Information Security Policy

Information Security Policy

Effective as of August 1, 2026

1. Security Vision

Asia Alliance Co., Limited (“Asia Alliance,” “we,” “us,” or “our”) is committed to protecting the confidentiality, integrity, and availability of the information entrusted to us.

As a company connecting customers, manufacturers, suppliers, logistics providers, and other business partners across global markets, we recognize information security as an important management responsibility and an essential foundation for reliable business relationships.

We take reasonable and proportionate measures to protect our information assets, support the continuity of our operations, and reduce the risk of unauthorized access, disclosure, alteration, loss, destruction, or disruption.

2. Scope of This Policy

This Information Security Policy applies to information assets handled by Asia Alliance, whether in electronic, physical, verbal, or other form, including:
  • Customer, supplier, manufacturer, and business partner information
  • Personal data
  • Contracts, transaction records, pricing information, and commercial terms
  • Product, sourcing, logistics, and supply chain information
  • Financial, accounting, legal, and compliance records
  • Trade secrets and other confidential business information
  • E-mail, documents, devices, applications, networks, cloud services, and other information systems
The policy applies to employees, officers, contractors, service providers, and other persons who are authorized to access or handle Asia Alliance information.

3. Information Security Objectives

Our information security practices are based on the following objectives:

Confidentiality

Information is accessible only to persons who are properly authorized and have a legitimate business need.

Integrity

Information is protected against unauthorized or accidental alteration, deletion, or corruption and is maintained accurately and reliably.

Availability

Information and systems required for business operations remain accessible to authorized users when reasonably needed.

Accountability

Responsibilities for protecting information are clearly assigned, and information security measures are reviewed and improved where appropriate.

4. Governance and Internal Controls

Asia Alliance maintains internal policies, procedures, and controls appropriate to the nature, scale, and complexity of our operations and information security risks.

We seek to:
  • Define responsibilities for information security
  • Apply appropriate approval and accountability procedures
  • Restrict access to information on a need-to-know and need-to-access basis
  • Maintain appropriate records of access, changes, and security-related activities where necessary
  • Review access rights when roles or responsibilities change
  • Promptly remove access when it is no longer required
  • Escalate material information security risks and incidents to management
Management oversees the implementation and periodic review of this policy.

5. Information Classification and Handling

We classify and handle information according to its sensitivity, business value, legal requirements, and the potential consequences of unauthorized disclosure, alteration, loss, or unavailability.

Confidential or sensitive information must be:
  • Accessed only for authorized business purposes
  • Shared only with persons who have a legitimate need to receive it
  • Stored and transmitted using appropriate safeguards
  • Protected during printing, copying, transportation, and remote access
  • Retained only for as long as reasonably necessary
  • Securely erased, destroyed, or disposed of when no longer required
Employees and authorized personnel are expected to exercise particular care when handling personal data, trade secrets, contracts, pricing information, and commercially sensitive communications.

6. Access Control and System Security

We implement security measures appropriate to the risks associated with our information systems and business activities.

These measures may include:
  • User identification and authentication controls
  • Strong password and account management practices
  • Access restrictions based on job responsibilities
  • Appropriate network, device, and endpoint protection
  • Anti-malware and other protective software
  • Security updates and software maintenance
  • Secure configuration of systems and applications
  • Appropriate protection for e-mail and file transfers
  • Backup and recovery arrangements
  • Physical safeguards for offices, equipment, records, and storage media
Access to information systems must not be shared with or made available to unauthorized persons.

7. Risk Assessment and Management

We identify and assess reasonably foreseeable information security risks, including:
  • Cyberattacks, phishing, malware, and unauthorized system access
  • Accidental disclosure or transmission of information
  • Loss or theft of devices, documents, or storage media
  • System failures, misconfigurations, and software vulnerabilities
  • Inappropriate access by employees, contractors, or third parties
  • Physical damage, business disruption, and loss of essential information
  • Security risks associated with cloud services and outsourced processing
Security measures are selected and reviewed according to the sensitivity of the information, the likelihood of an incident, the potential impact on affected parties, and the resources reasonably available to the company.

8. Third-Party and Service Provider Security

Where we engage service providers to host, store, transmit, maintain, or otherwise process information on our behalf, we take reasonably practicable steps to assess and manage the associated risks.

Where appropriate, we may:
  • Assess the reliability and security capabilities of service providers
  • Limit information shared with service providers to what is reasonably necessary
  • Include confidentiality and information security requirements in contracts
  • Require service providers to restrict access to authorized personnel
  • Require appropriate retention and secure deletion practices
  • Require prompt reporting of information security incidents
  • Review the service provider’s compliance where reasonably necessary
The level of oversight applied will depend on the nature and sensitivity of the information involved and the risks associated with the service.

9. Education and Awareness

Employees and other relevant personnel receive information security guidance or training appropriate to their roles and responsibilities.

Training and awareness activities may address:
  • Confidentiality obligations
  • Secure password and account practices
  • Phishing, fraudulent communications, and social engineering
  • Appropriate use of e-mail, internet, cloud services, and portable devices
  • Secure handling and disposal of confidential information
  • Identification and reporting of suspected security incidents
  • Responsibilities relating to personal data and business information
We encourage all personnel to remain alert and promptly report suspected security weaknesses or incidents.

10. Business Continuity and Recovery

We maintain reasonable arrangements intended to support the continuity and recovery of important business operations following a system failure, cyber incident, physical disruption, or other significant event.

Depending on operational requirements and risk, these arrangements may include appropriate backups, alternative communication methods, recovery procedures, and coordination with relevant service providers.

Business continuity and recovery arrangements are reviewed and improved where appropriate.

11. Information Security Incident Response

Suspected or actual information security incidents must be reported promptly through the appropriate internal channels.

When an incident occurs, Asia Alliance will take reasonable steps to:
  • Gather relevant information and assess the nature and scope of the incident
  • Contain the incident and prevent further unauthorized access, loss, or disruption
  • Protect affected systems, information, and business operations
  • Assess the potential impact on customers, business partners, and other affected persons
  • Recover affected systems and information where practicable
  • Investigate the cause of the incident
  • Document material findings and actions taken
  • Implement corrective measures to reduce the risk of recurrence
  • Notify affected persons, regulators, law enforcement agencies, or other relevant parties where appropriate or required by applicable law
Incident response measures will be proportionate to the nature and severity of the incident and the potential harm that may result.

12. Compliance and Personal Data Protection

We comply with applicable laws, regulations, contractual requirements, and internal policies relating to information security.

Where an information security matter involves personal data, we handle the matter in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong, our Privacy Policy, and other applicable requirements.

Information security must not be compromised in pursuit of commercial or operational objectives.

13. Monitoring and Continuous Improvement

We periodically review this policy and the effectiveness of our information security measures in light of:
  • Changes in our business operations and information systems
  • Changes in technology and security threats
  • Identified risks and vulnerabilities
  • Information security incidents and lessons learned
  • Changes in applicable legal, regulatory, and contractual requirements
  • Feedback from employees, business partners, and service providers
Where weaknesses or deficiencies are identified, we take reasonable steps to address them and improve our information security practices.

14. Reporting Security Concerns

Questions, suspected vulnerabilities, or information security incidents relating to Asia Alliance may be reported to:

Security Contact

Asia Alliance Co., Limited
Room 1911, Lee Garden One, 33 Hysan Avenue, Causeway Bay, Hong Kong
Telephone: +852 2598 8776
E-mail: inquiry@asia-alliancehk.com

15. Changes to This Policy

We may update this Information Security Policy from time to time to reflect changes in our operations, technology, risks, or applicable requirements.

Any revised policy will be published on our website with an updated effective date.
CONTACT top
Asia Alliance
Supporting diverse industries with trusted solutions.
Explore Our Business