Website legal policy

Information Security and Personal Data Breach Statement

This public statement summarises Lily Asia’s approach to protecting website and business information. Detailed controls and incident procedures are maintained internally and are not published for security reasons.

Effective date: 19 July 2026  |  Version 1.0

1. Security governance

Security responsibilities are assigned based on role, access is limited to business need, and service providers are selected and contracted with regard to confidentiality, privacy and security requirements.

2. Safeguards

3. Incident response

Suspected incidents are assessed, contained, investigated, documented and remediated. Where a personal data breach is likely to affect individuals or notification is required, we will communicate with affected persons and relevant authorities in the form and timeframe required by applicable law.

4. User responsibilities

Users should keep devices and browsers updated, avoid sending sensitive information through unsecured channels, verify payment instructions and report suspicious activity promptly.

5. Security reports

Report a suspected vulnerability or data incident to business@lilyinasia.com with the subject “Security Incident”. Do not include exploited personal data or publicly disclose details before coordinated remediation.