COVID-19 Recovery app Website Privacy Policy:

 

The Chinese University of Hong Kong (the University) as a data user undertakes to comply with the requirements of the Personal Data (Privacy) Ordinance to ensure that personal data kept are accurate, securely kept and used only for the purpose for which they have been collected.

 

This privacy policy (together with our end-user licence agreement (EULA) and any additional terms of use incorporated by reference into the EULA, together our Terms of Use) applies to your use of:-

 

 

The App is a lifestyle management tool and does not provide personalised medical advice. Use of the App is not a substitute for medical advice. You should not rely on the App to take any action or refrain from taking any action in a manner which is inconsistent with medical advice. If you are in any doubt you should seek medical advice before taking any action or refraining from taking any action in reliance on the App.

 

This privacy policy is provided in a layered format so you can click through to the specific areas set out below.

 

Please also use the Glossary in Section 10 below to understand the meaning of some of the terms used in this privacy policy.

 

1. IMPORTANT INFORMATION AND WHO WE ARE

2. THE DATA WE COLLECT ABOUT YOU

3. HOW IS YOUR PERSONAL DATA COLLECTED

4. HOW WE USE YOUR PERSONAL DATA

5. DISCLOSURES OF YOUR PERSONAL DATA

6. INTERNATIONAL TRANSFERS

7. DATA SECURITY

8. DATA RETENTION

9. YOUR LEGAL RIGHTS

10. GLOSSARY

 

1. IMPORTANT INFORMATION AND WHO WE ARE

Purpose of this Privacy Policy

This privacy policy aims to give you information on how the University

collects and processes your personal data through your use of this App, including any data you may provide through this App.

 

Controller

The University is the controller and responsible for your personal data (collectively referred to as “The Chinese University of Hong Kong”, “the University”, “we”, “us”, or “our” in this privacy policy). If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact us.

 

 

 

 

Third-party links

Our Sites may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. Please note that these websites and any services that may be accessible through them have their own privacy policies and that we do not accept any responsibility or liability for these policies or for any personal data that may be collected through these websites or services, such as Contact and Location Data. Please check these policies before you submit any personal data to these websites or use these services.

 

2. THE DATA WE COLLECT ABOUT YOU

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). There are certain types of more sensitive personal data (known as special category data) which require a higher level of protection, such as information about a person’s health.

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

 

 

We will also collect, store and use the following more sensitive types of personal information:

 

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific App feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.

 

3. HOW IS YOUR PERSONAL DATA COLLECTED?

We will collect your personal data in the following ways:

 

 

Purpose/activity

Type of data

Lawful basis for processing

To install the App and register you as a new App user

Identity

Contact

Device

Your consent

To deliver Services to you accessible through the app.

Identity

Contact

Device

Marketing and Communications

Your consent

Performance of a contract with you

To manage our relationship with you including notifying you of changes to the App or any Services

Identity

Contact

Profile

Marketing and Communications

Your consent

Performance of a contract with you

Necessary for our legitimate interests (to keep

records updated and to analyse how users of

the App use our products/ Services)

Necessary to comply with legal obligations

(to inform you of any changes to our terms and

conditions)

To enable you to participate in a survey

Identity

Contact

Device

Profile

Marketing and Communications

Your consent

Performance of a contract with you

Necessary for our legitimate interests (to analyse how

 users use our products/Services and to develop

 them and grow the App)

To administer and protect our business and this App including troubleshooting, data analysis and system testing

Identity

Contact

Device

Necessary for our legitimate interests (for running

 our App, provision of administration and IT services,

 network security)

To deliver content and advertisements to you

To make recommendations to you about goods or services which may interest you

To measure and analyse the effectiveness of the advertising we serve you

To monitor trends so we can improve the App

Identity

Contact

Device

Content

Profile

Usage

Marketing and Communications

Consent

Necessary for our legitimate interests

(to develop our products/Services and grow our

business/ the App)

 

 

 

Cookies

We use cookies to distinguish you from other users of the App, App Site, the distribution platform (Appstore) or Services Sites and to remember your preferences. This helps us to provide you with a good experience when you use the App or browse any of Our Sites and also allows us to improve the App and Our Sites. For detailed information on the cookies we use, the purposes for which we use them and how you can exercise your choices regarding our use of your cookies, see our cookies policy on our website.

 

4. HOW WE USE YOUR PERSONAL DATA

We will only use your personal data when the law allows us to do so. Most commonly we will use your personal data in the following circumstances:

 

Please see the Glossary below in Section 9 to find out more about the types of lawful basis that we will rely on to process your personal data.

Purposes for which we will use your personal data

 

How we use particularly sensitive personal information

We will only process special categories of personal information (such as your Health Data) when we have your explicit consent to do so. The situations in which we will process your health data are listed below:

 

Disclosures of your personal data

When you consent to providing us with your personal data, we will also ask you for your consent to share your personal data with the third parties set out below for the purposes set out in the table Purposes for which we will use your personal data and How we use particularly sensitive personal information above:

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

 

 

5. INTERNATIONAL TRANSFERS

 

To the extent permitted by the laws of Hong Kong, we may share the data collected with our research partners globally.

 

6. DATA SECURITY

All information you provide to us is stored on servers securely. Where we have given you (or where you have chosen) a password that enables you to access certain parts of Our Sites, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.

Once we have received your information, we will use strict procedures and security features to try to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator when we are legally required to do so.

 

7. DATA RETENTION

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

 

In some circumstances you can ask us to delete your data: see the section on Your Legal Rights below for further information.

In some circumstances we will anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

 

8. YOUR LEGAL RIGHTS

Under certain circumstances you have the following rights under data protection laws in relation to your personal data.

You can exercise any of these rights at any time by contacting us at jclongcovid@cuhk.edu.hk 

 

9. GLOSSARY

Lawful basis

Consent means processing your personal data where you have signified your agreement by a statement or clear opt-in to processing for a specific purpose. Consent will only be valid if it is a freely given, specific, informed and unambiguous indication of what you want. You can withdraw your consent at any time by contacting us.

 

Legitimate Interest means the interest of our research in conducting and managing our academic activities to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.

 

Performance of Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.

 

Comply with a legal obligation means processing your personal data where it is necessary for compliance with a legal obligation that we are subject to.

 

Third parties

Internal third parties

Other departments /institutions/centers/entities in The University who provide support for this project.

 

External third parties

 

Your legal rights

You have the right to:

 

(a)    if you want us to establish the data’s accuracy;

(b)    where our use of the data is unlawful but you do not want us to erase it;

(c)    where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or

(d)    you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.