Privacy Policy
App Name: BSP
Developer: Beneficial Sino-Pass Service (Zhejiang) Co., Ltd.
1. Preface
This Privacy Policy (hereinafter referred to as “this Policy”) is entered into between Beneficial Sino-Pass Immigration Services (Zhejiang) Co., Ltd. (hereinafter referred to as the “Operator”) and users (hereinafter referred to as “users”) of Beneficial Sino-Pass APP (hereinafter referred to as “this APP”). It aims to clarify the scope and methods of the Operator’s collection, use, storage, disclosure, transfer and deletion of users’ personal data, as well as relevant rights and obligations. The Operator strictly complies with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) (hereinafter referred to as “PDPO”) and relevant data protection laws to protect the security of users’ personal data privacy.
A user’s downloading, installation, registration, login to this APP or use of any APP Service shall be deemed that the user has fully read, understood and voluntarily accepted all terms of this Policy and agreed to the Operator’s processing of their personal data in accordance with this Policy. If a user does not agree to any terms herein, the user shall immediately cease downloading, installing, registering for and using this APP and related services.
2. Definitions
2.1 Personal Data: refers to data relating to a living individual, whether true or not, from which it is practicable for the identity of the individual to be directly or indirectly ascertained, in accordance with the definition under PDPO, including but not limited to users’ identity information, contact information, immigration-related information, device information, usage records, etc.
2.2 Sensitive Personal Data: refers to personal data falling under sensitive categories as stipulated by PDPO, including but not limited to users’ Hong Kong identity card numbers, passport numbers, immigration records, biometric identification information (such as facial recognition images), health information, etc.
2.3 Data Processing: refers to all acts related to personal data, including collection, recording, storage, retention, access, use, disclosure, transfer, deletion, destruction, etc., in accordance with the definition under PDPO.
2.4 Data Subject: refers to the living individual to whom personal data relates, i.e., users of this APP.
3. How We Use Cookies and Similar Technologies
3.1 Cookies
To ensure the normal operation of the website, we will store small data files named Cookies on your computer or mobile device. Cookies usually contain identifiers, site names and some numbers and characters. With the help of Cookies, the website can store data such as your preferences or items in your shopping cart.
We will not use Cookies for any purposes other than those described in this Policy. You may manage or delete Cookies according to your own preferences. You can clear all Cookies stored on your computer, and most web browsers are equipped with a function to block Cookies. However, if you do so, you will need to manually change user settings every time you visit our website.
3.2 Web Beacons and Pixel Tags
In addition to Cookies, we also use other similar technologies such as web beacons and pixel tags on the website. For example, emails we send you may contain clickable URLs linking to our website content. If you click on such links, we will track the click to help us understand your product or service preferences and improve customer service. Web beacons are usually transparent images embedded in websites or emails. With the help of pixel tags in emails, we can know whether an email has been opened. If you do not want your activities to be tracked in this way, you may unsubscribe from our mailing list at any time.
3.3 Do Not Track
Many web browsers are equipped with a Do Not Track function, which can send Do Not Track requests to websites. At present, major Internet standard organizations have not formulated relevant policies to regulate how websites should respond to such requests. However, all our websites will respect your choice if your browser has Do Not Track enabled.
4. Collection of Personal Data
4.1 Scope of Collection
The Operator only collects necessary personal data from users for the purpose of providing APP Services, following the principles of “lawfulness, fairness, transparency and necessity”, and shall not collect personal data irrelevant to the services. The specific scope of collection is as follows:
(1) Identity Verification Data: Hong Kong identity card numbers, full names, genders, dates of birth, document images (Hong Kong identity cards, passports, etc.), facial recognition images and other information provided by users during registration, login and use of APP Services, for identity verification to ensure compliance and security of services and meet immigration administration requirements;
(2) Contact Information: Users’ mobile phone numbers, email addresses, etc., for sending verification codes, service notifications, consultation replies and other communications between the Operator and users;
(3) Immigration-Related Data: Passport numbers, Exit-Entry Permit numbers, endorsement information, travel destinations, travel dates and other information voluntarily provided by users when using services such as visa / endorsement application and immigration record inquiry, for processing relevant services;
(4) Device and Usage Records: Information automatically generated by devices when users use this APP, including but not limited to device models, operating system versions, IP addresses, browser types, usage time, duration of use, operation records, page browsing records, etc., for optimizing APP performance, improving service quality and ensuring system security;
(5) Other Voluntarily Provided Data: Relevant information (such as consultation content, suggestions and opinions) voluntarily provided by users when using online consultation, feedback and other services, for handling users’ inquiries and feedback.
4.2 Methods of Collection
4.2.1 Active Collection: Personal data actively filled in, uploaded and submitted by users during registration, login and use of APP Services;
4.2.2 Automatic Collection: Device information, usage records and other data automatically collected through devices and systems when users use this APP (such collection shall be notified to users in advance; users may disable relevant permissions through device settings, which may affect the normal use of some services);
4.2.3 Third-Party Collection: With users’ consent, collecting relevant user data from legitimate and compliant third-party institutions such as the Hong Kong Immigration Department and Hongkong Post Certification Authority for identity verification and service processing (data processing by third-party institutions shall comply with PDPO and relevant laws);
4.2.4 Collection of Sensitive Personal Data: When collecting sensitive personal data from users, the Operator shall separately obtain users’ explicit consent, clearly inform users of the purpose, use and scope of collecting such data. Users may voluntarily choose whether to provide such data; failure to provide sensitive personal data may result in unavailability of some services but shall not affect the use of other non-sensitive services.
4.3 Collection Notice
Before collecting users’ personal data, the Operator shall explicitly inform users of the types of personal data to be collected, collection purposes, scope of use and relevant rights via APP pop-ups, agreement prompts and other means. Collection of relevant personal data may only be conducted after users confirm their consent.
If the personal data provided by users is incomplete or inaccurate, the Operator reserves the right to require users to supplement or correct such data; otherwise, the Operator may be unable to provide corresponding APP Services to users.
5. Use of Personal Data
5.1 Purposes of Use
After collecting users’ personal data, the Operator shall only use such data for the following legitimate purposes and shall not exceed such scope:
(1) Provision of APP Services: including but not limited to identity verification, visa / endorsement application and appointment, immigration record inquiry, document status inquiry, online consultation, emergency assistance guidance, etc.;
(2) Service Quality Optimization: Optimizing APP functions, interface design and service processes based on users’ usage records and feedback to improve user experience;
(3) Security Assurance: Identifying abnormal account logins, preventing account theft, combating illegal and irregular activities, and ensuring the security of the APP system and users’ personal data;
(4) Service Notifications: Sending service-related notifications and reminders to users (such as appointment success notifications, document progress reminders, policy update notifications, etc.);
(5) Compliance Requirements: Providing users’ personal data in accordance with relevant Hong Kong laws, immigration administration requirements and instructions from law enforcement agencies;
(6) Other Purposes with Users’ Explicit Consent: Such as sending immigration-related information and promotional materials from the Operator with users’ consent (users may withdraw such consent at any time).
5.2 Restrictions on Use
5.2.1 When using users’ personal data, the Operator shall follow the principle of “minimum necessity” and only use personal data necessary to achieve service purposes, without exceeding the scope of such purposes;
5.2.2 Without users’ explicit consent, the Operator shall not use users’ personal data for purposes irrelevant to APP Services;
5.2.3 The Operator shall not use users’ sensitive personal data for non-core service purposes such as advertising and commercial marketing;
5.2.4 When using users’ personal data, the Operator shall take security measures such as encryption and anonymization to prevent disclosure, tampering and abuse of personal data.
6. Storage and Security of Personal Data
6.1 Storage Methods and Period
6.1.1 The Operator shall store users’ personal data on servers meeting relevant Hong Kong security standards, which are located within the Hong Kong Special Administrative Region (if transfer to regions outside Hong Kong is required, users shall be notified in advance and obtain their explicit consent, and the recipient shall be ensured to meet protection standards stipulated by PDPO and relevant laws).
6.1.2 The Operator shall store users’ personal data only for the shortest period necessary to achieve service purposes. Upon expiration, users’ personal data shall be deleted or anonymized in accordance with PDPO and relevant laws (except as required by laws and regulations to retain such data, e.g., data for compliance review and dispute resolution shall be retained for no longer than the period prescribed by law).
6.1.3 After a user cancels their APP account, the Operator shall delete or anonymize all of the user’s personal data within 15 working days (except as required by laws and regulations to retain such data).
6.2 Security Assurance Measures
The Operator strictly complies with PDPO and relevant data security laws and takes the following security assurance measures to protect the security of users’ personal data and prevent unauthorized access, disclosure, tampering and abuse of personal data:
(1) Technical Assurance: Adopting internationally recognized advanced encryption standards (such as HTTPS transmission encryption and data storage encryption) to encrypt users’ personal data; establishing a comprehensive system security protection system to guard against network attacks, virus intrusion and other security risks;
(2) Management Assurance: Establishing a strict personal data management system, clarifying permissions and procedures for data processing, imposing strict access control and privacy protection training on employees accessing users’ personal data, and signing confidentiality agreements;
(3) Compliance Assurance: Conducting regular compliance reviews of personal data processing processes to promptly identify and rectify security risks; complying with international standards ISO/IEC 27001 and ISO/IEC 27701 regarding information security management and privacy management to ensure personal data security;
(4) Emergency Response: Establishing an emergency response mechanism for personal data leakage. In the event of personal data leakage, loss or other circumstances, the Operator shall immediately take remedial measures and promptly notify users and the Office of the Privacy Commissioner for Personal Data (PCPD) in accordance with PDPO and relevant laws.
Users shall properly keep their APP account numbers, passwords, verification codes and relevant authentication information. Users shall bear all losses arising from personal data disclosure due to improper safekeeping by users themselves, and the Operator shall not be liable for compensation.
7. Disclosure and Transfer of Personal Data
7.1 Restrictions on Disclosure
Without users’ explicit consent, the Operator shall not disclose users’ personal data to any third party, except under the following circumstances:
(1) Requirements of Laws and Regulations: Disclosing users’ personal data in accordance with relevant Hong Kong laws, court judgments, rulings or instructions from law enforcement agencies (such as the Hong Kong Immigration Department, police, etc.);
(2) Service Necessity: Disclosing necessary user personal data to legitimate and compliant third-party service providers (such as technical support, payment services, identity verification institutions, etc.) for the completion of APP Services, provided that such third-party service providers sign confidentiality agreements and undertake to process users’ personal data in strict accordance with PDPO and relevant laws without using such data for other purposes;
(3) Protection of Rights and Interests: Disclosing necessary user personal data in emergency situations (such as preventing personal injury, property loss, combating illegal crimes, etc.) to protect the legitimate rights and interests of users, the Operator or third parties;
(4) User Consent: Disclosing users’ personal data to third parties with users’ explicit written or verifiable oral consent.
7.2 Restrictions on Transfer
7.2.1 The Operator shall not transfer users’ personal data to regions outside the Hong Kong Special Administrative Region unless the following conditions are met:
(1) Obtaining users’ explicit consent;
(2) The personal data protection standards of the recipient’s region meet the requirements of PDPO and relevant laws, or the Operator signs an agreement with the recipient to ensure that the recipient takes security assurance measures equivalent to those of the Operator to protect users’ personal data;
(3) Otherwise provided by laws and regulations.
7.2.2 If the Operator undergoes any change such as merger, division, acquisition or sale involving the transfer of users’ personal data, users shall be notified 7 working days in advance. The recipient shall be ensured to continue to abide by this Policy and PDPO provisions; otherwise, the transfer of users’ personal data shall not be conducted.
8. Users’ Personal Data Rights (Pursuant to PDPO)
In accordance with PDPO and relevant laws, users, as data subjects, shall enjoy the following personal data rights, and the Operator shall provide necessary assistance for users to exercise such rights:
8.1 Right of Access: Users shall have the right to inquire about their personal data from the Operator and understand the collection, use, storage, disclosure and other circumstances of such data. The Operator shall respond within 15 working days upon receipt of the inquiry application (complex cases may be extended to 30 working days with prior notice to users).
8.2 Right of Correction: If users find that their personal data is inaccurate or incomplete, they shall have the right to request the Operator to correct or supplement such data. The Operator shall complete the correction within 15 working days upon receipt of the correction application (complex cases may be extended to 30 working days with prior notice to users) and promptly notify users upon completion.
8.3 Right of Erasure: Users shall have the right to request the Operator to delete their personal data. The Operator shall complete the deletion within 15 working days upon receipt of the deletion application under any of the following circumstances:
(1) Personal data has exceeded the storage period necessary for service purposes;
(2) Users withdraw consent to the processing of personal data;
(3) The Operator processes users’ personal data in violation of this Policy or PDPO;
(4) Users cancel their APP accounts.
Note: The Operator may refuse to delete personal data required to be retained by laws and regulations, but shall inform users of the basis and period of retention.
8.4 Right to Withdraw Consent: Users shall have the right to withdraw consent to the processing of personal data (including collection and use of sensitive personal data) at any time. Upon withdrawal of consent, the Operator shall cease processing such personal data, without affecting lawful processing completed prior to the withdrawal or users’ use of other APP Services not requiring such personal data.
8.5 Right to Complaint: If users believe that the Operator’s personal data processing acts violate PDPO and this Policy and damage their legitimate rights and interests, users shall have the right to complain to the Operator or to the Office of the Privacy Commissioner for Personal Data (PCPD) in Hong Kong.
8.6 Methods of Exercising Rights: Users may submit applications for exercising rights through “Personal Center – Privacy Settings” in the APP or by contacting the Operator’s customer service. The Operator may require users to provide necessary authentication materials to ensure the legality and authenticity of the applications.
9. Privacy Notice for Third-Party Services
This APP may contain links to third-party services (such as payment services, map services, online consultation services, etc.). The personal data processing acts of third-party service providers are not governed by this Policy and shall be solely responsible by such third parties.
When using third-party services, users shall carefully read the privacy policies of such third parties and understand the relevant rules on third-party collection, use and storage of personal data. The Operator shall not be liable for privacy infringements by third-party service providers.
10. Data Processing for AI Services
10.1 To provide AI services, we may collect your questions, conversation content, usage records and other necessary information. We only process data to the minimum extent necessary for service provision.
10.2 We may use anonymized and de-identified data to improve AI models, algorithms and service quality. Personal identifiers will be removed before data is used for optimization.
10.3 AI-related data will be stored securely and retained only for a reasonable period necessary for service operation and legal compliance.
10.4 You may request to access, correct or delete your AI conversation data in accordance with applicable laws.
11. Youdao Translation SDK Service
11.1 When you use the translation function, you authorize this application to transmit your text, voice, images and device information (including Android ID) to Beijing NetEase Youdao Computer System Co., Ltd. for translation processing. You may refer to Youdao’s privacy policy for its data rules.
SDK Name: Image Translation Android SDK(com.youdao.sdk.ydonlinetranslate)
Organization: Beijing NetEase Youdao Computer System Co., Ltd.
Purpose: For user translation services
Types of personal information collected: Device information (OAID, Android ID), network type, device model, application information (application name, application version number)
Official website link or privacy protection statement: https://ai.youdao.com/DOCSIRMA/html/agreement/privacy/tpfy/index.html
12. Modification and Notification of the Privacy Policy
12.1 The Operator reserves the right to modify or supplement this Privacy Policy in accordance with PDPO and relevant laws, APP service optimization, adjustment of data processing methods and other needs.
12.2 The modified Privacy Policy shall be notified to users via APP pop-ups, notifications and other means. If users do not raise objections within 7 days from the date of receiving the notice, they shall be deemed to have accepted the modified Policy. If users do not agree to the modified Policy, they shall immediately cease using this APP and related services, this Policy shall terminate, and the Operator shall handle users’ personal data in accordance with the provisions hereof.
12.3 If modifications to this Privacy Policy involve users’ core rights (such as scope of personal data collection, purposes of use, disclosure methods, etc.), the Operator shall separately send notifications to users and obtain their explicit consent before such modifications take effect.
13. Disclaimer
13.1 The Operator shall not be liable for any disclosure, loss or tampering of users’ personal data caused by force majeure (including but not limited to earthquakes, typhoons, floods, fires, wars, network outages, system failures, etc.).
13.2 Any disclosure, loss or tampering of personal data caused by users’ own operational errors, equipment failures, network problems, third-party software interference, account theft and other reasons shall be borne by users themselves, and the Operator shall not be liable for compensation.
13.3 The Operator shall not be liable for any responsibilities arising from the disclosure of users’ personal data in accordance with PDPO and relevant laws, court judgments or instructions from law enforcement agencies, or the disclosure or transfer of personal data with users’ explicit consent.
13.4 The Operator shall not be jointly or severally liable for any disclosure, loss or tampering of users’ personal data caused by third-party service providers’ violation of relevant provisions. Users may pursue liabilities against such third-party service providers.
14. Dispute Resolution
14.1 The conclusion, performance, interpretation and dispute resolution of this Privacy Policy shall be governed by the laws of the Hong Kong Special Administrative Region of the People’s Republic of China.
14.2 Any dispute arising from this Privacy Policy between both parties shall be resolved through friendly negotiation first. If negotiation fails, either party may institute legal proceedings in the District Court of Hong Kong or apply for mediation to the Office of the Privacy Commissioner for Personal Data (PCPD) in Hong Kong.
15. Miscellaneous
15.1 This Privacy Policy is an appendix to the APP User Agreement and shall have the same legal effect as the User Agreement. Acceptance of the User Agreement by users shall constitute acceptance of this Privacy Policy.
15.2 The Operator’s customer service contact: support@cnbsp.com. Users may consult personal data-related questions, submit applications for exercising rights and provide feedback or complaints through this contact.
15.3 This Privacy Policy shall take effect on the date when users download, install, register for, log in to this APP or use any APP Service, and shall remain valid until the termination hereof.
Beneficial Sino-Pass Immigration Services (Zhejiang) Co., Ltd.
Date: 2026.04.23