HONG KONG AIRLINES PRIVACY POLICY
Hong Kong Airlines Limited ("HKA", "we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy informs you as to how we look after your personal data (regardless of how and where we collect the data), what your data privacy rights are, how you can control your data, and how the laws protect you.
We review and update our Privacy Policy on a regular basis, and this policy from time to time may be modified without further notice. This Privacy Policy was last reviewed and/or updated on 1 November 2024, , and all changes become effective immediately after posting. If you would like to request a copy of the historical HKA Privacy Policy, please contact us.
1.Important information and who we are
HKA is committed to complying with the requirements set out in applicable data privacy laws and regulations. We process personal data in accordance with the provisions of Personal Data (Privacy) Ordinance of Hong Kong and other applicable data protection legislations. This Privacy Policy sets out the basis and aims to give you detailed information on how HKA collects and processes your personal data. To facilitate your understanding of this Privacy Policy and the meaning of the terms used, you may refer to Section 12. Glossary in this Policy.
It is also important that you read this Privacy Policy together with any other privacy notices we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we use your data. This Privacy Policy supplements the other privacy notices and is not intended to override them.
In the event of any inconsistency between the English version and the Chinese version of this Privacy Policy, the English version shall prevail.
HKA as the Data Controller/User
When HKA takes control of your personal data, we shall be the Data Controller/User as defined in applicable data privacy laws and be responsible for your data.
Contact HKA through our Data Privacy Manager
HKA has its headquarters in Hong Kong, and we have appointed a Data Privacy Manager who is responsible for overseeing this Privacy Policy and other matters/enquiries in relation to personal data privacy in HKA. Contact details are as below:
Full name of legal entity: |
Hong Kong Airlines Limited |
Delegated department unit: |
Legal and Audit Department |
Email address: |
|
Postal address: |
Data Privacy Manager Legal and Audit Department Hong Kong Airlines Limited
28 Kwo Lo Wan Road, Hong Kong International Airport, Lantau, Hong Kong Special Administrative Region |
If you have any questions about this Privacy Policy, wish to make a request to exercise your legal rights in respect of your personal data, or cannot find what you are looking for regarding data privacy from this Privacy Policy, please email us at dataprivacy@hkairlines.com to get more information, make a request, raise your concern or provide feedback. We encourage you to provide us with as much information as possible in the email (including background information and additional contact information, if applicable), so we can attend to your case effectively and in a timely manner. If you are not satisfied with our response, you may also contact the authority responsible for administering the privacy laws in your country/area.
If you have made a flight booking with us but the flight(s) in your booking is to be operated by other airline(s), such other airline(s) is also a “Data Controller/ User”. If you have made a booking for non-flight services through us, such as hotel or car rental bookings, the provider of such services is also a “Data Controller/ User”. You may access the privacy policies of the other airlines and non-flight service providers from them directly.
2.Applicability of this Privacy Policy
This Privacy Policy applies when you interact with us through HKA website or mobile app and provide us personal data, for example, to:
- purchase flights, holidays or any other products or services from us
- sign up to any HKA newsletter or publication
- take part in any HKA promotion or competition
- to make an enquiry or a complaint
This Privacy Policy may also apply when you provide personal data directly to HKA and receive products/ services from one of our group companies or business affiliates or partners, includes but not limited to TravelSky Technology Limited and its subsidiaries, SATS HK Limited (“SATSHK”), HKA Holidays Limited (“HKAH”) and Fortune Wings Club (“FWC”).
In addition to the above stated, this Privacy Policy may apply when HKA collects and processes your personal data through some of our trusted third parties or from other different channels. Please refer to the specific terms and conditions under each particular point of data collection. HKA is always committed to being transparent with you about how we handle your personal data when you interact with us.
For more details on the internal/external third parties of HKA, you may refer to Section 12. Glossary in this Policy.
3.The personal data we collect about you
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
We may collect, use, store and transfer different kinds of personal data about you, which we have grouped together as follows:
- Identity Data, include first name, maiden name, last name, nationality and passport details, username or similar identifier, marital status, title, date of birth, gender and other identification details (which may include your image).
- Contact Data include billing address, delivery address, email address and telephone numbers (including emergency contact details).
- Financial Data, include bank account and payment card details.
- Transaction Data, include details about payments to and from you and other details of products and services you have purchased from us.
- Technical Data, include internet protocol (IP) address (IP address), your login data, browser types and versions, time zone settings and locations, browser plug-in types and versions, operating systems and platforms and other technologies on the devices you use to access HKA website or mobile app.
- Profile Data, include your username and password, purchases or orders made by you, your interests, preferences, feedback and survey responses.
- Usage Data, include information about how you use our website, mobile app, products and services. These also include records of your interactions with us through the call centre and social media.
- Marketing and Communications Data include your preferences in receiving marketing from us and our third parties and your communication preferences.
When you use the Hong Kong Airlines mobile app, we need to obtain some authorisations from you in order to provide you with better services. We will first seek your consent. You can also turn off the relevant permission authorisations through the settings of the mobile phone operating system.
Mobile App Permissions |
Descriptions |
Phone Permission |
It is used for us to contact passengers in order to communicate with passengers and provide services, such as: handling ticket reservations, mobile boarding services, etc.; or notifications that are issued by our Customer Service Centre to passengers, etc. |
SMS Permission |
It is used for us to contact passengers in order to communicate with passengers and provide services, such as: issuing Fortune Wings Club membership authentication code, Fortune Wings Club membership password authentication code, electronic voucher use authentication code, etc. |
Location Permission |
It is used to quickly locate the city where the passenger is located in order to confirm the departure point for flight reservation. |
Camera/ Photo Permission |
It is used for scanning codes, identifying boarding passes, etc. |
Storage Permission |
It is used for picture storages, saving QR code to phone album and other related features. |
Remark: |
If you refuse to give authorisation for the relevant permission, you will not be able to use the concerned service function, but it will not affect your normal use of other functions. |
In addition, we will also collect the device information about your mobile app in order to provide the relevant service functions, including app information (app crash information and app installation list), device parameters and system messages (International Mobile Equipment Identity (IMEI)), equipment type, device model, operating system version and the hardware-related information, the equipment network environment information (Internet Protocol (IP) Address), wireless network information, base station information, and other network-related information.
We also use the following Software Development Kit (SDK):
Name of the SDK |
Purpose of Usage |
The Collected Personal Information |
Related Privacy Policy Link |
Alipay |
Alipay payment |
- Apple Computer, the MAC address - Basic Service Set Identifiers (BSSID) - Service Set Identifier - Subscriber Identification (SIM) Card serial number - Hardware serial number/ Build serial - Device screen density and International Mobile Equipment Identity (IMEI) - International Mobile Subscriber Identity (IMSI) |
|
|
payment |
- Mobile Equipment Identity (MEI) - Apple Computer, the MAC address - Android identification code and sequence number - Wireless Local Area Network (WLAN) access point |
|
|
(“Share”) |
Device identification code, e.g. Android’s: - International Mobile Equipment Identity (IMEI) - Identifier - Mobile Equipment Identifier (MEID) - International Mobile Subscriber Identity (IMSI) - Sequence number - Integrated Circuit Card Identifier (ICCID) - Apple Computer, the MAC address - Wireless Local Area Network (WLAN) access point |
|
AutoNavi |
Positioning navigation |
To identify the location |
|
Alibaba Cloud |
Risk control |
Sensor |
Alibaba Cloud International Website Privacy Policy |
“Push” |
“Push technology” |
To capture the Secure Digital (SD) Card data and device ID, e.g.: - Apple Computer, the MAC address - International Mobile Equipment Identity (IMEI) |
We also collect, use and share Aggregated Data for different purposes, such as statistics or customer demographics. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website or mobile app feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this Privacy Policy.
Collecting and processing personal data of minors
Please note, neither our website nor mobile app is intended for use by children aged below 16.
We do not knowingly collect and process personal data of children aged below 16 without parental or guardian consent, unless permitted by applicable law. If we become aware that personal data of children aged below 16 has been collected without parental or guardian consent, we will delete the relevant data and/or unsubscribe the relevant marketing subscription accordingly. In normal situation, we may not be able to automatically distinguish the age of persons who access and use HKA’s website or mobile app. If the parent or guardian becomes aware that personal data of children aged below 16 has been collected by HKA without parental or guardian consent, please contact us (refer to Section 1 of this policy).
For the purpose of (i) managing travel arrangements of people travelling with children aged below 16 or (ii) taking care of Unaccompanied Children and Minors on our flights or (iii) other legitimate reasons, HKA may collect personal data of the children aged below 16. Before personal data of children aged below 16 is to be processed, unless otherwise specified, HKA requires consent of the parent or guardian who is aged 18 or above and holds parental responsibility over the children.
At the time you provide any personal data of children aged below 16 to HKA for processing, you confirm that you are aged 18 or above, give your consent to HKA and authorise processing of the children’s personal data as the parent or guardian.
Collecting and processing Special Categories of Personal Data
Unless otherwise required to do so in order to comply with specific laws/regulatory authorities’ requirements (e.g. advance passenger information, passenger name records, new technology of using facial recognition for airport check-in services, etc.) or necessary to provide certain services to you (e.g. special assistances, delivering your chosen meal preferences, etc.) at airports or on board our aircrafts, we shall not collect or process any Special Categories of Personal Data about you (these include but not limited to the details about your race or ethnicity, religious or philosophical belief, sex life, sexual orientation, political opinion, trade union membership and information about your health and genetic and biometric data). Where Special Categories of Personal Data are required from you in order to provide certain services, we will obtain your consent before collecting and processing the Special Categories of Personal Data.
Collecting and processing data on Criminal Convictions and Offences and Passengers’ Behaviours
We may receive Criminal Convictions and Offences Data from law enforcements and other governmental authorities, and record data on Passengers’ Behaviours and/or interactions with staff before, during and after a flight. The purpose of such data collection is to protect the safety of our passengers, staff and equipment. Processing of such data is carried out in accordance with applicable legal and regulatory requirements.
Help us to keep your personal data update and accurate
It is important that the personal data we hold about you are accurate and current. Please keep us informed of any changes to your personal data.
If you fail to provide personal data required
Where we need to collect your personal data by law or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into it with you (e.g. to provide you with goods or services). In such a case, we may have to cancel the contract you have with us (e.g. order of products or services) and at the same time we shall notify you about the arrangement.
4.How is your personal data collected
We collect data from and about you through different methods, include but not limited to:
- Direct interactions
You may give us your Identity Data, Contact Data, Financial Data and/or other personal information by filling in forms or by corresponding with us by posts, phones, emails or otherwise. These include the personal data you provided to us or our service providers when you:
- apply for our products or services;
- purchase our products or services;
- create an account on our website or mobile app;
- subscribe to our services or publications;
- request marketing materials to be sent to you;
- request special services or assistance;
- enter in a competition, promotion or survey; or
- give us feedback or file a complaint.
In addition, from your direct interaction with our staff before, during and after a flight, we may record information about your behaviours and/or interactions with us.
- Automated technologies or interactions
As you interact with our website or mobile app, we may automatically collect Technical Data about your equipment, browsing actions and patterns. We collect such personal data by using cookies, server logs and/or other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see our Cookies Policy for further details.
- Third parties or publicly available sources
We may also receive personal data about you from various third parties and public sources, include but not limited to those as set out below:
- Technical Data from the following parties:-
- Analytics service providers, such as Google Analytics and Facebook Analytics;
- Advertising networks; and
- Search information providers
- Profile Data from social networks
- Contact Data, Financial Data and Transaction Data from the providers of technical, payment and delivery services.
- Identity Data and Contact Data from data brokers or aggregators.
- Identity Data and Contact Data from publicly available sources (e.g. publicly available databases).
- Criminal Convictions and Offences Data from law enforcement and other governmental authorities.
Please note, the third parties or publicly available sources may be based anywhere in the world. Please see Section 9 below for the measures we put in place regarding international transfers of your personal data.
Further privacy notice at the point of data collection
At the time we collect any personal data from you, we do our best to make further notice to you highlighting the certain uses of your personal data, how the data are kept, and how you may exercise your rights regarding the data.
If you provide us with information about other individuals, please inform those individuals about the Privacy Notice and this Privacy Policy.
5.How we use your personal data
We will only use your personal data when the applicable laws allow us to do so. Most commonly, we will use your personal data in the following circumstances:
- Where we need to perform the contract we are about to enter into it or have entered into it with you;
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those legitimate interests;
- Where we need to comply with a legal or regulatory obligation.
Purposes for which we will use your personal data
We have set out below, in a table format, descriptions of all the ways we plan to use your personal data and the type(s) of lawful basis that we rely on to process the data. We have also identified what our legitimate interests are where appropriate. Generally, we obtain consent from you before we process your personal data, but we do not rely on consent as the legal basis for processing personal data.
Note that we may process your personal data on one or more lawful basis depending on the specific purpose for which we are using your data. Please contact us if you need more details about the specific legal basis we are relying on to process your personal data.
Purpose/Activity |
Type of data |
Lawful basis for data processing |
To register you as a new customer |
(a) Identity (b) Contact |
Performance of a contract with you |
To process and perform your flight booking including: (a) Manage payments, fares, fees and charges (b) Notify you of relevant flight information such as pre-flight check-in and changes to your flight |
(a) Identity (b) Contact (c) Financial (d) Transaction |
Performance of a contract with you |
To register you as a new member of Fortune Wings Club through our website/mobile app |
(a) Identity (b) Contact (c) Profile |
Performance of a contract with you |
To keep your records accurate and updated |
(a) Identity (b) Contact (c) Profile |
(a) Performance of a contract with you (b) Your consent (c) Necessary for our legitimate interests (to keep our records updated, given that we have obtained your consent) |
To ask you to provide feedback about your experience with us and our partners |
(a) Identity (b) Contact (c) Profile (d) Usage |
(a) Your consent (b) Necessary for our legitimate interests (to interact with response provided by you and to study how you use our products/services, given that we have obtained your consent) |
To enable you to participate in a prize draw, competition or to complete a survey |
(a) Identity (b) Contact (c) Profile (d) Usage (e) Marketing and Communications |
(a) Your consent (b) Necessary for our legitimate interests (to interact with response provided by you and to study how you use our products/services, given that we have obtained your consent) |
To administer and protect our business, website and mobile app (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data, and fraud prevention) |
(a) Identity (b) Contact (c) Technical |
(a) Necessary for our legitimate interests (to run our business, to provide administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise) (b) Necessary to comply with a legal obligation |
To deliver relevant website/mobile app content and advertisements to you, and to measure or understand the effectiveness of the advertising we serve to you |
(a) Identity (b) Contact (c) Profile (d) Usage (e) Marketing and Communications (f) Technical |
Your consent (for us to study how you use our products/services and to develop our business and marketing strategy)
*Please note that you have the right to control advertising preference at any time. Should you wish your personal data not to be used in this regard under the Google and Facebook tools we may utilise, below are the opt-out options offered by Google and Facebook respectively:
Double click for Publishers (Google Inc.): https://adssettings.google.com/authenticated
Facebook Audience Network (Facebook, Inc): https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen |
To use data analytics to improve our website/mobile app, products/services, marketing, customer relationships and experiences |
(a) Technical (b) Usage |
Your consent (for us to define types of customers for our products and services, to keep our website/mobile app updated and relevant, and to develop our business and marketing strategy)
*Please note that you have the right to control advertising preference at any time. Should you wish your personal data not to be used in this regard under the Google and Facebook tools we may utilise, below are the opt-out options offered by Google and Facebook respectively:
Double click for Publishers (Google Inc.): https://adssettings.google.com/authenticated
Facebook Audience Network (Facebook, Inc): https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen |
To make suggestions and recommendations to you about goods or services that may be of interest to you
|
(a) Identity (b) Contact (c) Technical (d) Usage (e) Profile |
Your consent (for us to make direct marketing to you)
|
To protect the safety of our passengers, staff, aircrafts and equipment
|
(a) Identity (b) Criminal Convictions and Offences (c) Passengers’ Behaviours |
(a) Necessary to protect our legitimate interests (to protect the safety of our passengers, staff, aircrafts and equipment) (b) Necessary to comply with a legal obligation (c) Necessary to protect vital interests (to protect the lives of our passengers and staff) |
Change of purpose on personal data processing
We will only use your personal data for the purposes for which we collected them, unless we reasonably consider that we need to use them for another reason that is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purposes, please contact us.
If we need to use your personal data for a new and unrelated purpose, we will notify you, explain on the lawful basis which allows us to do so, and obtain consent from you where appropriate. However, please note that we may process your personal data without your knowledge or consent where this is required or permitted by law.
Use of your personal data for marketing
HKA strives to provide you with choices regarding certain personal data uses, particularly around marketing and advertising.
- Promotional offers from us
We strive to offer you the best products and services, and we do our best to find the most relevant products, services and offers for you when we make our marketing and promotions. We may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what you may want or need, or what may be of interest to you.
We may use your personal data in marketing of our promotions (e.g. for direct marketing). We shall obtain your opt-in consent at the time of personal data collection before using your personal data for any marketing communications, as appropriate and required by applicable laws.
You may receive marketing communications from us via specific channels after you provide us with your details for requesting information from us, for purchasing goods or services, for entering a competition, for registering a promotion or for other activities with us, while in our records, we have obtained your opt-in consent for using your personal data in marketing.
- Third-party marketing
We may also have a chance to share your personal data with our third parties for marketing purposes. In this case, we will get your opt-in consent before any sharing or disclosure of your personal data with third parties.
- Opt-out of marketing communications
In relation to any marketing communications delivered to you (e.g. via email or text message or other applicable channels), you have the right to refuse marketing at any time (e.g. by opt-out or withdrawal of consent). There are various ways available for you to request us or the third parties to stop delivering you marketing communications, including:
- in case you are already our registered member, you may log into your account and adjust your marketing preferences at any time;
- click and follow the “opt-out link” available in any marketing communications delivered to you; or
- contact us or the third party directly.
Please note that, where you may have opted out of receiving the marketing communications, this will not apply or affect the non-marketing communications that we send to you in respect of your purchase of our products and services, e.g. live information about your flight with us, disruption alerts or other operational updates as may be necessary from time to time.
Regarding sale of personal data/information
Hong Kong Airlines does not, nor do we plan to, sell any of the personal data/information we have collected about you in the course of our normal operations. Should there is change in our practice, we shall update this Privacy Policy and ensure you are aware of the change.
6.Retention period of personal data
HKA has a policy which sets the data retention period for each personal data collection. We will retain your personal data for as long as necessary to fulfil the personal data collection purposes, which the data collection purposes include satisfying any legal, regulatory, accounting, or reporting requirements. Normally, the retention period will not exceed 7 years after the purposes of the data collection are fulfilled unless it is retained for fulfilling legal obligations or with legitimate reasons.
In order to determine the appropriate retention period of specific personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of the personal data, the purposes for which we process the personal data and whether we can achieve those purposes through other means, and the applicable legal and regulatory requirements. To request more details on HKA’s personal data retention policy or the retention period of your personal data, you may contact us.
In some circumstances we may anonymise your personal data (so that the data can no longer be associated with you) for research or statistical purposes; in which case, we will use the anonymised data indefinitely without further notice to you.
When your personal data is no longer needed, we will destroy the data securely.
7.Security of your personal data
We have put in place appropriate security measures to prevent your personal data from accidentally lost or unauthorised use, access, alteration or disclosure. In addition, we limit access to your personal data to those employees, agents, contractors and/or other third parties who have the business need to know and are subject to duty of confidentiality.
We also have put procedures in place to deal with any suspected personal data breach and will notify you and applicable regulator(s) of confirmed data breach where we are legally required to do so.
8.Disclosure of your personal data
For the purposes set out in the table in Section 5 of this policy, we may have to share your personal data with the parties as set out below:
- Internal Third Parties, as set out in Section 12. Glossary.
- External Third Parties, as set out in Section 12. Glossary.
- Third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owner(s) shall use your personal data in the same way as set out in this Privacy Policy.
In addition to the purposes of data usage as set out in Section 5 of this policy, we may also disclose your personal data/information to third parties for our legitimate business purposes, including but not limited to auditing, safety & security, technical debugging, short-term uses, service performance, internal research, and product/service testing or improvement. The relevant personal data/information that may have been disclosed are as follow:
|
|
(You may refer to Section 3 of this Policy for definitions of relevant data categories)
In accordance with applicable laws, we require all relevant third parties to respect and maintain the privacy and security of your personal data.
Third-party links
This website or mobile app may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites, plug-ins and applications and are not responsible for their privacy policy/statements. When you leave our website or mobile app, we encourage you to read the respective privacy policy of websites or applications you visit.
9.International transmissions of your personal data
We may share your personal data with the HKA group of companies, business affiliates and partners for legitimate purposes, and this may involve transmitting your data to/between countries/areas.
Please note that your personal data may be transferred outside the country/area where you are located, including to countries/areas with a lower level of data privacy and protection.
If you are based outside of Hong Kong
Many of our External Third Parties are based outside of Hong Kong. At the time you provide personal data through this website or mobile app, a transmission of your personal data outside of Hong Kong may take place to process your data.
Whenever we need to transfer your personal data out of Hong Kong, we ensure a similar degree of data protection is afforded to ensure your personal data is only transferred to countries/areas that have been deemed to provide level of protection for personal data by the applicable local government authorities.
10.Your legal rights
Under certain circumstances and in accordance with applicable data protection laws, you have the following right(s) in relation to your personal data:
- Request access to your personal data
- Request correction of your personal data
- Request erasure of your personal data
- Object to processing of your personal data
- Request restriction of processing your personal data
- Request transfer of your personal data
- Right to withdraw consent
You may delete your registered HKA Mobile Website Account at any time. Please refer to the “Deletion of Registered HKA Mobile Website Account” for the details.
If you like to delete your Registered HKA Mobile Website Account:
- Step 1: Login with your registered HKA Mobile Website Account.
- Step 2: Go to the avatar position (in the upper left corner) of [Mine]. After the page is reset, click the [Delete Account] at the bottom of the page.
- Step 3: Follow the instructions to view the account information, confirm the account cancellation instructions, and complete the cancellation process. After cancellation, the successful cancellation will be displayed.
If you want to terminate your Fortune Wings Club (“FWC”) account, please contact HKA Customer Service Centre. Please note that once your FWC account is cancelled, you may not be able to log in your account by any of the FWC members’ website or mobile app, including Hong Kong Airlines, Hainan Airlines, Grand China Air, Tianjing Airlines, Lucky Air, Capital Airlines, Fuzhou Airlines, Suparna Airlines, Gulf Airlines, Urumqi Airlines, Air Changan, Air Guilin and West Air.
If you wish to exercise any of the right(s) set out above, please contact us.
Data Access Request
We have set out procedures to respond to your request when you exercise your right to access and correct your personal data.
What we need from you
We may need to request specific information from you to help us confirm your identity and warrant your rights to your personal data. This is a security measure to ensure that your personal data is not disclosed to any person who has no right to receive it. We may also contact you and ask for further information in relation to your request in order to speed up our response.
Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you of this as soon as possible and keep you updated on the progress.
A reasonable fee may be charged
You will not have to pay a fee to access your personal data. However, we may charge a reasonable fee if the request is clearly unfounded, repetitive or excessive. We may also charge printing fees and/or handling fees in accordance with the actual consumption or labour costs, while not excessive.
Refusal of your data access request
In the circumstances that your data access request is clearly unfounded, repetitive or excessive, we reserve the right to refuse to comply with your request.
11.Cookies
You can set your internet browser to refuse all or some of the browser cookies, or to alert you when cookies are being used. If you disable or refuse cookies, please note that some parts of HKA website or mobile app may become inaccessible or not function properly. For more information about the cookies we use, please click here.
12. Glossary
Privacy Notice means a statement made to a data subject that describes how we collect, use, retain and disclose personal data.
LAWFUL BASIS
Legitimate Interest means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impacts on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impacts on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impacts on you in respect of specific activities by contacting us.
Performance of a Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.
Comply with a legal or regulatory obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.
THIRD PARTIES
Internal Third Parties mean other companies in the HKA group of companies, including but not limited to:
(i) TravelSky Technology Limited (“TravelSky”)
TravelSky is a subsidiary of China TravelSky Holding Company Limited, which is the dominant provider of information technology solutions for Hong Kong’s aviation and travel industry. TravelSky provides HKA a range of aviation services, including but not limited to providing aviation technology services, distributing information technology services, accounting, settlement and clearing services, conducting electronic transactions, and managing travel-related information. This HKA Privacy Policy may apply when TravelSky receives and processes your data from HKA to facilitate the ticketing, check-in and boarding activities.
(ii) SATS HK Limited (“SATSHK”)
SATS HK Limited is a joint venture of Hong Kong Airlines Limited and SATS Limited, and provides a range of ground handling services from passenger handling services, ramp handling, flight operations, baggage handling, load control to cargo services at the Hong Kong International Airport. This Privacy Policy may apply when SATSHK receives and processes your data from HKA to facilitate the ticketing, check-in and boarding activities of your flight.
(iii) HKA Holidays Limited (“HKAH”)
HKAH is a wholly-owned subsidiary of HKA and offers versatile travel packages for travellers to and from Hong Kong. This Privacy Policy may apply when your data is collected through HKA website or mobile app for processing your order of HKAH travel products or services. However, any personal data submitted to HKAH directly shall subject to HKAH’s own privacy policy. Please take time and read the respective policy.
(iv) Fortune Wings Club (“FWC”)
HKA is one of the flying partners of FWC, and any personal data collected through HKA website or mobile app in respect of the FWC frequent flyer programme shall also be subject to this Privacy Policy. However, any personal data submitted to FWC frequent flyer program directly or via other registration channels shall be subject to FWC’s own privacy policy and/or privacy policies of other flying partners. Please take time and read the respective policy.
Depending on the circumstances, the internal third party may act as an independent data controller, a joint data controller with HKA, or a data processor of HKA. HKA and all internal third parties are committed to protecting your privacy at the highest standard as always.
External Third Parties mean other companies outside the HKA group of companies, including but not limited to:
- business affiliates or partners acting as independent data controller or joint data controller with HKA, including other airlines, hotels, transport operators, travel agents, or marketing partners;
- service providers acting as data processors of HKA, including those agents providing airport/ground handling and/or inflight services in our route network. HKA permits the service providers to process your personal data on behalf of us for specified purposes, which you can find details set out in Section 5 in this Policy. Common services offered by the providers include special assistance to passengers, call centre operation, sales & marketing support, inflight meal service, IT and system administrative service and website maintenance;
- professional advisers (can be independent data controller, joint data controller or data processor depending on circumstances), including lawyers, bankers, auditors and insurers who provide legal, consultancy, banking, accounting and insurance services;
- government, regulators and other authorities (normally as independent data controller/user) which may require reporting of data processing activities in certain circumstances (e.g. for safety, security, or tax purposes) in accordance with applicable laws. The authorities may request disclosure of information in relation to passengers’ travel documents, booking details and/or flight itinerary records; and
- payment processors such as banks and credit card issuers (normally as independent data controller/user), which may collect personal data for detecting or preventing fraudulent transactions.
The external third parties can be based in/outside of Hong Kong. Therefore, it is possible that your personal data can be transferred outside your country/area for legitimate purposes. Details on international data transmissions can be referred to Section 9 in this policy.
YOUR LEGAL RIGHTS
While subject to applicable data privacy laws of your country/location, you have the right to:
Request access to your personal data (commonly known as a "Data Access Request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
Request erasure of your personal data. This enables you to ask us to delete or remove your personal data under specified circumstances, including where there is no good reason for us continuing to process the data, where you have successfully exercised your right to object to processing or withdraw consent (see below), where we may have processed your information unlawfully, or where local law requires us to erase your personal data, etc. Note, however, that we may not always be able or necessary to comply with your request of erasure for specific legal reasons and/or under certain exemptions provided by the laws, which the reason will be notified to you, if applicable, at the time of your request.
In the event that your personal data/information has already been transferred to third parties, we shall communicate your request of erasure to the relevant parties to delete your personal data/information from their records accordingly.
Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impact on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data's accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
Request the transfer of your personal data to you or to a third party. We will provide you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
Opt-out from sale of your personal data/information. Although HKA does not or does not plan to sell your personal data/information, you can always send us email to inform us of your intention for not to sell your personal data/information, and we shall take record of your intention accordingly. However, as permissible under applicable data privacy law, should HKA decide to sell your personal data/information in the future, we may contact you in no less than 12 months after your last given intention and obtain your consent for a sale of personal data. If you do not consent, we will not proceed with the sales any further.
Non-discrimination for exercising your privacy rights. We will not discriminate against you for exercising your rights by:
- denying goods or services to you;
- charging different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties;
- providing a different level or quality of goods or services to you; or
- suggesting that you will receive a different price or rate for goods or services or a different level or quality of goods or services.