Effective Date: 25 May 2026
Introduction
Welcome to Jucha.com. This Privacy Policy ("Policy") is established and published by AppWave Limited (a company incorporated in the Hong Kong Special Administrative Region, hereinafter referred to as the "Company" or "we") in accordance with the Personal Data (Privacy) Ordinance (Cap. 486 of the Laws of Hong Kong) ("PDPO").
This Policy forms an integral part of the Terms of Use of Jucha.com and supplements the Third-Party Account Authorized Login Agreement. We fully appreciate the importance of personal data privacy to you and are committed to collecting, using, storing, processing, disclosing and protecting personal data strictly in compliance with the PDPO, in particular the six Data Protection Principles set out in Schedule 1 thereto, and the best practice guidelines issued by the Privacy Commissioner for Personal Data, Hong Kong ("Privacy Commissioner").
Jucha.com is dedicated to providing users with "simple, convenient, efficient and comprehensive" domain name-related information query services, striving to create an information-rich, highly accurate and reliable comprehensive domain information query platform.
Please read and fully understand this Policy, in particular the important terms identified in bold or underlined text, before using our services. Your continued access, registration, login or use of our services signifies that you have read, understood and agreed to all terms of this Policy. If you do not agree to any term of this Policy, you should immediately cease using our services.
1. Definitions
1.1 "Jucha.com" or "Platform" means the comprehensive domain name information query service platform operated by AppWave Limited, accessible at www.jucha.com.
1.2 "User" or "you" means any individual or entity that accesses and/or uses the products and services provided by Jucha.com.
1.3 "Personal data" has the meaning assigned to it in section 2(1) of the PDPO, namely: (a) any data relating directly or indirectly to a living individual; (b) from which it is practicable for the identity of the individual to be directly or indirectly ascertained; and (c) in a form in which access to or processing of the data is practicable.
1.4 "Data subject" means the individual who is the subject of the personal data.
1.5 "Domain name query" means queries of basic domain information, filing (ICP) information, backlink information, registration information, Whois information, website history, interception detection, offline query and other data.
1.6 "Third-party account" means an account with any of the following third-party platforms that may be used by a User to log into Jucha.com: Juming account, Juyu account, Google account, Apple account, X (formerly Twitter) account, and any other third-party login methods announced on our official website.
1.7 "User behaviour data" means data generated through your use of the Platform's services that relates to usage behaviour, including but not limited to query records, feature usage preferences, page browsing paths, dwell time, click behaviour and account activity.
1.8 "Anonymised/aggregated data" means data that has been processed so that it can no longer be used to identify a specific individual and cannot be re-identified, or statistical data derived from the aggregation of group data.
1.9 "Cookies" means a technology whereby, when a user visits the Platform equipped with Cookies functionality, the Platform's server automatically sends Cookies to the user's browser and stores them on the user's computer hard drive for the purpose of recording future visit activities and related settings.
1.10 "Force majeure" means any unforeseeable (or, if foreseeable, unavoidable in occurrence or consequences) event beyond the reasonable control of either party that prevents full performance of this Policy, including natural disasters, government acts, social abnormal events, hacker attacks, technical controls imposed by telecommunications authorities, or any other natural or man-made disasters occurring during the term of this Policy.
2. Collection of Personal Data
2.1 Collection Principles
We collect personal data in accordance with Data Protection Principle 1 (Purpose and Manner of Collection) of the PDPO, by lawful and fair means, for purposes directly related to our functions and activities. We only collect personal data that is necessary and adequate for, and not excessive in relation to, the purpose for which it is collected.
2.2 Personal Data You Provide Voluntarily
(A) Account Registration Data
When you register an account on our Platform, we may collect the following data:
(a) email address;
(b) username/display name;
(c) your self-created login password (irreversibly encrypted);
(d) registration time and registration IP address.
(B) Third-Party Account Login Data
When you log in by authorising a third-party account, pursuant to the Platform's Third-Party Account Authorized Login Agreement, we may obtain the following data from the authorising third-party platform:
(a) your user identification code (User ID) on the third-party platform;
(b) username/display name;
(c) email address verified by the third-party platform;
(d) login credentials, tokens or statuses related to security authentication;
(e) profile picture and other basic account data that you choose to share on the third-party platform.
We will not obtain your account password on the third-party platform, nor will we modify or operate such third-party account without authorisation.
(C) Customer Service Data
When you request technical support, lodge a complaint or provide feedback via email, our ticket system or other means, we may collect:
(a) your name (or username);
(b) email address;
(c) the description of your issue, correspondence records, and any other supporting data you voluntarily provide.
(D) Transaction and Points Data
When you use services such as offline queries that consume points or involve payment, we may collect necessary transaction records and points usage status.
2.3 Data Collected Automatically
When you access and use Jucha.com, we may automatically collect the following data:
(A) Technical Data
(a) IP address;
(b) browser type and version;
(c) operating system type and version;
(d) device identifiers and screen resolution;
(e) domain name of your internet service provider (ISP);
(f) date, time and duration of access;
(g) URLs of pages browsed and clicked, and referrer URLs.
(B) Query Service Related Records
(a) Online queries: To provide query services and ensure the normal operation of our systems, we may record your operation time, operation type (such as comprehensive query, WHOIS query, etc.) and basic interaction information. We do not store the specific domain name content you query online, and you cannot view historical specific query records through our Platform.
(b) Offline queries: When you use the offline query service, we will record the domain name list you submit, the type of query and related operational information so as to complete the background query tasks and enable you to view the query order and results in your member centre. Such records will only be available for your review for a limited period, after which they will be removed from your visible records.
2.4 User Behaviour Data
To improve service quality, optimise user experience, research domain industry trends and generate industry insights, we may collect and analyse your user behaviour data on our Platform, including but not limited to:
(a) domain name query records (including queried domain names, function modules used and query times);
(b) feature usage frequency and preferences;
(c) page browsing paths and dwell time;
(d) click behaviour, search habits and interaction data;
(e) account activity and preferred tools.
The collection and analysis of such data will be conducted in an aggregated or anonymised manner. We will apply technical measures during data processing to render such data incapable of identifying a specific individual. We may use the results of the analysis of anonymised or aggregated data to compile and publish user behaviour reports, domain industry trend reports, market research reports or statistical insights. Such reports will not contain any data capable of identifying a specific individual.
2.5 Data from Publicly Available Sources
Given that Jucha.com is a domain name information query platform, we may obtain, cache, organise or display data from public databases, registries, registrars, ICP filing systems, search engines and other publicly available sources, including:
(a) Whois information;
(b) domain name registration status, registration date and expiration date;
(c) DNS information;
(d) website filing (ICP) information;
(e) website history;
(f) security detection results;
(g) search engine inclusion and weight data;
(h) backlink information.
The above information primarily originates from third-party public databases or sources made public in accordance with law. Such information does not fall within the definition of "personal data" governed by this Policy, but we will still observe reasonable information management practices in handling it.
3. Use of Personal Data
3.1 Use Principle
In accordance with Data Protection Principle 3 (Use of Personal Data) of the PDPO, personal data will only be used for the purpose specified at the time of collection or for a directly related purpose. Any use beyond the original purpose must obtain your express consent in accordance with the PDPO, unless otherwise provided by law.
3.2 Service Provision and Maintenance
We use personal data to:
(a) complete user registration, login and identity authentication;
(b) provide, maintain and optimise various service functions, including comprehensive domain query, WHOIS query, website history query, filing query, search engine inclusion and weight query, interception detection, offline query, etc.;
(c) manage member accounts, the points system and query orders;
(d) send you necessary service-related notifications (such as service changes, security alerts, offline query completion notices, etc.) via email;
(e) respond to your technical support requests, enquiries and feedback.
3.3 Security and Risk Control
We use personal data to:
(a) maintain account security, conduct abnormal login monitoring and risk control;
(b) prevent fraud, abuse, malicious queries, crawler attacks and other abnormal behaviour;
(c) identify security risks and ensure system stability and data security;
(d) investigate and handle suspected breaches of the Terms of Use.
3.4 Data Analysis and Industry Research
We may, based on user behaviour data, query data and overall Platform usage, carry out the following:
(a) research on domain market trends and industry hotspots;
(b) statistical analysis of user preferences and service effectiveness;
(c) optimisation of product features, recommendation algorithms and user experience;
(d) generation and external publication of anonymised or aggregated user behaviour reports, domain industry trend reports, market research reports or statistical insights;
(e) market research and business analysis.
Except as otherwise required by laws and regulations, we will not disclose information that can directly identify a user in such reports.
3.5 Marketing and Promotion
With your express consent, we may use the email address you provide to send you electronic communications, promotional materials, service updates or event invitations. You may withdraw such consent at any time via written notice or the unsubscribe method specified in the email. Withdrawal of consent does not affect the lawfulness of processing based on consent prior to such withdrawal.
3.6 Legal and Compliance Obligations
We may use personal data for the following purposes:
(a) compliance with applicable laws, regulations and regulatory requirements;
(b) responding to requests from judicial, law enforcement or regulatory authorities;
(c) handling complaints, domain name disputes, infringement issues or legal proceedings;
(d) fulfilling requirements of ICANN, domain name registries or relevant industry policies.
4. Accuracy of Personal Data
4.1 Obligation of Accuracy
In accordance with Data Protection Principle 2 (Accuracy and Retention of Personal Data) of the PDPO, we shall take all practicable steps to ensure that personal data held by us is accurate, up-to-date and complete having regard to the purpose for which it is used.
4.2 Right of Correction
You have the right to request correction of any personal data that is inaccurate, incomplete, misleading or outdated. If you find that your personal data needs updating, please notify us via the contact method set out in Article 15.
4.3 Right of Access and Fees
You have the right under the PDPO to ascertain whether we hold your personal data and to access such data, as well as to inquire about our policies and practices regarding the personal data we hold. To exercise these rights, please submit a request in writing via the contact method set out in Article 15 of this Policy. We may charge a reasonable fee for handling an access request.
5. Retention and Deletion of Personal Data
5.1 Retention Period Principle
Pursuant to Data Protection Principle 2 and section 26(1) of the PDPO, personal data shall not be kept longer than is necessary for the fulfilment of the purpose (including any directly related purpose) for which it was collected. When personal data held by us is no longer required for the purposes described in this Policy, we will take all practicable steps to delete it.
5.2 Statutory and Industry Retention Requirements
Notwithstanding Article 5.1, where necessary for the performance of statutory dispute resolution procedures, compliance with the requirements of domain name industry regulatory bodies, or compliance with applicable laws, we are required to retain the necessary data elements for not less than 15 months following:
(a) the date of termination of the relevant service relationship; or
(b) the date of completion of the change of account ownership,
whichever is later.
Where any law prohibits the deletion of such data, or where retention is required in the public interest (including historical preservation), we will continue to retain the data in accordance with the law.
5.3 Deletion Measures
We will take the following practicable deletion measures:
(a) regularly review personal data stored in our systems to determine whether retention remains necessary;
(b) identify and flag personal data that has exceeded the applicable retention period;
(c) permanently delete personal data from active systems, backup systems and cloud platforms in accordance with internationally recognised standards (such as NIST SP 800-88 and ISO/IEC 27040), ensuring that it is not recoverable by reasonably available means;
(d) maintain records of deletion operations, including the categories of data processed, methods used, execution date and responsible person, for compliance review.
5.4 Anonymisation as an Alternative to Deletion
Where data needs to be retained for research, statistical or industry reporting purposes, we will irreversibly anonymise the personal data so that it can no longer be used to directly or indirectly identify an individual, ensure that the anonymised data cannot be re-identified, and not use it in any way that reveals the identity of any individual. Upon completion of anonymisation, the original personal data will no longer be retained in an identifiable form.
5.5 Long-term Retention of Aggregated and Anonymised Data
Data that has been anonymised or aggregated and is no longer capable of identifying an individual is not subject to the above retention periods and may be retained long-term for research, statistical and report publication purposes.
6. Security of Personal Data
6.1 Technical and Organisational Measures
In accordance with Data Protection Principle 4 (Security of Personal Data) of the PDPO, we will take all practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss or use, including but not limited to:
(a) using SSL/TLS encryption technology to protect data during transmission;
(b) implementing encryption and de-identification processing for stored personal data;
(c) implementing strict access control mechanisms, firewalls and intrusion detection systems;
(d) conducting regular security reviews, vulnerability assessments and log audits;
(e) establishing data backup and disaster recovery mechanisms.
6.2 Personnel Access and Confidentiality
Access to and processing of personal data shall be limited to authorised personnel, agents or contractors who are bound by contractual or statutory confidentiality obligations. We provide regular privacy protection and information security training to personnel with access to personal data.
6.3 Handling of Security Incidents
In the event of a security incident involving personal data, a data breach or unauthorised access, we will, in accordance with the PDPO and guidelines issued by the Privacy Commissioner, promptly take remedial measures (including but not limited to ceasing the infringement, assessing the impact and repairing vulnerabilities), and, depending on the severity of the incident and legal requirements, notify the affected data subjects and/or relevant regulatory authorities as soon as reasonably practicable.
7. Cookies and Similar Technologies
7.1 Purposes of Use
We may use cookies, pixel tags, local storage and similar technologies to:
(a) save your login status and account preferences;
(b) identify users to provide personalised services;
(c) compile visitor traffic statistics, analyse user behaviour and optimise page display;
(d) record browsing habits to improve website management and services;
(e) assist in preventing security risks and fraudulent activities.
Cookies do not enable us to access other information stored on your device.
7.2 Management
You may manage, restrict or disable cookies through your browser settings. Please note, however, that disabling cookies may affect certain features of the Platform (such as automatic login, personalised recommendations, etc.), but you will still be able to access most basic content of the Platform.
8. Disclosure of Personal Data
8.1 Disclosure Principle
Personal data will be kept strictly confidential, but may be disclosed where necessary to fulfil the purposes set out in this Policy. We will not sell your personal data to third parties for commercial gain.
8.2 Disclosure to Service Providers
We may disclose personal data to service providers, contractors, agents or professional advisors bound by contractual confidentiality obligations, to assist us in operating the Platform and providing services, including but not limited to:
(a) cloud service providers and data storage service providers;
(b) security monitoring and technical support service providers;
(c) email communication service providers;
(d) data analysis and research service providers.
Such third parties may only access personal data to the extent necessary to perform their functions and must comply with privacy protection standards no less stringent than those required by this Policy.
8.3 Legally Compelled Disclosure
We may disclose your personal data in the following circumstances:
(a) where disclosure is required by applicable laws, regulations, court orders or regulatory authorities;
(b) to fulfil legal obligations within or outside Hong Kong;
(c) to protect the public interest, national security or the vital interests of others;
(d) where necessary for the investigation, prevention or handling of fraud, security incidents or illegal acts.
8.4 Disclosure in Corporate Transactions
In the event of a merger, reorganisation, asset transfer, consolidation or similar corporate transaction, relevant personal data may be transferred as part of the transaction assets. In such an event, we will require the recipient to continue to comply with this Policy, or will separately notify you of the relevant privacy arrangements and obtain consent as required by law.
8.5 Prohibition on Commercial Disclosure
Without the prior express consent of the data subject, we will not disclose, sell, rent, transfer or otherwise share your personal data (including but not limited to email address and user behaviour data) with any third party or affiliate for their marketing, promotional or advertising purposes.
9. Cross-border Transfer of Personal Data
9.1 Necessity of Cross-border Transfer
In the course of providing our services, we may need to transfer personal data outside the Hong Kong Special Administrative Region for purposes including but not limited to:
(a) data storage, backup and recovery via cloud or distributed systems;
(b) DNS hosting, security monitoring and technical infrastructure operation and maintenance;
(c) compliance with requirements imposed by ICANN, domain name registries or applicable laws of the relevant jurisdiction;
(d) transfer to overseas service providers to assist in the performance of their functions.
The jurisdictions to which personal data is transferred may vary depending on operational, contractual and technical factors.
9.2 Contractual Safeguards
Where applicable, we will enter into written contractual arrangements with overseas recipients to ensure that personal data transferred outside Hong Kong is afforded a level of protection substantially equivalent to that required under the PDPO. Such contracts may refer to the Recommended Model Contract Clauses for Cross-border Transfer of Personal Data published by the Privacy Commissioner in 2022, and shall include the following:
(a) restriction of data use to the purposes specified for the transfer;
(b) prohibition of retention beyond the period necessary for processing;
(c) implementation of adequate technical and organisational security measures;
(d) restriction on further disclosure to other parties without our prior written consent.
9.3 User Acknowledgement
By continuing to use our services after the effective date of this Policy, you are deemed to have acknowledged, accepted and not objected to the transfer of your personal data outside Hong Kong as described in this Article. If you do not agree to such transfer, you should immediately cease using our services and may address any inquiries or objections to the contact details set out in Article 15 of this Policy.
9.4 Transfer Security Measures
All cross-border transfers of personal data shall be conducted via secure communication channels and encryption protocols, and shall be subject to strict internal access controls to minimise the risk of unauthorised access, interception or data loss.
10. User Rights
Under the PDPO, you have the following rights in respect of your personal data held by us. To exercise any of these rights, please submit a request in writing via the contact method set out in Article 15 of this Policy:
10.1 Right of Access: You have the right to ascertain whether we hold your personal data and to access such data and its uses.
10.2 Right of Correction: You have the right to request correction of any personal data that is inaccurate, incomplete, misleading or outdated.
10.3 Right to Object: You have the right to request that we cease using your personal data for direct marketing purposes, or to object to our continued processing of your personal data based on specific legitimate interests.
10.4 Right to Erasure: Subject to the provisions of the PDPO and the extent permitted by law, you have the right to request that we delete your personal data held by us.
10.5 Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent prior to such withdrawal, but may affect your ability to continue using certain service features.
10.6 Exercise and Timeframe: We may charge a reasonable fee for handling access requests. We will respond to your request within the statutory timeframe prescribed by the PDPO and cooperate with you in exercising your rights to the extent reasonably practicable. If you refuse to provide the personal data we request, we may be unable to perform our contractual obligations or provide the corresponding services.
11. Third-Party Services
11.1 Links to Third-Party Websites
The Platform may contain links to third-party websites, tools or services. This Policy does not apply to such third-party websites or services. We accept no responsibility for the privacy practices, information handling methods or content of such third parties, nor for their accuracy, quality, security, legality, intellectual property compliance or privacy policies. You should review the relevant terms and privacy policies of such third-party services yourself and assume all associated risks when using them.
11.2 Third-Party Account Login
When you log in using a third-party account, the Platform only uses such account for identity authentication. It does not grant you any additional rights with respect to the third-party platform, nor does it alter the legal relationship between you and the third-party platform. We accept no liability for the availability, stability, policy changes or technical issues of any authorised third-party platform.
12. Protection of Minors' Privacy
12.1 Nature of Service and Principle
The Platform is not specifically designed for minors, and we have no intention of collecting personal data from minors. We solemnly declare that: any minor under the age of 16 participating in online activities should first obtain verifiable consent from their parent or legal guardian (collectively, "Guardian").
12.2 Guardian Consent
If you are under the age of 18, you should obtain the consent of your parent or legal guardian before using the Platform. Guardians bear the primary responsibility for protecting the privacy rights of minors in the online environment.
12.3 Actions Upon Discovery
If we discover any personal data of a minor collected without guardian consent, or if you have used our services and provided personal data without guardian consent while being a minor, we will take reasonable steps to delete such data from our records, or continue to use it only after obtaining verifiable guardian consent.
12.4 Guardian Rights
Guardians of minors have the right to:
(a) review the data collected from their child or ward;
(b) refuse further collection or use of their child's or ward's personal data;
(c) request modification or deletion of their child's or ward's personal data;
(d) refuse further contact between the Platform and their child or ward.
13. Disclaimer and Limitation of Liability
13.1 Force Majeure
In the event of a force majeure event (including but not limited to earthquakes, typhoons, fires, floods, war, strikes, riots, hacker attacks, technical controls imposed by telecommunications authorities, or any other natural or man-made disasters) that prevents us from fully performing our obligations under this Policy, we will notify you as soon as reasonably practicable and will be exempted from liability to the extent affected by such force majeure event.
13.2 Third-Party Factors
We accept no liability, to the fullest extent permitted by law, for any leakage, loss, delay or tampering of personal data caused by factors beyond our reasonable control, including your terminal equipment, network environment, internet service provider, third-party service providers, etc.
13.3 User's Own Acts
You shall be solely responsible for any leakage of personal data resulting from your own acts, including but not limited to disclosing your account password to others, publishing personal data in public forums or comment sections, or failing to keep your login credentials secure.
13.4 Cap on Liability
To the fullest extent permitted by law, we accept no liability for any direct, indirect, special, incidental or consequential damages (including loss of profits) arising out of or in connection with the use of the Platform's services or this Policy. Our total liability to you or any third party (whether in contract, tort or otherwise) shall not exceed the amount (if any) paid by you for accessing the Platform.
14. Policy Updates
14.1 Right to Update
We reserve the right, at our sole discretion, to amend, update or modify this Policy to reflect changes in laws, regulatory requirements, technology or operational needs.
14.2 Effectiveness and Notice
The revised Policy will be published on our official website (www.jucha.com) and will take effect on the date of publication, unless otherwise stated. If the changes to this Policy constitute a material change, we will notify you through appropriate means, including but not limited to a prominent notice on the website or email notification.
14.3 Continued Use Deemed Acceptance
Your continued use of the Platform after the effective date of the revised Policy signifies your unconditional and unreserved acceptance of and agreement to be bound by the then-current terms of the Policy. We encourage you to review this Policy periodically to understand how we protect your personal data.
15. Complaints and Dispute Resolution
15.1 Internal Complaint Handling
If you believe that we have not complied with the PDPO or this Policy, you have the right to lodge a complaint with us. We will investigate and respond to your complaint as soon as possible and take appropriate remedial measures (where reasonable and practicable). Without prejudice to your legal rights, we encourage data subjects to first communicate with us directly to resolve the matter before lodging a complaint with the Privacy Commissioner for Personal Data, Hong Kong.
15.2 Governing Law
This Policy shall be governed by and construed in accordance with the laws of the Hong Kong Special Administrative Region of the People's Republic of China.
15.3 Dispute Resolution
Any dispute arising out of or in connection with this Policy shall first be resolved through friendly negotiation between the parties. If negotiation fails, either party may submit the dispute to the Hong Kong International Arbitration Centre (HKIAC) for arbitration in accordance with its arbitration rules then in effect. The seat of arbitration shall be the Hong Kong Special Administrative Region. The arbitral award shall be final and binding on both parties.
15.4 Severability
If any provision of this Policy is held to be invalid, void or unenforceable, such provision shall be deemed severable and shall not affect the validity and enforceability of the remaining provisions.
16. Contact Information
If you have any questions, comments or complaints regarding this Policy or how we handle personal data, or if you wish to exercise any of the rights set out in Article 10 of this Policy, please contact us via the online contact channel available on our website (www.jucha.com).
We will respond to your request within a reasonable time. For requests requiring further identity verification or involving complex processing, we may require additional time, but we will endeavour to complete the process within the statutory timeframe prescribed by the PDPO.
Domain Query Tool