1. Who we are
Hexaflare Co., Ltd. (“Hexaflare”, “we”, “us”, “our”) is a digital product agency incorporated in the Kingdom of Cambodia. We design and build websites, mobile applications and AI tools for business clients.
Registered address:
Hexaflare Co., Ltd.
4, Boeng Reang, Daun Penh
120204 Phnom Penh, Cambodia
Company registration number: to be confirmed
Contact for privacy matters:
contact@hexaflare.ai
For the personal information described in this policy, Hexaflare acts as the data controller — meaning we decide why and how it is processed. Where we process information on behalf of a client, we act as a data processor; see section 11.
2. Scope of this policy
This policy applies to personal information we process when you:
- visit hexaflare.ai or any of its subdomains;
- contact us by email, phone, messaging app or a form on our site;
- engage us as a client, supplier or partner, or work with us on a project;
- apply for a role with us or send us an unsolicited application.
It does not cover third-party websites we link to, nor the products we build and operate for clients under those clients’ own privacy policies.
3. Information we collect
3.1 Information you give us
- Identity and contact details — name, company, job title, email address, phone number, messaging handle.
- Project information — what you tell us about your business, requirements, budget and timeline.
- Correspondence — the content of emails, messages, call notes and meeting records.
- Commercial and billing details — contracts, invoices, bank or payment references, tax details where required.
- Recruitment information — CV, cover letter, work history and anything else you choose to send.
3.2 Information collected automatically
When you visit our website, our hosting infrastructure and any analytics we use may record:
- IP address (often truncated or anonymised), approximate country or city;
- date and time of the request, the pages or files requested, and the referring page;
- browser type and version, operating system, device type, screen size and language;
- basic performance and error information used to keep the site working.
Our website is a static site delivered from Cloudflare’s global network. Cloudflare processes request data on our behalf to serve pages and protect the site against abuse.
3.3 Information from other sources
- publicly available business information (company websites, business registries, professional networks);
- referrals and introductions from mutual contacts or partners;
- service providers we use for email, scheduling or accounting.
3.4 Sensitive information
We do not seek special categories of personal data (such as health, religious or political information) and ask that you do not send them to us unless we have specifically requested them for a defined purpose.
4. How and why we use your information
We use personal information only where we have a valid reason to do so. Where the EU/UK General Data Protection Regulation applies, the relevant legal bases are set out below.
| Purpose | Information used | Legal basis (GDPR) |
|---|---|---|
| Responding to enquiries and preparing proposals | Identity, contact and project information | Steps prior to entering a contract; legitimate interests |
| Delivering projects and providing support | Contact, project and correspondence data | Performance of a contract |
| Invoicing, accounting and tax records | Commercial and billing details | Legal obligation; performance of a contract |
| Operating, securing and improving our website | Technical and usage data | Legitimate interests in a secure, working website |
| Measuring website audience (if analytics are enabled) | Aggregated or pseudonymised usage data | Consent where required, otherwise legitimate interests |
| Sending occasional updates to business contacts | Name, email, company | Consent, or legitimate interests for existing clients |
| Recruitment | Application materials | Steps prior to a contract; legitimate interests |
| Establishing, exercising or defending legal claims | Any relevant records | Legal obligation; legitimate interests |
We do not sell personal information, and we do not use it for automated decision-making that produces legal or similarly significant effects.
5. Cookies and similar technologies
hexaflare.ai is a static website and does not set advertising or tracking cookies. We do not run third-party advertising pixels, and we do not build advertising profiles from your visit.
The only technologies that may be used are:
- Strictly necessary — cookies or tokens set by our hosting and security provider (Cloudflare) to deliver pages, balance load and protect against automated abuse. These cannot be switched off without breaking the site.
-
Web fonts — our pages currently load typefaces from Google Fonts, which
means your browser makes a request to
fonts.googleapis.comandfonts.gstatic.com. Google receives your IP address and browser information in order to serve the font files. Option: self-host the fonts to remove this third-party request entirely. - Audience measurement — to be confirmed: name the analytics tool once chosen (for example a privacy-friendly, cookieless tool such as Cloudflare Web Analytics or Plausible), or state that no analytics are used.
You can block or delete cookies through your browser settings at any time. If we later add any non-essential tracking, we will ask for your consent through a cookie banner before it is loaded, and this section will be updated.
6. Who we share information with
We share personal information only where it is necessary, and only with:
- Service providers who process data on our instructions — hosting and CDN, email, file storage, project management, accounting and payment providers.
- Clients and partners where you are working with us on a joint project and sharing is needed to deliver it.
- Professional advisers such as lawyers, auditors and accountants, where required.
- Authorities where we are legally obliged to disclose information, or to protect our rights, users or the public.
- A successor entity in the event of a reorganisation, merger or sale of the business, subject to the same protections.
Our providers are bound by contract to process personal data only on our instructions and to keep it secure. To be confirmed: the definitive list of processors actually in use (for example Cloudflare, Google Workspace, an accounting platform).
7. International transfers
We are based in Cambodia and use service providers located in other countries, including the United States, the European Union and elsewhere in Asia. This means your personal information may be transferred to, stored in and processed in countries whose data protection laws differ from those of your own country.
Where personal data is transferred out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses incorporated into our agreements with providers, together with technical measures such as encryption in transit.
8. How long we keep information
We keep personal information only for as long as we need it for the purposes described above. In practice:
- Enquiries that do not become projects — up to 24 months from the last contact.
- Client records and correspondence — for the duration of the engagement and up to 6 years afterwards, to handle questions, warranty and legal claims.
- Accounting and tax records — for the period required by Cambodian law and any other applicable tax rules.
- Job applications — up to 12 months, unless you ask us to keep them longer for future openings.
- Server logs — short retention periods set by our hosting provider, typically measured in days or weeks.
When information is no longer needed, we delete it or irreversibly anonymise it.
9. How we protect information
We apply technical and organisational measures appropriate to the risk, including:
- HTTPS/TLS encryption for all traffic to and from our website;
- access control on a need-to-know basis, with multi-factor authentication on business accounts;
- encrypted storage and managed, reputable cloud providers;
- separation of client production data from our internal systems;
- regular updates and patching of the systems we operate.
No method of transmission or storage is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the relevant people and authorities as required by applicable law.
10. Your rights and choices
Depending on where you live, you may have some or all of the following rights over your personal information:
- Access — ask for a copy of the personal data we hold about you.
- Rectification — ask us to correct information that is wrong or incomplete.
- Erasure — ask us to delete data we no longer have a reason to keep.
- Restriction — ask us to pause processing while a concern is resolved.
- Objection — object to processing based on our legitimate interests, and to direct marketing at any time.
- Portability — receive certain data in a structured, machine-readable format.
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting past processing.
To exercise any of these rights, write to contact@hexaflare.ai. We will respond within one month, and will tell you if we need more time or more information to identify you. Exercising your rights is free unless a request is manifestly unfounded or excessive.
Complaints. If you are in the European Economic Area or the United Kingdom and you believe we have not handled your information properly, you may lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.
Marketing. We send commercial messages only to business contacts, and every message includes a way to unsubscribe. You can also ask us to stop at any time by replying to any message or writing to the address above.
11. Data we handle on behalf of clients
When we build or operate a website, application or AI system for a client, we may access personal data belonging to that client’s users, customers or staff. In that situation:
- the client is the data controller and decides how that data is used;
- Hexaflare acts as a processor and works only on the client’s documented instructions;
- our obligations are set out in the services agreement and, where relevant, a separate data processing agreement;
- we do not use client data to train our own models or for any purpose of our own;
- any sub-processor we engage is bound by equivalent obligations.
If you are a user of a product we built for a client and you want to exercise your rights, please contact that organisation directly. We will assist them in responding to you.
12. Children’s privacy
Our website and services are intended for businesses and professionals. They are not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
13. Third-party links and services
Our website may link to third-party sites, social profiles or documents. We are not responsible for their content or their privacy practices. We encourage you to read the privacy policy of any site you visit from ours.
14. Changes to this policy
We may update this policy to reflect changes in our services, our providers or the law. The “last updated” date at the top of the page always shows the current version. If we make a material change, we will make it clear on this page and, where appropriate, notify you directly.
15. How to contact us
For any question about this policy or about how we handle your information:
Hexaflare Co., Ltd.
4, Boeng Reang, Daun Penh
120204 Phnom Penh, Cambodia
contact@hexaflare.ai