PRIVACY POLICY STATEMENT

  1. We are committed to safeguarding your privacy and ensuring that your Personal Data is protected. This Privacy Policy Statement explains the types of Personal Data we collect and how we process and protect that data.

  2. We shall keep your Personal Data confidential and shall ensure that our policies and practices with respect to the collection, use, retention, disclosure, transfer, security and access of your Personal Data comply with the laws and regulations of Hong Kong.



    Personal Information Collection Statement (“PICS”)

  3. This PICS is issued pursuant to the PDPO in relation to the operation of our business by [DoRich Limited] and their subsidiaries (together referred to as “we” or “our” or “us”).

  4. This PICS is last updated on the Effective Date.

  5. Definitions


    Under this PICS, unless the context otherwise requires, the following words and expressions shall have the following meanings:

    1. “Database” means the database of our customers’ Personal Data

    2. “Effective Date” means [dd/mm] 2022

    3. “App” means the mobile application operated by us

    4. “Affiliates” means any subsidiary or holding company of [DoRich Limited] or any other subsidiary of such holding company, which operate the Services business

    5. “Customer Hotline” the hotline number(s) as available on our [DoRich Platform]

    6. “[DoRich Platform]” means our App and our Website

    7. “Subsidiary” means all the entities controlled by and operating under [DoRich Limited] offering Services to customers

    8. “PDPO” means the Personal Data (Privacy) Ordinance (Cap.486), laws of Hong Kong

    9. “Personal Data” has the meaning ascribed to it in this PICS

    10. “Website” means [DoRich Website]

    11. “Registered Customer” means our customer who has registered for an account in our App or our Website

    12. “Services” means provision of services in relation to any of the following (whether through physical or online channels): [financial and related training and services].

    Personal Data: What We Collect, Why and How

  6. In order for you to become a Registered Customer and to enjoy our various services, it is necessary for you to provide us with certain essential Personal Data as indicated at the time of collection. We may also ask for other information which helps us to offer you tailored services that we think may be of interest to you. The types of personal data (“Personal Data”) we may collect include the following:

    1. Information about you and your account: Your personal information, such as, your name, gender, date of birth, nationality, contact details (i.e. residential and corresponding addresses), telephone number, email address, travel document, your membership number, your username and records of your earning and redemption activities;

    2. Your payment details: Payment details such as card holder name, credit or debit card number and expiry date, account information relating to other payment services (such as online or mobile payment services) and billing information;

    3. Your interests, preferences, habits and opinions: Information that we collect about your interests, preferences, habits and opinions, such as your hobbies, destinations and awards including services and events you are interested in, your opinion on our offers, your feedback and satisfaction scores regarding your redemption experiences;

    4. Our interactions with you: A record of any interactions and correspondence between us such as calls made through our call centre, any interactions you have with our staff or representatives for research (e.g. conversations with research interviewer), and non-research (e.g. our business events) purposes and any interactions with us or posts that refer to us on social media;

    5. Survey information: Your responses to surveys, research and contests (for examples stories, photos, ideas, etc.) conducted by us or on our behalf; and

    6. Your use of our website, mobile applications and social media platforms: Details of your visits to our website, your use of social media platforms and our mobile applications and other information collected through cookies and other tracking technology including information that you look at. We may also collect information about you that is publicly available online, including your social media profiles.

  7. Certain Personal Data (particularly payment details, contact information including corresponding address) are required for our services. For us to provide you with complete services, you agree to provide such Personal Data on a voluntary basis (including certain Personal Data set forth in 6.1 to 6.6 above), although you understand it is entirely optional for you to provide Personal Data. If you fail to supply such Personal Data as requested for specific services, we may be unable to deliver our services in full.

  8. We shall have the right to collect, hold, process and/or use, the Personal Data in the Database in each case for the purposes as set out in, and in accordance with, this PICS. If you are unable or unwilling to provide us with complete and correct Personal Data, we may not be able to provide or continue to provide our services to you.

  9. We will collect some Personal Data from you directly. We will collect other Personal Data from third parties including:

    1. our service providers and agents such as our call centre agents who provide customer service;

    2. the third parties that we partner with in connection with [DoRich Platform], including, providers of Services;

    3. our third party marketing and research partners;

    4. organisations which conduct credit and fraud checks; and

    5. providers of third party websites, apps and social media platforms.

    Use of your Personal Data

  10. You agree that the Personal Data you provide to us and all information relating to the use of our [DoRich Platform] may be used and retained by us:

    1. to process your application as a Registered Customer;

    2. to provide you with our services;

    3. for the normal management, operation, and maintenance of our [DoRich Platform];

    4. to provide you with regular communications from us with details of our business and relevant benefits;

    5. to provide you with Services which you have requested;

    6. to process your order for purchases at our [DoRich Platform], including verifying your payment details/status;

    7. to carry out prize draws, games or competitions of which you choose to participate;

    8. to operate and facilitate your participation in membership programs, such as processing your membership application and to ensure that you get the benefit of our membership programs;

    9. to administer your earning and redemption arrangements to send you service-related communications, to identify and verify your identity in connection with the services we provide and to provide or facilitate any special assistance you may have asked for;

    10. to carry out data sorting and analysis to enable us to better understand your characteristics and buying behaviour and to provide other services better tailored to your needs, and to assist us in selecting Services that are likely to be of interest to you. To conduct aggregated behavioural analysis and tailor and personalise awards and offers that we provide to you. We may also tailor our communications to you and tailor what we present to you to better match your preferences and interests;

    11. to provide member support, including responding to your enquiries, providing general assistance;

    12. for marketing purposes to provide you with marketing communications;

    13. for social interactions to carry out prize draws, games or competitions and to administer campaigns, contests and sweepstakes conducted by us when you choose to participate in them, including disclosing the winners of any such contests;

    14. to improve [DoRich Platform] and our membership programme for the benefit of our members generally, including to ensure that our websites, mobile applications and web pages (including social media pages) function correctly and in accordance with your preferences and circumstances;

    15. for legal and administrative purposes such as to comply with our legal and regulatory obligations, disclosure as required by applicable laws and regulations, prevention and detection of crime, verifying and processing payment, screening against fraud, criminal or unlawful activities, or abusive redemption activities, and identify suspicious membership accounts that may breach the [DoRich Platform] terms and conditions, investigation of complaints, suspected suspicious transactions, and research for service improvement, accounting, billing and audit purposes, developing, maintaining and testing our systems, for claims handling and for understanding, exercising, enforcing or protecting our legal rights and those of others.

    Who we share your Personal Data with

  11. In certain circumstances, we will disclose your Personal Data to following parties (“Data Transferees”) as described below:

    1. We will permit our third party service providers, including agents, contractors and our Affiliates, to use your Personal Data on our behalf for the purposes set out in this PICS. Such agents and contractors include operators of our IT systems and call centre.

    2. We may disclose your Personal Data to our Affiliates, so they can provide marketing services or conduct marketing or social interaction activities on our behalf such as campaigns, contests, sweepstakes, market research, member surveys and data analytics to help us improve and tailor our marketing activities and services. Subject to us having obtained appropriate consent from you, we may also disclose your Personal Data to any third party providing the following services, in order that they may direct market their services to you:

    • aforesaid Services;

    • financial, investment, insurance, banking and credit cards;

    • transportation, travel and accommodation;

    • sports, leisure, recreation and entertainment;

    • telecommunications products and services;

    • e-commerce (including trading and payment platforms and online auctions); and

    • donations and contributions for charitable and/or non-profit making purposes

    1. We may disclose and transfer (whether in Hong Kong or abroad) your Personal Data to our agents or contractors under a duty of confidentiality to us who provide administrative, data processing, research and marketing, distribution, telecommunications, professional or other similar services to us.

    2. We may also disclose and transfer (whether in Hong Kong or abroad) to any of our actual or proposed assignees or transferees of our rights with respect to your Personal Data in connection with restructuring of our business, merger (as between us and a third party), sale, or transfer (whether of assets or shares, in whole or in part), to use, hold, process or retain such Personal Data for the purposes set forth in this PICS.

    3. We may disclose your Personal Data to governments, regulatory authorities and bodies and to other individuals, bodies and organisations, such as, dispute resolution, prosecution and law enforcement bodies, legal advisers, and organisations which conduct credit and fraud checks, for the purposes of complying with our legal obligations. We may also disclose your Personal Data to such individuals, bodies and organisations to enable us to provide our services to you, as well as for any legal and administrative purposes.

    Direct Marketing and Promotion

  12. With your consent or indication of no objection,

    1. we may use Personal Data for direct marketing and promotional purposes, including:

      1. for sending or showing you updates on latest news, offers and promotions, including contests and sweepstakes, in connection with Services offered or to be offered in [DoRich Platform] and relating to parties including:

        1. us and/or our Affiliates;
        2. any third party that we cooperate with to provide benefits to you in relation to the following types of services:
          • aforesaid Services;
          • financial, investment, insurance, banking and credit cards;
          • transportation, travel and accommodation;
          • sports, leisure, recreation and entertainment;
          • telecommunications products and services;
          • e-commerce (including trading and payment platforms and online auctions); and
          • donations and contributions for charitable and/or non-profit making purposes.
      2. for tailoring and tracking your interactions with internet banner advertisement and links from [DoRich Platform] to third party websites.

  13. We may also use Personal Data to analyse your preferences and market trends and derive insights, which we may use to tailor the types of services and offers that we present to you. This may involve us combining Personal Data that we hold about your use of our services with information that we have collected about your web usage. We may also combine information that we have collected about you with information that we have collected about our other customers in order to derive these insights and establish market trends. We may provide these insights to our Affiliates and Data Transferees for their direct marketing and promotional purposes, which may involve us sharing Personal Data that we hold about you with them.

  14. We may communicate marketing, promotions and research invitations to you by post, email, phone, SMS, online (including by email or through your mobile device or via online banner advertisement) or other media and such other means whether now known or available in the future and, as appropriate and where required, we will ask you for your consent, or otherwise provide you with the opportunity to choose not to receive marketing, at the time we collect your data.

  15. You are provided an option for you to unsubscribe or opt out of further communication on any direct marketing communication sent to you and it is your choice to restrict your consent to provide certain kind of Personal Data, certain classes of marketing subjects offered by us and certain classes of persons to which we intend to provide for use in direct marketing.

  16. You understand and acknowledge that we may obtain a gain by way of commission, reward, fees or such other benefit from the use and provision to third parties of the Personal Data in the manner and for purposes as specified in this provision.

  17. Please note that if you choose to unsubscribe or opt out of marketing communication, you would still continue to receive administrative emails, account summaries and updates to our services (where applicable).



    Personal Data: What We Collect, Why and How

  18. We use cookies and similar technologies to collect data about you when you visit our Website and our other related websites (“Sites”). Cookies are files that store information on your computer hard drive or browser so that we can recognize your visit at our Sites at any time. We use cookies to give you the best possible experience on our Sites, by evaluating the use of our Sites and reviewing your browsing and purchase habits, personalizing your website experience, evaluating website activity on our Sites and generally making our Sites easier to use.

  19. The types of data we may collect from you when you visit the Sites include:

    1. information about the type of browser you use;

    2. details of the web pages you have viewed;

    3. your IP address and origins;

    4. the hyperlinks and services you have clicked;

    5. the duration and frequency of your visit; and

    6. the websites you visited before arriving at our Site.

  20. You may refuse to accept Cookies (by modifying the relevant Internet options or browsing preferences of your computer system), but to do so you may not be able to utilize or activate all of the functions and services of our Sites.

  21. [DoRich Platform] use cookies which, among other things, help us to improve your experience of [DoRich Platform] and to ensure that they perform as you expect them to. For detailed information on how we use cookies and the purposes for which we use then, please see our Cookies Policy.



    Transmission, storage and security of your Personal Data



    IT Security

  22. No data transmission over the Internet, a website, mobile application or via email or other message service can be guaranteed to be secure from intrusion. However, we endeavour to maintain commercially reasonable physical, electronic and procedural safeguards to protect your Personal Data in accordance with the requirements of data protection legislation.

  23. All Personal Data we collect about you is stored on our or our separate secure servers. We comply with our security policies and standards when accessing or using this information and restrict access to your Personal Data to those persons who need to use it for the purpose(s) for which it was collected. You are responsible for keeping any information that we send to you confidential and for complying with any other security procedures that we notify you of. In particular, where we have given you (or where you have chosen) a password or login which enables you to access certain parts of our website or mobile applications, we ask you not to share your password or login with anyone.



    Exporting your Personal Data

  24. Your Personal Data may be transferred outside the country in which you are located, including to countries with a lower level of data protection than in the country in which you are located. You hereby acknowledge any risk arising from and/or in connection with such transfer.



    Retention period

  25. We will retain your Personal Data for as long as is necessary for the processing purpose(s) for which it was collected and any other permitted linked purpose (for example where we are required to retain personal data for longer than the purpose for which we originally collected it in order to comply with certain regulatory requirements). Our retention periods are based on business needs and your information that is no longer needed is either irreversibly anonymised (and the anonymised information will be retained) or securely destroyed.



    Your Rights in relation to your Personal Data

  26. You have the right to:

    1. not providing any Personal Data to us;

    2. check whether we hold any of your Personal Data;

    3. access your Personal Data held by us;

    4. require us to correct any Personal Data which is inaccurate;

    5. ascertain our policies and practices (from time to time) in relation to Personal Data and the type of Personal Data held by us; and

    6. ask us to cease using your Personal Data for direct marketing purposes and opt out from receiving direct marketing materials from us at any time.

  27. Any request in relation to the above shall be emailed to the below contact:

    [DoRich Platform] Customer Service Department Email address: info@dorich.io

    For enquiries, please contact our Customer Hotline, which can be found on https://dorich.io.

  28. In accordance with the PDPO, we have the right to charge a reasonable fee for processing of any Personal Data access request.

  29. We will take reasonable steps to try and ensure that your Personal Data is accurate. To help us do this, please notify us of any changes to your Personal Data.



    Protecting your Personal Data

  30. We endeavor to maintain appropriate technical and organizational measures to protect the Personal Data you provide to us against accidental or unlawful usage, destruction, loss, alteration and disclosure of, or access to your Personal Data.



    Links to Other Sites

  31. [DoRich Platform] may contain links to other sites that are operated by third party with different privacy practices. You should remain alert when you leave our Website and read the privacy statements of other websites. We have no control over Personal Data that you submit to or receive from these third parties.



    Miscellaneous

  32. Nothing in this PICS shall limit your rights under the PDPO.

  33. If there is any inconsistency or conflict between the English and Chinese versions of this PICS, the English version shall prevail.

  34. The PICS shall be governed by, and construed in accordance with, the laws of the Hong Kong Special Administrative Region.

  35. We may change this Privacy Policy Statement and the PICS from time to time by posting an updated version on [DoRich Platform].

  36. You hereby acknowledge that during your interactions with us, you are not based in European Economic Area, Australia, Canada, People's Republic of China, Japan, Malaysia, Singapore, South Korea, Taiwan and United States, and the laws and regulations on personal data protection applicable to such regions, such as the EU General Data Protection Regulation (GDPR), shall not be applicable.

Last updated on 2023-05-22