Last updated: September 2026
1. Introduction and who we are
This website and the advisory practice behind it are developed and operated by the developer HBF Consult. The business entity responsible for the delivery of professional consulting services, for the running of this website, and for the management of the personal data that flows through them is HBF CONSULTING LIMITED, a company registered in the United Kingdom.
We understand that the decision to share personal details with a professional adviser is a matter of trust. This privacy policy sets out, in plain language and with no legal ambiguity hidden between the lines, exactly what information we hold, the reasons we hold it, how long we keep it, and the rights you hold over it. We encourage you to read this document together with our separate terms of service, because the two documents together describe the entire relationship between you and the firm.
HBF CONSULTING LIMITED provides advisory services in market entry, company formation and compliance, trade mission facilitation, financial modeling, and brand localization. Our operating address is Office 4th Floor, 205 Regent Street, London - W1B 4NB, United Kingdom (GB). When you contact us or instruct us, we act as a data controller in respect of the personal data you choose to provide.
2. The data controller
For the purposes of data protection law, the data controller is the company that determines why and how personal data is processed. In respect of all data described in this policy, the controller is:
HBF CONSULTING LIMITED, Office 4th Floor, 205 Regent Street, London - W1B 4NB, United Kingdom (GB).
You may direct any data protection request, question, or complaint to the firm through the correspondence details given at the end of this policy. We treat every such request as a priority and we answer it within the period required by law, which is ordinarily within one month of receiving the request together with any proof of identity we reasonably need.
Because the firm is based in the United Kingdom, and because it serves clients across the world, data protection requests can involve more than one legal regime. Where you are based in the European Economic Area, in the United Kingdom, or in another jurisdiction that recognises the right to data protection, we will apply the protections that apply wherever we operate, always preferring the highest standard available.
3. Scope of this policy
This policy applies to personal data collected through this website, through email correspondence, through telephone calls, and through any advisory engagement you enter into with the firm. Personal data means any information relating to an identified or identifiable individual, such as a name, an email address, a telephone number, or any other detail that can be used, on its own or together with other information, to identify a person.
Some information we hold concerns companies rather than individuals. Where you correspond with us in a professional capacity as a representative or a director of a business, the data we hold about you personally, including your name and contact details, is still covered by this policy even if the underlying engagement concerns a legal person.
This policy does not apply to third party websites that we may mention or link to. If you follow a link from our website to another site, that site has its own privacy arrangements and its own controller, and you should review its notice before providing any personal data there. We do not accept responsibility for the content or the data handling practices of external websites.
4. The personal data we collect
The personal data we collect depends on how you interact with us. In ordinary website use we gather only limited technical information. When you contact us or instruct us, we gather the details needed to establish and operate the relationship. The categories of data we may hold include the following.
- Identity data. Your full name, your job title, the name of the company you represent, and your professional role at that company.
- Contact data. Your business or personal email address, your telephone number, and your postal address where this is needed for correspondence or for the signing of documents.
- Correspondence data. The content of any message, enquiry, or instruction you send to us, together with records of our replies and of any telephone calls where a record is retained for professional purposes.
- Engagement data. Details necessary to deliver an advisory engagement, including information about your company, your market, your financial objectives, and your commercial plans that you choose to share with us.
- Technical data. Standard browser and device information such as an internet protocol address, the type and version of your browser, the pages you view on this website, the time of your visit, and a reference that lets us recognise a repeat visit. This data generally does not identify you as a named individual.
We do not deliberately collect data that is commonly described as special category data, such as information about racial or ethnic origin, health, religion, or trade union membership, unless you choose to share such information with us and it becomes relevant to the delivery of a service. We do not generally need such information and we ask you not to include it in ordinary correspondence about meeting logistics or billing.
5. How we collect personal data
Personal data reaches us through a small number of predictable routes rather than through hidden tracking. The main routes are described here so that you understand exactly where information about you comes from.
- Direct correspondence. When you write to dispatch@hbfconsult.mom, telephone +17793627254, or complete the contact form on this website, you provide your name, contact details, and the content of your message voluntarily.
- Engagements. When you enter into a retainer or a project, you provide the identity, contact, and background data necessary for us to deliver professional advice.
- Public contact events. When you meet us at a trade mission, conference, or similar event and hand us a card or correspondence, that information is entered into our records with your knowledge.
- Automated technical collection. As with almost all website operators, simple technical logs are recorded automatically when your browser requests a page from this site.
In each case we collect only what is proportionate to the purpose. We do not purchase databases of prospects, we do not rent contact lists, and we do not enrich the information you give us with data bought from brokers. The personal data we hold has been provided by you or generated directly through our legitimate professional relationship.
6. Purposes of processing
We use the personal data we hold for clear and limited purposes, listed here so that no purpose remains hidden. Each purpose is matched, later in this policy, to the legal basis that justifies it. The principal purposes are the following.
- To respond to your enquiries and to provide the information, quotation, or scope that you have requested.
- To establish, manage, and perform an advisory engagement, including preparing studies, forming companies, arranging trade missions, building financial models, and advising on brand localization.
- To communicate with you about the progress of an engagement and to meet our reporting obligations to you.
- To bill you accurately for services and to process payments and related records.
- To comply with our legal and regulatory obligations, including obligations to business registries and revenue authorities.
- To operate, secure, and improve this website, and to understand how visitors use it so that we can make the site clearer and more useful.
- To maintain professional records that support the continuity of advice and the defence of our professional position should a dispute arise.
We do not use the personal data we hold to build profiles for the purpose of automated marketing, we do not sell your information, and we do not use it for purposes that are incompatible with those described above. If we ever wish to use personal data for a materially different purpose, we will update this policy and, where the law requires, obtain your separate consent first.
7. Legal bases we rely upon
Data protection law in the United Kingdom and the European Economic Area requires a lawful basis for every act of processing. We rely on the following bases, depending on the circumstance of each use of data.
- Contract performance. Where processing is necessary to perform a contract with you, or to take steps you have asked for before entering into a contract, this is the applicable basis. This covers the delivery of a scoped advisory engagement.
- Legitimate interests. Where processing is not required by a contract but supports the reasonable operation of our business without overriding your rights, we rely on legitimate interests. This covers the security of our systems, the management of enquiries that do not yet amount to a contract, and the maintenance of professional records.
- Legal obligation. Where we are required to retain records or to disclose information in order to comply with law, including tax law and corporate filing laws, the processing is justified by that legal obligation.
- Consent. Where we ask you to agree to a specific use of your data, for example to receive a particular newsletter or marketing communication, we process that data on the basis of your consent, which you may withdraw at any time with effect for the future.
In respect of each category of data, we select the most appropriate basis and we retain documentation that records that reasoning. Where we process on the basis of legitimate interests, we balance our business interest against your data protection interests and freedoms in a documented assessment, and we proceed only where our interests are not overridden by your own.
10. Data retention
We keep personal data only for as long as it is needed for the purpose for which it was collected, and no longer. The precise period depends on the type of data and the legal and professional obligations that apply to it. Our retention approach is set out here in general terms.
- Enquiry correspondence. Simple enquiries that do not lead to an engagement are ordinarily retained for a short period, usually up to twenty-four months from the last contact, so that we can respond helpfully if you return to us.
- Engagement records. Documents and correspondence relating to a completed advisory engagement are retained for a longer period because professional advice carries a record of duty and because disputes can arise well after the advice is given. We ordinarily retain engagement records in accordance with the professional limitation periods that apply.
- Accounting and corporate records. Records required by law, including those relating to tax and to corporate filings, are retained for the period required by the relevant authority, and we keep a register that supports the accurate deletion of such data once that period ends.
- Technical logs. Standard server logs are retained only briefly, typically for a few weeks, and are used for security and for the reliable operation of the site.
When a retention period ends, or when you exercise a right that requires deletion and no legal obligation prevents it, we delete or anonymise the personal data so that it can no longer be linked to you. We do not keep data on the off chance that it might one day be useful; each record in our systems has a deletion date that our procedures enforce.
11. Security measures
We apply a set of security measures chosen to protect personal data against accidental loss, destruction, alteration, and unauthorised access or disclosure. The measures are proportionate to the sensitivity of the data and to the risk involved in handling it, and they are reviewed regularly as technology and threats evolve.
Access to personal data within the firm is restricted to those who need it in order to perform their role, and we keep a clear sense of who may access the records of a particular client. Systems that store personal data are protected by appropriate authentication and access controls, communication with us by email and through this website occurs over encrypted channels where the technology permits, and our providers are selected partly on the strength of the security they can demonstrate.
While we take reasonable and appropriate measures to protect personal data, no method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security against every conceivable threat. We encourage you to protect the credentials you use and to contact us promptly if you believe that a communication with us has been compromised in any way. If we become aware of a personal data breach that creates a risk to your rights and freedoms, we will notify the appropriate supervisory authority and, where required, notify you directly.
12. Your data protection rights
Depending on your location and on the basis of our processing, you hold a set of rights over your personal data. We honour these rights in full and we have designed our procedures so that exercising them is straightforward rather than adversarial. Your rights include the following, expressed here as they would commonly act in practice.
- The right to be informed. This policy is part of our compliance with that right, and we will answer reasonable questions about how your data is used.
- The right of access. You may request a copy of the personal data we hold about you and ask us to confirm what we process and why.
- The right to rectification. You may ask us to correct any personal data that is inaccurate or incomplete.
- The right to erasure. You may ask us to delete personal data in circumstances where the legal basis for processing no longer applies and no legal obligation requires us to keep it.
- The right to restrict processing. You may ask us to limit how we use your data, for example where you contest its accuracy and we are checking it.
- The right to data portability. Where processing is based on consent or a contract and is carried out by automated means, you may ask us to provide your data in a structured, machine-readable format.
- The right to object. You may object to processing that is based on legitimate interests or carried out for direct marketing.
- Rights in relation to automated decisions. We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing, so this right rarely arises in our practice.
To exercise any of these rights, contact us using the details at the end of this policy and tell us which right you wish to exercise and the data to which it relates. We may ask for identification to confirm that the request comes from you. You also have the right to lodge a complaint with the supervisory authority in the country where you live or work, or where you believe the processing has taken place. We would welcome the opportunity to resolve any concern with you directly before you approach an authority.
13. Privacy for Children
Our services are professional advisory services intended for companies and for adults acting in a commercial capacity. They are not directed at children, and we do not knowingly collect personal data from children under the age of sixteen. A child would have no reason to engage a market entry advisory firm, and the content of this website does not seek the participation of children.
If you believe that a child has provided personal data to us through this website or by any other means, please contact us so that we can investigate. Where we confirm that we hold personal data of a child without appropriate consent, we will delete it promptly and take reasonable steps to ensure that it is not used further. We encourage parents and guardians to stay involved in the online activity of the young people in their care and to correspond with us if they have any concern about the information a child may have shared.
14. Updates to this policy
We keep this privacy policy under review because the law, our services, and the technology we use all develop over time. When we make a change that affects the way personal data is handled, we will update the version date shown at the top of this page and, where the change is significant, we will draw it to the attention of clients and correspondents by the usual professional channels before the change takes effect.
Material changes might include a new service that collects additional data, a legal change that alters the obligations we face, or a technology change that introduces a new use of information. Where the law requires your consent to a change, we will obtain that consent before implementing it. You are encouraged to review this page occasionally, and the date at the top will always tell you which version you are reading.
15. Contacting the data controller
If you have any question about this policy, wish to exercise any of your rights, or wish to raise a concern about the way your personal data is handled, please contact the firm directly. We answer data protection correspondence personally and promptly, and we will never make exercising your rights difficult or costly.
HBF CONSULTING LIMITED
Office 4th Floor, 205 Regent Street, London - W1B 4NB, United Kingdom (GB)
Contact person: Li Chunyan
Email: dispatch@hbfconsult.mom
Telephone: +17793627254
In your message, briefly state the nature of your request so that we can direct it to the right member of the desk without delay. Where you ask to exercise a data protection right, we will confirm what we have done within the period required by law and we will keep the correspondence on record in line with our retention practices while it remains relevant.
Policy summary
For ease of reference, the central commitments of this policy may be reduced to a short summary. HBF CONSULTING LIMITED collects only the personal data you provide or that is created in the course of an engagement. We use that data to answer you, to deliver the advisory services you have requested, to invoice you, and to meet our legal obligations. We do not sell personal data, and we do not use it for purposes that go beyond the relationship we have with you.
We keep personal data only as long as it is needed, we protect it with measures proportionate to the risk, and we honour your rights of access, correction, deletion, restriction, and objection. If you have any doubt about how your data is treated, write to dispatch@hbfconsult.mom or call +17793627254 and we will give you a direct and complete answer. Our office, HBF CONSULTING LIMITED at Office 4th Floor, 205 Regent Street, London - W1B 4NB, United Kingdom (GB) always welcomes that conversation.