Privacy Policy for ProjectSoar-af.org
Project SOAR, a project of Achievement Foundation (“Project SOAR”, “we”, “our” or “us”), is committed to protecting the privacy of website visitors, service users, parents, guardians, children, volunteers, donors, partners, and other individuals who interact with us through ProjectSoar-af.org. This Privacy Policy explains how personal data is collected, used, stored, disclosed, and protected in connection with our website, programmes, services, events, and communications, in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (“PDPO”)
By using ProjectSoar-af.org, users agree to the collection and use of information in accordance with this Privacy Policy, to the extent permitted by applicable law. If a user does not agree with this policy, they should not use the website or submit personal information through it.
1. Scope
This Privacy Policy applies to personal data collected through this Website, online forms, event registration pages, email communications, enquiries, volunteer applications, donation-related communications, programme applications, and other interactions relating to Project SOAR.
This Policy also applies to personal data relating to children submitted by parents, guardians, schools, social workers, or other authorised persons for the purposes of programme participation, assessment, administration, and follow-up support.
2. Personal Data Collected
Depending on the nature of the interaction, Project SOAR may collect the following categories of personal data:
- identity information, including name, age, gender, and relationship to the child;
- contact information, including telephone number, email address, postal address, school name, and emergency contact details;
- child-related information, including developmental background, learning needs, emotional or social concerns, behavioural information, special educational needs-related information, and information relevant to programme suitability, where applicable and necessary;
- parent or guardian information, including household contact details and information relevant to communication, arrangements, support, and consent;
- volunteer or applicant information, including educational background, experience, availability, interview records, and, where appropriate, information relating to child safeguarding;
- communication records, including enquiries submitted through forms, email correspondence, feedback, and complaint records;
- media records, including photographs, video recordings, or audio recordings taken during activities, workshops, training sessions, or other events, where any consent required by law has been obtained; and
- technical information, including IP address, browser type, device information, pages visited, referral pages, and usage analytics collected through cookies or similar technologies.
Project SOAR shall collect personal data only on a lawful and fair basis and only to the extent necessary and not excessive for the relevant purpose.
3. Purposes of Collection
Personal data may be collected and used for one or more of the following purposes:
- handling enquiries, applications, registrations, referrals, and requests for information;
- assessing suitability for participation in programmes, groups, workshops, consultations, training, or related services;
- communicating with parents, guardians, participants, volunteers, schools, and partners regarding programme arrangements, schedules, updates, and follow-up matters;
- providing services and activities for children, parents, schools, or the community;
- coordinating volunteers, facilitators, trainers, supervisors, and administrative support;
- conducting internal administration, record keeping, child safeguarding, service monitoring, quality assurance, and risk management;
- conducting programme evaluation, impact assessment, reporting, and research, provided that data used for publication or external reporting may, where appropriate, be anonymised or aggregated;
- handling donations, sponsorship-related communications, partnership coordination, and stakeholder engagement, where applicable; and
- complying with legal, regulatory, safeguarding, insurance, governance, and accountability requirements.
Where personal data is intended to be used for a new purpose not directly related to the original purpose of collection, Project SOAR shall obtain such consent as may be required by applicable law or otherwise rely on another lawful basis for such use.
4. Children’s Privacy
Project SOAR recognises that personal data relating to children requires a higher degree of care, particularly where such data concerns emotional, behavioural, developmental, or special educational needs matters.
Where personal data relating to a child is collected through this Website or related forms, such data should generally be submitted by a parent, legal guardian, school, social worker, or other authorised adult for legitimate and service-related purposes.
Project SOAR does not seek to collect unnecessary personal data directly from children through general website browsing functions and shall take appropriate steps to ensure that only data relevant and necessary to the relevant service purpose is collected and retained.
5. Legal Basis and Consent
Where required, Project SOAR shall collect and use personal data on the basis of consent, explicit consent, or such other lawful and appropriate basis as may apply under applicable law.
In the case of sensitive child-related information, photographs, video recordings, testimonial materials, or any materials intended for use beyond core service administration, Project SOAR shall, where applicable, obtain the clear consent of the parent or legal guardian, unless otherwise permitted or required by law.
A data subject may choose not to provide certain personal data. However, failure to provide such data may affect Project SOAR’s ability to respond to enquiries, process applications, or provide relevant services.
6. Disclosure and Transfer
Project SOAR does not sell, rent, or trade personal data to third parties.
Personal data may be disclosed or transferred, on a need-to-know basis, to the following classes of persons:
- authorised staff, programme personnel, supervisors, and administrative support personnel involved in service delivery or website administration;
- volunteers, facilitators, consultants, or service providers who are subject to duties of confidentiality or contractual obligations, and only to the extent necessary for the discharge of their functions;
- partner schools, non-governmental organisations, professionals, funding bodies, insurers, or collaborating organisations, where such disclosure is necessary for programme coordination, child safeguarding, reporting, or administration, and only to the extent appropriate;
- service providers engaged to provide technical, hosting, analytics, form-processing, mailing, or information technology support on behalf of Project SOAR; and
- regulators, law enforcement agencies, courts, or other competent authorities where disclosure is required or permitted by law.
Where personal data is processed by third-party data processors on behalf of Project SOAR, contractual or other practicable means shall be adopted to ensure that such data is processed securely and only for authorised purposes.
7. Cookies and Analytics
ProjectSoar-af.org may use cookies and similar technologies for the purposes of improving website functionality, understanding website usage, analysing traffic, and supporting security and system performance.
Such technologies may collect technical and usage-related information, including device type, browser type, IP address, duration of visit, pages viewed, and referral pages.
Users may manage or disable cookies through their browser settings. However, doing so may affect the proper functioning of certain parts of this Website.
Where this Website uses third-party tools, including website analytics services, embedded video services, maps, donation platforms, or social media plugins, such third parties may collect data in accordance with their own privacy policies.
8. Direct Marketing
Where Project SOAR intends to use personal data for direct marketing purposes, including newsletters, programme updates, fundraising appeals, event promotion, or publicity materials, such use shall be carried out in accordance with the requirements of the Personal Data (Privacy) Ordinance, and the prescribed consent or indication of no objection of the data subject shall be obtained where applicable.
A data subject may, at any time and without charge, request that Project SOAR cease to use his or her personal data for direct marketing purposes.
Project SOAR shall not use personal data relating to children for direct marketing in any inappropriate or unfair manner.
9. Data Security
Project SOAR shall take all reasonable and practicable steps to safeguard personal data held by it against unauthorised or accidental access, processing, erasure, loss, or use, having regard to the nature of the data and the harm that could result from any improper use thereof.
Such measures may include access controls, password protection, secure cloud or storage arrangements, role-based access restrictions, confidentiality obligations, and administrative safeguards commensurate with the sensitivity of the data.
As data transmission over the internet cannot be guaranteed to be entirely secure, users should avoid transmitting unnecessary sensitive information through unsecured channels unless specifically requested through designated forms or appropriate procedures.
10. Retention
Personal data shall not be kept for longer than is necessary for the fulfilment of the purpose for which it is used, unless a longer retention period is required or permitted by law, or is necessary for child safeguarding, audit, funding, dispute handling, or lawful archival purposes.
Project SOAR shall review retained records from time to time and shall, where practicable, erase, anonymise, or securely destroy personal data which is no longer required.
11. Third-party Websites
This Website may contain links to websites, forms, resources, or platforms operated by third parties.
Project SOAR accepts no responsibility or liability for the privacy arrangements, security measures, or content of such third-party websites. Users should review the privacy policies and relevant terms of such websites before submitting any personal data to them.
12. Data Breach Handling
Notwithstanding the security measures in place, no system can completely eliminate data security risks. In the event of an actual or suspected personal data breach, Project SOAR shall assess the incident as soon as practicable and take such remedial action as may be appropriate in the circumstances.
Such action may, where necessary, include containment, internal investigation, record keeping, notification to affected persons, and reporting to the Office of the Privacy Commissioner for Personal Data or other relevant authorities, as appropriate.
13. Access and Correction Rights
Under the Personal Data (Privacy) Ordinance, a data subject has the right to request access to personal data held by Project SOAR about him or her, and to request correction of any personal data that is inaccurate, subject to applicable legal exemptions and procedural requirements.
Where personal data relating to a child is concerned, any such request should generally be made by a parent, legal guardian, or other person lawfully authorised to act on behalf of the child.
Requests for access, correction, withdrawal of consent, or other privacy-related enquiries may be made through the following contact:
Data Protection Contact
Project SOAR / Achievement Foundation
Email: info@projectsoar-af.org
Phone: +852 2463 3231
Address: Room 3, 8/F, Kingsford Industrial Centre, No.13 Wang Hoi Road, Kowloon Bay, Kowloon, Hong Kong
Project SOAR may take reasonable steps to verify the identity of the applicant before processing any such request.
14. Policy Updates
Project SOAR may amend this Privacy Policy from time to time to reflect changes in legal requirements, website functions, operational arrangements, or programme content.
Any revised version shall be published on ProjectSoar-af.org and shall state the effective date or last updated date. To the extent permitted by law, continued use of this Website after such update may be treated as acceptance of the revised Privacy Policy.
Effective Date: 25 July 2026
Last Updated: 25 July 2026
