|
Privacy
ACE Insurance Limited
(“ACE”) is committed to the protection of Personal Data
which You provide to us. ACE’s own policies and
procedures, including ACE’s Privacy Policy Statement,
have been designed to ensure that Your Personal Data is
protected. ACE is committed to complying with the
Personal Data (Privacy) Ordinance (Cap.486) ("PDPO")
when collecting, holding, processing or using Personal
Data in Hong Kong. In so doing, ACE will ensure
compliance by our staff with the strictest standards of
security and confidentiality.
In this Privacy Policy
Statement, "You" (or "Your") refers to you, being a user
of the ACE website and who provides Personal Data to
ACE. "Personal Data" means personally identifiable
information, as more specifically defined in the PDPO.
Our Privacy Policy
Statement contains the following important information
regarding Your interaction with us:
The Principles
|
1. |
Collection of Personal Data |
|
2. |
Use of Personal Data |
|
3. |
Data Quality |
|
4. |
Data Security |
|
5. |
Openness |
|
6. |
Access and Correction |
Principle 1- Collection
of Personal Data
ACE will only collect Personal Data that is adequate and
necessary for and directly related to our provision of
insurance products and services and the other purposes
of our collection of Personal Data as set out in our
Personal Information Collection Statement
("Primary Purpose").
ACE will only collect Personal Data by lawful and fair
means. Personal Data is collected when You use or visit
ACE's website and submit other information (including
Personal Data) to ACE. Personal Data may also be
collected if You submit an insurance proposal form to
ACE.
Some information is collected automatically when you
visit the ACE website because your IP address needs to
be recognised by the server. We may use the IP
address information to monitor and analyse how parts of
the ACE website are used.
We may use cookies for a number of purposes as set out
in our website
Terms of Use.
Our cookies will track only Your activity relating to
your online activity on our website and will not track
Your other Internet activity. Our cookies do not
gather personally identifiable information. Please
refer to our website Terms of Use for Our policy on the
use of cookies.
At or before the time
ACE collects Personal Data from You, ACE will take
practical steps to ensure You are aware of:
|
a. |
The purposes for which the Personal Data is
collected and used; |
| b. |
The classes of persons to whom ACE may transfer
the Personal Data; |
|
c. |
Whether it is obligatory or voluntary for You to
provide the Personal Data; and |
|
d. |
If it is obligatory for You to provide the
Personal Data, the consequences for You if Personal Data
is not provided. |
Principle 2 – Use of
Personal Data
ACE will only use Personal Data for a purpose other than the Primary
Purpose of collection (a "Secondary Purpose") if:
|
a. |
the Secondary Purpose is directly related to the
Primary Purpose of collection; or |
|
b. |
You consent to the use or disclosure; or |
|
c. |
the Secondary Purpose is direct marketing and ACE
gives You the express opportunity at the time of first
contact to decline to receive any further direct
marketing communications; or |
|
d. |
any of the relevant exemptions under the PDPO
apply. |
At or before the time ACE first uses the Personal Data for the purpose for
which it was collected from You, ACE will take practical
steps to ensure that You are aware of:
|
a. |
Your rights to request access to and to request
the correction of the Personal Data; and |
|
b. |
The name and address of the individual to whom
any such request may be made. |
ACE may share Personal
Data it has collected with such persons set out in the
Personal Information
Collection Statement.
Principle 3 – Data
Quality
ACE will take practical steps to ensure that the Personal Data it collects, uses
or discloses is accurate, complete and up to date,
having regard to the purpose (including any directly
related purpose) for which the Personal Data are or are
to be used. Please refer to Principle 6 below for
details on how You can obtain and correct any Personal
Data relating to You that we may hold.
ACE will retain Your
Personal Data for as long as is necessary for the
purposes set out in Principles 1 and 2 above as well as
for purposes set out in the
Personal Information Collection Statement. ACE
will take reasonable steps to destroy or permanently
de-identify Personal Data if it is no longer needed for
such purposes. Principle 4 – Data
Security
ACE will take all practical steps to ensure that Personal Data it holds
are protected against unauthorised or accidental access,
processing, erasure or other use. ACE provides a highly
secure online infrastructure for activities conducted
via its website, including SSL (secure socket layer)
encryption, IDS (intrusion detection system) and the use
of firewalls and anti virus software. ACE also adopts
stringent security procedures with the use of user ID
and passwords, time stamping and audit trails for all
transactions, together with a dedicated internal
transaction security policy. ACE's online
infrastructure is closely monitored and maintained, with
data backup and data recovery procedures and mechanisms.
Principle 5 -
Openness
ACE has clearly expressed policies and practices on its management of
Personal Data. These policies are set out in this
document, which ACE makes available to anyone who
requests it.
Principle 6 - Access
and Correction
Your rights under the
PDPO:
Under the PDPO, You have the right (subject to certain exemptions) to:
|
a. |
check whether ACE holds any Personal Data
relating to You and request access to such Personal
Data; and |
|
b. |
request ACE to correct any Personal Data relating
to You which is inaccurate. |
Subject to certain exemptions under the PDPO, ACE will
grant access to and correct Personal Data as requested
by You. If ACE holds Personal Data about You and You
are able to establish that the Personal Data is not
accurate, complete and up to date, ACE will take
reasonable steps to correct Your Personal Data so that
it is accurate, complete and up to date. ACE will
provide reasons for any denial of access or a refusal to
correct Personal Data.
Your requests to access or correct Your Personal Data
will be actioned within 40 days of our receipt of Your
request and copies of the requested Personal Data or
Personal Data so corrected will be posted to your
current address.
Practical Steps:
|
a. |
If You wish to be provided with a copy of Your
Personal Data, please contact our Privacy Officer at: |
|
|
ACE Insurance Limited,
25th Floor Shui On Centre,
No.6-8 Harbour Road,
Wanchai
Hong Kong
|
|
b. |
You may also correct
Personal Data provided under a proposal form which You have
previously submitted to ACE by submitting an amended
proposal form to ACE. |
|
c. |
If You prefer, all Personal
Data may be corrected if you contact our Customer Relations
Team at:
|
|
|
ACE Insurance Limited
Claims Department
25th Floor, Shui On Centre
6-8 Harbour Road
Wanchai
Hong Kong
|
| d. |
ACE prefers to receive data access and correction requests by post. |
|
e. |
When submitting a data
access or correction request, please provide ACE with
documentary proof of identity. We need proof of Your
identity so we do not release Your Personal Data to
unauthorised persons.
|
Charges
ACE will not charge You
for lodging a request for access to Your Personal Data
and if ACE levies any charges for providing Personal
Data, such charges will not be excessive. No fee is
charged for data correction requests.
Further Information
If you have any queries about our Privacy Policy Statement and practices, please contact:
ACE Insurance Limited,
25th Floor Shui On Centre,
No.6-8 Harbour Road,
Wanchai,
Hong Kong
|