WINNER MEDICAL (HONG KONG) LIMITED, and from time to time, its holding company and subsidiaries (together the “Group”) (and each being “we”, “us” or “GOLAB” or “member of the Group” for the purposes of this Privacy Statement) recognise our responsibilities in relation to the collection, holding, processing, use and/or transfer of personal data under the Personal Data (Privacy) Ordinance (Cap. 486).
By using our services and providing personal information to us, you acknowledge that you have read this Statement, and subject to your explicit consent which we may separately seek from you as may be required by applicable law, you consent to the terms of this Statement.
If you do not agree with the terms in this Statement and have concerns about the categories of personal data, we require from you, please do not provide any personal information to us without contacting us.
Please note that if you do not provide us with your personal data (or relevant personal data relating to persons you acting on behalf) we may not be able to provide the goods and/or services you have asked for or process your requests, applications or registrations.
1. Personal Data We Hold
1.1. The personal data we collect (which includes sensitive personal data as defined under relevant applicable laws and regulations), includes the following:
(a) identity information – your name, postal address, personal contact details (including email address and telephone numbers), date of birth, gender, Hong Kong Identify Card number / Passport number / Home Return Permit number;
(b) medical related information – travel history, related health / medical history, specimen sample, genetic information through processing the DNA sample submitted by you; and
(c) technical information – web behavior information and preferences such as IP address, browser type and version, time zone settings, browser plugin types, operating systems and platform, device information (including where mobile device the IMEI number, wireless networks and general network information).
1.2. If you make use of any social media features or platforms, either on our website and/or mobile application, or otherwise through a social media provider, we may access and collect information about you via that social media provider in accordance with their policies and based on your privacy settings with the relevant social media provider, including but not limited to your name, gender, birthday, email address, address, location etc.
1.3. You may choose not to provide us with the personal information which we required for creating an account and/or placing the Order, however we may not be able to provide the goods and/or services you have asked for or process your requests, applications or registrations.
2.1. Personal data is collected for the following purposes:
(a) to process and administer your account, to process requests, applications or transactions placed by you, or any other documents or samples you may submit to us from time to time;
(b) to verify your identity;
(c) to conduct research and statistical analysis;
(d) to design new or enhance existing products, information and services provided by us;
(e) to communicate with you including to send you administrative and technical communications about any account you may have with us, to provide technical support or notify about future changes to this privacy statement;
(f) to manage customer relationship with you;
(g) to operate and administer any loyalty or reward programmes;
(h) to monitor and conduct analysis of your preference regarding the use of our website and/or mobile application in order to operate, evaluate and improve the website, the mobile application, our goods and services;
(i) to make disclosure when required by law, regulation, or court order of any jurisdiction, and/or as requested by any government, regulatory or law enforcement authority or administrative organisation, which may be within or outside The Hong Kong Special Administrative Region of the People’s Republic of China;
(j) to conduct direct marketing activities;
(k) other purposes as notified at the time of collection; and/or
(l) other purposes directly relating to any of the above.
3.1. We may retain your information for as long as necessary to fulfill the purpose(s) for which it is collected or as otherwise required to ensure compliance with applicable laws and regulations. As a general rule the maximum retention period is 7 years.
3.2. In the event you consent to our retention of the sample you provided us and/or the genetic information obtained from processing such sample for the purpose of education or research, reasonable steps will be taken to anonymise such information to the extent that you will no longer be identified.
4. Direct Marketing
4.1. The Group may use your name, telephone number, postal address and email address for direct marketing of health, body check, and laboratory testing services, products, events and campaigns for the Group.
4.2. If you wish us to exclude your personal data for direct marketing purposes, please send us an email, along with your name and account username to our Data Protection Officer at email@example.com.
5. Transfer of Personal Data
5.1. Except to the extent you have already opted out, we may transfer your name, postal address, telephone number and email address to other members of the Group for the purpose of enabling those members of the Group to send promotional materials to you and conduct direct marketing.
5.2. For one or more of the purposes specified above, your personal data may be:
(a) transferred to other members of the Group and made available to appropriate persons in the Group, in Hong Kong or elsewhere and in this regard you consent to the transfer of your data outside of Hong Kong;
(b) supplied to any agent, contractor or third party who provides administrative, telecommunications, computer, payment, debt collection, data processing or other services to GOLAB and/or any of other member of the Group in Hong Kong or elsewhere;
(c) any person, government or law enforcement authority or administrative organisation; and
(d) other parties as notified to you at the time of collection.
5.3. We may also disclose your personal information to third parties under the following circumstances:
(a) when explicitly requested by you including delivering your testing report(s)/result(s) to third parties as requested by you; and/or
(b) as required by and/or in accordance with applicable law or regulation to law enforcement, regulatory and other government agencies and authorities, professional bodies and other third parties.
6. Access and Correction of Personal Data
6.1. You have the right to ascertain whether we hold your personal data, to obtain a copy of the data, and to correct any data that is inaccurate. You may also request us to inform you of the type of personal data held by us.
6.2. Requests for access and correction of personal data or for information regarding policies and practices and kinds of data held by us should be made by email and addressed to our Data Protection Officer at firstname.lastname@example.org.
6.3. A reasonable fee may be charged to offset our administrative and actual costs incurred in complying with your data access requests.
7. Termination or Cancellation
7.1. Should your account or relationship with us be cancelled or terminated at any time, we shall cease processing your personal data as soon as reasonably practicable following such cancellation or termination, provided that we may keep copies of your data as is reasonably required for archival purposes, for use in relation to any actual or potential dispute, for the purpose of compliance with applicable laws and regulations and for the purpose of enforcing any agreement we have with you, for protecting our rights, property or safety, or the rights, property or safety of our employees, and for performing or discharging our functions, obligations and responsibilities.
Version: 21 Jan 2021