|
May 21, 2012
PERSONAL DATA (PRIVACY) ORDINANCE - PRIVACY POLICY
STATEMENT
GENERAL
This policy statement provides information on the obligations and policies
of
hahk.com, its subsidiaries, affiliates, and associated companies (the "Company")
under the Hong Kong SAR Personal Data (Privacy) Ordinance 1995 - Cap.486 (the "Ordinance").
Although this policy specifically addresses the Company's obligations in respect of the
laws of the Hong Kong SAR, the Company believes the principles embedded in the Ordinance are
equal to any in the world in respect of the protections they provide to an individual. As
such, the Company undertakes to apply, where practicable, those principles and the processes
set out herein to its operations globally.
Where the Company's operations are subject to privacy legislation other than that of Hong
Kong SAR, then this policy shall be applied so far as practicable and consistent with such
local legislation. For further details on the Company's compliance with the Ordinance and
any other privacy legislation, please contact the Company's Privacy Compliance Officer
privacy@hahk.com.
Throughout this policy, our use of the term "personal data" has the meaning ascribed to it
by the Ordinance.
OUR CORPORATE POLICY
The Company shall fully comply with the obligations and requirements of
the Ordinance. The Company's officers, management, and members of staff shall, at all times,
respect the confidentiality of and endeavor to keep safe any and all personal data collected
and/or stored and/or transmitted and/or used for, or on behalf of, the Company.
The Company shall endeavor to ensure all collection and/or storage and/or transmission
and/or usage of personal data by the Company shall be done in accordance with the obligations
and requirements of the Ordinance.
Where an individual legitimately requests access to and/or correction of personal data
relating to the individual, held by the Company, then the Company shall provide and/or
correct that data in accordance with the times and manner stipulated within the
Ordinance.
STATEMENT OF PRACTICES
TYPES OF PERSONAL DATA COLLECTED
For the purpose of carrying on the Company's business, including registration and
administration of the Company's telecommunications and related products and services
(including relevant online services), you may be requested to provide personal data such as,
but not limited to, the following, without which it may not be possible to satisfy your
request:
- Your name;
- Service installation address, correspondence address, and/or billing address;
- Account details, including account numbers, service numbers, or user accounts;
- Payment details, including credit card and banking information;
- Contact details, including contact name and telephone number or email address; or
- Information for the verification of identity, including identification type and
identification number.
In some instances, you may also be requested to provide certain data that may be used to
further improve our products and services and/or better tailor the type of information
presented to you. In most cases, this type of data is optional although, where the requested
service is a personalised service, or provision of a product is dependant on your providing
all requested data, failure to provide the requested data may prevent us from providing the
service to you. This type of data includes, but is not limited to:
- Your age;
- Gender;
- Salary range and employment details;
- Education and Profession;
- Hobbies and leisure activities;
- Other related products and services subscribed to; and
- Family and household demographics.
In support of the telecommunications and other services offered by the
Company, information may be automatically collected relating to those services so we may
perform accurate reporting and administration of your accounts such as, but not limited to,
call/connection time, duration, origin, and destination.
The Company's Web servers may also collect data relating to your online session, the use
of which is to provide aggregated, anonymous, statistical information on the server's usage
so that we may better meet the demands and expectations of visitors to our sites. This type
of data may include, but is not limited to:
- The browser type and version;
- Operating system; and
- The IP address and/or domain name.
Some of the Company's Websites may place a "cookie" on your machine; for example to
provide personalised services and/or maintain your identity across multiple pages within or
across one or more sessions. This information may include, but is not limited to, relevant
login and authentication details as well as information relating to your activities and
preferences across our Websites.
Under certain circumstances, telephone calls made to our order and/or service hotlines
and/or inquiry telephone numbers are recorded for the purposes of quality control, appraisal,
as well as staff management and development. Unless expressly indicated at the time of
calling, such recordings are NOT personal data of the caller and therefore, in respect of the
caller, are not subject to the various provisions of the Ordinance and the caller has no
rights and/or claims; either statutory, contractual or tortious, over or to such data. At
all times, every care is taken to protect such recordings from inadvertent and/or
unauthorized access.
ACCURACY OF PERSONAL DATA
Where possible, we will validate data provided using generally accepted practices and
guidelines. This includes the use of check sum verification on some numeric fields such as
account numbers or credit card numbers. In some instances, we are able to validate the data
provided against pre-existing data held by the Company. In some cases, as per the
requirements of the Ordinance, the Company is required to see original documentation before
we may use the personal data such as with Personal Identifiers and/or proof of address.
RETENTION OF PERSONAL DATA
The Company will destroy any personal data it may hold in accordance with our internal
retention policy. The policy states that:
- Personal data will only be retained for as long as is necessary to fulfil the original or
directly related purpose for which it was collected, unless the personal data is also
retained to satisfy any applicable statutory or contractual obligations; and
- Personal data are purged from the Company's electronic, manual, and other filing systems
in accordance with specific schedules based on the above criteria and the Company's internal
procedures.
DISCLOSURE OF PERSONAL DATA
All personal data held by the Company will be kept confidential but the Company may, where
such disclosure is necessary to satisfy the purpose, or a directly related purpose, for which
the data was collected provide such information to the following parties:
- Any subsidiaries, holding companies, associated companies, or affiliates of, or companies
controlled by, or under common control with the Company;
- Any person or company who is acting for or on behalf of the Company, or jointly with the
Company, in respect of the purpose or a directly related purpose for which the data was
provided;
- Any other person or company who is under a duty of confidentiality to the Company and has
undertaken to keep such information confidential, provided such person or company has a
legitimate right to such information; and
- Any financial institutions, charge or credit card issuing companies, credit information
or reference bureaux, or collection agencies necessary to establish and support the payment
of any services being requested.
Personal data may also be disclosed to any person or persons that have a right under the
Ordinance to gain access to such information provided they are able to prove their authority
to access such information. For example, if the Company were served with a court order
demanding certain customer information then the Company would disclose the information to the
duly appointed officer of the court or such other persons as the court orders.
TRANSFER OF PERSONAL DATA OUTSIDE OF HONG KONG
At times it may be necessary and/or prudent for the Company to transfer certain personal
data to places outside of the Hong Kong SAR in order to carry out the purposes, or directly
related purposes, for which the personal data were collected. Where such a transfer is
performed, it will be done in compliance with the requirements of the Ordinance.
SECURITY OF PERSONAL DATA
Physical records containing personal data are securely stored in locked areas and/or
containers when not in use.
Computer data are stored on computer systems and storage media to which access is strictly
controlled and/or are located within restricted areas.
Access to records and data without appropriate management authorization are strictly
prohibited. Authorizations are granted only on a "need to know" basis that is commensurate
with an individual's Company responsibilities and their training.
Records of the Company are under the control of assigned information officers who are
responsible to ensure the transfer of or access to information is legitimate and complies
with the Ordinance.
Audit records may be produced to validate data modifications in order to verify the data's
integrity.
There may be violations logging processes for investigation of any unauthorized attempt to
access information.
Encryption technology, such as SSL, may be employed for the transmission of data collected
online.
|