Privacy Policy

Effective Date: September 2025
Last Updated: September 2025

1. Introduction

Cheng-Lan Foundation Limited ("we","us" or "our") is committed to protecting your privacy and complying with the Personal Data (Privacy) Ordinance (Cap. 486) of the Laws of the Hong Kong Special Administrative Region.

This Privacy Policy Statement explains how we collect, use, disclose, transfer, and store your personal data when you use our website at http://chenglan.org (the "Site") and our related services. Please read this policy carefully to understand our practices.

By using our Site and services, you acknowledge you have read and understood this policy.

2. Personal Information Collection Statement (PICS)

This section serves as our Personal Information Collection Statement as required by the PDPO.

Purposes of Collection: Your personal data is collected for the following purposes:

  • To process your registrations for our programmes, events, and services;
  • To provide and administer the services you request;
  • To communicate with you about your account, our programmes, or enquiries;
  • To send you marketing and promotional communications (where you have given your consent);
  • To conduct research and analysis to improve our Site, services, and user experience;
  • To ensure the security of our Site and services;
  • To comply with any applicable legal or regulatory obligations.

Classes of Transferees: Your personal data may be disclosed to:

  • Our trusted third-party service providers who assist us in operating our website, conducting our business, or servicing you (e.g., IT service providers, email marketing platforms, payment processors). These parties are contractually bound to protect your data and use it only for the purposes we specify.
  • Any person or entity to whom we are required to make disclosure under any law applicable in or outside of Hong Kong.

Overseas Transfers: Some of these third-party service providers may be located outside of Hong Kong. In such cases, we will ensure that appropriate safeguards are in place to protect your personal data in accordance with the requirements of the PDPO.

Voluntary/Mandatory Nature of Supply: The provision of personal data is generally voluntary. However, if you do not provide certain mandatory data (which will be indicated as such on our collection forms), we may be unable to provide you with the specific service you request (e.g., processing your programme registration).

Data Access & Correction Rights: You have the right to request access to and correction of your personal data held by us. Please see Section 7 for details.

3. Information We Collect

We may collect the following types of information:

Information You Provide Directly: This includes information you provide when you subscribe to our mailing list, register for a programme, or contact us. This may include your first name, last name, email address, organisation name, and job title.

Automatically Collected Technical Information: When you visit our Site, we automatically collect certain information from your device, such as your IP address, browser type, operating system, referring URLs, access times, and pages visited. We collect this information through cookies and similar technologies to ensure the security and proper functioning of our Site and for internal analytics. For more details, please see our Cookies section below.

Cookies: Our Site uses "cookies" – small text files stored on your device – to enhance your user experience, analyse site usage, and assist in our marketing efforts. You can control the use of cookies at the individual browser level. If you choose to disable cookies, it may limit your use of certain features or functions on our Site.

4. How We Use Your Information

We use the information we collect for the purposes outlined in the PICS (Section 2), including:

  • To perform our contractual obligations to you.
  • To pursue our legitimate interests in improving our services and Site security, provided such interests are not overridden by your rights.
  • To send marketing communications where we have your explicit consent.
  • To comply with our legal obligations.

5. Data Retention

We will retain your personal data only for as long as necessary to fulfil the purposes for which we collected it, including to satisfy any legal, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for processing, and whether we can achieve those purposes through other means.

6. How We Protect Your Information

We implement appropriate technical and organisational security measures designed to protect your personal data against accidental, unauthorised, or unlawful access, disclosure, alteration, loss, or destruction. These measures include encryption, firewalls, and access controls. However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

7. Your Rights (Access & Correction)

In accordance with the PDPO, you have the right to:

  • Request access to a copy of the personal data we hold about you.
  • Request correction of any inaccurate personal data we hold about you.
  • Withdraw your consent for marketing communications at any time, by using the unsubscribe link in our emails or by contacting us.

To exercise your rights of access and correction, please send a written request to our Data Protection Officer at the contact details provided in Section 10. We may charge a reasonable fee for processing a data access request as permitted under the PDPO.

8. Use of Site by Minors

Our Site is not directed to individuals under the age of 18. We do not knowingly solicit or collect personal data from children. If you are under 18, you must obtain consent from your parent or guardian before providing any personal data to us.

9. Third-Party Links

Our Site may contain links to other websites not operated by us. This Privacy Policy does not apply to those third-party sites. We encourage you to review the privacy policies of any third-party site you visit.

10. Changes to This Policy

We may update this Privacy Policy Statement from time to time to reflect changes in our practices or the law. The updated version will be indicated by an updated "Last Updated" date at the top of this page. We encourage you to review this policy periodically to stay informed about how we are protecting your information.

11. How to Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy Statement or our data handling practices, please contact our Data Protection Officer:

By Post:
Data Protection Officer
Cheng-Lan Foundation Limited
Room 2203, 22/F Far East Financial Centre
16 Harcourt Road
Admiralty, Hong Kong