1. Overview
This policy statement is provided by BabyMall in accordance with the Personal Data (Privacy) Ordinance—Chapter 486 of the Hong Kong Special Administrative Region (“the Ordinance”), detailing our responsibilities and guidelines.
Although this policy specifically outlines our responsibilities under the laws of the Hong Kong SAR, we believe that the principles of personal data protection in the Ordinance are similar to those in laws worldwide. Therefore, where feasible, we will implement these principles and the procedures outlined here globally.
When our operations are subject to privacy laws outside the Hong Kong SAR, this policy will be implemented as far as practicable and consistent with those laws.
The term “personal data” in this policy has the meaning ascribed to it in the Ordinance.
2. Company Policy
Our company complies with the responsibilities and requirements of the Ordinance. All personnel, management, and employees must keep confidential and properly safeguard all personal data collected and/or stored and/or transmitted and/or used by the company (or on behalf of the company) at all times.
We ensure that all personal data collected, stored, transmitted, or used are handled in accordance with the responsibilities and requirements stipulated in the Ordinance.
If an individual lawfully requests access to and/or correction of the personal data held by the company about them, we will provide and/or correct such data within the time and manner prescribed by the Ordinance.
3. Personal Data Collection Statement
Categories of Personal Data Collected
We may request you to provide the following personal data to register and manage your services (including online services). Without such data, it may be impossible to fulfill your service requests. This data includes (but is not limited to):
a. Name;
b. Contact details, including contact person’s name, phone number, or email address.
In certain circumstances, you may be asked to provide specific information to help us improve our products and services and to offer you information that meets your needs. In most cases, you may choose not to provide this information. However, if the service is personalized or the supply of products requires all the requested information, failure to provide such data may prevent us from providing the desired service. This data includes (but is not limited to):
a. Age;
b. Gender;
c. Salary level;
d. Education level and occupation;
e. Interests and leisure activities;
f. Other relevant products and services used; and
g. Household and home statistics.
h. Credit card information (used only for customers’ personal online purchases of our goods).
Our web server may also collect information about your internet connection in an anonymous manner for aggregate statistical purposes, enhancing our services to better meet the needs and expectations of website visitors. This data includes (but is not limited to):
a. Browser type and version;
b. Operating system; and
c. Internet Protocol (IP) address and/or domain name.
d. Location
4. Use of Cookies
When you browse our website, unless otherwise stated, we only record that you have visited but do not collect any personally identifiable information. Any cookies used on any part of this website (if any) are not used to collect personally identifiable information. Cookies are computer files stored on users’ computers, used to obtain configuration information and analyze browsing habits. Cookies can save you from re-registering every time you visit the website and are usually used to track your preferred website themes. You have the right to choose not to accept cookies, but if you do so, you may not be able to use or activate certain functions of our website.
5. Use of Personal Data
The personal data you provide to us will be used for the following purposes (“Specified Purposes”):
a. Registering on our website to use and/or activate certain features;
b. Providing and delivering the products/services you have ordered, reserved, or requested, and contacting you regarding such products/services;
c. Operating our business, including registering and managing our website;
d. Conducting data sorting and analysis to better understand your characteristics and purchasing behavior, providing you with other services that better meet your needs, and assisting us in selecting products/services you may be interested in;
e. Performing aggregate customer behavior analysis and conducting any other analysis, survey, or research related to our products/services;
f. Any other administration, operation, and maintenance of our products/services/website; and
g. Usage as required by law.
6. Retention of Personal Data
Our company will destroy any personal data held in accordance with our internal retention policies. These policies state:
a. Personal data will be retained until the specified purpose has been achieved, unless such data is required to be retained under any applicable laws or contractual requirements; and
b. According to the above criteria and our internal procedures, personal data will be purged from the company’s electronic, manual, and other storage systems after a specific retention period.
7. Disclosure of Personal Data
All personal data held by our company will be kept confidential. However, we may disclose such data to the following parties when necessary to achieve the specified purposes:
a. Any subsidiary, holding company, affiliated company, or company owned by our company or under the same control or associated with our company;
b. Any individual or company acting on behalf of our company or jointly with our company to achieve the specified purposes;
c. Any other individual or company responsible for keeping such data confidential for our company and who has the legal right to access such data; and
d. Any individual who has the right to access such data under the Ordinance but must prove their authority to access the data; and
e. Any party to whom data must be disclosed due to court orders or government directives. For example, if a court issues an order requiring our company to provide certain customer information, we will disclose such data to the officially appointed personnel of the court.
8. Security of Personal Data
Physical records containing personal data are properly stored in locked storage when not in use. Electronic data is stored in computer systems and storage media with restricted access areas, and access to the data is strictly regulated.
No individual may access records and data without formal authorization from management. Such rights are granted on a “need-to-know” basis and depend on the individual’s duties and training within the company. Our records are controlled by designated data specialists responsible for ensuring that data transfers or access are legal and comply with the Ordinance. We may implement audit logs to verify data changes and ensure data integrity. Procedures may be in place to record violations to investigate unauthorized attempts to access data. When transmitting collected sensitive data online, we may use encryption technologies like SSL.
9. Access and Correction of Personal Data
Under the Ordinance, individuals have the right to:
a. Ascertain whether our company holds personal data about them and (if so) obtain a copy of such data;
b. Request our company to correct any inaccurate personal data about them to fulfill the purpose for which the data is used; and
c. Ascertain our company’s policies and practices regarding their personal data, in general terms, to ensure compliance with this policy and practices.
Individuals can exercise their rights by logging in with their preset username and personal password. Upon being satisfied with the authenticity and validity of the access request, our company will make every effort to comply and respond within the timeframe stipulated by the Ordinance.
Individuals can exercise their correction rights by logging in with their preset username and personal password. Upon being satisfied with the authenticity and validity of the correction request, our company will make every effort to comply and respond within the timeframe stipulated by the Ordinance.
10. Direct Marketing Materials
In accordance with the Ordinance, our company will comply with an individual’s request not to use their personal data for direct marketing purposes. Without your consent or indication of no objection, we will not use your personal data for direct marketing or provide it to others for direct marketing. Even if you have given consent, you have the right to opt-out of receiving direct marketing materials at any time. If you wish to start or stop receiving our direct marketing materials, please email us atadmin@babymall.hkor unsubscribe via the link in our newsletters. You can also change the email address used to receive direct marketing materials.
11. Contact Details Regarding Our Personal Data (Privacy) Ordinance
Please email us at:admin@babymall.hk
Disclaimer:This English disclaimer is a translation of the Chinese version. In case of any discrepancy or inconsistency between the Chinese and English versions, the English version shall prevail.
© Copyright 2024 BabyMall - All Rights Reserved