Privacy Policy and Personal Information Collection Statement

By using this website, you agree to the responsibilities and policy statements listed in it. If you continue to use this website and mobile application after making amendments to these terms, it shall be deemed that you have accepted the amendments. This Statement applies to HERO PLUS (HONG KONG) LIMITED (referred to as “HERO PLUS” or “we”). HONG KONG PROPERTY FINANCE LIMITED is part of a group of companies under HERO PLUS (HONG KONG) LIMITED (referred to as “HERO PLUS”). In this Statement, the term “data subjects” or “you” shall include visitors to this website and users, applicants for Buy Now Pay Later and customers of Buy Now Pay Later. The content of this Statement shall apply to all data subjects and form part of the terms and conditions of the Buy Now Pay Later Agreement and/or any agreement or arrangement that the data subjects have or may enter into with HERO PLUS from time to time. In the event of any inconsistency or discrepancy between this Statement and the relevant agreement or arrangement, this Statement shall prevail insofar as it relates to the protection of the data subject’s personal data.

HERO PLUS Privacy Principles

HERO PLUS values your trust. HERO PLUS is committed to the full implementation and compliance with the six data protection principles and the requirements of the Personal Data (Privacy) Ordinance (Cap. 486, Laws of Hong Kong) (the “Ordinance”). This Statement is intended to assist you in understanding HERO PLUS’s privacy policies and practices in relation to the personal data.

Our Pledge

We pledge to safeguard your personal data by complying with the requirements of the Ordinance as well as the relevant codes of practice and guidance notes issued by the Office of the Privacy Commissioner for Personal Data. We will ensure that all our employees and third parties with permitted access to your personal data uphold these obligations.

Collection of Personal Data

Personal data means any information relating to an individual from which the identity of the individual can be ascertained, directly or indirectly. We may collect the following data relating to you, which may be personal data from time to time, including but not limited to: name; age; gender; phone number; email address; HKID number or passport number; birth date; personal finance status (including need for instalments); income or assets information; education level; employment information; residential information; bank account or credit card account details; Facebook ID and first name displayed in Facebook; LinkedIn ID and related information; preferences related to any products or services; communications between you and HERO PLUS; data regarding your visits to and use of HERO PLUS website and HERO PLUS Mobile App; and location data.

In addition, when you use HERO PLUS website and HERO PLUS Mobile App, we may automatically collect certain data which may, when combined with other information about you, be personal data, including but not limited to:

  • attributes of the equipment or device you are using, such as the operating system, hardware version, device settings, software and device identifiers;
  • device locations, including specific geographic locations identified through GPS, Bluetooth or WiFi signals or other means;
  • connection information such as the name of your mobile operator, ISP or other service provider, browser type and IP address;
  • the website and HERO PLUS Mobile App from which you have reached HERO PLUS website and HERO PLUS Mobile App;
  • the HERO PLUS website and HERO PLUS Mobile App pages viewed;
  • details of the products and services on the HERO PLUS website and HERO PLUS Mobile App that you look at, information, tools and content available on HERO PLUS website and HERO PLUS Mobile App that you use; and
  • links from HERO PLUS website and HERO PLUS Mobile App that you click on.

With your request or authorization, HERO PLUS may additionally receive information about you from our business partners or co-branding partners or from credit reference agencies. HERO PLUS may also obtain information about you from the public domain.

We may use the personal data collected for the purpose set out in the Personal Information Collection Statement (see below). The use and disclosure of personal data and your right to access or correct your personal data held by HERO PLUS are also set out in the Personal Information Collection Statement (see below).

Use of Cookies

Cookies are small data files which are placed on data subject’s device when data subject visits HERO PLUS’s website and HERO PLUS Mobile App, or clicks on HERO PLUS’s online advertisements. Cookies or similar technologies are used for the following purposes:

  1. statistical analysis of your on-site behaviour such as number of visits to our site, page views, length of time spent on each page. These are aggregated and therefore anonymous.
  2. provide enhanced user experience, remember your preference within our website, enable easy navigation between public section and member owner section of our web property.
  3. promote personalized products using your visited pages, and the website links you have followed to:
    • make HERO PLUS’s website and HERO PLUS Mobile App more relevant to your interests;
    • provide online advertisements or offers on HERO PLUS’s website and HERO PLUS Mobile App or third-party websites which are most likely to interest you;
    • evaluate the effectiveness of HERO PLUS’s online marketing and advertising programs.

The above cookies may be placed on data subject’s device by HERO PLUS or by third parties on HERO PLUS’s behalf (for example, advertising networks and providers of external services like web traffic analysis services). Information recorded through the use of cookies by third parties are aggregated and then shared with HERO PLUS as anonymous aggregated research data. No personal contact information about data subjects is collected or shared by third parties with HERO PLUS as a result of the use of cookies.

Most web browsers are initially set up to accept cookies. Should you wish not to be tracked by this kind of technology, you can choose to ‘not accept’ cookies by changing the settings on your web browser. However, if you block all cookies, including strictly necessary cookies, you may not be able to use the HERO PLUS website or and HERO PLUS Mobile App.

Security and retention of Personal Data

  1. Security of your personal data is important to us. We take appropriate action to protect personal data from loss, misuse, unauthorized access or disclosure, alteration or destruction using the same safeguards as we use for our own proprietary information. All information you provide to us is stored on secure servers and any payment transactions will be encrypted using SSL technology. Where we have given you (or where you have chosen) a password which enables you to access certain parts of our website(s) or website/IT portal(s)/mobile application(s), you are responsible for keeping this password confidential. We ask you not to share a password with anyone.
  2. We will put in place measures such that your personal data in our possession or under our control is destroyed and anonymized as soon as it is reasonable to assume that (a) the purpose for which that personal data was collected is no longer being served by the retention of such personal data; and (b) retention is no longer necessary for any other legal or business purposes.
  3. If we outsource and entrust your personal data with data processors, we will use contractual and other means to monitor the data processors’ compliance with this Privacy Policy.
  4. The transmission of information through the internet is not completely secure. Although we use security measures to secure your personal data, we cannot guarantee the security of your personal data transmitted through the internet and any transmission is at your own risk.

Retention of personal data

  1. We will keep your personal data for as long as your account registered with us is being accessed.
  2. If your account registered with us has not been accessed over a period of [three years] or we have closed your account upon your request (“End Date”), your personal data will be retained by us for seven years after the End Date. We may retain your personal data for a longer period if it is necessary for us to do so to comply with our contractual or legal obligations, or you have consented to our continued retention of it.
  3. At the end of the retention period, we will ensure that your personal data, all app-related data and account-related information will be deleted. For any physical documents containing your personal data, the documents will be shredded or otherwise destroyed by means that ensure the confidential and secure destruction of the documents.
  4. We will ensure that our data processor who we transfer your personal data to in compliance to this Privacy Policy only retain your personal data for as long as is necessary for the fulfillment of the Purposes for which your personal data has been disclosed to them and will delete personal data held if personal data is no longer required for those Purposes unless any deletion is prohibited under law or it is in the public interest for the personal data to not be deleted.

Purpose of Collection

  1. For the purposes of the provision of services by HERO PLUS, it is necessary for data subjects to supply HERO PLUS with personal data for the opening or continuation of accounts and for the purposes of the establishment or continuation of Buy Now Pay Later facilities and related financial services or the processing of new or renewal applications or other services through HERO PLUS website and HERO PLUS Mobile App.
  2. Failure to supply such personal data by data subjects may result in HERO PLUS being unable to open or continue accounts, provide Buy Now Pay Later facilities and related financial services or process applications or other services.
  3. For the purposes of the provision of services by HERO PLUS, personal data of data subjects may also be obtained from credit reference agency (whose contact details can be provided upon request) or from the public domain through different channels, including public registers, public search engines, public directories or any social media with public view setting authorized by the data subject. In addition, device information may be collected from data subjects’ web browsers.

Use of Personal Data

  • considering and processing applications for products and services and the daily operation of products and services (including Buy Now Pay Later facilities and related financial products and services provided to data subjects);
  • conducting credit checks whenever appropriate (including at the time of application for loan and when we review credit which normally takes place one or more times each year);
  • creating and maintaining HERO PLUS’s credit scoring or risk related models;
  • ensuring ongoing credit worthiness and good standing of data subjects;
  • assisting other financial institutions to conduct credit checks and to collect debts;
  • designing and developing loan/credit facilities and related financial products and services for customers’ use;
  • conducting marketing research or developing membership programmes;
  • subject to obtaining the consent of data subjects, direct marketing services, marketing products, services and other subjects as described in paragraphs 6 and 7 below;
  • determining the amounts of indebtedness owed to or by data subjects;
  • exercising HERO PLUS’s rights under contracts with data subjects, including collecting amounts outstanding from data subjects;
  • meeting obligations, requirements and arrangements, of HERO PLUS whether compulsory or voluntary, to comply with or in connection with:
  • any law, regulation, judgement, court order, voluntary code, sanctions regime applicable to HERO PLUS existing currently or in the future;
  • any guidelines, guidance, rules or codes of practice or requests given, published or issued by any legal, regulatory, governmental, tax, law enforcement or other authorities, relevant stock exchange, self-regulatory or industry bodies or associations of financial service providers within or outside Hong Kong existing currently or in the future;
  • any present or future contractual or other commitment with legal, regulatory, judicial, administrative, public or law enforcement body, or governmental, tax, revenue, monetary, court or other authorities, relevant stock exchange, self-regulatory or industry bodies or associations of financial service providers or any of their agents that is assumed by, imposed on or applicable to HERO PLUS; and
  • any agreement or treaty between the authorities described in (iii) above;
  • complying with any obligations, requirements, policies, procedures, measures or arrangements of HERO PLUS for the use of data and information for compliance with sanctions or prevention or detection of money laundering, terrorist financing or other unlawful activities;
  • enabling an actual or proposed assignee or transferee of all or any part of HERO PLUS’s business and/or assets, or participant or sub-participant of HERO PLUS’s rights in respect of loans/credit facilities relating to data subjects, to evaluate the transaction intended to be the subject of the assignment, transfer, participation or sub-participation and enabling the actual assignee or transferee to use such data in the operation of the business or rights assigned;
  • comparing data of data subjects or other persons for credit checking, data verification or otherwise producing or verifying data, whether or not for the purpose of taking action against such data subjects;
  • maintaining a credit history of the data subjects (whether or not there exists any relationship between the data subjects and HERO PLUS) for present and future reference;
  • any other purposes relating to the purposes listed above.

Use of Personal Data

All personal data held by HERO PLUS will be kept confidential but HERO PLUS may disclose or transfer such information to the following parties for the purposes set out in Use of Personal Data above:

  • any agent, contractor, sub-contractor or associates of HERO PLUS (including its employees, officers, agents, contractors, service providers and professional advisers);
  • any third-party service provider who provides administrative, professional, advisory, telecommunication, information service, computer, payment, data processing, debt collection or other services to HERO PLUS in connection with the operation or maintenance of its business;
  • any other person who is under a duty of confidentiality to HERO PLUS and has undertaken to keep such information confidential
  • the drawee bank providing a copy of a paid cheque (which may contain data about the payee) to the drawer;
  • credit reference agencies and, in the event of default, debt collection agencies;
  • any authority, body, association or persons mentioned in paragraph 4(k) above;
  • any actual or proposed assignee or transferee or HERO PLUS or, participant or sub-participant of HERO PLUS’s rights in respect of loans/credit facilities relating to data subjects;
  • any persons giving or proposing to give a guarantee or security to guarantee or secure the data subject’s obligations to HERO PLUS;
  • business partners or co-branding partners of HERO PLUS, together with whom HERO PLUS provides products or services to data subjects;
  • subject to obtaining the consent of data subjects in connection with the purpose set out in paragraph 4(h) above:
  • third party financial institutions, insurers, credit card companies, securities, commodities and investment services providers, third-party membership programme providers or our co-branding partners; and
  • external service providers (including but not limited to mailing houses, telecommunication companies, telemarketing and direct sales agents, call centres, data processing companies and information technology companies).
Personal data collected in Hong Kong by HERO PLUS may be transferred in and to a place outside Hong Kong.

Direct Marketing

  1. HERO PLUS intends to use a data subject’s data to conduct direct marketing of products or services and requires the data subject’s consent (which includes an indication of no objection) for that purpose. In this connection, please note that:
    • the name, contact details, products and other service portfolio information, transaction pattern and behaviour, financial background and demographic data of data subject held by HERO PLUS from time to time may be used by HERO PLUS in direct marketing;
    • the classes of services, products and subjects which may be marketed includes credit/loan facilities and other financial services and products, membership programmes and related products and services, products and services offered by our co-branding partners;
    • the above services, products and subjects may be provided by HERO PLUS, third party financial institutions, insurers, securities and investment services providers, third-party membership programme providers or our co-branding partners;
    • in addition to marketing the above services, products and subjects itself, HERO PLUS also intends to provide the data described in sub-paragraph 1 above to all or any of the persons described in sub-paragraph 3 above for use by them in marketing those services, products and subjects, and HERO PLUS requires the data subject’s consent (which includes an indication of no objection) for that purpose; and
    • HERO PLUS may receive money or other property in return for providing the data to the other persons in sub-paragraph 3 above and, when requesting data subject’s consent or no objection as described in sub-paragraph 4 above, HERO PLUS will inform the data subject if we will receive any money or other property in return for providing the data to the other persons.
  2. If you do not wish HERO PLUS to use or provide to the other persons your data for use in direct marketing as described above, you may exercise your opt-out right by notifying us:

    Data Protection Officer
    HERO PLUS (HONG KONG) LIMITED
    8/F, MW Tower, 111 Bonham Strand
    Sheung Wan, Hong Kong
    Email: cs@heroplus.xyz

Access and Correction of Personal Data

Under and in accordance with the terms of the Ordinance and the Code of Practice on Consumer Credit Data (the “Code”), you have the right:

  • to check whether HERO PLUS holds personal data about you and to access such data;
  • to require HERO PLUS to correct any personal data relating to you which is inaccurate;
  • to ascertain HERO PLUS’s policies and practices in relation to personal data and to be informed of the kind of personal data held by HERO PLUS;
  • in relation to consumer credit data, to be informed, upon request, which items of personal data are routinely disclosed to credit reference agencies or debt collection agencies and be provided with further information to enable the making of an access and correction request to the relevant credit reference agency or debt collection agency; and
  • in relation to consumer credit data, upon termination of your account by full repayment and on condition that there has not been, within 5 years immediately before account termination, any material default on your account, to instruct HERO PLUS to make a request to the credit reference agency to delete from its database any account data relating to your terminated account.
  1. If you default in repayment, unless the amount in default is fully repaid or written off (otherwise than due to a bankruptcy order) before the expiry of 60 days from the date such default occurred, your account repayment data (as defined in the Code) may be retained by the credit reference agency until the expiry of 5 years from the date of final settlement of the amount in default.
  2. If any amount owed by you is written off due to a bankruptcy order being made against you, your account repayment data (as defined in the Code) may be retained by the credit reference agency, regardless of whether the account repayment data reveals any material default, until the expiry of 5 years from the date of final settlement of the amount in default or the expiry of 5 years from the date of your discharge from bankruptcy as notified to the credit reference agency by you with evidence.
  3. In accordance with the terms of the Ordinance, HERO PLUS has the right to charge a reasonable fee for the processing of any data access request.
  4. You should send any requests for access to personal data or correction of personal data or for information regarding our policies and practices to:

    Data Protection Officer
    HERO PLUS (HONG KONG) LIMITED
    8/F, MW Tower, 111 Bonham Strand
    Sheung Wan, Hong Kong
    Email: cs@heroplus.xyz

  5. Nothing in this Notification shall limit the rights of the data subjects under the Ordinance.
  6. In case of discrepancies between the English and Chinese versions, the English version shall prevail.