隱私政策
1. 我們的承諾
我們感謝您對我們的信任。我們承諾致力保護您的私隱,採取所有合理的預防措施,及遵從所有適用有關保障個人資料的法例及規定來保護您的個人資料的安全及不被濫用。這私隱政策的目的是幫助您了解我們收集您的個人資料的種類,如何使用及保護您的個人資料及您的權利及選擇。
2. 我們收集個人資料的類別
我們收集個人資料類別,包括但不限於:
a. your title, name, gender, telephone number, email address, home, mailing, billing, delivery address or other contact information, your day and month of birth, your payment information, username and password, and other personal data you voluntarily provide to us; and
b. IP address, real-time geographic location data, browser settings, browsing records, referring websites, and other internet log on information of your computer, mobile, or other electronic/communication devices.
3. 收集您的個人資料
我們可能通過不同方式獲取有關您的個人資料,例如:
a. when you shop at our online or physical store;
b. when you participate in our events or promotions;
c. when you apply for our loyalty or promotion programs;
d. when you register an account with us;
e. when you participate in any surveys or marketing campaigns;
f. when you login to visit our websites, use our mobile applications or view any of our social media pages;
g. when you contact us whether in person, by phone, by email or via any social media platforms, to make enquires or provide information;
h. when verifying your identity;
i. when you subscribe to our marketing or promotional materials.
您可選擇不向我們提供所要求的個人資料,但若您選擇不提供,我們可能無法為您提供我們的產品、服務或優惠,或您或未能登入我們的平台或使用某些功能。
您有權要求我們提供有關您的個人資料及改正、更新或刪除該等資料。若您在歐盟居住,您就您的個人資料享有額外的權利,請參閱第11項「資料當事人的權利」。
4. 收集個人資料的目的
您的個人資料可能會用作以下一個或多個用途(「目的」):
a. communicating with you;
b. verifying your identity and any accounts you have with us;
c. administering any loyalty or other marketing, promotional or corporate programs that we are involved in, including providing you with the benefits that you are entitled;
d. processing your orders for products and services you place with us (such as maintaining your shopping cart, attending to billing, payments, refunds and delivery arrangements);
e. handling and responding to your inquiries, suggestions or complaints;
f. conducting customer surveys or organizing events for customers;
g. providing you with customer service;
h. conducting analysis to help us better understand our customers and to improve our services and products;
i. customising the information displayed on our shopping websites/apps and social networking/media platforms to create better customers experience;
j. designing targeted promotional offers;
k. conducting advertising activities, including targeted advertising;
l. conducting direct marketing activities;
m. fulfilling our obligation to maintain records of processing activities;
n. meeting legal, regulatory or compliance requirements, dealing with enquires from law enforcement or regulatory bodies or for the purpose of obtaining legal advice; and
o. any other purposes directly related to any of the above purposes.
我們只會收集為達到指定目的所需要或與該目的有直接關係的個人資料。若我們打算將個人資料用於其他不在上述的目的,我們會在使用您的個人資料前先取得您的同意。
5. 直接促銷
We intend to use your personal information for direct marketing which will include the marketing and promotion of all products and services offered by the LMCHING Group Limited (comprising all companies wholly-owned by LMCHING Group Limited which are engaged in the sale of cosmetic and beauty-related products/services). We will not provide your personal information to third parties for use in their direct marketing activities.
如您希望取消收取與直銷活動有關的訊息,您可參照下文「聯絡我們」列出的方法與我們的客戶服務主任聯絡,以表明您的選擇或要求我們更改您的選擇(不另收費)。如以電郵形式收取直銷活動有關的訊息,請按照提供的取消訂閱連結取消接收訊息。
歐盟的顧客,除非您反對直接促銷收取訊息,我們依賴合法利益作為使用您的個人資料向您直接促銷的法律基礎。您有權在任何時間取消收取與直銷活動有關的訊息。您可(a)參照「聯絡我們」的方法與我們的客戶服務主任聯絡或(b)如以電郵形式收取訊息,按下提供的取消訂閱連結。我們會將您的決定妥善存檔,而您取消收取與直銷活動有關訊息的決定不會影響我們之前處理個人資料的合法性。
6. 使用您的個人資料
我們會依照相關的法律及規條處理(包括但不限於收集,儲存,保存,使用,轉讓及披露)您所提供的資料。我們會確保您的資料安全,準確及更新,並不會儲存長於需要的時間。
7. 處理歐盟顧客個人資料的法理基礎
我們在維護我們的利益下可以使用您的個人資料,但這些利益將不會凌架在對您的潛在損害之上。
我們相信我們有一定的法理基礎使用您的個人資料,包括但不限於:
▪ conducting business by providing services to you, including verifying your identity and any accounts you have with us; administering any loyalty or other marketing activities, processing your orders for products and maintaining your shopping cart, attending to billing, payments, refunds and delivery arrangements; handling and responding to your inquiries, suggestions or complaints; conducting analysis and for other Purposes, providing you with direct marketing communication as you can reasonably expect at the time and in the context of collection of your personal information that processing for direct marketing purpose may take place;
▪ to help us satisfy our legal obligations (for example, in relation to prevention of money laundering and anti-terrorism);
▪ to help us understand our customers better and provide better, more relevant services to them;
▪ to ensure that our service runs smoothly;
▪ to help us keep our systems secure and prevent unauthorised access or cyber-attacks; and
▪ to drive commercial value for the benefit of our shareholders.
我們在您的同意下可以使用您的個人資料。您的同意在符合以下條件下方為有效:
▪ It has to be given freely, without us putting you under any type of pressure;
▪ You have to know what you are consenting to – so we will make sure we give you enough information;
▪ You should only be asked to consent to one thing at a time – we therefore avoid "bundling" consents together so that you do not know exactly what you are agreeing to; and
▪ You need to take positive and affirmative action in giving us your consent – we are likely to provide a tick box for you to check so that this requirement is met in a clear and unambiguous fashion.
您有權在任何時候撤回同意,我們在下面「聯絡我們」一項提供了詳細的方法。
履行我們的合約責任: 我們為了履行與您的合約是可以使用您的個人資料的,例如我們需要取得您的信用咭及銀行戶口資料去處理您的付款。
履行我們的法律責任: 除為了履行與您的合約外,我們亦可以為了遵守及履行我們的法律責任使用您的個人資料。
8. 透過自動方式收集的資料
曲奇(Cookies)是當您瀏覽網站時,瀏覽器儲存於電腦或其他互聯網相關設備內的資料。我們會使用Cookies作不同用途:
a. Strictly Necessary Cookies. These cookies are essential, as they enable you to browse our website and use its features, such as accessing log-in or secured areas. These cookies cannot be switched off or otherwise the website would not work properly. However, these cookies do not store any personal data.
b. Functionality Cookies. These cookies are used to enhance your shopping experience. For example, they allow us to remember what your preferred country is and what items you have added to your shopping cart when you visit our website again. The information these cookies collect may be anonymous, and they are not used to track your browsing activity on other sites. They are optional to users.
c. Targeting Cookies. Many of these are provided by third parties. These cookies can remember that your device has visited a site, and may also be able to track your device’s browsing activity on other sites. Examples of what we are using are Google Analytics and Adobe Analytics. Such information may be shared with other advertising networks to deliver the advertising. Again, you can block these cookies.
若您在沒有更改設定的情況下繼續使用,您即同意我們在我們的網站使用這些Cookies.
如何控制及刪除Cookies
您可以設定您的瀏覽器禁止所有或部份Cookies運作,請按以下的連結:
Chrome: https://support.google.com/chrome/answer/95647
Internet Explorer: https://support.microsoft.com/en-gb/help/17442/
Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences
Safari: https://support.apple.com/kb/ph21411
請注意,若您更改您的瀏覽器禁止某種Cookies, 您可能不能進入我們部份的網站, 我們其他的服務亦可能不能正常運作。
除了使用Cookies,我們也會透過我們的流動應用程式或網上平台以自動方式收集您的資料,例如網絡伺服器記錄檔(Web Server Logs)。網絡伺服器記錄檔是您在使用流動裝置或個人電腦瀏覽網站的活動記錄。例如網絡伺服器記錄檔可以記錄您搜查過的關鍵字或到訪過的網上連結,它亦可記錄您的瀏覽器資料如IP地址及伺服器在瀏覽器所裝置的Cookies。由自動方式收集的資料可被用作我們某部份的目的。
9. 閉路電視
我們店內為保安理由裝置了閉路電視。從閉路電視所獲得的資料只會在符合個人資料(私隱)條例的要求下使用及不會保留超過實際所需的時間。
10. 分享的資料及如何分享
We may disclose or transfer your personal data to companies within the LMCHING Group Limited or to any third party service providers or business partners, whether within or outside your jurisdiction, as necessary on a need-to-know basis to fulfil any of the Purposes. For transfer of personal data outside your jurisdiction, we will adopt contractual or other appropriate measures to safeguard your personal data, to provide a standard of protection at least comparable to that standard under the data protection laws in your jurisdiction, and to use them only to fulfil the above Purposes on our behalf or otherwise in accordance with any other cross-border data transfer mechanisms under the data protection laws of your jurisdiction.
我們也會基於法律或規條的要求或在保護我們的利益而必需的情況(在法律容許下) 披露或轉移您的個人資料到其他地方, 例如因可能出現的索償向保險公司披露。我們亦會保留任何因合併,吞併或公司重組(在法律容許下)而轉移您的個人資料的權利。
11. 資料當事人的權利
您有權向我們索取我們持有關於您的個人資料副本或修改我們持有關於您不正確或不完整的個人資料。我們不會無故拖延,並會在您所屬司法管轄區內的個人資料法時限內處埋您的要求(視乎我們在法律容許的延長期限)。若我們拒絕您索取或修改個人資料的要求,我們會向您解釋拒絕的原因。
歐盟的居民,您在我們管有或處埋您的個人資料的任何時間內根據「通用數據保障條例」可享有以下權利:
i. Right to object
▪ You have the right to object to us processing your personal data for one of the following reasons: (i) where it is within our legitimate interest; (ii) to enable us to perform a task in the public interest or exercise official authority; (iii) to send you direct marketing materials; and/or (iv) for scientific, historical, research, or statistical purposes.
▪ The “legitimate interests” category above is the one most likely to apply in relation to our relationship, and if your objection relates to us processing your personal data because we deem it necessary for our legitimate interests, we will act on your objection by ceasing the activity in question unless we:
· have compelling legitimate grounds for processing which overrides your interests; or
· are processing your data for the establishment, exercise or defence of a legal claim.
ii. Right to withdraw consent
▪ Where we have obtained your consent to process your personal data for certain activities (for example, for automatic profiling), you may withdraw this consent at any time and we will cease to carry out the particular activity that you previously consented to, unless we consider that there is an alternative legal basis to justify our continued processing of your data for this purpose, in which case we will inform you of the same.
iii. Right to submit a data subject access request (DSAR)
▪ You may ask us to confirm what information we hold about you at any time, and request us to modify, update or delete such information. We may ask you for more information about your request. We may refuse your request where we are legally permitted to do so, and we will inform you of the reasons for our refusal. If we provide you with access to the information we hold about you, we will charge you if your request is "manifestly unfounded or excessive". If you request further copies of this information from us, we may charge you a reasonable administrative cost where legally permissible.
iv. Right to erasure
▪ You have the right to request that we "erase" your personal data in certain circumstances. Normally, the information must meet one of the following criteria:
· the data is no longer necessary for the purpose for which we originally collected and/or processed them;
· where previously given, you have withdrawn your consent to us processing your data, and there is no other valid reason for us to continue processing;
· the data has been processed unlawfully (i.e. in a manner which does not comply with the GDPR);
· it is necessary for the data to be erased in order for us to comply with our obligations as a data controller under EU or Member State law; or
· if we process the data because we believe it necessary to do so for our legitimate interests, you object to the processing and we are unable to demonstrate overriding legitimate grounds for our continued processing.
▪ We would only be entitled to refuse to comply with your request for erasure for one of the following reasons:
· to exercise the right of freedom of expression and information;
· to comply with legal obligations or for the performance of a public interest task or exercise of official authority;
· for public health reasons in the public interest;
· for archival, research or statistical purposes; or
· to exercise or defend a legal claim.
▪ When complying with a valid request for the erasure of data, we will take all reasonably practicable steps to delete the relevant data.
v. Right to restrict processing
▪ You have the right to request that we restrict our processing of your personal data in certain circumstances.[1] Upon acceptance of your request, we can only continue to store your data and will not be able to carry out any further processing activities with it until either: (i) one of the circumstances (as listed in footnote 1) is resolved; (ii) you consent; or (iii) further processing is necessary for either the establishment, exercise or defence of legal claims, the protection of the rights of another individual, or reasons of important EU or Member State public interest.
▪ The circumstances in which you are entitled to request that we restrict the processing of your personal data are:
· where you dispute the accuracy of the personal data that we are processing about you. In this case, our processing of your personal data will be restricted for the period during which the accuracy of the data is verified;
· where you object to our processing of your personal data for our legitimate interests. Here, you can request that the data be restricted while we verify our grounds for processing your personal data;
· where our processing of your data is unlawful, but you would prefer us to restrict our processing of it rather than erasing it; and
· where we have no further need to process your personal data but you require the data to establish, exercise, or defend legal claims.
▪ If we have shared your personal data with third parties, we will notify them about the restricted processing unless this is impossible or involves disproportionate effort. We will notify you before lifting any restriction on processing your personal data.
vi. Right to rectification
▪ You also have the right to request that we rectify any inaccurate or incomplete personal data that we hold about you, including by means of providing a supplementary statement. If we have shared this personal data with third parties, we will notify them about the rectification unless this is impossible or involves disproportionate effort. You may also request details of the third parties that we have disclosed the inaccurate or incomplete personal data to. Where we think that it is reasonable for us not to comply with your request, we will explain our reasons for this decision.
vii. Right of data portability
▪ The right of data portability applies to: (i) personal data that we process automatically (i.e. without any human intervention); (ii) personal data provided by you; and (iii) personal data that we process based on your consent or in order to fulfil a contract.
▪ You have the right to transfer your personal data between data controllers which means that you are able to transfer the details we hold on you to another employer or a third party. We will provide you with your data in a commonly used machine-readable format to allow you to effect such transfer. Alternatively, we may directly transfer the data for you.
viii. Right to lodge a complaint with a supervisory authority
▪ You also have the right to lodge a complaint with your local supervisory authority.
如您想行駛這些權利或取消您同意我們處理您的個人資料(當我們處理的法律基礎是同意) ,這私隱政策下面「聯絡我們」的部份有詳細列出如何聯絡我們。請留意,我們會保留與您的通訊以便處理您提出的問題。
Please note that we may keep a record of your communications to help us resolve any issues which you raise.If you consider that our processing of your personal information infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection in your habitual residence or to our representative whose contact details may be found at the “Contact Us” section below.
12. 保留個人資料
我們會不時覆核我們管有的個人資料。我們保留您的個人資料的時間不會長於為完成目的所需的時間,除相關的法律及規定容許外,我們會在合理時間內盡快刪除已完成目的的個人資料。
我們會在保存期限到期後永久刪除您的個人資料,但您某部份的個人資料仍會儲存在我們的系統,如等侯被覆蓋的資料。為了我們的目的,這些資料不能再被使用,換言之,即使該資料存在於電子系統,也不能被我們的員工再索取或使用。
13. 資枓保護
為了保護並防止您的個人資料遭受意外、非法或未經授權的閱覽,我們會維持適當的措施去保障我們收集及處理您的個人資料的保密性及安全性。
14. 第三方網站
本私隱政策僅適用於我們,而不適用於任何其他第三方(包括他們營運的網站)。當點擊連結及/或廣告標語把您連線到第三方的網站或與我們關聯公司的網站,您將會受到他們的私隱政策約束。雖然我們支持互聯網私隱的保護,我們將不會承擔由我們網絡以外第三方所採取的任何行動。
15. 兒童政策
我們的網站及流動應用程式不適用於16歲或以下的人士直接使用。假如您是16歲或以下,您應該在家長或監護人陪同下使用我們的網站及流動應用程式及不應逞交任何個人資料給我們。
16. 修改私隱政策
我們可能不時修改本私隱政策,並於我們的網站及流動平台公佈。您可不時瀏覽本私隱政策,以確保您得悉最新版本。
17. 聯絡我們
如果您對本隱私政策有任何疑問或想行使您索取及更改您的個人資料的權利
▪ by telephone: +852 36195561;
▪ by e-mail: yourexpert@lmching.com; or
▪ by mail: LMCHING Group Limited: Unit A, 1/F, Hover Industrial Building, 38 Kwai Cheong Road, Kwai Chung, Hong Kong
本私隱政策有英文版本及中文版本。如英文版本及中文版本之間存在歧義,概以英文版本為準。
LMCHING Group Limited
[1] 您可要求我們限制處理您的個人資料的情況包括: (a) 當您爭議我們處理有關您的資料的準確性。在此情況下,我們處理您的個人資料將會受到限制,直至該資料的準確性得到核實; (b) 當您反對我們有合法利益處理您的個人資料。這情況下您可限制我們處理您的個人資料,直至我們的合法利益得到核實; (c) 當我們不合法地處理您的個人資料,但您選擇限制我們處理而非刪除您的個人資料; (d)在我們已經不需要再處理您的個人資料的情況下您需要該資料建立,進行或抗辯法律索償。