In case of any discrepancy between the Chinese and English versions, the Chinese version shall prevail.
The following declarations must be made to you in accordance with the "Personal Data Protection Act".
Welcome to use the related services provided by Simple Information, Inc. (hereinafter referred to as "the Company"). According to Article 8, Paragraph 1 of the Personal Data Protection Act (hereinafter referred to as "PDPA"), to ensure the protection of users' personal data, privacy, and rights, when you have read and agreed to the "Simple Information, Inc. Privacy Policy", it indicates that you are willing to exercise the rights of consent granted by law.
I. Purpose of Personal Data Collection
- The collection of personal data in this industry includes activities related to information, communication, telecommunications, computer system design, data processing, and data supply services.
- The above-related business activities or other work within the scope defined by business items.
II. Categories of Personal Data Collection
Identification categories (for example: Chinese and English names, national ID number, identification codes, contact phone numbers, addresses, email addresses, bank account numbers and account names, other identification numbers).
III. Period, Area, Parties, and Method of Using Personal Data
- Period of Use: The retention period necessary for the Company or business operations.
- Scope of Use: Your personal data will be used in areas where the Company provides services.
- Units of Use: The Company, cooperative promotion units, business-related institutions, and legally authorized investigation agencies or financial supervisory authorities.
- Methods of Use: Electronic documents, paper documents, or automated machines or other non-automated methods.
IV. Rights Granted by the Personal Data Protection Act
According to Article 3 of the PDPA, you may exercise the following rights regarding your personal data held by the Company:
- Rights to inquiry, review, copy, supplement, correction, request to cease collection, request to cease processing, request to cease use, and request for deletion.
- Regarding the methods of data provision, processing period, inquiry fees, and payment deadline for users exercising the above rights, all shall be handled in accordance with laws, the Company's business regulations, and service contract provisions. Necessary cost fees may be charged. However, the Company may decline customer applications based on considerations such as necessary business operations and legal retention periods according to Articles 10 and 11 of the Personal Data Protection Act.
V. Personal Data Protection Measures
The Company has implemented the following necessary measures for personal data protection:
- Allocation of management personnel and adequate resources
- Definition of personal data scope
- Risk assessment and management mechanisms for personal data
- Incident prevention, notification, and response mechanisms
- Internal management procedures for personal data collection, processing, and utilization
- Data security management and personnel management
- Awareness promotion and education training
- Equipment security management
- Data security audit mechanisms
- Usage records, tracking data, and evidence preservation
- Overall continuous improvement of personal data security maintenance
