This website is designed to be accessible for both visually impaired students and the general public. Visitors can adjust the font size, background color, brightness, and contrast according to their individual needs.
Privacy Policy Statement of Little Dreams Free Learning Space
This Privacy Policy Statement (this “Statement”) applies to all departments, service units and volunteer projects of Little Dreams Free Learning Space (English name: Little Dreams Free Learning Space, hereinafter referred to as “the Organisation”). The term “we” as used herein refers, depending on the context, to the Organisation or its relevant departments and service units.
1.1 The Organisation respects personal privacy. Every employee and volunteer takes the protection of personal data privacy as their own responsibility. As a data user, the Organisation fully implements and complies with the six Data Protection Principles set out in the Personal Data (Privacy) Ordinance (Cap. 486) (the “Ordinance”) and all relevant provisions of the Ordinance.
1.2 We ensure that all personal data collected, held, processed, used, retained, disclosed, transferred, secured and accessed are strictly handled in accordance with the duties and requirements stipulated in the Ordinance.
Depending on different service recipients and operational needs, the Organisation holds the following categories of personal data:
2.1 Student / Service User Data: including the names, Hong Kong Identity Card numbers, contact telephone numbers, email addresses, correspondence addresses, schools and grades attended, academic performance information, proof of financial status (including Comprehensive Social Security Assistance (CSSA) supporting documents) of students applying for free tutoring services and their parents/guardians.
2.2 Volunteer Tutor / Volunteer Data: including the names, Hong Kong Identity Card numbers, contact details, educational qualifications and professional credentials (including proof of a bachelor’s degree or above), Sexual Conviction Record Check (SCRC) results, Certificate of No Criminal Conviction (CNCC) results, as well as service records, training records and attendance hours of volunteer tutor applicants.
2.3 Donor Records: including the names, contact details, donation amounts and methods, bank or credit card information of individuals who make monetary or in-kind donations to the Organisation, for the purpose of administering donations.
2.4 Board Member and Member Records: including application information, fee payment records, and meeting attendance records of the Organisation’s corporate members and individual members.
2.5 Employee and Job Applicant Records: including personal data of the Organisation’s employees and job applicants for human resources management purposes.
2.6 Website Visitor Records: The Organisation’s service providers may record the domain name server addresses of website visitors and the pages visited, but such records do not involve the visitor’s personal data and are used only for statistical purposes.
3.1 The main purposes for which the Organisation collects and holds personal data are as follows:
(a) Provision of Free Tutoring Services: processing and assessing applications for free tutoring services, including verifying the applicant’s financial hardship status (e.g., verifying the authenticity of CSSA proof with the Social Welfare Department), matching suitable volunteer tutors to service users, following up on service progress and evaluating service effectiveness.
(b) Volunteer Tutor Management: processing volunteer tutor applications and selection, conducting Sexual Conviction Record Checks and Certificate of No Criminal Conviction checks, arranging training and service matching, recording service hours and providing service certifications.
(c) Donation Administration: handling donation administration, including issuing donation receipts, sending acknowledgement letters, recording donation information, and processing matters related to tax deduction applications.
(d) Membership and Organisational Affairs Management: processing membership applications, collecting membership fees, arranging meetings and activities, and maintaining contact with members.
(e) Promotion and Publicity: sending the Organisation’s service information, event invitations, newsletters and fundraising appeals to service users, donors, members and volunteers (see direct marketing arrangements in Chapter 5).
(f) Internal Administration and Research: conducting service statistics, research and surveys to improve service quality and assess social impact.
3.2 The Organisation will not use or provide personal data to third parties for purposes unrelated to the Organisation’s objects, nor will it sell or transfer personal data to other organisations for commercial purposes without the explicit consent of the data subject.
4.1 The Organisation takes practicable steps to ensure that the personal data it holds is accurate and is not kept longer than is necessary for the fulfilment of the purpose for which it is used.
4.2 The general retention periods for various types of personal data are as follows:
(a) Data of successful service applicants (students): retained for no more than seven years after the termination of the service relationship, for follow-up purposes and handling enquiries.
(b) Data of unsuccessful service applicants: retained for no more than six months after notification of the application result, and then securely destroyed.
(c) Volunteer tutor data: retained for no more than two years after the termination of the service relationship. If a volunteer tutor application is unsuccessful, the personal data (including SCRC and CNCC results) will be securely destroyed within no more than six months after completion of the selection process.
(d) Donor records: In accordance with the relevant provisions of the Inland Revenue Ordinance, donation receipts and related records must be kept for no less than seven years to comply with tax deduction audit requirements.
(e) Data of unsuccessful job applicants: retained for no more than two years after completion of the recruitment process, and then securely destroyed.
4.3 When personal data is no longer required for the purpose for which it was originally collected, the Organisation ensures that the data is permanently deleted or anonymised in a secure manner, so that the data no longer identifies the individual.
5.1 The Organisation intends to use the personal data (including names, telephone numbers, email addresses and correspondence addresses) of service users, donors, members and volunteers for direct marketing purposes, including but not limited to: sending the Organisation’s service information, event invitations, volunteer recruitment appeals, donation appeals and newsletters.
5.2 Pursuant to section 35C of the Ordinance, before using personal data for direct marketing, the Organisation must:
(a) Provide prior notice: inform the data subject that the Organisation intends to use his/her personal data for direct marketing;
(b) Obtain consent: provide a clear channel for the data subject to indicate whether he/she consents;
(c) Provide information: clearly state the type of personal data to be used and the class of services/activities to be marketed;
(d) Provide an opt-out channel: provide a free channel for the data subject to request, at any time, to stop the use of his/her personal data for direct marketing.
5.3 If a data subject does not wish to receive direct marketing information, he/she may at any time and free of charge notify the Organisation in writing to request the cessation of the use of his/her personal data for direct marketing purposes. Upon receipt of such request, the Organisation will immediately cease such use.
5.4 If the Organisation intends to provide personal data to a third party for direct marketing purposes, it must first obtain the data subject’s written consent and strictly comply with the relevant requirements of sections 35J to 35L of the Ordinance.
6.1 The Organisation takes all practicable steps to protect personal data against unauthorised or accidental access, processing, deletion, loss or use.
6.2 Specific security measures include:
(a) Access control: only authorised employees and designated personnel may access personal data, and access rights are limited to what is strictly necessary for the performance of their duties.
(b) Data encryption: all personal data transmitted or stored electronically is protected using industrystandard encryption technology.
(c) Physical security: personal data stored in hard copy is kept in locked storage facilities, and unauthorised persons are not permitted to enter the relevant storage areas.
(d) Information technology security: the Organisation’s computer systems and networks are equipped with firewalls, antivirus software and other security measures to prevent malicious software and unauthorised access.
(e) Staff training: the Organisation provides regular training on personal data privacy protection to employees and volunteers to ensure they understand and comply with relevant requirements.
6.3 If the Organisation engages thirdparty service providers to process personal data (e.g., cloud storage services, data processing services), the Organisation takes appropriate contractual measures to ensure that such service providers comply with data security standards at least equivalent to those of the Organisation.
7.1 The Organisation may disclose or transfer personal data to third parties in the following limited circumstances:
(a) To verify the authenticity of CSSA supporting documents by checking the applicant’s financial status information with the Social Welfare Department (or relevant government authorities);
(b) To conduct Sexual Conviction Record Checks and Certificate of No Criminal Conviction checks by submitting the relevant personal data of volunteer tutor applicants to the Hong Kong Police Force;
(c) To handle tax deduction matters related to donations by submitting the relevant donation records of donors to the Inland Revenue Department;
(d) To conduct service research and evaluation by providing anonymised statistical data to academic or research institutions engaged by the Organisation;
(e) To comply with any legal or regulatory requirements or court orders.
7.2 Except for the above circumstances, the Organisation will not disclose or transfer personal data to any third party without the prior consent of the data subject. All personal data collected by the Organisation is kept strictly confidential.
8.1 Under section 18 and section 22 of the Ordinance, data subjects have the right to request access to and correction of their personal data held by the Organisation.
8.2 Data subjects wishing to access or correct their personal data should submit their request in writing to the Organisation and provide sufficient information to verify their identity.
8.3 The Organisation will respond to a data access request within 40 days of its receipt, in accordance with section 19 of the Ordinance.
8.4 Except where explicitly permitted by section 28 of the Ordinance, the Organisation will not charge any fee for complying with or refusing to comply with a data access request or a data correction request.
8.5 If the Organisation refuses to comply with a data access request or a data correction request by reason of an applicable exemption, the Organisation will record the reasons for the refusal and keep such record for no less than four years in accordance with section 27 of the Ordinance.
9.1 The Organisation’s website may use “cookies” technology. Cookies are small text files stored on a visitor’s computer hard drive by the website, used to record the visitor’s browsing preferences and improve the website experience.
9.2 The cookies used by the Organisation do not collect personal data that identifies individual visitors. If cookies involve the collection of personal data, the Organisation will provide a clear Personal Information Collection Statement and obtain the visitor’s informed consent before collection.
9.3 Visitors may refuse to accept cookies by adjusting their browser settings, but this may cause some functions of the Organisation’s website to operate improperly.
10.1 The Organisation has taken all reasonable and practicable steps to protect the security of personal data. However, due to the nature of the Internet, it is impossible to guarantee that the security of data transmission over the Internet will be absolutely free from interference. The Organisation shall not be liable for any data leakage or loss arising from circumstances beyond its reasonable control, including but not limited to hacking attacks, computer virus intrusion, telecommunications network failures, etc.
11.1 The Organisation reserves the right to update or amend this Privacy Policy Statement at any time. Any updated version will be published on the Organisation’s website (if any) or made available upon request.
11.2 In the event of material amendments, the Organisation will notify data subjects by appropriate means (e.g., email notification or website announcement).
For any enquiries regarding this Privacy Policy Statement, or to request access to, correction of, or deletion of personal data, or to request the cessation of use of personal data for direct marketing purposes, please contact in writing:
Little Dreams Free Learning Space
Email address: hello@littledreams.org.hk
(This Privacy Policy Statement was last updated on 9 June 2026.)