communications only where we have a lawful basis to do so, which is normally your consent or an existing business relationship. If you tell us you would like to hear about our services, we may send you occasional updates about our work, our service standards, and relevant technology changes that may affect your systems.
Every marketing message we send includes a simple way to opt out, and we honour every opt-out request promptly. You can also tell us at any time, by email or telephone, that you no longer wish to receive marketing material, and we will update our records so that you hear from us only about the services you actually use.
Opting out of marketing does not affect the service messages we send you as a client, such as invoices, support notifications, security alerts, and reports we are required to deliver under your agreement. Those messages are part of the service, not part of marketing, and they will continue while the engagement continues.
13. Privacy for Children
Our website and services are intended for businesses and professionals, and they are not directed to children. We do not knowingly collect personal information from children under the age of 16, and we have designed our processes so that the information we collect normally concerns organisations and the adults who represent them.
If you are a parent or guardian and you believe your child has provided personal information to us, contact us using the details in the Contact Us section of this Policy, and we will take steps to remove that information from our records and to confirm in writing what we have done.
We encourage parents and guardians to supervise the online activity of children and to contact us promptly if they have any concern about the handling of information. We treat every request concerning a child with particular care, and we act on it promptly and thoroughly, without requiring a lengthy process before we respond.
14. Third-Party Services
Our website and services may contain links to external websites and may rely on third-party services for functions such as hosting, analytics, payment processing, and email delivery. These third parties operate under their own privacy policies and are responsible for their own handling of information.
We do not control, and we are not responsible for, the privacy practices of external websites, and we encourage you to read the privacy policy of any external service before you provide information to it. A link on our website to another site does not mean that we endorse that site or its practices.
Before we engage a third-party provider, we review its security and privacy practices, and we bind it by contract to process information only for the purposes we authorise and to protect it to standards consistent with this Policy. If a third-party service is added, changed, or removed, we update this Policy so that it remains an accurate description of how information flows through our services.
15. Data Breach Response
Lacomo Limited maintains a documented incident response plan for the protection of information. If a breach of personal information is discovered, we act without delay to contain the incident, to assess the scope and impact, and to take steps to protect the affected individuals and systems.
Where the law requires it, we notify the relevant supervisory authority and the affected individuals within the required timeframes, describing the nature of the breach, the information involved, and the steps we have taken in response. We keep a record of every confirmed breach and of the actions taken, and we review each incident to improve our controls so that similar events are less likely to occur in the future.
Our clients with managed agreements are notified through the escalation path described in their service agreement, and every breach notification is handled by a named senior engineer. We treat the discovery of a vulnerability as an opportunity to improve, not as something to hide, and we are transparent with our clients about the state of their environments.
16. Automated Decision Making
We do not use automated decision making, including profiling, that produces legal or similarly significant effects on you. Where we evaluate a request or a system condition, any assessment that could affect you materially is reviewed by a person before any decision is made.
We may use automated tools for technical monitoring, such as uptime checks, anomaly detection, and alerting. The outputs of these tools are always reviewed by our engineers before any action is taken, and the tools themselves are configured by our team, not by an external vendor acting independently.
If a monitoring system flags an issue with a client system, a named engineer is alerted and takes responsibility for the response. We believe that decisions affecting people should be explainable, and our processes are designed so that you can always ask a human about any outcome that affects you. If you have a question about how a decision was reached, contact us and we will explain it in plain language.
17. Accuracy of Information
We take reasonable steps to keep the information we hold accurate, complete, and up to date. We ask you to tell us when your contact details change, and we review the contact records we hold for active engagements on a regular basis.
If you believe that any information we hold about you is inaccurate, contact us using the details in the Contact Us section and we will correct it without undue delay. Where we have shared information with a third party, we will take reasonable steps to notify that party of the correction so that its records are also updated.
We keep the personal information of clients and enquirers in systems that are protected by the security measures described in the Data Security section of this Policy, and we limit the people who can edit that information to those who need to do so for the operation of the business.
18. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, in technology, or in the law. When we make changes, we revise the last updated date shown at the top of this Policy and we post the updated version on this page.
Where a change is significant, we will take reasonable steps to bring it to your attention, such as a notice on our website or an email to clients where we hold a contact address. Significant changes include changes to the categories of information we collect, the ways we use information, or the parties with whom we share it.
Continued use of our website or services after a change takes effect constitutes acceptance of the updated Policy. We encourage you to review this Policy periodically so that you stay informed about how we handle information. The version of this Policy that applies to you is the one in effect at the time of your use of the website or services.
19. Contact Us
If you have any question about this Privacy Policy, about the information we hold, or about any privacy request, you may contact us at any time. Our developer and operating company is Lacomo, and the services are provided by Lacomo Limited.
You can reach us by email at contact@lacomo.lol or by telephone at +16783978621. Our registered office is at Rm 1603 16/F THE L PLZ, 367-375 QUEENS RD C, Sheung Wan, Hong Kong (HK).
We will acknowledge your message promptly and we will respond fully within a reasonable period. If you are not satisfied with our response, you may also have the right to complain to the relevant data protection authority in your jurisdiction. We take privacy questions seriously and we treat every message as a priority, because trust is the foundation of every engagement we take on.