{"id":14800,"date":"2023-11-10T01:55:49","date_gmt":"2023-11-09T17:55:49","guid":{"rendered":"https:\/\/greatplacetowork.com.hk\/ch\/?page_id=14800"},"modified":"2023-11-10T01:57:31","modified_gmt":"2023-11-09T17:57:31","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"14800\" class=\"elementor elementor-14800\" data-elementor-post-type=\"page\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-ca68229 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"ca68229\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c796e47\" data-id=\"c796e47\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f3473cf elementor-widget elementor-widget-text-editor\" data-id=\"f3473cf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2><strong>Great Place To Work China Privacy &amp; Security Notice<\/strong><\/h2><h3><span style=\"font-weight: 400;\">Scope<\/span><\/h3><p><span style=\"font-weight: 400;\">This Privacy &amp; Security Notice describes Great Place To Work Hong Kong (hereafter the \u201cGPTW\u201d) privacy practices in connection with:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Our websites and subpages located at <\/span><a href=\"https:\/\/www.greatplacetowork.com\/\"><span style=\"font-weight: 400;\">https:\/\/www.greatplacetowork.<\/span><\/a><span style=\"font-weight: 400;\">cn and <\/span><a href=\"https:\/\/www.greatplacetowork.com\/\"><span style=\"font-weight: 400;\">https:\/\/www.greatplacetowork.<\/span><\/a><span style=\"font-weight: 400;\">hk\u00a0 (hereafter the \u201cSites\u201d)<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Our products and services<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">This Privacy &amp; Security Notice does not cover GPTW\u2019s privacy practices for:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GPTW employees, contractors, or job applicants<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Children and\/or Minors. Our Site is neither designed nor intended for any visitors under 18 years of age. If you have any reason to believe that a visitor to our Site is under <\/span><span style=\"font-weight: 400;\">18<\/span><span style=\"font-weight: 400;\"> years old, please contact us at <\/span><a href=\"mailto:privacy@greatplacetowork.com\"><span style=\"font-weight: 400;\">privacy_cn@greatplacetowork.com<\/span><\/a><span style=\"font-weight: 400;\"> and we will endeavor to delete the information from our databases.<\/span><\/li><\/ul><h4><span style=\"font-weight: 400;\">What is Personal Information?<\/span><\/h4><p><span style=\"font-weight: 400;\">For purposes of this Privacy &amp; Security Notice, personal information means information collected by GPTW relating to an identified or identifiable natural person recorded electronically or by other means, but does not include anonymized information.<\/span><\/p><h4><span style=\"font-weight: 400;\">Links to Third-party Websites<\/span><\/h4><p><span style=\"font-weight: 400;\">For your convenience, the Site may contain links to third-party websites and\/or information. When you access those links, you leave GPTW\u2019s Site and are redirected to a third-party website. GPTW does not control third-party websites, and the privacy practices of third parties might differ from GPTW\u2019s privacy practices. We do not endorse or make any representations about third-party websites. When you share personal information with third-party websites, the third-party processing is not covered by this Privacy &amp; Security Notice. We encourage you to review the privacy policy of any website or company before sharing personal information.<\/span><\/p><h3><span style=\"font-weight: 400;\">GPTW\u2019s Privacy Practices Affecting Users of Our Site<\/span><\/h3><h4><span style=\"font-weight: 400;\">Sources of Personal Information We Collect From Site Visitors:<\/span><\/h4><p><span style=\"font-weight: 400;\">GPTW collects personal information from individuals who access our Site:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directly from a website visitor<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">From service providers or other third parties; and<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatically from a web visitor\u2019s visit or activity on our site.<\/span><\/li><\/ul><h4><span style=\"font-weight: 400;\">Information Collected Directly From Website Visitors<\/span><\/h4><p><span style=\"font-weight: 400;\">GPTW collects personal information when you visit our Site and when you choose to provide personal information. For example, we collect information when you contact us via our Site, provide your email, phone number or other similar contact information, such as the information that you provide when you sign up for a webinar.<\/span><\/p><h4><span style=\"font-weight: 400;\">What We Collect<\/span><\/h4><p><span style=\"font-weight: 400;\">The personal information collected from a visitor to our Site may include:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Name<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Company<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job Title<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Address<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Phone Number<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email Address<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">If you register to attend a GPTW sponsored Event, we may require certain data in some instances, including:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Emergency contact<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dietary preferences<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Health and safety information<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Billing information (such as billing name, billing address, and credit card number)<\/span><\/li><\/ul><h4><span style=\"font-weight: 400;\">Information Provided by Third Parties or Publicly Available Sources<\/span><\/h4><p><span style=\"font-weight: 400;\">We may receive information about you from other sources and combine that information with the information we collect directly. Examples of information we may receive from other sources include: purchased business contact information and from publicly accessible websites, such as your company\u2019s website, professional network services, or press releases. Business contact information may include:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">First name<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Last name<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business email<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telephone number<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Company name<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job level<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Functional role<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business street address<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Online identifier<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Employment history<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">We use this data for our internal customer analytics, to identify prospective customer marketing opportunities, and to improve the relevance of our Site content and our advertising.<\/span><\/p><h4><span style=\"font-weight: 400;\">Information Collected by Cookies<\/span><\/h4><p><span style=\"font-weight: 400;\">Like many websites, GPTW uses cookies and similar tracking technologies (including for analytics, functionality, advertising, and other purposes).<\/span><\/p><p><span style=\"font-weight: 400;\">You can set your Internet browser or operating system settings to stop accepting new cookies, to receive notice when you receive a new cookie, to disable existing cookies, to omit images (which will disable pixel tags) or adjust your tracking preferences. Note that the opt-out will apply only to the browser that you are using when you elect to opt out of advertising cookies. Without cookies or pixel tags though, you may not be able to take full advantage of our sites\u2019 features.<\/span><\/p><h4><span style=\"font-weight: 400;\">Information Collected for Analytics<\/span><\/h4><p><span style=\"font-weight: 400;\">Our Site may record information concerning how often you use the application, the events that occur within the application, aggregated usage, performance data, your IP address. We do not link the information we store within the analytics software to any personal information you submit within the Site.<\/span><\/p><p><span style=\"font-weight: 400;\">If you use certain systems provided by GPTW, we will collect data from you to enable multifactor authentication, such as mobile number, email address, or unique verification identifier.<\/span><\/p><h4><span style=\"font-weight: 400;\">Information Collected Directly From Social Media Features<\/span><\/h4><p><span style=\"font-weight: 400;\">Our website may host various blogs, forums, wikis, and other social media applications or services that allow you to share content with other users (collectively \u201cSocial Media Applications\u201d). Any personal information or other information that you contribute to any Social Media Application can be read, collected, and used by other users of that Social Media Application over whom we have little or no control. Therefore, we are not responsible for any other user\u2019s use, misuse, or misappropriation of any personal information or other information that you contribute to any Social Media Application.<\/span><\/p><h4><span style=\"font-weight: 400;\">Other Information<\/span><\/h4><p><span style=\"font-weight: 400;\">If GPTW collects any other personal information from you, we will explain which personal information is collected and the purpose for its collection.<\/span><\/p><h4><span style=\"font-weight: 400;\">Why We Use Your Personal Information<\/span><\/h4><p><span style=\"font-weight: 400;\">Our purposes of processing personal information include:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To fulfill the purpose(s) for which the information was collected or provided, including to communicate with you and respond to your inquiries and requests;<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To improve our site, products and services, through testing, research, analysis and product development;<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To market, advertise, and promote our products and services, such as to make suggestions and recommendations to you about products or services that may be of interest to you;<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To provide training related to the products and services, such as making available training materials or events (whether in-person or online) for which we may use your personal information to provide notices and information regarding such training and events;<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">For security, audit, internal investigation, and fraud prevention purposes, such as to prevent unauthorized access or disclosure, to maintain data accuracy, to protect the confidentiality, integrity, and availability of your personal information; to allow only the appropriate use of your personal information; to identify any fraudulent, harmful, unauthorized, unethical or illegal activity;<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To manage litigation, such as in connection with establishing, exercising, or defending our legal rights where it is necessary for our legitimate interests or the legitimate interests of others;<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To improve the content and format of our Site by using cookies and other similar technologies, such as to measure the preferences of our Site visitors, analyze trends, administer the Site, analyze use of the Site, and to gather demographic information about visitors to the Site;<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">For other purposes for you have provided consent;<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To aggregate or deidentify your personal information so that the information can no longer be linked to you or your device and use and share such data for any business purpose in accordance with applicable law; and<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To comply with all applicable legal obligations, such as to comply with subpoenas and other court orders to process data where we have determined there is a legal requirement to do so.<\/span><\/li><\/ul><h4><span style=\"font-weight: 400;\">Site Security<\/span><\/h4><p><span style=\"font-weight: 400;\">GPTW utilizes physical, technical, and administrative controls and procedures designed to safeguard the information we collect, prevent unauthorized access or disclosure, to maintain data accuracy of your personal information, and to restrict the processing of your personal information as set forth in this Privacy &amp; Security Notice.<\/span><\/p><p><span style=\"font-weight: 400;\">We utilize a variety of physical and logical access controls, firewalls, anti-virus, and backup systems. We use encrypted sessions when collecting or transferring sensitive data through our Site.<\/span><\/p><p><span style=\"font-weight: 400;\">We limit access to your personal information and data to those persons who have a specific business purpose for maintaining and processing such information. Our employees who have been granted access to your personal information are made aware of their responsibilities to protect the confidentiality, integrity, and availability of that information and have been provided training and instruction on how to do so.<\/span><\/p><h3><span style=\"font-weight: 400;\">GPTW\u2019s Privacy Practices Affecting Users of Our Product<\/span><\/h3><p><span style=\"font-weight: 400;\">We generally market and sell our Product to businesses, not consumers.\u00a0 Our commitments regarding the personal information we collect, use, and disclose about the end users of the Product are largely driven by our contracts with business customers.\u00a0 The information provided below is intended to help our business customers understand our privacy practices.\u00a0 If you are an end user of one of our products or services, you are encouraged to contact your employer with questions about how your personal information is being collected, used, and disclosed.<\/span><\/p><h4><span style=\"font-weight: 400;\">Information we Collect<\/span><\/h4><p><span style=\"font-weight: 400;\">In most instances, GPTW customers are the controllers of the personal information they collect, create, communicate, and store in our Product.\u00a0 The types of personal information that can be stored in our Product may include, but is not limited to:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">End User Names<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Company Names<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Job Titles<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Business Addresses<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email Addresses<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Any personal information provided to us by Users of our Product, and which is required for us to execute our agreements with our Customers.<\/span><\/li><\/ul><h4><span style=\"font-weight: 400;\">Use of Information We Collect<\/span><\/h4><p><span style=\"font-weight: 400;\">When we act as a processor, the personal information we collect is used to deliver our products and services to Customers.\u00a0 Any personal information we use is done in accordance with our contracts with our Customers.<\/span><\/p><p><span style=\"font-weight: 400;\">Because our business clients are data controllers, it is primarily them who must undertake efforts regarding how information is collected and processed in accordance with data-protection laws.\u00a0 Therefore, if you have questions or concerns about the processing of your information as an end user, you should contact your employer directly or refer to its separate privacy policies.\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">GPTW does not give anyone access to the personal information maintained in the Product unless:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">It is permitted to do so in its contract with the Customer.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The Customer instructs GPTW to do so;<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The Customer consents (e.g., subprocessors used by GPTW);<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">If GPTW is legally obligated to do so; or<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">If GPTW has a legitimate interest (as defined under PIPL, GDPR and other applicable laws) to do so.<\/span><\/li><\/ul><h4><span style=\"font-weight: 400;\">Data Retention<\/span><\/h4><p><span style=\"font-weight: 400;\">GPTW will only retain personal information for the length of time necessary to fulfill the purpose(s) for which the information was collected or as required or permitted by applicable laws, (including the resolution of disputes) and in accordance with our customer contracts.<\/span><\/p><p><span style=\"font-weight: 400;\">To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of the personal information, the purposes for which we process your personal information, and whether we can achieve those purposes through other means, and the applicable legal requirements.<\/span><\/p><p><span style=\"font-weight: 400;\">When we no longer require your personal information, we will either delete or deidentify (anonymize) it or, if this is not possible, we will securely store it in accordance with this policy and cease use of the personal information until deletion is possible. If we deidentify (anonymize) your personal information (so that it is no longer associated with you), we may retain this information for longer periods. To support our research and enable historical comparisons, we retain deidentified data indefinitely.<\/span><\/p><h4><span style=\"font-weight: 400;\">Disclosure of Personal Information<\/span><\/h4><p><span style=\"font-weight: 400;\">We do not sell your personal information to third parties.\u00a0 We may, however, share your information with:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Affiliates, Licensees, and Subsidiaries.\u00a0 We might share personal information with our affiliates, licensees, and subsidiaries in order to deliver a product or service or to complete a task requested by our customer.\u00a0<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Third Party Suppliers or Service Providers.\u00a0 We might engage with third parties (suppliers and\/or service providers) in order to deliver a product or service, perform certain functions such as enhancing the Product, or complete a task requested by our customer. We have contracts with our Third Party Suppliers or Service Providers to perform certain functions on our behalf, and only at our direction.\u00a0 Our third parties are bound by confidentiality agreements, only have access to personal information to the extent necessary to provide these contracted services, and are only permitted to process personal information in accordance with our instructions (and for the purposes we disclose).\u00a0<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">In addition, GPTW might disclose personal information if we in good faith believe that it is necessary:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To comply with the law or with a legal process<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To protect or defend our rights and property<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To protect against misuse or unauthorized use of our website<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">To protect the personal safety or property of our users or the public (among other things, this means that, if you provide false information or attempt to pose as someone else, information about you may be disclosed as part of any investigation into your actions).<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">In connection with, or during negotiations for, an acquisition, merger, asset sale, or other similar business transfer that involves all or substantially all of our assets or functions where personal information is transferred or shared as part of the business assets (provided that such party agrees to use or disclose of personal information consistent with our Privacy &amp; Security Notice or gains your consent for other uses of disclosures).\u00a0<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">We will not cross-reference your personal information with that of any other customer or entity.\u00a0 GPTW does not support \u201cback door\u201d access to any of its products, services, or operations (including our data stores) by any government or third party.\u00a0 GPTW does not share its encryption keys or provide the ability to break our encryption keys with any government or third party.\u00a0<\/span><\/p><h3><span style=\"font-weight: 400;\">Protecting Your Information<\/span><\/h3><p><span style=\"font-weight: 400;\">GPTW has many dedicated policies, practices, and protocols to protect our IT infrastructure, networks, devices, and data from unauthorized access, collection, retention, and use of sensitive, confidential, and\/or proprietary customer or user data, including personal information.\u00a0 These policies, practices, and protocols include, but are not limited to:<\/span><\/p><h4><span style=\"font-weight: 400;\">Product Security<\/span><\/h4><p><span style=\"font-weight: 400;\">Engineering and development access to the components that comprise the Product is restricted using methods including, but not limited to, Single Sign-On, two factor authentication, network segmentation, and IP restriction. Access to servers and services inside the primary Product boundary is controlled using centralized accounts, two-factor authentication, and bastion hosts. We employ separation of duties between developers and operations staff to limit access to the Product environment to those with a legitimate business need. The Product is protected by a web application gateway and an outbound firewall with IdP. Data is encrypted in transit and at rest using encryption that meets the current NIST standard.<\/span><\/p><h4><span style=\"font-weight: 400;\">Access Provisioning and Review<\/span><\/h4><p><span style=\"font-weight: 400;\">We have a policy and process for creating new accounts, adding and removing permissions from existing accounts, and deprovisioning access upon separation. Required approvals are collected from supervisors and application \/ group owners to ensure that requests are reviewed for appropriateness by multiple leaders before permissions are granted. In addition, we conduct a quarterly two-phase access review that engages both supervisors and group owners. GPTW employee permissions related to the Product that grant access to customer data are included in this access provisioning and review process. The Product provides customers with real-time information about the user accounts they have created and gives them the ability to change or revoke access at any time. Customers are responsible for managing access to the platform by creating and revoking user accounts.<\/span><\/p><h4><span style=\"font-weight: 400;\">Endpoint Security<\/span><\/h4><p><span style=\"font-weight: 400;\">Our employee endpoints (laptops and mobile devices) are connected to endpoint management software. In order to sign on to any GPTW SSO protected resource (including the Product), an employee must be using a device registered in our endpoint management software that meets our compliance policy. The compliance policy is designed to ensure that a device meets our standards for minimum operating system version, hard drive encryption, secure boot\/anti-rooting, firewall enablement, anti-virus, etc. Users and administrators are notified when a device is out of compliance. Non-compliant devices are automatically blocked from accessing company resources once the compliance grace period expires.<\/span><\/p><h4><span style=\"font-weight: 400;\">Vulnerability Management<\/span><\/h4><p><span style=\"font-weight: 400;\">Our employee endpoints (laptops and mobile devices) as well as servers in the Product environment are connected to vulnerability management software. We actively scan for vulnerabilities and have a vulnerability management policy and procedure designed to limit the number of known vulnerabilities and number of exposed devices, according to the severity of the vulnerability. We have periodic vulnerability management meetings to review current remediation status, plan future remediations, manage exceptions and accepted risk, and review aged vulnerabilities as time passes and the technical landscape evolves. On laptops and mobile devices, we automatically update critical software (operating systems, browsers, productivity software). Inside the Product environment, we periodically update minor versions of operating systems, databases, and other critical software through our change management process following validation in pre-production environments.<\/span><\/p><h4><span style=\"font-weight: 400;\">Backup and Disaster Recovery<\/span><\/h4><p><span style=\"font-weight: 400;\">The Product environment is periodically backed up. All persistent data is backed up with at least a 24 hour recovery point objective. Data that changes frequently is backed up more frequently (up to and including continuous backup). Backups are persisted to geo-redundant online storage at least every 24 hours to protect against the catastrophic failure of a given data center. The majority of our infrastructure is implemented using infrastructure as code. We have documentation and code allowing us to build a new Product environment in the event of a major disaster. We test our disaster recovery procedure annually.<\/span><\/p><h4><span style=\"font-weight: 400;\">Data Classification, Handling, and Labeling<\/span><\/h4><p><span style=\"font-weight: 400;\">We have a data classification, handling, and labeling policy. Data is classified according to its risk. Employees receive training on the policy and its practical implementation. We have a detailed list of all data artifacts related to or produced by the Product that explains their classification in detail.<\/span><\/p><h3><span style=\"font-weight: 400;\">Global Laws and Regulations<\/span><\/h3><p><span style=\"font-weight: 400;\">We commit to comply with all applicable laws and regulations including, but not limited to, the following outlined below.<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Personal Information Protection Law of the People&#8217;s Republic of China<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">General Data Protection Regulation (GDPR) European Union (EU)\u00a0<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">The PIPL\/GDPR is not limited to the Chinese\/EU. It applies to all organizations that target, collect, or use the personal data of any China\/EU resident and mandates organizations to:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Know what data they hold and have appropriate rights to use the data.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Be accountable and able to answer questions about what type of data they hold, and in some cases, delete data they no longer need.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Notify supervisory authorities of data breaches.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Use vendors that comply with the principles of the PIPL\/GDPR<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">GPTW is committed to compliance with the PIPL\/GDPR and all applicable laws.\u00a0\u00a0<\/span><\/p><h4><span style=\"font-weight: 400;\">International Transfers of Personal Information<\/span><\/h4><p><span style=\"font-weight: 400;\">GPTW operates globally and, as such, may process personal data worldwide to provide customer support; in connection with GPTW sub-processors, a list of which is available below and their own sub-processors, where applicable; and in connection with GPTW professional services.\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">The transfer of personal data from China to other countries is governed by the Personal Data Protection Law of the People&#8217;s Republic of China.<\/span><\/p><p><span style=\"font-weight: 400;\">If you require an amendment to include any new control or requirement, please contact privacy_cn@greatplacetowork.com.<\/span><\/p><h4><span style=\"font-weight: 400;\">Data Processing<\/span><\/h4><p><span style=\"font-weight: 400;\">As part of providing the Product to you, we currently engage the following sub-processors:<\/span><\/p><table><tbody><tr><td><p><b>Name<\/b><\/p><\/td><td><p><b>Website<\/b><\/p><\/td><td><p><b>Details<\/b><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Alibaba<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">https:\/\/www.alibabacloud.com<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Provides the hosting environment and software development tools for the Product.<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Integral Tech for Business Management<\/span><\/p><\/td><td><p><a href=\"https:\/\/htecgroup.com\/\"><span style=\"font-weight: 400;\">https:\/\/itbm.mx\/<\/span><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">Provides software engineering and operational support services for the Product.<\/span><\/p><\/td><\/tr><\/tbody><\/table><h4>\u00a0<\/h4><h4><span style=\"font-weight: 400;\">Data Subject Rights<\/span><\/h4><p><span style=\"font-weight: 400;\">If you have a question or request concerning personal information held by GPTW, including your personal information collected through the use of the Product please email privacy_cn@greatplacetowork.com.\u00a0 To protect your privacy and security, we may take reasonable steps to verify your identity before responding to your request.\u00a0 We will respond to your request within a reasonable timeframe and as otherwise required by applicable law in your location.<\/span><\/p><h3><span style=\"font-weight: 400;\">Updates To Our Global Privacy &amp; Security Notice<\/span><\/h3><p><span style=\"font-weight: 400;\">GPTW reserves the right to update or change portions of this statement at any time and without prior notice. If we change or update this statement in a material way, we will process new personal information received under this Global Privacy &amp; Security Notice according to the terms of this Notice, unless you consent otherwise.<\/span><\/p><h3><span style=\"font-weight: 400;\">How To Contact GPTW<\/span><\/h3><p><span style=\"font-weight: 400;\">If you have any questions or comments about this Global Privacy &amp; Security Notice, GPTW\u2019s\u00a0 privacy practices or if you would like us to update information or preferences you provided to us, please e-mail us at: privacy_cn@greatplacetowork.com<\/span><\/p><p><span style=\"font-weight: 400;\">Written responses may also be submitted to:<\/span><\/p><p><i><span style=\"font-weight: 400;\">General Counsel<\/span><\/i><i><span style=\"font-weight: 400;\"><br \/><\/span><\/i><span style=\"font-weight: 400;\">Great Place To Work\u00ae Shanghai<\/span><span style=\"font-weight: 400;\"><br \/><\/span><span style=\"font-weight: 400;\">(Add Address )<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Great Place To Work China Privacy &amp; Security Notice Scope This Privacy &amp; Security Notice describes Great Place To Work Hong Kong (hereafter the \u201cGPTW\u201d) privacy practices in connection with: Our websites and subpages located at https:\/\/www.greatplacetowork.cn and https:\/\/www.greatplacetowork.hk\u00a0 (hereafter the \u201cSites\u201d) Our products and services This Privacy &amp; Security Notice does not cover GPTW\u2019s [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"site-sidebar-layout":"no-sidebar","site-content-layout":"page-builder","ast-site-content-layout":"full-width-container","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"disabled","ast-breadcrumbs-content":"","ast-featured-img":"disabled","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[],"class_list":["post-14800","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Privacy Policy - GPTW Greater China<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Privacy Policy - GPTW Greater China\" \/>\n<meta property=\"og:description\" content=\"Great Place To Work China Privacy &amp; Security Notice Scope This Privacy &amp; Security Notice describes Great Place To Work Hong Kong (hereafter the \u201cGPTW\u201d) privacy practices in connection with: Our websites and subpages located at https:\/\/www.greatplacetowork.cn and https:\/\/www.greatplacetowork.hk\u00a0 (hereafter the \u201cSites\u201d) Our products and services This Privacy &amp; Security Notice does not cover GPTW\u2019s [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"GPTW Greater China\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/GreatPlaceToWorkInGreaterChina\/\" \/>\n<meta property=\"article:modified_time\" content=\"2023-11-09T17:57:31+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"17 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/\",\"url\":\"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/\",\"name\":\"Privacy Policy - GPTW Greater China\",\"isPartOf\":{\"@id\":\"https:\/\/greatplacetowork.com.hk\/ch\/#website\"},\"datePublished\":\"2023-11-09T17:55:49+00:00\",\"dateModified\":\"2023-11-09T17:57:31+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u4e3b\u9801\",\"item\":\"https:\/\/greatplacetowork.com.hk\/ch\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Privacy Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/greatplacetowork.com.hk\/ch\/#website\",\"url\":\"https:\/\/greatplacetowork.com.hk\/ch\/\",\"name\":\"GPTW Greater China\",\"description\":\"Great Place to Work\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/greatplacetowork.com.hk\/ch\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Privacy Policy - GPTW Greater China","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/","og_locale":"en_US","og_type":"article","og_title":"Privacy Policy - GPTW Greater China","og_description":"Great Place To Work China Privacy &amp; Security Notice Scope This Privacy &amp; Security Notice describes Great Place To Work Hong Kong (hereafter the \u201cGPTW\u201d) privacy practices in connection with: Our websites and subpages located at https:\/\/www.greatplacetowork.cn and https:\/\/www.greatplacetowork.hk\u00a0 (hereafter the \u201cSites\u201d) Our products and services This Privacy &amp; Security Notice does not cover GPTW\u2019s [&hellip;]","og_url":"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/","og_site_name":"GPTW Greater China","article_publisher":"https:\/\/www.facebook.com\/GreatPlaceToWorkInGreaterChina\/","article_modified_time":"2023-11-09T17:57:31+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/","url":"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/","name":"Privacy Policy - GPTW Greater China","isPartOf":{"@id":"https:\/\/greatplacetowork.com.hk\/ch\/#website"},"datePublished":"2023-11-09T17:55:49+00:00","dateModified":"2023-11-09T17:57:31+00:00","breadcrumb":{"@id":"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/greatplacetowork.com.hk\/ch\/privacy-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u4e3b\u9801","item":"https:\/\/greatplacetowork.com.hk\/ch\/"},{"@type":"ListItem","position":2,"name":"Privacy Policy"}]},{"@type":"WebSite","@id":"https:\/\/greatplacetowork.com.hk\/ch\/#website","url":"https:\/\/greatplacetowork.com.hk\/ch\/","name":"GPTW Greater China","description":"Great Place to Work","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/greatplacetowork.com.hk\/ch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/greatplacetowork.com.hk\/ch\/wp-json\/wp\/v2\/pages\/14800","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/greatplacetowork.com.hk\/ch\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/greatplacetowork.com.hk\/ch\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/greatplacetowork.com.hk\/ch\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/greatplacetowork.com.hk\/ch\/wp-json\/wp\/v2\/comments?post=14800"}],"version-history":[{"count":3,"href":"https:\/\/greatplacetowork.com.hk\/ch\/wp-json\/wp\/v2\/pages\/14800\/revisions"}],"predecessor-version":[{"id":14803,"href":"https:\/\/greatplacetowork.com.hk\/ch\/wp-json\/wp\/v2\/pages\/14800\/revisions\/14803"}],"wp:attachment":[{"href":"https:\/\/greatplacetowork.com.hk\/ch\/wp-json\/wp\/v2\/media?parent=14800"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/greatplacetowork.com.hk\/ch\/wp-json\/wp\/v2\/categories?post=14800"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}