Médecins Sans Frontières Hong Kong (MSFHK)
1. ABOUT THIS PRIVACY NOTICE
Médecins Sans Frontières Hong Kong (“MSFHK”, “we”, “our”, “us”) respects your personal data privacy when collecting, using, processing, storing, transferring and destructing personal data. This Privacy Notice (“Notice”) explains our policies and practices, and applies to information collection and use, including but not limited to, while you are visiting and using our websites and other offline channels. It is written in accordance with relevant data protection laws in force in places including but not limited to Hong Kong. “Personal Data” means information relating to you or other identifiable individual. When we collect personal data from individuals, we will provide them with a Personal Information Collection Statement ("PICS"), or by a separate notification, on or before the collection in an appropriate format and manner. Please read the following carefully to understand our policy and practices on how your Personal Data will be collected and processed. By providing your Personal Data to us, you are consenting to this Notice, and the collection, use, transfer, storage and processing of your Personal Data as mentioned in this Notice. If you are under the age of 18, you must have a representative, e.g. parent or guardian, accepting this Notice on your behalf before providing any Personal Data to us. If you’ve any questions please contact us at email@example.com
2. WHEN DO WE COLLECT INFORMATION ABOUT YOU?
We collect your personal data and other information:
You may give us personal information directly when you donate, sign up for one of our events, apply for employment or volunteer opportunities, communicate with us, sign up for email newsletters and leave a comment/message on our social media accounts etc. You may also share your personal information on emergency for REACH platform. Typically, we collect your Personal Data in the following ways. Please note that the ways below are indicative only and non- exhaustive:
Communications and Events Related
Human Resources Related
Emergency Support Related
We may get your personal information via a fundraising organization or platform if you’ve told them that you’re supporting MSFHK and with your consent. Please check their privacy policies when you give them your information.
We may get information about you from your social media accounts or networking sites. Facebook and Twitter are examples. We can do this if you’ve set your account settings to give us permission. Please check your settings and their privacy policies for more details.
Like most websites, we use “cookies” to identify you when you visit our website. Our websites may contain links to other sites that may use cookie technology. We do not have access to, or control over, these cookies.
What are cookies?
Cookies are small text files that are transferred from the website to your computer, phone or tablet. Websites store cookies on your internet browser (Chrome, Firefox or Internet Explorer, for example) when you visit. Every time you return to the site and navigate around it picks up these bits of information. There are several types of cookie and they each have different functions and uses. Some cookies can be really helpful and most websites rely on them in order to work properly and to understand what their users do when they visit.
Types of cookies
The four categories, from the least to the most intrusive, are:
What cookies do we use?
You can control and/or delete cookies at any time. You can also get rid of all the cookies already on your computer. Most web browsers automatically accept cookies, but you should be able to change your browser to prevent that. If you want to know how to do this please look at the help menu on your web browser. Instructions on how to do so will vary from browser to browser but you can find out more information at www.aboutcookies.org.
3. WHAT INFORMATION DO WE COLLECT?
Personal data that we may collect from you:
When you donate, we may also collect your bank or credit card details in compliance with the PCI Compliance Regulations.
We may also collect Sensitive Personal Data when you apply for field work in MSFHK missions.
4. HOW DO WE USE YOUR INFORMATION?
As a general rule, your personal data will not be used for any other purpose than that for which they were voluntarily provided to us. Your personal data are shared or transferred to third parties if such sharing or transfer is authorized by you or required to achieve the purposes for which you have provided them to us. It means that we may share your personal data with service providers, who help assist us in fulfilling our purposes. For instance, by registering to our newsletter, you consent that your personal data (name and email) be processed for the purpose of sending you emails. Personal data may also be shared with third parties when required by law or by a court order.
Your Personal Data may be used in the following ways, although these situations are not exhaustive:
Save for the aforementioned ways, we will only use your personal information where the law allows us to. We use your personal information only where:
If you have given us consent to use your personal information for a specific purpose, you have the right to withdraw your consent any time by contacting us, but please note this will not affect any use of your information that has already taken place.
How we use your data depends on why you are providing it
ONLINE/ OFFLINE FORMS AND FEEDBACK
We’ll use your personal information to respond to your questions, requests, register you for events and react to the input on REACH.
We use surveys to understand who visits our websites and how they use it, helping us to create better content for you and make our websites easier to use. We may ask for your email address if you’re happy to be involved in future surveys or testing. We’ll only use this to ask you to help us with these types of requests.
We use your information to process and keep a record of your donation, in accordance with the relevant legislation on data retention. We also use your data to provide you with the tax documentation you need.
From time to time, we may use your Personal Data (including your name, contact details, demographic information, information collected from donor survey, and donation history to provide you with emails, updates, invitations, newsletters, phone calls or text messages about our fundraising events and initiatives, to invite you to make a donation and/or to invite you to participate in donor survey, but only if you consent to our doing so when we collect your Personal Data.
Even if you have given us your consent to use your Personal Data for direct marketing purposes, you may withdraw your consent at any time free of charge by emailing to firstname.lastname@example.org or following the instructions on how to unsubscribe which are
contained in all of our email newsletters. The withdrawal of your consent will be processed and will take effect as soon as possible.
We may use publicly available information from your profile to target you with specific posts that may interest you. We’ll never ask for personal or sensitive information on social media. We may repost or share your posts on social media if it relates to MSFHK and our work. We may respond to questions, queries or comments left on our social media channels. We may use information found on your profile to help us answer these.
Check your social media accounts if you want to change the information you make public. Our websites use sharing buttons which share our web pages to social media platforms. Use these buttons at your own discretion. Social media platforms may track these shares through your accounts.
RECRUITMENT & EMPLOYMENT
When you apply for employment or volunteer position in MSFHK office or MSFHK missions, personal data submitted will be used solely for recruitment purposes include identifying job applicants, evaluating applications, making employment/appointment decisions, background or integrity checks, employer references, and contacting you by phone, email or in writing). If application is successful, your personal data will be stored in our personnel records.
5. WHO HAS ACCESS TO YOUR DATA?
Your information is only accessible by trained personnel, including employees and volunteers. We regularly review who has access to your information. As a general rule, your personal data will only be accessible insofar as it is necessary to fulfill the purpose for which it was collected. For instance, the data you provide for donations will be accessible to our donations department, our fundraising and marketing team and to service providers, if any, for the purpose of processing your donation. We do comprehensive checks on any contractors before we work with them. We always put a contract in place that sets out how they manage the personal data they collect or have access to.
We may use other companies to help us manage and store personal data and to carry out certain activities on our behalf. Our main data processors' services are listed below, but we may enlist the services of others from time to time:
We operate globally and may have a need to transfer certain data to countries outside Hong Kong. In the event the country where the data is transferred does not provide an adequate level of protection, we make sure to implement technical and organizational measures to protect your data.
If you are located in the European Economic Area (“EEA”), your personal data may be transferred to countries located outside the EEA which do not provide a similar or adequate level of protection to that provided by countries in the EEA. Such transfers will only be made in accordance with applicable laws including where necessary for us to comply with our contractual obligations with you. We will take all steps reasonably necessary to ensure that any personal data are treated securely and inaccordance with this Notice.
Should you have any questions in this respect we please contact us at email@example.com.
POLICY TOWARDS CHILDREN
Our services are not directed to individuals under 16. We do not knowingly collect personal information from individuals under 16. If we become aware that an individual under 16 has provided us with personal information, we will take steps to delete such information. Contact us if you believe that we have mistakenly or unintentionally collected information from an individual under 16.
6. HOW WE SHARE INFORMATION WE COLLECT
We may share personal information on aggregated or de-identified basis with third parties for research and analysis, profiling, and similar purposes to help us improve our services.
If you use any third-party software in connection with our services, for example any third-party software that our website integrates with, you might give the third-party software provider access to your account and information. Policies and procedures of third-party software providers are not controlled by us, and this policy does not cover how your information is collected or used by thirdparty software providers. We encourage you to review the privacy policies of third-party software providers before you use the third-party software.
Our website may contain links to third-party websites over which we have no control. If you follow a link to any of these websites or submit information to them, your information will be governed by their policies. We encourage you to review the privacy policies of third-party websites before you submit information to them.
We may share your information with government and law enforcement officials to comply with applicable laws or regulations, for example when we respond to claims, legal processes, law enforcement, or national security requests.
7. HOW DO WE KEEP YOUR INFORMATION SAFE?
We use appropriate technical and organizational measures and precautions in order to protect your personal data and to prevent the loss, misuse or alteration of your personal data. For example, we use industry standard SSL certificates in our websites, it is a global standard security technology that enables encrypted communication between the web browser and the web server.
We have adopted the following measures to protect the security and integrity of your personal information:
We have put in place procedures to deal with any suspected privacy breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
While we implement safeguards designed to protect your information, please note that no transmission of information on the Internet is completely secure. We cannot guarantee that your information, during transmission through the Internet or while stored on our systems or processed by us, is absolutely safe and secure.
We only retain personal information for so long as it is reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. We periodically review the basis and appropriateness of our data retention policy.
8. HOW LONG DO WE KEEP YOUR INFORMATION?
We keep your information for as long as it’s necessary in connection with the purposes defined above in “How do we use your information?” and for the purpose of providing you with your tax receipt. For instance and as a general rule, we keep your email for the purpose of sending you a newsletter until you unsubscribe.
If you request to receive no further contact from us, we'll keep the basic information about you on our suppression list in order to avoid sending you unwanted materials in the future, for the duration allowed by the application legislation.
9. OUR LEGAL BASIS FOR PROCESSING PERSONAL DATA
We need a lawful basis to collect and use personal data under data protection law. The law allows ways to process personal data (and additional ways for sensitive personal data). Below are relevant to the types of processing that MSFHK carries out:
Our legitimate interests include:
10. YOUR DATA PRIVACY RIGHTS?
Visiting our sites, you acknowledge the collection and use of your personal data by us as outlined in this Notice. If you do not agree with the use of your personal data as set out in this Notice, please do not use our sites.
Under the Hong Kong Personal Data (Privacy) Ordinance, you have the right:
If you are in an EU Member State, subject to certain limitations and/or restrictions, you have the right under the data protection laws in the EU:
You may opt out of receiving marketing materials from us. Please note, however, that even if you opt out from receiving marketing materials from us, you will continue to receive notifications or information from us that are necessary for the use of our services.
As a security measure, we may need specific information from you to help us confirm your identity when processing your privacy requests or when you exercise your rights.
Any request as mentioned hereinabove will normally be addressed free of charge. However, we may charge a reasonable administration fee if your request is clearly unfounded, repetitive, or excessive.
We will respond to all legitimate requests within one (1) month. Occasionally, it may take us longer than a month if your request is particularly complex or if you have made a number of requests.
Individuals in the EU also have the right to lodge a complaint about the processing of their personal data with their local data protection authority.
Please contact us in the first instance if you have any questions or concerns. If you have unresolved concerns, you have the right to file a complaint with a data protection authority in the country where you live or work or where you feel your rights have been infringed.
If you wish to exercise one of the above rights, please contact us through 22/F Pacific Plaza, 410-418 Des Voeux Road West, Sai Wan, Hong Kong or firstname.lastname@example.org.
Where permitted by law to do so, we may charge a reasonable fee for processing a data access request.
11. WHEN DO WE UPDATE THIS NOTICE?
We change this Privacy Notice when we need to. If we make any significant changes in the way we treat your personal information we’ll make this clear on our websites. By continuing to use our website or other platform after the changes come into effect, you agree to be bound by the revised Privacy Notice.
Last updated on 31/12/2018