PRIVACY POLICY STATEMENT

Effective Date: 1 August 2020

We, Vincent Medical Holdings Limited (the“Company”, also “we”, “us” and “our”) and/or our group of companies (“Group”, including the Company, its affiliates, subsidiaries and associated entities), respect the privacy of every individual who visits this website (the “Website”) and uses our products and services (collectively “Products & Services”, individually “Products” and “Services”). We follow this privacy policy statement (“Privacy Policy Statement”) on the data collected from our users (“you”, “your” or “customer(s)”) .

We and our Website may ask you to provide certain information through online resources and communications, including the website, e-mails or other online methods (collectively, “Online Sources”) or offline channels. We shall treat the Personal Data that you provide from Online Sources and offline channels according to this Privacy Policy Statement and to applicable laws and regulations. This Privacy Policy Statement does not apply to the links or external Online Sources of the third parties in our Website, of which we have no control on the contents and privacy policies therein.

A. Information Collected

Your use of our Website and Products and Services are subject to our Terms & Conditions (“T&C“) at here. This Website serves as providing the information in relation to certain updates and news on developments in our Company as well as our Products and Services. You may not access or use any information of this Website or access to our Products and Services if you do not accept the T&C. You shall also be subject to any guidelines or rules applicable to this Website and its contents that may be posted at our Website from time to time. All such guidelines or rules are hereby incorporated by reference into the T&C.

  1. Information directly provided by you
    We may collect your following contact and other identification information: In certain circumstances (including but not limited to using our Products & Services and/or creating or registering any account with our Website), you may need to provide us your contact and other identification information, such as your name, phone number, company address, and email address (and other identifying information you agree to submit or provide).:
  2. Automatically Collected Information
    Please refer to this link for further details regarding our cookies policy. Set out below is a brief description of the information being automatically collected.
    i. We and some third parties may automatically receive certain types of information technology (“IT”) data and information whenever you browse our Website or interact with us on our Website and in some e-mails that we send to each other which include, for example, cookies, Web server logs/IP addresses, and third party application, content tools and other information (including but not limited to the pages that you accessed, the date and time you accessed to these pages, your search queries, information on your device (hardware model, operating system version, unique device identifiers, Internet protocol address, hardware settings, browser type, browser language), the date and time of your request and referral URL)
    ii. Cookies. When you access our Website, a piece of information will be produced and placed automatically in your computer’s hard disk as cookie(s). The cookie uniquely identifies your browser to the server. Cookies and/or other similar technologies (including but not limited to web beacons, tags, script and device identifies) allow us to store information on the server to help make the Web experience better for you and to conduct site analysis and web site performance review. Most web browsers are set up to accept cookies, although you can reset your browser to refuse all cookies or to indicate when a cookie is being sent. Note, however, that some portions of our sites may not work properly if you refuse cookies.
    iii. Web Server Logs/IP Addresses. An IP address is a number assigned to your computer whenever you access the Internet. Such number can be used to identify the computer used on the Internet and to allow computers and servers to recognize and communicate with each other. Such information shall be collected to conduct system administration, security measure endorsement and produce information in aggregate form to the affiliates, business partners, and/ or vendors for site analysis, website performance review and security management.

B.   How We Collect Your Personal Data

  1. We may collect your Personal Data by various means including but not limited to the following:
    i. via the Websites;
    ii. contact or enquiry forms (whether completed via the Websites);
  2. We will also collect your other automatically collected information through automated means as set out above and further described in our Cookies Policy.

C. Use of the Personal Data

  1. The Company, including its affiliates, subsidiaries, divisions and groups worldwide and/or the companies we hire to perform services on our behalf will use any Personal Data you choose to give us to provide you our Service and to comply with your requests for our Products and Services. We shall retain control of and responsibility for the use of this information. Some of this data may be stored or processed at computers located in other jurisdictions, whose data protection laws may differ from the Hong Kong. In such cases, we shall take measures that appropriate protections are in place to require the data processor in that country to maintain protections on the data that are equivalent to those that apply in Hong Kong.
  2. We may use the information you provided for the following purposes:
    i. To send you newsletters to inform you the latest news and events and in this regard, the Personal Data will be used in connection with the Company’s marketing and other marketing communication directly with you;
    (a). By confirming your acceptance, you agree and consent that we may send you product and promotional emails or notifications about our Products and Services, and offers on new products, services, promotions or contests. You can unsubscribe from receiving these direct marketing and/or marketing communications or opt out from the same by following the procedure as set out in Paragraph D(1) below.
    (b). No Third-Party Direct Marketing Use. We shall not sell or otherwise transfer the personally identifiable information that you provide to us at our Website to any third parties for their own direct marketing use unless we provide clear notice to you and obtain your explicit consent for your data to be shared in this manner.

    ii. To provide and improve our Products & Services to you and product range and product feedback (including but not limited to the maintenance and update of our Products & Services);
    iii. To allow you to file and notify us of formal complaints and to provide you customer support as well as to answer your questions, resolve disputes, or troubleshoot problems;
    iv. To respond to your enquiries;
    v. To take part in our surveys;
    vi. To process your job application and the recruitment process, if applicable
    vii. To enforce our T&C and other agreements binding between us; and
    viii. in connection with our business development, such as for marketing and statistical analysis;
    ix. to respond to appropriate requests of legitimate government agencies or where required by applicable laws, court orders, or government regulations; 
    x. where needed for corporate audits or to investigate or respond to a complaint or security threat;
    xi. if you do not wish to use or provide your Personal Data for use of any purposes as described above, you may your opt-out right by notifying us.
    xii. To operate, maintain, analyze and improve our relevant Products & Services. These activities may include (inter alia) the followings:
    (a). communicate with you, and implement your requests;
    (b). host our Website, authenticate your access and provide personalized content and information;
    (c.) contact you about any relevant information about our Products and Services (e.g. policy changes, security updates or issues, etc.);
    (d). monitor, detect, investigate and prevent prohibited or illegal behaviors on our Products and Services, to combat spam and other security risks.

D.   Your Rights and Choices

  1. You have several choices regarding your visit on our Website. You could decide not to submit any Personal Data at all by not entering it into any forms or data fields on our sites and not using any available personalized services. You could also decide to opt out for particular services or communications provided by us by notifying us in writing. If you decide to unsubscribe from a service or communication, we will work to remove your information promptly, although we may require additional information before we can process your request.
  2. If you choose to submit Personal Data, you have a number of rights in relation to the Personal Data that we hold about you. These rights are subject to certain exemptions and do differ across the jurisdictions in which we operate. In summary, your rights are set out as below:
    i. Request access to the personal data we hold about you
    Subject to any applicable exceptions, we will provide you with a copy of your Personal Data within the timescales set out in relevant legislation. We will do this for a reasonable fee, in accordance with applicable legislation, unless the request is manifestly unfounded or excessive, in particular because of its repetitive character.
    ii. Right to rectification
    If the information we hold about you is inaccurate, you have the right to have this information rectified. You should list out the specific information to be rectified and the corrections to be made and send us an application.
    iii. Right to erasure / ‘Right to be forgotten’
    You can ask us to delete or remove your information in certain circumstances. Whenever you have given us your consent to use your Personal Data, you have the right to change your mind at any time and withdraw that consent. In cases where we are processing your Personal Data on the basis of our legitimate interests, you can ask us to stop processing your data for reasons connected to your individual situation. We must then do so unless we believe we have a legitimate overriding reason to continue processing your Personal Data.
    iv. Right to restriction of processing
    In certain circumstances, you a have a right to request the restriction of the processing of your information.
    v. Right to data portability
    In certain circumstances, you may have the right to obtain your Personal Data in a structured, commonly used and machine-readable format and to reuse it elsewhere or ask us to transfer it to a third party of your choice.
    vi. Right to object
    In certain circumstances, you have a right to object to processing being carried out by us. Where Personal Data is being processed for direct marketing purposes, you have a right to object at any time
  3. Without prejudice to the aforesaid rights and choices, you may request us to perform the following activities subject to the applicable privacy laws and regulations:
    i. to check whether we hold data about you and/or access to such data;
    ii. to require us to correct any data relating to you which is inaccurate; and
    iii. to ascertain our policies and procedures in relation to data and to be informed of the kind of Personal Data held by us and/or you have access to.
  4. For any requests for access to or correction of data held by us, or for information regarding our data policies and practices and kinds of data held by us are to be addressed as follows:

Data Protection Officer  
Vincent Medical Holdings Limited
Flat B2, 7/F., Phase 2,
Hang Fung Industrial Building, 2G Hok Yuen Street,
Hung Hom, Kowloon, Hong Kong

Should you have any queries, please do not hesitate to contact our designated hotline 852 2365 5688 or by email at investors@vincentmedical.com.

5. We have the right to charge a reasonable fee for the processing of any data access request.

E.    Security

  1. The Company uses technology and security precautions, rules and other procedures to protect your personal information from unauthorized access, improper use, disclosure, loss or destruction. For such purposes, we have adopted the Secure Server Technology to ensure that all data submitted through our Website is reasonably protected. Access will be restricted to our employees, who are authorized and trained to handle such data, and who are under strict confidentiality obligations.
  2. It is, however, your responsibility to ensure that you have adopted adequate security measures (e.g. up-to-date antivirus software, personal firewall, and web browser configuration etc.) to your computer so that your computer is secured and protected against malicious software, such as trojans, computer viruses and worm programs, and that the risk of your data and passwords being disclosed to unauthorized third parties can be reduced. It shall also be your responsibility to take the security measures as set out in our T&C.
  3. Despite our security measures above, we cannot guarantee there shall be no breach of the security of your Personal Data. While we shall, as far as practicable, take measures to protect the relevant systems, networks, hardware and/or software and prevent any further breaches, we shall not be liable for any loss, damages, expenses or fees incurred as a result of or in connection with such security breach and/or the data loss.

F.    Retention of the Personal Data

  1. Whenever we collect or process your Personal Data, we will only keep it for as long as is necessary for the purpose for which it was collected but subject to satisfying any legal, accounting or reporting requirements, we usually keep it no longer than 6 years from the date when (i) you cease to be a customer; or (ii) our last communication with you (whichever is later) (unless we are legally required or have a legitimate business interest to retain the same for a longer period).
  2. In some circumstances, you can ask us to delete your Personal Data.

G.   Data Sharing and Transfer

  1. Except provided otherwise in this Privacy Policy Statement and T&C, the Company will not share your Personal Data about you with third party companies or agents unless we have obtained your explicit consent or unless as required by law and regulation. All these companies and agents are required to comply with the terms of our privacy policies.
  2. We shall keep your Personal Data confidential but we may provide, transfer or disclose such data or information to anyone or more of the following parties (whether within or outside Hong Kong) for the purposes set out above:
    i. general service providers, including but not limited to:
    a. payment processors as necessary to enable your payment for our Products and Services; and
    b. courier/shipping companies (in cases of (inter alia) delivering our Products and Services materials and/or other marketing communication to you

    ii. third party cloud service providers in providing security of data storage and protect data in the event of a natural disaster or other disruption to our Products and Services;
    iii. Automatically Collected Information as set out in Paragraph A(2) and Cookies Policy;
    iv. commonly owned entities which may include any members of our Group (i.e. our subsidiaries, our corporate parent, or any other subsidiaries owned by our corporate parent) in order to provide you better service and improve user experience; and
    v. any person or entity to whom the Company or any other member of our Group is under an obligation or otherwise required to make disclosure under the requirements of any laws or regulations binding on or applying to the Company or any other member of our Group.

  H.   Links to Other Sites

Our Website may contain links to other web sites which provides helpful information to our users. This Privacy Policy Statement does not apply to those sites where the Company does not possess control. You should contact them directly for their privacy policies.

I.    Privacy Policy Statement for Children

Our Website is directed at an adult who is 18 years old or older. We do not intend to collect any Personal Data from anyone we know to be under the age of 18 without the prior consent of his/ her parent(s), guardian, or legal representative who has the right, upon request, to view the information provided by the child and/or to require that it be deleted.

J.    Note to Users of Business or Professional Users

If you have a business or professional relationship with the Company, we may use the data and information that you submit on our Website to fulfill your requests and develop our business relationship with you and the entities you represent. We may also share such information with third parties acting on our behalf.

K.   Updates to Privacy Policy Statement

The Company may from time to time revise this Privacy Policy Statement without prior notice to the visitors or users. Any changes shall be communicated promptly on this page. Your continued use of our Website shall be indicated as your consent to the update of the Privacy Policy Statement. This Privacy Policy Statement was last updated on and effective from 1 August 2020.

L.   Prevailing Language

The English version of this Privacy Policy Statement shall prevail if there is a conflict between the English version and the Chinese version.

M. How to Contact the Company

For questions or if you wish the Company to update, amend or delete your Personal Data or profile, please contact us by email investors@vincentmedical.com.