Privacy
How personal information is handled.
Last updated 23 September 2026.
This notice applies to this website, direct business enquiries and the administration and delivery of prospective or current advisory relationships. A client agreement, data-processing agreement or mandate-specific notice may supplement it where the work requires different or more detailed handling.
Privacy at a glance
- Controller: Alter Way Studio Ltd., incorporated in Hong Kong. Manuel Baigorri is the contact.
- Purpose: to operate and secure the website, respond to enquiries, assess and administer engagements, deliver agreed work and meet legal and business-record obligations.
- Data: limited technical website data, professional contact and correspondence data, and information necessary for an agreed mandate.
- Sharing: only with necessary service providers, authorised specialists or where law requires it.
- Your rights: contact manuel@manuelbaigorri.com. If you are in the EU or EEA you may complain to the supervisory authority of your country; in Hong Kong, to the Privacy Commissioner for Personal Data.
Who is responsible
For this website and direct business enquiries, the data controller is Alter Way Studio Ltd., a company incorporated in Hong Kong, registered at Unit 2406B, 24/F, Low Block, Grand Millennium Plaza, 181 Queen’s Road Central, Sheung Wan, Hong Kong. The controller is the party responsible for deciding why and how personal information is used. Manuel Baigorri acts for the company and is the point of contact for any privacy question or request: manuel@manuelbaigorri.com. Where this notice says “I”, it means Manuel Baigorri acting for Alter Way Studio Ltd.
The practice is established in Hong Kong and is subject to the Personal Data (Privacy) Ordinance. Advisory services are also offered to organisations and individuals in the European Union and the European Economic Area, so the EU General Data Protection Regulation applies to that processing as well. Where the two regimes differ, the standard that gives you the stronger protection is applied. Other national laws may apply where a mandate requires it.
Website data and hosting
The site is deliberately simple. It uses no contact forms, analytics, advertising pixels, behavioural tracking or non-essential cookies. It does not profile visitors or make automated decisions about them.
IONOS Cloud S.L.U. provides website hosting and professional email. Its standard Hosting information states that it processes the referrer, requested page or file, browser and operating-system details, device type, access time and an anonymised IP address to provide security, stability and service quality. It states that these website data are kept for 8 weeks and are not transferred to third countries outside the European Union. This description applies to the standard IONOS Hosting product and will be reviewed if the contracted product or configuration changes.
That statement covers the technical website data held by IONOS. Email is different. A message you send is read and answered by me, and I work from Hong Kong and from other countries, so correspondence does leave the European Union. This is covered under International transfers below.
Information received directly
If you email, connect through LinkedIn, join a meeting or explore an engagement, I may receive your name, professional role and organisation, contact details, correspondence, scheduling information and any information you choose to provide. If work proceeds, I may also process proposal, contract, conflict-check, invoicing and engagement-administration records, together with limited personal information contained in materials supplied for the mandate.
Please do not send sensitive personal information unless it is necessary for a clearly defined purpose and we have agreed a secure way to handle it.
Why information is used
Personal information is used only to respond to an enquiry; take requested steps before a contract; establish, deliver and administer an engagement; maintain security and business records; meet legal, tax, insurance or professional obligations; and establish, exercise or defend legal claims.
Depending on the context, the legal basis is taking steps at your request before entering a contract, performing a contract, complying with a legal obligation, or a legitimate interest in responding to professional enquiries, managing client relationships, protecting information and operating an independent advisory practice. Consent is used where the applicable law requires it and may be withdrawn at any time.
I do not operate a marketing mailing list, sell personal information, or share it for cross-context behavioural advertising.
Client mandates and data roles
The applicable agreement determines the data-protection roles for each mandate. Where a client determines why and how personal information is processed, the client remains the controller and I process the information only under documented instructions. For my own contracting, invoicing, conflict management, legal obligations and professional records, I may act as an independent controller.
Who may receive information
Information is not disclosed beyond what is necessary. It may be processed by carefully selected providers supporting website hosting, email, secure document storage, communications, accounting, legal advice, insurance or information security. IONOS Cloud S.L.U. supports the website and professional email. A specialist collaborator receives personal information only where the mandate requires it, the client has authorised the involvement where appropriate, and confidentiality and data-protection obligations are in place. Information may also be disclosed where required by law or necessary to protect legal rights.
Use of artificial intelligence
ChatGPT, provided by OpenAI, may be used as an assistive working tool for tasks such as structuring, drafting, analysis, research support or quality review. It is not the system of record, is not used to make solely automated decisions about individuals and does not replace professional judgment.
Client-confidential or personal information is not submitted unless the use is necessary for the agreed work, permitted by the client or contract, and supported by an appropriate business service, processing terms and data controls. Otherwise, material is excluded, minimised, anonymised or replaced with synthetic information. Material outputs are reviewed by a person before use.
International transfers
The practice is based in Hong Kong and the work is carried out across several countries. If you are in the EU or EEA and you write to me, your correspondence is read and administered outside the EEA. Hong Kong is not covered by a European adequacy decision, so where the GDPR applies these transfers rely on a legally recognised basis assessed before the transfer is made: for direct correspondence, that a transfer is necessary to take steps at your request before a contract or to perform a contract with you; for service providers, approved contractual clauses or an equivalent safeguard, with supplementary protections where appropriate.
Some providers or client teams also operate across more than one country. The same assessment of provider, location and transfer basis is made in each case.
How long information is kept
Information is kept only for as long as needed for the stated purpose:
- Enquiries that do not become an engagement: normally up to 12 months after the last meaningful contact.
- Engagement working files and routine correspondence: for the engagement and normally up to 24 months after completion, unless the agreement or a legal need requires a different period.
- Signed agreements, invoices and essential legal, tax or audit records: normally up to six years after the engagement, or longer where applicable law or a live claim requires it.
- Technical website logs: the standard IONOS Hosting period is currently eight weeks; a different contracted product or justified security event may require a different period.
At the end of the applicable period, information is securely deleted or anonymised. Encrypted backups expire through the normal backup cycle.
Your rights
Depending on your location and the law that applies, you may have rights to request access, correction, deletion, restriction or portability; object to certain processing; withdraw consent; know the categories and recipients of information; and complain to a supervisory authority. Where applicable, you may also opt out of sale or sharing and limit certain uses of sensitive personal information. I do not sell personal information, share it for behavioural advertising or use it for solely automated decisions.
Send a request to manuel@manuelbaigorri.com with the subject “Privacy request”. I may ask for proportionate information to verify identity and will respond within the period required by applicable law. Some rights are subject to legal exceptions, including confidentiality owed to other people, legal privilege and mandatory record-keeping.
Security and confidentiality
Reasonable technical and organisational safeguards are used to protect personal information, including restricted access, secure service providers, device protection and controlled retention. No email or online system is completely secure, so please do not send unrequested sensitive or highly confidential material by ordinary email.
LinkedIn and external services
This site links to LinkedIn but does not embed LinkedIn tracking. If you visit or message through LinkedIn, that platform processes information under its own privacy terms. The same principle applies to any other external site you choose to visit from this website.
Children
This website and the advisory services are intended for professional audiences and are not directed to children.
Changes and complaints
This notice will be updated if the site, services, providers or legal requirements materially change. The current version will always appear on this page.
If you have a concern, please contact me first at manuel@manuelbaigorri.com. You may also complain to the data-protection authority in the country where you live or work. In Hong Kong that is the Office of the Privacy Commissioner for Personal Data. In the EU or EEA it is the supervisory authority of your country of residence, your place of work, or the place where the matter arose.