Klaire M.D. Co., Ltd. (“the company”) welcomes every website user into the website under the company’s management. This website will provide the users’ information, news, and various articles under terms and conditions.
Terms and conditions
1. Types of personal data
• Personal data means any information relating to a person, which enables the identification of such person, whether directly or indirectly, but not including the information of the deceased persons in particular. The personal data are listed as follows:
o General personal data means personal information, contact information, accessories/devices information, registration numbers that identify the specific ownership, and including information or anything that presented in the form of documents, files, reports, books, diagrams, drawings, photos, video recordings or sound recordings via electronic devices, or any other mean that will present the recorded contents relevant to personal information that enables the identification of a person.
o Sensitive personal data means personal data relating to race, ethnic, sexual behavior, criminal history, health information (medical history, blood test result, medical examination result), disability, genetic data, biometric data, facial, retinal, or fingerprint recognition, or any other information that Personal Data Protection Committee prescribed and classified as sensitive personal data under personal data protection laws.
2. Purposes of collection, use, or disclosure of personal data
• To provide suitable services for users’ needs. The company will use users’ personal data to provide services that satisfy the users’ contractual purposes or respond to the users’ requests as follows: product order, product delivery.
• To comply with legal obligations in compliance with the relevant laws, i.e., securities and exchange laws, tax laws, anti-money laundering laws, computer laws, and bankruptcy law. The company collects, uses, and discloses personal data such as patient information, etc. Additionally, the company has the responsibility to follow the orders of agencies or legal authorities. The company may also need to cooperate with relevant foreign agencies in providing information.
• For legitimate interests of the company, other persons or legal persons such as
o The security measures. The company records CCTV at the entrances and areas within the company.
o Customer relations include providing services to users, complaint management, satisfactory assessment, user attendance by the company’s staff, occasional communication or presentation of the services that are beneficial to users.
o The risk management, supervision, internal organization, and prevention of illegal conduct such as corruption, cyberbullying, money laundering, and other laws.
o The personal data safety measures such as data anonymization.
o For the business purpose. The company collects personal information for data retention, statistical analysis of data, or the company’s publicity such as video or sound recordings, etc.
• For the benefits of users when using products and services that the users have consented such as to provide users with better services and more suitable for the users’ needs, to provide the users with offers, special privileges, suggestions, and news, including opportunities to join special activities, etc.
3. Sources of personal data
• Directly from users such as information the users’ input during the service registration, medical records, or the information received during the communication between users and the company or the company’s staffs, information from the use of the company’s services, contacts, visits, website searches, call center and other channels provided by the company, and including the information from activity participations.
• Tracking technology when the customers use the company’s website and application.
• Affiliated companies.
• Third-party such as:
o Governmental agencies
o Financial institutes
o Representatives, agents, and other brokers
o Business partners
o Information providers
o Social media platforms and advertisers.
The sources mentioned above are solely to update the users’ personal data to be present and improve the company’s services into better quality and efficiency.
4. Period of data collection and retention
5. Disclosure of personal data
The company will not disclose personal data to any person without prior consent from the users. Nevertheless, the users acknowledge and accept that for the efficiency of service providing or legal compliance, the company may disclose the users’ personal data to the following persons:
o Affiliated companies
o The company’s staffs
o Domestic and foreign data processing providers
o Agencies or legal authorities
Moreover, the company may have to disclose the users’ personal data to comply with the law, such as disclosing to governmental agencies, state organization, supervising authorities of the servicers or the supervising authorities of the users, and including the requests to disclose the data as stipulated by the laws, i.e., the information request for filing the litigations or legal proceedings, or the request from private organizations or other third parties relating to the legal procedures, or the request to forward the patient information to the Department of Health Service Support, Ministry of Public Health, and including the cases where it is appropriate and necessary to enforce the company’s terms and conditions. The disclosure may also take place during the organization restructure, the company mergers or acquisitions where the company may transfer all or part of users’ personal data that the company collected to the relevant companies.
6. Sending or transferring personal data to foreign countries
The company may transmit or transfer personal data collected, used, or disclosed to foreign countries. The destination countries or the international organizations that receive the personal data must have adequate personal data protection standards in coordination with the laws.
7. Rights of data subjects
Under the personal data protection law, you have the rights to proceed as follows:
Right to withdraw consent: If you have given consent, we will collect, use, or disclose your personal data whether you had consented before the date the personal data protection law was enforced or afterward. You have the right to withdraw your consent at any time.
Right to access: you have the right to access your personal data under our responsibility, request us to make a copy of the data for you, and request us to disclose how we retrieved your personal data.
Right to data portability: you have the right to receive your personal data if we can arrange such personal data to be in the format that is readable or commonly used by ways of automatic tools or equipment and can be used or disclosed by automated means. You also have the right to request us to send or transfer your personal data to other data controllers when it is possible to do so by automated means and receive your personal data, which we sent or transferred using such means to the other data controller directly unless it is impossible to do so because of the technical circumstances.
Right to object: you have the right to object to the collection, use, or disclosure of your personal data at any time, suppose that the collection, use, or disclosure of your personal data were proceeded necessarily with legitimate interests of us, other persons or legal persons without exceeding the scope you can reasonably expect or proceeding for the public interest obligations.
Right to erasure/destruction: you have the right to request us to delete, destroy or anonymize your personal data if you believe that your personal data had been collected, used, or disclosed without legitimate ground of relevant laws, or you think that we no longer need to store it for the purposes stated in this policy, or when you have exercised your right to withdraw consent or right to object.
Right to restriction of processing: you have the right to restrict the use of personal data temporarily when we are pending an examination process following your request to rectify your personal data or your objecting request. Or in other cases where the data is no longer necessary for us, and we have to delete or destroy it per relevant law, you request us to restrict its use instead.Right to rectification: you have the right to rectify your personal data to be accurate, up-to-date, complete, and does not cause a misunderstanding.
• Rectification or deletion of personal data: the users can rectify or delete the users’ personal data at any time. The users can request a form regarding personal data to fill in and send it back to the company through email: firstname.lastname@example.org . The deletion of data may prevent the users from using the company’s services or lessen the services’ efficiency.
Nonetheless, although the company has already proceeded with the users’ requests, there may be a record or copy of such data at the company’s server or backup system for data backup if there are errors, defects, or system failures.
• Request to access and obtain the electronic copy of personal data, request to disclose and transfer personal data to other persons by automatic means, request to restrict or suspend the use of personal data, or the rejection of data processing: the users can ask for the “form regarding the personal data” to fill in and send it back to the company via email email@example.com or call: 02-227 0600.
• Consent withdrawal: the users can withdraw the users’ consents given to the company regarding data processing or specific activities by contacting the company via email: firstname.lastname@example.org or call: 02-227 0600.
o If you no longer want to receive news via telephone: please inform us via email: email@example.com
o If you no longer want to receive news through email: the customers can click “unsubscribe from news” from within the email you received from the company immediately.
• Complaint lodging: the users have the right to make a complaint to the expert committee under the Personal Data Protection Act if the company or personal data processor including the staffs or employees of the company or data processor breach or do not comply with the Act or the announcement made under the Act.
8. Consequences of consent withdrawal
The data subjects may withdraw the consent to let the company collect, use, or disclose personal data as mentioned above by informing the company. The company may ask for reasons for such withdrawal.
The consent withdrawal of data subjects will not affect the collection, use, or disclosure of personal data that the data subjects had consented to prior.
In addition, before I gave my consent, I have read and understood the terms and conditions in disclosing personal data as stated explicitly above. I expressed my consent to be bound by following this term and condition, including all the future rules.
9. Report on the breach of personal data
If there is a breach of your personal data, we will promptly inform the Office of the Personal Data Protection Commission within 72 hours after we learned about the breach. Suppose the violation has a high risk that will affect your rights and freedom. In that case, we will inform you about the breach and the remedy thereof immediately through various channels such as website, SMS, email, phone number, or letter, etc.
10. Dispute resolution
In resolving any dispute arising from this company’s website, if the users encounter the problem or damages from any text, content, or service, and including the violation of rights or intellectual rights that appeared on the company’s website, the company has dispute resolution as follows:
10.1 The injured person must file the complaint in writing explicitly to the company’s staffs at the address below by stating the following details:
• Name, address, current address
• Current phone number/email
• Details on the complaints or the evidence regarding the illegal conduct (if any)
• Suggestion or recommendation or request that would like the company to proceed
10.2 You must proceed with such complaint filing or suggestion by contacting:
• M.D. Health and Beauty Co., Ltd.
• Phone number: 02-227 0600
• Email: firstname.lastname@example.org
After the company acknowledges the abovementioned complaints, the company will contact the relevant persons and inform the managing director or the delegation of the company and proceed with the resolution within 15 days from the date stated in your written complaint that contains the details as the company mentioned above. Pending the investigation, you agree to refrain from filing a case or waive your rights to file complaints in civil or criminal proceedings as the company needs time to examine and investigate the facts further.
The company reserves the right to edit, change, add, or remove any term or condition relating to this website with or without prior announcement to the website users. The company holds no responsibility towards any website user or person. If the website users continue using this website when there is any change, it will be deemed that they have already accepted such changes.Your use of this website has been deemed an acceptance and agreement to this term and condition of the website. Using this website in the future after a change or addition to this term and condition of the company’s website will assume that you have accepted the term and condition that have been amended.
Effective from 1 April 2021
Klaire M.D. Co., Ltd.