Privacy notice
Last updated: 1 August, 2026
Introduction
At HeySMS, privacy and responsible data handling are part of providing a reliable communications service.
This Privacy Notice explains what personal data we handle, why we use it, who we may share it with, how we protect it, and the rights available to individuals.
It also explains an important distinction in our services:
- when we handle information about our Website https://heysms.com visitors, business contacts, Customers for our own business purposes, HeySMS generally acts as a data user; and
- when our Customers use HeySMS to send messages to their own users or recipients, HeySMS generally processes the relevant personal data on behalf of the Customer.
This Privacy Notice also serves as our general Privacy Policy Statement for the purposes of the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486).
1. Who we are?
HeySMS is operated by FlipNames Limited, a company incorporated in Hong Kong (Company Registration Number 3289778 and Business Registration Number 75424130).
Our registered address is:
Rm 7B, One Capital Place
18 Luard Road
Wan Chai
Hong Kong
Е-mail: info@heysms.com
2. Who and what this Privacy Notice covers
This Privacy Notice applies when you:
- visit or interact with the HeySMS Website https://heysms.com;
- submit a Contact Us or other enquiry form;
- contact our sales or support teams;
- communicate with us by email, telephone or other business channels;
- represent a Customer or prospective Customer;
- act as a supplier, partner, adviser or other business contact.
In these situations FlipNames Limited acts as a data user in the terms of the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486).
HeySMS is a business-to-business service. Our Website and services are intended primarily for organisations and persons acting in a professional or business capacity. We do not intentionally collect minors data or sensitive or special categories of data.
This Notice also contains a short explanation of personal data that HeySMS processes on behalf of Customers when providing messaging services. Those activities are principally governed by our contractual arrangements with the relevant Customer, including applicable data processing terms.
3. What personal data we collect
The information we collect depends on how you interact with us.
We aim to collect only information that is reasonably necessary for the relevant business purpose.
3.1 Contact and business information
We may collect:
- your name;
- business email address;
- telephone number;
- company or organisation name;
- job title or professional role;
- country or region;
- preferred contact details; and
- other business information you choose to provide.
3.2 Enquiries and communications
When you contact us, we may collect:
- the subject and content of your enquiry;
- information entered into our Website forms;
- correspondence with our sales or support teams;
- information provided during calls or meetings; and
- other information you voluntarily provide in connection with your request.
Please provide only information that is reasonably necessary for your enquiry.
Our public contact forms are not intended for passwords, authentication codes, financial account details, identification documents, health information or other unnecessary sensitive information.
3.3 Customer and contractual relationship information
Where your organisation enters into, or considers entering into, a business relationship with HeySMS, we may collect personal data relating to the persons involved in negotiating, managing or administering that relationship, including:
- names and business contact details of Customer representatives;
- job titles and professional roles;
- details of authorised contractual, commercial, finance or compliance contacts;
- information provided for customer onboarding, due diligence or compliance purposes;
- other personal data reasonably necessary to establish, manage, perform or document our contractual relationship with the Customer.
We use this information to communicate with the Customer, negotiate and enter into agreements, administer the contractual relationship.
3.4 Technical and Website information
When you access our Website or services, certain technical information may be generated automatically.
Depending on the relevant technology, this may include:
- IP address;
- browser type;
- operating system;
- device type;
- date and time of access;
- referring page;
- Website or service interactions;
- security information;
- error and diagnostic records; and
- other technical logs needed to operate and protect our systems.
Technical information may constitute personal data where an individual can practicably be identified from that information, alone or together with other information available to us.
3.5 Information from other sources
We may also receive professional contact information from:
- your employer or organisation;
- another representative of your organisation;
- an existing Customer;
- a business partner;
- a person who introduces you to HeySMS;
- service providers supporting our business operations; or
- publicly available professional or corporate sources.
We use information obtained from other sources only for appropriate business purposes and in accordance with applicable privacy requirements.
4. How and why we use personal data
We only use personal data for clear, lawful and legitimate business purposes. In practice, this means we may use it to:
- respond to your questions and discuss our services;
- start and manage our business relationship with you or your organisation;
- provide support and handle billing or other administrative matters;
- keep our Website, services and systems secure;
- improve how our services work; and
- meet our legal, regulatory and compliance obligations.
We do not use personal data for unrelated purposes. If we ever need to use it for a new purpose, we will only do so where the PDPO allows it or where the required consent has been obtained.
5. Personal data processed on behalf of our Customers
When Customers use HeySMS to send communications to their users or other recipients, we may process personal data provided by or generated on behalf of those Customers.
In these circumstances, the Customer generally decides why and how the personal data is used, and HeySMS acts as a data processor on the Customer’s behalf. We process this data only as necessary to provide and support the agreed services and in accordance with the Customer’s instructions and our contractual arrangements with them.
The Customer is responsible for providing appropriate privacy information to its users and recipients and for handling their privacy requests. Where appropriate, HeySMS assists the Customer in fulfilling those obligations.
Further details of this processing are set out in the applicable Data Processing Terms of the relevant Service Agreement.
If you receive a message through HeySMS
If you receive a message sent through HeySMS on behalf of one of our Customers and want to know:
- why your personal data was used;
- why you received the message;
- how to exercise privacy rights; or
- how to stop receiving communications,
you should normally contact the organisation identified as the sender. That organisation is generally responsible for deciding why your personal data is used.
6.Who we share personal data with
We only share personal data when it is reasonably necessary to run our business, provide our services or meet our legal obligations.
We may share it with service providers that support our business, such as hosting and IT providers, security and communication services, payment providers and professional advisers.
We only provide them with the information they need for their role and take reasonable steps to ensure that personal data is kept confidential, secure and used only for the agreed purposes.
We may also disclose personal data where required or permitted by law, including to courts, regulators or law-enforcement authorities, or where necessary to protect our legal rights or in connection with a merger, acquisition or other corporate transaction.
We do not sell personal data.
7. International Data Transfers
HeySMS provides communications services to businesses operating internationally. Our Customers, telecommunications partners, technical service providers or other recipients may operate in different jurisdictions. Privacy and data-protection laws in those jurisdictions may differ from Hong Kong law.
We are committed to protecting personal data wherever it is processed. Where personal data is processed outside Hong Kong, we take reasonable steps and exercise due diligence to ensure that it is handled securely and in accordance with this Privacy Notice and the Personal Data (Privacy) Ordinance.
Depending on the circumstances, these measures may include:
- appropriate due diligence;
- confidentiality requirements;
- contractual data-protection obligations;
- restrictions on use;
- information-security requirements;
- access controls;
- retention and deletion requirements; and
- incident-notification arrangements.
Where an additional international data-transfer mechanism is required under another applicable privacy law, we will implement an appropriate mechanism where relevant.
8. Cookies and similar technologies
HeySMS does not currently use cookies for advertising or behavioural marketing purposes.
We also do not currently operate a cookie-based advertising or user-profiling programme through the Website.
Our contact forms are protected by Google reCAPTCHA, which helps distinguish genuine users from automated or abusive submissions.
In providing that security functionality, Google may receive or generate technical information about your device or interaction with the Website and may use cookies or similar technologies in accordance with its own privacy terms.
We use reCAPTCHA for Website security and spam prevention, not for HeySMS advertising or marketing.
If we introduce analytics, advertising or other non-essential tracking technologies in the future, we will update this Privacy Notice and provide appropriate information and choices before or when those technologies are introduced.
You may also manage cookies and similar technologies through your browser settings where relevant.
9. Direct marketing
HeySMS does not currently use personal data collected through the Website for direct marketing.
In particular:
- submitting a Contact Us form does not subscribe you to marketing;
- requesting information about HeySMS does not constitute consent to receive promotional communications; and
- we do not currently provide Website contact data to third parties for their own direct marketing.
If we decide to introduce direct marketing in the future, we will implement a separate process that complies with the applicable requirements of the PDPO.
Before using personal data for direct marketing, we will provide the required information and obtain the individual’s consent or indication of no objection where required.
10. How long we keep personal data
We do not keep personal data for longer than reasonably necessary. The appropriate retention period depends on the type of information and the reason for which it is held.
We consider factors including:
- the purpose for which the information was collected;
- whether an enquiry develops into a business relationship;
- the duration of the Customer relationship;
- operational and security requirements;
- contractual obligations;
- accounting and record-keeping requirements;
- applicable legal obligations and limitation periods; and
- the need to establish, exercise or defend legal claims.
As part of our normal business practices, we may keep records of our transactions, communications and contractual relationship with you for a reasonable period where this is needed for verification, compliance, accounting, dispute resolution or other legitimate business purposes.
When personal data is no longer needed for the purpose for which it was collected, or for a directly related purpose, we take reasonable steps to securely delete, destroy or anonymise it.
11. How we protect personal data
We maintain technical and organisational measures designed to protect personal data against unauthorised or accidental access, processing, erasure, loss or use.
Depending on the systems and information involved, these measures may include:
- restricting access according to business need;
- authentication and account-security controls;
- encryption where appropriate;
- infrastructure and network security;
- security monitoring and logging;
- measures to detect suspicious or unauthorised activity;
- confidentiality obligations;
- security requirements for service providers;
- internal policies and procedures; and
- incident-response processes.
Only authorised persons who reasonably need personal data for their work or to provide the relevant service are given access to it.
12. Your privacy rights
The PDPO gives individuals specific rights in relation to their personal data.
Subject to applicable requirements and exceptions, you may:
- ask whether we hold personal data about you;
- request access to a copy of personal data we hold about you; and
- request correction of personal data that is inaccurate.
12.1 Data access requests
We will normally comply with a valid Data Access Request within 40 days after receiving it, subject to the circumstances, procedures and exemptions provided by the PDPO. Where permitted by law, we may charge a fee for complying with a Data Access Request. Any fee charged will not be excessive.
If we are unable to comply with the request within the required period, we will deal with the request in accordance with the PDPO.
12.2 Data correction requests
If personal data supplied to you in response to a Data Access Request is inaccurate, you may make a Data Correction Request in accordance with the PDPO.
Where we are satisfied that the relevant data is inaccurate, we will make the necessary correction and provide the corrected data within the period required by the PDPO, subject to any applicable exceptions.
Requests relating to personal data for which HeySMS acts as the data user should be sent to:
FlipNames Limited / HeySMS
Rm 7B, One Capital Place
18 Luard Road
Wan Chai
Hong Kong
Email: info@heysms.com
When necessary, we may request information reasonably required to:
- verify your identity;
- identify the personal data concerned; and
- understand the scope of your request.
12.3 Customer-controlled data
If your request relates to a message sent by a HeySMS Customer and HeySMS processes the relevant information only on that Customer’s behalf, the Customer will normally be responsible for handling the request. We may therefore refer you to the relevant Customer or assist that Customer in responding where appropriate.
12.4. Complaints
If you have a question or concern about how HeySMS handles personal data, we encourage you to contact us first at info@heysms.com.
You may also lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD) if you consider that your personal data has been handled in contravention of the PDPO.
13. Changes to this Privacy Notice
Our technology and services may evolve over time, and we may update this Privacy Notice to reflect. The current version will be published on the HeySMS Website together with the date on which it was last updated.