Statement of Policy
XCEPT Limited (“XCEPT”) respect personal data privacy. We will comply with the Personal Data (Privacy) Ordinance (Cap. 486 of the laws of Hong Kong SAR) (the “Ordinance”) and are committed to fully implement the data protection principles promulgated under the Ordinance.
Statement of Practices
Information We Collect
From time to time, we may collect various types of personal information (“personal information” or “personal data”) (such as email address, name and contact number) from you in connection with our provision of services, activities and facilities, including but not limited to account registration, ticketing transaction, e-newsletter subscription, event registration, membership, payment, following up on enquiries, and conducting customer surveys, etc.
Parent or guardian must consent to our collection and use of personal data of minors under the age of 18.
Main Purpose of Collecting Personal Data
The main purposes of collecting the personal data are as follows:
for processing your service requests (i.e. event registration, ticket purchase, e-newsletter subscription, product purchase, and member registration, etc.) with us and providing you with the services;
for facilitating communications between you and us;
for notifying you of changes to our services that may affect you;
for responding to and following up on your enquiries;
for direct marketing upon obtaining explicit consent from you;
for managing customer relationships within XCEPT;
for communicating with you for potential support to XCEPT that is relevant to your interests and appropriate;
for conducting statistical analysis, research, surveys, quality assurance and review;
for executing the service contract between you and XCEPT; and
for other purposes directly relating to any of the above.
We may collect and combine information from you (through various channels, such as online channels like websites / mobile applications, offline channels like physical application forms, or publicly available information about you. We use this information to help improve your experience and communicate with you about events or offerings that may be of interest.
Implementation of Practices
XCEPT will implement the practices at (a) to (d) below in accordance with the data protection principles in the Ordinance.
(a) Collection of personal data
When collecting personal data, the Group will satisfy itself that:
the purposes for which the data is collected are lawful and directly related to a function or activity of the Group;
the manner of collection is lawful and fair in the circumstances; and
the personal data collected is necessary but not excessive for the purpose(s) for which it is collected.
When we collect personal data from a data subject, the data subject will be provided with a Personal Information Collection Statement (“PICS”) on or before the collection in an appropriate format and manner. Practicable steps will be taken to ensure that:
the data subject is informed of whether it is obligatory or voluntary to supply the data and, if obligatory, the consequences in failing to do so; and
the data subject is explicitly informed of the purpose(s) for which the personal data is to be used, the classes of persons to whom the data may be transferred or disclosed, the rights of the data subject to request access to and correction of the data, and the contact details of the officer to whom any such request may be made.
If the Group intends to use the personal data collected for a new purpose, other than the purpose of first collection as stated in the PICS, we will obtain a prior consent from the data subject before the usage. If the data subject is under the age of 18, we will only use the personal data for a new purpose after we obtained a prior consent from the parent or guardian of the data subject.
(b) Accuracy and retention of personal data
Personal data collected and maintained by the Group will be as accurate, complete, and up-to-date as is necessary for the purpose(s) for which it is to be used.
The Group maintains a personal data inventory, which contains the kinds of personal data that we hold, the purposes for which the personal data is collected, used and disclosed, and how the personal data is stored. The personal data inventory will be reviewed periodically to ensure that it is accurate and up-to-date.
We will only retain your personal data for as long as is reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for personal data, we will consider the amount, nature, and sensitivity of the personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. Should there be a need to retain personal data for statistical purposes, such personal data will be anonymised so that the individuals concerned can no longer be identified.
(c) Use of personal data
All personal data collected will be used only for purposes which are directly related to the discharge of the Group’s activities or functions. We will never sell or rent your information with any other organisation outside the Group. We will ask for your consent to share personal information with third parties (except for those already listed out in this Statement) unless otherwise required or permitted by law. We may transfer your personal information to our service providers such as IT contractors, cloud service providers and confidential documents disposal service agents, etc. in order for them to perform services on our behalf. We require all service providers to respect the security of your personal data and comply with the Ordinance. We do not allow our service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions. Personal data may also be disclosed to other entities which are authorised to receive such information for law enforcement, prosecution or review of decisions purposes. The data subject will be informed of the transferees of personal data when the data subject’s personal data is collected. For personal data that is stored in cloud servers of cloud service providers for the Group, personal data may be transferred out of Hong Kong where the cloud servers are located.
If personal data is to be used for a purpose other than the purposes for which the data is collected, prior consent will be sought from the data subject. In seeking the consent, all practicable steps will be taken to ensure that (i) information provided to the data subject is clearly understandable and readable; and (ii) the data subject is informed that he is entitled to withhold his consent or withdraw his consent subsequently by giving notice in writing.
We will not use personal data or provide personal data for use in direct marketing without data subject’s explicit consent. If the Group intends to use the personal data for direct marketing, we will obtain explicit consent from the data subject before using the data subject’s personal data and will notify the data subject when using personal data in direct marketing for the first time, and will cease to use the data in direct marketing if the data subject so requires. If the Group intends to provide personal data to another person for use by that other person in direct marketing, we will inform the data subject in writing in advance that the Group intends to provide the personal data and will not provide the personal data unless it has received the data subject’s explicit consent. A data subject may require the Group to cease using the data subject’s personal data in direct marketing by informing the Group via email.
(d) Security of personal data
We observe strictly the relevant security standards and regulations. Security arrangements will be reviewed regularly to ensure that personal data is protected against loss and unauthorised or accidental access, use, disclosure, modification and erasure. The security arrangements include, without limitation, the following:
restriction of access to personal data on a “need-to-know” basis;
regular review and enhancement of security measures for protection of personal data in the servers, user computers, or transmission of electronic messages;
regular change of passwords for IT facilities, or accounting and personnel systems;
encryption of all backup tapes that are to be transported to offsite storage;
limited staff access rights to office areas storing confidential information; and
provision of clear guidelines to staff as to the types of data that may or may not be disclosed to an enquirer and implementation of appropriate identity verification procedures to confirm the enquirer’s identity.
Use of Cookies
When you browse our websites / mobile application, cookies will be stored in your computer's browser. The purposes of using cookies are to remember the browsing preferences (e.g. language, font size) you have chosen in our websites / mobile application to customise your experience. You have a choice not to accept the cookies. If you do not accept the cookies, our websites / mobile application will not be able to remember your browsing preferences and we may not be able to deliver the full features of our websites / mobile application to you. We also use third party cookies such as Google Analytics to analyse anonymised data to help us understand how our audiences interact with our websites / mobile application so that we can improve the overall experience. The cookie itself does not collect any Personally Identifiable Information.
Website Statistics
When you visit our websites / mobile application, we will record your visit only as a “hit”. The webserver makes a record of your visit that includes your IP addresses (and domain names), the types and configurations of browsers, language settings, operating systems, previous sites visited, and time/duration and the pages visited (collectively, “ webserver access log ”). We use the webserver access log for the purpose of maintaining and improving our websites / mobile application such as to determine the optimal screen resolution, or which pages have been most frequently visited. We use such data only for website / mobile application enhancement and optimisation. User data is all anonymous.
Linking with Third Parties
Please be aware that our websites / mobile application may contain links to other sites hosted by third parties. Different rules may apply to their collection, use, or disclosure of your personal information. We encourage you to review other websites’ policies before revealing any personally identifiable or sensitive information. We do not control, and are thus not responsible for, the content or privacy practices and policies of such other sites and under no circumstances shall we have any liability whatsoever for the activities conducted by or at any website accessed from or through the Group’s website
Incident Reporting and Breach Handling
A mechanism is set up for incident reporting and breach handling in case there is a loss or leakage of personal data, or there is a reason to believe that the personal data held by the Group has been compromised.
Enquiries
Any enquiries regarding personal data privacy policy and practice may be addressed to us via email at e@xcept.hk.
Interpretation
Words used herein which import the singular only also include the plural and vice versa where the context so admits.
Words used herein which import one gender (whether masculine, feminine or neuter) shall be taken to include any other gender where the context so admits.
Chinese version of this Statement is for reference only. In the event of any discrepancies or inconsistency between the English and Chinese versions of this Statement, the English version shall apply and prevail.
Personal Information Collection Statement
Collection of your personal data
XCEPT Limited (“XCEPT”) and its subsidiaries including XCEED Limited and XPLOR Limited (collectively the “Group” or “we”) collect your personal data to provide our services to you and to improve customer experience.
Purposes of personal data collection and usage
We will use your personal data for one or more of the following purposes:
for processing your service requests (i.e. event registration, ticket purchase, e-newsletter subscription, product purchase, and member registration, etc.) with us and providing you with the services;
for facilitating communications between you and members of the Group in respect of your service requests;
for notifying you of changes to our services that may affect you;
for responding to and following up on your enquiries;
for conducting statistical analysis, research, surveys, quality assurance and review; and
if you give your consent for direct marketing:
for communicating with you on events, services, promotions and special offers provided by the Group;
for communicating with you for potential support to the Group; and
for other purposes directly relating to any of the above.
We will collect and combine information you provide to us through various channels, such as online channels like websites / mobile applications, offline channels like physical application forms, or publicly available information about you. We use this information to help improve your experience and communicate with you about events and offerings that may be of interest.
Use of personal data
The personal data collected will be used only for purposes as stated above. We will never sell or rent your information with any other organisation outside the Group. We will ask for your consent to share personal information with third parties (except for those already listed out in this Statement). We may transfer your personal information to our service providers such as IT contractors, cloud service providers and confidential documents disposal service agents, etc. in order for them to perform services on our behalf. We require all service providers to respect the security of your personal data and comply with the Personal Data (Privacy) Ordinance (Cap. 486 of the laws of Hong Kong SAR) (“the Ordinance”). We do not allow our service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions. We may transfer your personal data outside of Hong Kong for necessary handling, processing or storage.
Data access and correction requests
You have the right to request access to and correction of your personal data held by the Group. Such request should be made in writing to us at e@xcept.hk.
Use of data in direct marketing
We intend to use your personal data and/or transfer your personal data to the subsidiaries of the Group for use in direct marketing, and we may not so use and/or transfer your personal data unless we have received your consent (which includes an indication of no objection to the intended use and/or transfer).
We may use and/or transfer to the subsidiaries of the Group your name, contact details (such as email address), preferences and interests and transaction data for providing you with information that is of interest on events, services, promotions and special offers provided by the Group and ways to support the Group. Please indicate your consent or no objection for such use and/or transfer in the relevant online or offline forms at the time of collection of your information.
If you do not wish to receive information from the Group for the aforementioned direct marketing purposes, you may choose to opt-out from direct marketing at any time, free of charge, by emailing us at e@xcept.hk.
Language versions
In case of discrepancies between the English and Chinese versions of this Statement, the English version shall apply and prevail.