Skip to content
Home/Legal & Policies/Privacy Policy

Privacy Policy

How Homura Network collects, uses, and protects your personal information in accordance with privacy laws and compliance standards.

Last updated: August 28, 2026

HOMURA NETWORK LIMITED PRIVACY POLICY

1. Introduction and Scope

Homura Network Limited ("Homura Network", "we", "us", or "our") is dedicated to protecting the privacy of our customers, website visitors, and service users. We are committed to transparency, operational integrity, and responsible data governance across our computing, hosting, infrastructure, software, and telecommunications services.

This Privacy Policy explains how we collect, use, process, disclose, retain, transfer, and safeguard Personal Data. For the purposes of this Policy, "Personal Data" means any information relating to an identified or identifiable natural person.

Unless expressly designated otherwise on an invoice or service schedule, Homura Network Limited is the Data User under the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"). Under other applicable data protection frameworks, Homura Network may act as a Data Controller or Data Processor, depending on the nature and purpose of the relevant processing activity, as further described in this Policy.

1.1 Applicable Scope and Framework

This Policy applies to all websites, portals, APIs, and commercial services offered under the Homura Network brand, including:

  • Virtual Private Servers (VPS) and Dedicated Compute;
  • Web, Application, and Shared Hosting;
  • NAT and shared-IP services, including NAT.Toys;
  • Network connectivity, IP transit, BGP routing, and infrastructure services;
  • Software licensing, applications, and related development services;
  • eSIM, roaming, and telecommunications connectivity services; and
  • Physical products, SIM cards, or equipment supplied in connection with our services.

This Policy should be read in conjunction with our Terms of Service, the Compute & Hosting Services Policy, and any applicable product-specific schedules or Personal Information Collection Statements (PICS).

2. Personal Data We Collect

We collect only the Personal Data reasonably necessary to administer accounts, fulfill orders, process payments, provide technical support, secure infrastructure, prevent abuse, and comply with legal obligations.

2.1 Account and Identity Information

When you create an account, purchase services, or communicate with us, we collect basic contact and organizational details. This typically includes your full name, company name, email address, telephone number, billing and physical address, country of residence, and account credentials.

2.2 Payment and Commercial Records

We retain commercial records associated with your transactions, including invoices, billing history, payment methods, transaction identifiers generated by payment processors, and refund or chargeback records.

Payment Security Notice: Sensitive payment credentials are processed directly by the applicable third-party payment provider. Where payment cards are used, full card details and CVV security codes are handled by applicable PCI-DSS compliant payment processors and are not directly stored by Homura Network. Depending on the payment method, we may receive transaction identifiers, payment tokens, limited card metadata such as the last four digits, wallet or blockchain transaction information, and payment-validation or risk metadata provided by the applicable processor.

2.3 Website Access, Device, and Technical Telemetry

When you interact with our websites and client portals, our systems automatically collect technical telemetry. This includes your IP address, browser type and version, operating system, device characteristics, language preferences, referring URLs, session timestamps, and authentication logs necessary for access security and threat mitigation.

2.4 Service, Network, and Telecommunications Data

Depending on the specific services you utilize, we process operational and diagnostic network metadata:

  • Compute and Network Services: Assigned IP addresses, port usage, bandwidth volume, connection telemetry, resource consumption, and incident/abuse-related logs.
  • eSIM and Mobile Connectivity: Identifiers and network metadata including ICCID, EID, IMEI, MSISDN (where allocated), network registration status, roaming partner networks, and aggregated data consumption.

2.5 Support and Correspondence Records

We retain records of your communications with Homura Network, including support tickets, technical diagnostic inquiries, email correspondence, and chat transcripts to maintain accurate service history and assist in issue resolution.

2.6 Enhanced Verification Data (When Required)

To prevent fraud, verify payment authenticity, comply with regulatory requirements, or investigate severe abuse, we may occasionally request additional verification documents, such as government-issued photo identification, proof of address, or payment ownership verification. Such verification is not collected by default and is handled with strict confidentiality.

3. How We Use Personal Data

We process Personal Data for the purposes described below and, where applicable, on an appropriate lawful basis under applicable data protection law:

  1. Contract Performance: Provisioning and maintaining services, managing accounts, processing invoices and payments, and delivering customer support.
  2. Legal and Regulatory Compliance: Fulfilling statutory accounting, taxation, auditing, telecommunications, and other legal or regulatory requirements, and responding to valid legal orders.
  3. Security, Fraud, and Abuse Prevention: Protecting accounts and infrastructure, mitigating cyberattacks, screening potentially fraudulent orders, investigating unauthorized access, and enforcing service policies. Where applicable, such processing may be based on our legitimate interests in protecting our services, customers, and network.
  4. Service Operations and Reliability: Monitoring infrastructure performance, capacity planning, diagnosing technical faults, and maintaining or improving service reliability.
  5. Operational Communications: Sending transactional notices regarding invoices, service expiration, maintenance, security, and policy changes.
  6. Consent: Where required by applicable law, we rely on consent for optional activities such as direct marketing or certain non-essential tracking technologies.

3.1 Direct Marketing Policy

We do not send unsolicited marketing communications without your explicit consent or lawful opt-in where required by the PDPO and international privacy laws. Routine service, security, billing, and operational notifications do not constitute direct marketing. You may opt out of optional promotional communications at any time free of charge via the unsubscribe link in the communication or by contacting us.

4. Customer Content and Processing Roles

Files, operating systems, applications, databases, software, and private communications stored, hosted, or transmitted by a customer within their compute, storage, or hosting environments are defined as "Customer Content".

  • Customer Responsibility for Customer Content: The customer determines how Customer Content is used within the Service and is responsible for compliance with applicable data protection requirements in its capacity as a controller, data user, processor, or other applicable regulated party.
  • Homura Network's Processing Role: To the extent Homura Network processes Personal Data contained in Customer Content solely on behalf of a customer in providing infrastructure or hosting services, Homura Network acts as a Data Processor, as applicable. Homura Network may separately act as a Data User or Data Controller in relation to account, billing, security, fraud-prevention, abuse, and other operational data processed for its own legitimate purposes.
  • Non-Inspection Principle: Homura Network does not routinely inspect, monitor, or access Customer Content stored within customer-managed environments.
  • Strictly Limited Technical Access: Authorized personnel may access customer environments only in strictly defined circumstances: (a) upon explicit customer request or authorization for technical support; (b) to mitigate active security incidents or severe network abuse; or (c) where required by a binding legal order from a competent judicial or regulatory authority.
  • Customer Security Responsibility: Customers are solely responsible for configuring robust passwords, applying security patches, maintaining firewalls, and keeping independent data backups. Homura Network is not liable for unauthorized access, data compromise, or loss resulting from customer-managed configuration errors or unpatched customer applications.

5. Information Sharing and Third-Party Disclosures

Homura Network does not sell or rent Personal Data to third parties or use Personal Data for third-party targeted advertising.

We disclose Personal Data only where reasonably necessary to provide and secure our services, process transactions, obtain professional services, or comply with applicable legal requirements. Categories of recipients may include:

Provider Category Operational Purpose Typical Data Shared Representative Providers
Payment Gateways Payment processing, billing reconciliation, fraud screening, chargeback dispute defense Name, email, billing address, transaction amount, IP/device tokens Stripe, PayPal, CoinPayments, Cryptomus
Fraud & Risk Prevention Fraud detection, order risk scoring, identity validation Account identifiers, IP address, device fingerprints, billing metadata FraudLabs Pro, MaxMind
CDN, DNS & Security Web performance, DNS routing, DDoS mitigation, web application firewall (WAF) IP address, connection telemetry, HTTP request metadata Cloudflare
Data Centers & Infrastructure Physical server hosting, network hardware, remote-hands support Assigned IP allocations, server identifiers, operational telemetry Regional Tier-III/IV Data Centers globally
Upstream Network & Transit Internet connectivity, BGP routing, IP transit IP packet headers, routing metadata, network flow data Upstream Tier-1/2 Transit Providers & IXPs
eSIM & Mobile Partners eSIM profile provisioning, roaming connectivity, carrier fulfillment ICCID, EID, IMEI, roaming usage metrics RedteaGo, CMLink, partner mobile operators
Logistics & Shipping Delivery of physical hardware, SIM cards, or equipment Name, shipping address, recipient phone number DHL, FedEx, local postal operators
Professional Advisers Legal counsel, statutory audits, accounting, corporate compliance Information strictly relevant to the legal or audit matter Legal counsel, external audit firms
Legal Authorities Compliance with statutory mandates, court orders, or lawful subpoenas Data strictly mandated by applicable legal process Courts, law enforcement, tax authorities

6. Cookies and Tracking Technologies

We use cookies, local browser storage, and related technologies to deliver a secure and seamless web experience:

  • Essential Cookies: Required for user authentication, session security, shopping cart operations, and anti-bot protection. These cannot be disabled without impairing website functionality.
  • Functional Preferences: Storing your chosen language, display themes, and localized UI settings.
  • Analytics & Measurement: Analytics services (e.g., Cloudflare Web Analytics and privacy-configured Google Analytics) may be used to measure site performance and improve user flows. Where supported, these services are configured to minimise unnecessary collection and cross-site tracking.

You can manage or disable optional cookies through your browser settings.

7. Data Storage Locations and International Processing

Homura Network Limited is headquartered in Hong Kong. We and our authorized service providers process data across secure facilities globally:

  • Central Account and Billing Data: Account credentials, invoices, commercial records, and support tickets are processed and securely stored in our central infrastructure located in Hong Kong, the United States, or certified regional cloud environments.
  • Customer Content (VPS & Hosting): Primary live Customer Content stored on your VPS or hosting environment is ordinarily stored in the data center region selected for the applicable service (e.g., Hong Kong, Singapore, Tokyo, Los Angeles). Where backup, snapshot, replication, or disaster-recovery functionality is provided, copies may be stored or processed in geographically separate secure facilities as necessary to provide those functions or as otherwise disclosed for the applicable service.
  • Telecommunications and Roaming Data: eSIM and roaming traffic metadata are processed across local carrier networks and partner platforms as required for international cellular routing.
  • Cross-Border Safeguards: Personal Data may be processed in jurisdictions with data protection laws different from those of Hong Kong. Where cross-border processing occurs, we apply appropriate technical, organisational, and, where required by applicable law, contractual safeguards. These may include encryption in transit, access controls, and contractual data-protection obligations imposed on relevant service providers.

8. Data Retention and Deletion

We retain Personal Data only for as long as necessary to fulfill the operational, contractual, and legal purposes for which it was gathered:

  • Customer Content: When a compute or hosting service is cancelled or terminated, active virtual instances, associated disks, and customer-accessible snapshots are deleted as part of service deprovisioning in accordance with our service terms. Residual copies contained in backup or disaster-recovery systems, if any, are deleted or overwritten in accordance with the applicable backup retention cycle, unless retention is required by law or for an unresolved security or legal matter.
  • Invoicing and Financial Records: Generally retained for seven (7) years to satisfy Hong Kong statutory accounting, tax reporting, and audit requirements, or for a longer period where required by applicable law or reasonably necessary for an unresolved dispute, investigation, or legal claim. After the applicable retention period, Personal Data contained in such records is deleted, anonymized, or otherwise retained only where a continuing lawful retention requirement applies.
  • Identity and Verification Documents: Government ID copies, proof of address, and sensitive verification documents collected for fraud screening are securely deleted within ninety (90) days after verification is completed, unless extended retention is required by applicable law, a regulatory requirement, an ongoing fraud investigation, or a legal dispute.
  • Network and Operational Logs: Operational telemetry, access logs, and firewall records are retained for a rolling period of 6 to 18 months for diagnostic, security, and abuse analysis before being purged or aggregated.
  • Account and Correspondence Data: Support tickets and contact history are maintained while the account is active and for a reasonable period following account closure to resolve residual inquiries, defend against legal claims, or prevent recurring fraud.

9. Data Security and Breach Notification

We deploy comprehensive administrative, physical, and technical safeguards to protect Personal Data against unauthorized access, accidental loss, disclosure, alteration, or destruction. Key security measures include:

  • Encrypted communications (TLS/HTTPS, SSH, VPN protocols);
  • Strict principle of least privilege (PoLP) access controls for internal personnel;
  • Continuous network perimeter monitoring, DDoS mitigation, and intrusion prevention;
  • Regular system patching, vulnerability assessments, and infrastructure hardening.

9.1 Data Breach Response

In the event of a confirmed security incident affecting Personal Data under our direct control, we maintain a structured incident-response process and will take appropriate measures to contain, investigate, and remediate the incident.

Where notification is required by applicable law, or where notification is appropriate having regard to the nature of the incident and the risk of harm to affected individuals, we will notify affected individuals, the PCPD, and/or other competent authorities as appropriate.

Notifications will be made within applicable statutory timeframes and, where no mandatory timeframe applies, as soon as reasonably practicable having regard to the circumstances of the incident.

10. Your Privacy Rights

Your rights regarding Personal Data depend on the data protection laws applicable to you.

10.1 Hong Kong PDPO Rights

Under the Hong Kong Personal Data (Privacy) Ordinance, you may:

  • Request Access: Request confirmation of whether Homura Network holds Personal Data relating to you and, where applicable, obtain a copy of that data.
  • Request Correction: Request correction of inaccurate Personal Data held about you.

Valid data access and correction requests are handled in accordance with the procedures and statutory timeframes prescribed by the PDPO, which generally require a response within forty (40) days.

10.2 Additional Rights and Requests

Where provided by applicable law, or where offered by Homura Network as an additional privacy measure, you may also request:

  • deletion of Personal Data that is no longer required;
  • closure of your account; or
  • an export of certain account or service data in a structured format.

Such requests remain subject to applicable statutory retention requirements, security and fraud-prevention requirements, ongoing disputes, legal claims, and other lawful grounds for retention.

Where other data protection laws apply to you, additional statutory rights may be available under those laws.

To submit a privacy request, contact:

privacy@homura.network

Our services are strictly intended for individuals who have reached the age of legal majority in their jurisdiction (typically 18 years or older) or entities represented by authorized personnel. We do not knowingly collect Personal Data from minors without verifiable parental or guardian consent. If you believe a minor has submitted Personal Data without proper authorization, please contact privacy@homura.network for prompt deletion.

12. Policy Updates

We may periodically update this Privacy Policy to reflect modifications in our service portfolio, technology stack, legal requirements, or business practices. The latest revision date is prominently displayed at the top of the policy page. Significant changes will be communicated through our client portals, email notices, or announcements.

13. Contact and Business Information

  • Legal Entity: Homura Network Limited
  • Business Registration: BRN 75553711
  • Registered Office: Room 25, 5/F, Block B, Kwai Shing Industrial Building Phase 1, 36-40 Tai Lin Pai Road, Kwai Chung, N.T., Hong Kong
  • Privacy & Data Inquiries: privacy@homura.network
  • Abuse & Infringement: abuse@homura.network
  • Customer Support: Existing customers may submit a ticket via the client portal (Homura.Network, NAT.Toys, eSIM.day).

14. Language and Governing Version

This Privacy Policy may be translated into multiple languages for customer convenience. In the event of any material inconsistency, discrepancy, or interpretive conflict between translated versions and the English version, the English version shall prevail to the maximum extent permitted by applicable law.