We take your privacy seriously
당사는 귀하의 개인정보 보호를 매우 중요하게 생각합니다
개인정보 처리방침
발효일: 2026년 8월
SoftwareOne 및 그 계열사(이하 통칭하여 "SoftwareOne", "당사", "당사의")는 개인정보 보호를 최우선으로 생각합니다. 본 개인정보 처리방침은 어떠한 개인정보를 이용할 수 있는지, 이를 어떻게 활용하는지, 그리고 개인정보 보호 권리가 무엇인지 안내합니다.
처리하는 개인정보의 항목 및 방식은 당사와의 관계에 따라 달라집니다. 따라서 본 개인정보 처리방침의 특정 섹션은 적용되지 않을 수 있으며, 반대로 둘 이상의 섹션이 복합적으로 적용될 수도 있습니다.
고객을 대리하여 개인정보 수탁자(Data Processor)로서 개인정보를 처리하는 경우에는 본 개인정보 처리방침이 적용되지 않음을 유의하시기 바랍니다. 이러한 경우, 개인정보 처리는 당사와 고객[개인정보 처리자(Data Controller)] 간의 별도 계약에 따라 규율됩니다.
본 개인정보 처리방침에 당사가 운영하거나 통제하지 않는 제3자 웹사이트로 연결되는 링크가 포함되어 있는 경우, 해당 웹사이트에서 제공하는 개인정보의 처리에 대한 책임은 해당 웹사이트 제공업체에 있습니다. 이에 따라 해당 업체의 개인정보 처리방침을 확인하시는 것을 권장합니다. 이러한 제3자 웹사이트에서 개인정보가 이용 및 처리되는 방식을 통제할 수 없으며, 해당 제공업체의 개인정보 이용에 대해 책임을 지지 않습니다.
회사 소개
개인정보 처리에 책임을 지는 주체는 웹사이트 방문, 서비스 이용, 이벤트 신청 또는 채용 지원 등을 통해 관계를 수립한 SoftwareOne 법인[“개인정보 처리자(Data Controller)”]입니다. 각 SoftwareOne 법인에 대한 자세한 정보는 여기에서 확인할 수 있습니다.
개인정보를 수령할 때(직접 수집하거나 대리하는 회사 또는 기타 제3자로부터 제공받는 경우 일체), 이를 다음과 같은 목적 및 법적 근거에 따라 처리할 수 있습니다.
사용자 계정 생성 및 관리
웹사이트, 플랫폼, 애플리케이션 또는 기타 제품 및 서비스를 안전하게 액세스하고 활용하기 위해, 사용자 계정을 등록하고 유지해야 할 수 있습니다. 이러한 계정에 등록할 때와 해당 계정의 인증, 관리 및 유지 관리 과정에서 개인정보를 처리합니다.
웹사이트, 플랫폼, 애플리케이션 또는 기타 제품 및 서비스를 둘러보기 위해 데모 또는 평가판 계정을 생성하는 경우 개인정보를 수집할 수 있으며, 이를 통해 접근을 인증하고 임시 서비스 기능을 제공하며 이용량을 모니터링하고 데모 또는 평가판 계정에 관한 안내를 제공합니다.
웹사이트, 플랫폼, 애플리케이션 또는 기타 제품 및 서비스에서 개인정보 수집·처리 목적 및 방법을 설명하는 별도의 개인정보 처리방침을 안내하는 경우, 해당 방침을 참조하시기 바랍니다.
관련 개인정보 항목: 연락처 정보(예: 성명, 이메일, 전화번호, 직책, 회사명), 등록 일시, 로그인 정보, 이용 데이터, 활동 데이터.
해당 개인정보 처리를 위한 법적 근거는 체결한 계약의 이행이며, 이를 바탕으로 계정을 생성, 관리 및 유지합니다.
요청에 대한 응답
소통 및 채팅 기능, 문의 양식 또는 기타 수단을 통해 접수된 요청을 처리하기 위해 개인정보를 수집할 수 있습니다.
관련 개인정보 항목: 연락처 정보(예: 성명, 이메일, 전화번호, 직책, 회사명), 우편 주소, 국가, 요청 내용, 요청 일자 및 자발적으로 공개할 수 있는 기타 데이터.
해당 개인정보 처리를 위한 법적 근거는 해당되는 경우 법적 의무 또는 계약상 약속의 이행이며, 그렇지 않은 경우에는 상호작용을 관리하고 만족스러운 서비스 및 경험을 제공하려는 정당한 이익입니다.
게시물 및 댓글
웹사이트, 플랫폼, 애플리케이션 및 기타 제품·서비스에 게시물을 올리거나 댓글을 달 수 있습니다. 이러한 경우 작성한 콘텐츠는 공개적으로 액세스할 수 있습니다. 게시물 또는 댓글은 게시 전 수동 검토를 거칠 수 있으며, 이로 인해 실제 화면에 표시되기까지 지연이 발생할 수 있음을 유의하시기 바랍니다. 성명 또는 별칭을 제공하는 경우, 해당 이름은 게시물 또는 댓글 옆에 함께 게시됩니다.
관련 개인정보 항목: 성명 또는 별칭, 게시물 또는 댓글 내용, 등록 일시 및 자발적으로 공개할 수 있는 기타 데이터.
해당 개인정보 처리를 위한 법적 근거는 상호작용을 관리하고 제품 및 서비스를 개선하려는 정당한 이익입니다.
뉴스레터
뉴스레터에 가입할 수 있으며, 이를 통해 IT 산업의 최신 트렌드 및 주요 현황, 신제품 또는 서비스, 향후 개최될 이벤트, 특별 혜택 및 IT 의사 결정권자를 위한 중요한 일정에 대한 정보를 제공받을 수 있습니다.
가입 시 이메일 주소가 요구됩니다. 특정 지역의 경우, 가입 양식을 완료한 후 확인 이메일을 발송할 수 있습니다. 이러한 경우 확인 이메일에 포함된 링크를 클릭하기 전까지는 가입이 활성화되지 않습니다.
뉴스레터에 등록하는 경우, 뉴스레터에 개별 추적 기술을 포함할 수 있으며, 이를 통해 발송된 뉴스레터의 접근 또는 개봉 시점을 인식하고 뉴스레터 내의 링크를 개별화하여 어떤 링크를 언제 클릭했는지 확인할 수 있습니다.
언제든지 뉴스레터 수신을 거부할 수 있습니다. 서신의 마지막 부분에 있는 수신 거부 링크를 사용하거나, info.global@softwareone.com으로 이메일을 보내시면 됩니다.
관련 개인정보 항목: 연락처 정보(예: 성명, 이메일, 전화번호, 직책, 회사명), 국가, 참여 지표(예: 뉴스레터 개봉 여부, 개봉 일시, 뉴스레터 접근 횟수, 클릭한 링크).
개인정보 처리를 위한 법적 근거는 뉴스레터 수신에 대한 동의입니다.
마케팅
마케팅 목적으로, 잠재 고객을 포함하여 고객 또는 파트너를 대리하여 소통할 때 개인정보를 수집합니다. 또한 마케팅 서신에 사용할 목적으로 해당 정보를 공유할 수 있도록 법적으로 권한을 부여받은 검증된 제3자 제공업체로부터 개인정보를 수령할 수 있습니다. 관심을 가질 만한 향후 이벤트, 제품, 서비스 및 기타 혜택을 안내하는 것을 포함하되 이에 국한되지 않는 마케팅 목적으로 해당 개인정보를 처리합니다.
추가로, IP 주소 데이터와 이메일 개봉 및 링크 클릭과 같은 참여 지표를 자동으로 수집하기 위해 개별 추적 기술을 사용할 수 있으며, 이는 성과를 모니터링하고 마케팅 활동의 관련성 및 효과성을 향상시키는 데 활용됩니다.
관련 개인정보 항목: 연락처 정보(예: 성명, 이메일, 전화번호, 직책, 회사명) 및 제공하는 기타 모든 데이터.
개인정보 처리를 위한 법적 근거는 동의 또는 마케팅 서신을 발송하려는 정당한 이익입니다.
라이선스 및 기술 사용 분석
고객과의 상업적 관계 맥락에서, 관계의 전체 라이프사이클에 걸쳐 고객의 요구사항을 깊이 이해하고 관리하며 지원하기 위해 소프트웨어 라이선스 및 기술 사용 환경과 관련된 정보를 처리할 수 있습니다.
기술 환경에 대한 접근 권한을 부여받았거나 당사 또는 승인된 제3자 툴에 온보딩한 경우, 관련 플랫폼 또는 기술 범위 내에서 라이선스 유형, 할당 및 사용 현황에 대한 가시성을 확보할 수 있습니다. 여기에는 이러한 접근이 승인된 경우 당사를 통해 취득한 라이선스뿐만 아니라 다른 제공업체로부터 취득한 라이선스도 포함될 수 있습니다.
이 정보를 사용하여 라이선스 및 사용 최적화를 지원하고, 서비스 이용 자격을 검증하며, 사용자당 또는 라이선스당 기준으로 가격이 책정되거나 제공되는 서비스를 관리하고, 전체 고객 기반 전반의 취합된 트렌드를 분석합니다. 이러한 분석은 신제품 및 서비스의 개발, 기존 제품 및 서비스의 개선, 관련 상업적 기회의 식별에도 활용될 수 있습니다.
고객이 부여한 접근 범위 또는 적용 가능한 계약상의 약정 범위를 벗어나 라이선스 또는 사용 데이터에 접근하거나 이를 처리하지 않습니다.
관련 개인정보 항목: 사용자 또는 기기 식별자, 라이선스 할당 및 사용 데이터, 서비스 사용 지표, 관련 기술 메타데이터.
해당 개인정보 처리를 위한 법적 근거는 당사의 제품 및 서비스를 관리·개발하고, 관계의 전체 라이프사이클 동안 고객을 지원하며, 상업적 활동을 수행하려는 정당한 이익 및 해당하는 경우 계약상 의무의 이행입니다.
쿠키 및 기타 유사 기술
웹사이트, 플랫폼, 애플리케이션 및 기타 제품·서비스를 이용할 때 쿠키 및 유사 기술을 사용할 수 있습니다. 쿠키는 웹사이트가 기기에 저장하는 작은 텍스트 파일입니다. 웹사이트가 선호도, 로그인 정보, 브라우징 활동을 기억하도록 도와 더욱 개인화되고 효율적이며 원활한 온라인 경험을 제공하며, 일반적으로 웹사이트 트래픽 분석, 사용자 세션 관리 및 관심사에 맞춘 콘텐츠 제공에 사용됩니다.
필수 쿠키
웹사이트 작동에 필수적인 쿠키이며 비활성화할 수 없습니다.
기능성 쿠키
폰트, 동영상, 지도, 소셜 플러그인 및 임베디드 서비스 등 추가 기능과 제3자 콘텐츠를 제공하는 쿠키입니다.
분석 및 마케팅 쿠키
이용자가 웹사이트와 상호작용하는 방식을 파악하고 광고와 마케팅 활동을 지원하는 쿠키입니다.
쿠키를 사용하는 목적 중 하나는 이용 데이터를 처리하여 웹사이트, 플랫폼, 애플리케이션 또는 기타 제품과 서비스를 어떻게 이용하고 상호작용하는지 분석함으로써 온라인 경험을 개선하기 위함입니다. 또한 웹사이트 이용 현황을 분석하고 기능을 개선하고자 익명화된 세션 녹화 파일을 생성하기 위해 제3자 툴을 사용할 수 있습니다. 해당 녹화 파일에는 개인정보가 포함되지 않으며, 개인정보 보호를 위해 민감한 필드는 마스킹 처리됩니다.
당사 웹사이트 외부에서 타겟 광고를 게재하고 광고 효과를 측정하기 위해 교차 기기 추적 기술을 사용할 수도 있습니다. 쿠키 배너에 명시된 제3자 제공업체는(비필수 쿠키가 활성화된 경우) 브라우저 또는 기기에 액세스하거나, IP 주소를 분석하거나, 식별 특성을 저장 또는 판독하거나, 추적 픽셀에 접근할 수 있습니다. 이러한 특성은 다른 웹사이트에서 기기를 인식하는 데 사용됩니다. 사용자 데이터로 제3자 제공업체 서비스에 가입하는 경우, 노트북, 스마트폰, 태블릿 등 서로 다른 기기 간 식별 정보가 연계될 수 있습니다. 이를 통해 해당 제공업체는 여러 기기에 걸쳐 광고 캠페인을 관리할 수 있습니다.
웹사이트를 최적화하여 설계하고 재방문자를 식별하기 위해 웹 분석 툴을 사용할 수도 있습니다. 이러한 툴은 가명을 기반으로 이용 프로파일을 생성하며, 쿠키 배너에 안내된 대로 쿠키를 활용합니다.
또한 서버에 저장되지 않는 특정 서비스를 웹사이트에 임베드하여 제공하기도 합니다. 예를 들어, 지도를 사용하여 SoftwareOne 법인의 정확한 위치를 확인하거나 동영상을 시청할 수 있습니다. 특정 지역의 경우, 임베디드 콘텐츠가 포함된 웹사이트, 플랫폼, 애플리케이션 또는 기타 제품과 서비스에 액세스하더라도 제3자 제공업체에 어떠한 정보도 자동으로 제공되지 않도록 조치하며, 로컬에 저장된 썸네일 이미지만을 표시합니다. 이러한 경우 제3자 제공업체의 콘텐츠는 쿠키 배너를 통해 동의한 후에만 로드됩니다. 콘텐츠를 시청할 때 해당 제3자 제공업체는 웹사이트에 접속했다는 정보와 서비스 제공에 필요한 관련 이용 데이터를 수령하게 됩니다. 제3자 제공업체가 수행하는 추가적인 개인정보 처리 행위에 대해서는 어떠한 영향력도 행사할 수 없습니다.
쿠키 배너는 제3자가 제공하며, 제공업체를 포함하여 사용하는 쿠키 목록을 보여줍니다. 기본 설정에서는 필수 쿠키만 활성화됩니다. 쿠키 배너를 통해 추가 쿠키 설정 허용 여부를 결정할 수 있으며, 언제든지 쿠키 배너를 통해 선호 설정을 변경할 수 있습니다.
관련 개인정보 항목: IP 주소, 기기 및 브라우저 정보, 보안 및 봇 탐지 시그널, 쿠키 동의 선호 설정, 웹사이트 상호작용 데이터(예: 동영상 시청, 지도 이용, 임베디드 콘텐츠 상호작용), IP 주소 기반의 대략적인 위치, 기술적 요청 및 성능 데이터, 방문 페이지 및 브라우징 행태(예: 클릭, 스크롤, 이동 경로), 페이지 체류 시간 및 세션 지속 시간, 쿠키 식별자 및 광고 ID, 전환 및 참여 이벤트(예: 양식 제출, 상호작용), 마케팅 및 캠페인 성과 데이터.
필수 쿠키와 관련된 개인정보 처리는 웹사이트, 플랫폼, 애플리케이션을 화면에 표시하려는 정당한 이익에 기반합니다. 비필수 쿠키 및 유사 기술의 경우 동의를 법적 근거로 합니다.
디지털 제품 및 서비스에서의 인공지능(AI) 활용
생성형 AI를 포함한 인공지능("AI") 툴을 사용하여 웹사이트, 플랫폼, 애플리케이션 및 기타 제품 또는 서비스와 상호작용하는 방식을 지원할 수도 있습니다(예: 채팅 어시스턴트 구동, 콘텐츠 번역 또는 요약, 표시되는 내용의 개인화, 게시물 및 댓글 중재, 제품 기능 제공 또는 개선). 다만, 해당 결과물이 개인에게 중대한 영향을 미칠 수 있는 경우에는 담당자의 검토를 거치게 됩니다.
소셜 미디어 채널 방문자
주요 소셜 미디어 플랫폼을 방문할 때 개인정보를 처리할 수 있습니다(주요 프로필 목록은 아래와 같습니다).
- LinkedIn: https://www.linkedin.com/company/SoftwareOne
- X: https://x.com/SoftwareOne, https://x.com/SWO_Careers
- Facebook: https://www.facebook.com/Softwareone/, https://www.facebook.com/softwareonecareers
- Instagram: https://www.instagram.com/softwareone/, https://www.instagram.com/swocareers/
- YouTube: https://www.youtube.com/SoftwareOne-global
- Tik Tok: https://www.tiktok.com/@swocareers?_r=1&_t=ZN-94SU63n1PIl
해당 소셜 미디어 플랫폼 제공업체와 함께 개인정보 처리에 대한 공동 책임을 부담합니다. 이와 관련하여 소셜 미디어 플랫폼 제공업체 역시 개인정보 처리 목적과 수단을 독자적으로 결정하며, 이에 대해 제한적인 범위 내에서만 영향력을 행사할 수 있습니다.
소셜 미디어 플랫폼에 입력한 데이터(댓글, 동영상, 사진, '좋아요', 공개 메시지 등)는 소셜 미디어 플랫폼 제공업체를 통해 게시되며, 이를 다른 목적으로 사용하지 않습니다. 그럼에도 불구하고 필요한 경우 해당 콘텐츠를 삭제할 권리를 보유합니다. 소셜 미디어 피드의 기능인 경우 콘텐츠를 웹사이트에 공유할 수 있으며, 소셜 미디어 플랫폼을 통해 소통할 수 있습니다.
소셜 미디어 플랫폼 중 하나를 통해 요청을 제출하는 경우, 요청 내용에 따라 기밀성이 보장되는 다른 안전한 소통 채널을 안내할 수 있습니다. 제공된 다른 채널을 통해 언제든지 비공개로 요청을 보내실 수 있습니다. 개인정보에 대한 특정 처리 활동에 반대하고자 하는 경우, "문의 정보" 섹션에 설명된 대로 연락해 주시기 바랍니다. 요청을 검토하여 응답할 수 있는 사안인지, 그리고 해당 처리 활동에 대해 영향력을 행사할 수 있는지 여부를 결정합니다. 그렇지 않은 경우, 해당 소셜 미디어 플랫폼 제공업체에 직접 문의해야 할 수 있습니다.
홍보 목적으로 소셜 미디어 플랫폼을 이용할 수 있습니다. 이 과정에서 당사는 해당 소셜 미디어 플랫폼 제공업체가 제공하는 인구통계학적 특성, 관심사 기반, 행동 기반 또는 위치 기반의 타겟 그룹 특성을 활용할 수 있습니다. 데이터 처리에 제한적인 범위 내에서만 영향력을 행사할 수 있으며, 해당 소셜 미디어 플랫폼 제공업체가 제공하는 통계 기능을 비활성화할 수 없습니다.
개별 소셜 미디어 채널에 대한 전환 추적 옵션을 사용합니다. 이를 위해 전환 데이터를 수집하고자 웹사이트에 상응하는 픽셀 또는 태그를 통합했습니다. 쿠키 배너를 통해 이러한 비필수 쿠키의 허용 여부를 결정할 수 있으며, 선호 설정을 조정할 수 있습니다.
소셜 미디어 활동을 지원하기 위해 생성형 AI를 포함한 AI 툴을 사용할 수 있습니다(예: 캡션 초안 작성 또는 번역, 시각적 콘텐츠 생성 또는 조정, 자체 운영 페이지의 댓글 중재, 취합된 형태의 참여도 분석). 단, 모든 콘텐츠는 게시 전에 담당 팀의 검토를 거칩니다. 소셜 미디어 제공업체가 자체적으로 운영하는 AI 기능은 해당 제공업체의 개인정보 처리방침을 따릅니다.
소셜 미디어 플랫폼 제공업체에 의한 데이터 처리
소셜 미디어 플랫폼 제공업체는 웹 추적 방식을 사용할 수 있습니다. 웹 추적은 소셜 미디어 플랫폼 계정에 로그인되어 있는지 여부와 관계없이 수행될 수 있습니다. 앞서 언급한 바와 같이, 소셜 미디어 플랫폼의 웹 추적 기능은 통제 범위를 벗어나며 이러한 기능을 비활성화할 수 없습니다. 해당 소셜 미디어 플랫폼 제공업체는 프로필과 행동 데이터를 사용하여 습관, 개인적 관계 및 선호도를 평가할 수 있음을 유의하시기 바랍니다. 관련 소셜 미디어 플랫폼 제공업체에 의한 데이터 처리에 대해 어떠한 영향력도 행사할 수 없습니다.
소셜 미디어 플랫폼에서의 개인정보 처리에 대한 자세한 내용은 아래 나열된 각 제공업체의 개인정보 처리방침을 확인하시기 바랍니다.
- LinkedIn: https://www.linkedin.com/legal/privacy-policy
- X: https://x.com/en/privacy
- Facebook: https://www.facebook.com/privacy/explanation
- Instagram: https://help.instagram.com/155833707900388
- YouTube: https://policies.google.com/privacy?hl=en
- TikTok: https://www.tiktok.com/legal/page/us/privacy-policy/en
관련 개인정보 항목: 성명, 회사명, 이메일 주소, 국가 및 자발적으로 당사에 제공하는 기타 모든 정보.
해당 개인정보 처리를 위한 법적 근거는 소셜 미디어 플랫폼에서 브랜드, 서비스, 제품을 광고 및 홍보하고, 마케팅 활동의 효과성과 관련성을 향상시켜 전반적인 마케팅 성과를 개선하려는 정당한 이익입니다. 이와 유사하게 홍보(PR) 및 커뮤니케이션의 이익을 위해 개인정보를 처리합니다. 또한 비필수 쿠키의 배포에 대해서는 동의에 기반하며, 쿠키 배너를 통해 언제든지 선호 설정을 조정할 수 있습니다.
고객, 비즈니스 파트너 및 이해관계자
제품 또는 서비스의 구매 및 이용
제품 또는 서비스의 구매와 이용을 원활하게 지원하기 위해, 개인정보를 처리할 수 있습니다. 이러한 개인정보는 직접 제공받거나, 관련 고객, 공급업체 또는 비즈니스 파트너가 제공할 수 있습니다.
제공되는 제품 또는 서비스에 따라 두 가지 서로 다른 역할로 개인정보를 처리합니다.
- 특정 제품 또는 서비스의 경우, 개인정보 처리의 목적과 수단을 독립적으로 결정합니다.
- 다른 제품 또는 서비스의 경우, 고객을 대리하여 개인정보 수탁자로서 행동합니다. 이러한 경우 구체적인 처리 활동은 당사와 고객 간에 체결된 적용 가능한 개인정보 처리 약정에 상세히 규정되어 있습니다.
해당 처리를 통해 계약 협상 및 체결, 가격 정보 제공을 포함하여 개인 및 대리하는 회사와의 관계를 관리하고 운영할 수 있습니다.
이와 유사하게 일부 제품 또는 서비스를 제공하는 동안, 사이버 보안 위협을 탐지, 조사 및 대응하기 위해 특정 데이터를 처리할 수 있습니다. 여기에는 시스템 모니터링, 보안 이벤트 분석 및 고객 환경에 영향을 미치는 잠재적 침해 사고 대응이 포함됩니다.
구매를 진행하기 전에 제품 또는 서비스를 둘러보고자 데모 또는 평가판 계정을 생성하는 경우, 개인정보를 수집할 수 있습니다. 이를 통해 접근을 인증하고, 임시 서비스 기능을 제공하며, 제품 또는 서비스의 이용량을 모니터링하고 데모 또는 평가판 계정과 관련하여 소통합니다.
경험, 관심사, 제품 또는 서비스에 대한 피드백을 깊이 이해하고 이를 개선하는 동시에, 고객, 비즈니스 파트너 및 기타 이해관계자와 수립한 관계를 발전시키기 위해 수시로 시장 조사 및 만족도 조사를 실시할 수 있습니다. 이러한 경우 해당 처리에 반대할 권리가 있습니다. 권리 행사 방법에 대한 자세한 내용은 "문의 정보" 섹션에서 확인할 수 있습니다.
관련 개인정보 항목: 연락처 정보(예: 성명, 이메일, 전화번호, 직책, 회사명), 로그인 인증 정보, 등록 일시, 이용 데이터, 시스템 및 보안 로그(예: 인증 로그, 네트워크 트래픽 메타데이터, 엔드포인트 텔레메트리), IP 주소, 기기 식별자, 기기 및 애플리케이션 데이터(예: 호스트 이름, 운영체제 상세 정보, 애플리케이션 사용 메타데이터), 침해 사고 관련 데이터(예: 악성 행위로 의심되는 활동과 관련된 파일, 메모리 데이터 또는 로그) 및 제품 또는 서비스를 구매하고 이용하는 동안 자발적으로 제공하는 기타 데이터.
해당 개인정보 처리를 위한 법적 근거는 법적으로 대표하는 법인과 당사가 체결하는 계약을 관리, 체결 및 이행함으로써 제품 또는 서비스를 판매하려는 정당한 이익입니다. 시장 조사 또는 설문조사를 수행할 때, 그리고 데모 계정을 생성하여 잠재 고객의 법적 대리인에게 제품 또는 서비스의 미리보기를 제공할 때도 동일한 법적 근거에 기반합니다.
제품 및 서비스 개선
제품 또는 서비스를 이용하는 동안, 통계 및 개선 목적으로 이를 분석하기 위해 개인정보를 처리할 수 있습니다.
관련 개인정보 항목: 성명, 이메일, IP 주소, 방문한 콘텐츠, 방문 일시, 전송된 데이터 양, 접근 상태, 웹 브라우저 및 운영체제, 유입된 경로를 나타내는 이전 방문 페이지(리퍼럴) 링크.
해당 개인정보 처리를 위한 법적 근거는 전반적인 성과를 파악하고 제품 또는 서비스를 개선하며, 궁극적으로 이용 경험을 향상시키려는 정당한 이익입니다.
고객 신용 검증
계약을 체결하기 전에 고객에 대한 신용 조사를 실시하여 지속적인 비즈니스 관계 동안의 재무적 리스크를 관리하고자 개인정보를 처리할 수 있습니다. 이는 또한 거래를 개시하기 전에 전사적자원관리(ERP) 시스템 내에서 고객 정보 및 신용 한도를 내부적으로 검증하는 절차를 포함할 수 있습니다.
관련 개인정보 항목: 연락처 정보(예: 성명, 이메일, 전화번호, 직책, 회사명), 금융 이력, 신용 점수, 대금 지급 행태, 미결제 채무, 식별 번호(예: 부가가치세 번호 또는 회사 등록 번호), 신용 조회 기관으로부터 수령한 데이터(해당 정보가 개인과 관련된 경우).
해당 개인정보 처리를 위한 법적 근거는 신용도를 평가하고 재무적 위험 노출을 최소화하려는 정당한 이익입니다.
실사 및 스크리닝
비즈니스를 수행하기 전에, 고객, 비즈니스 파트너 또는 관련 이해관계자를 대리하여 연락할 때 당사는 실사 또는 스크리닝을 수행하고자 개인정보를 처리할 수 있습니다. 실사 또는 스크리닝 활동은 관련 법령이 허용하는 범위 내에서 보안, 개인정보 보호 및 청렴성 검증을 포함할 수 있습니다.
관련 개인정보 항목: 연락처 정보(예: 성명, 이메일, 전화번호, 직책, 회사명) 및 자발적으로 제공하는 기타 데이터.
해당 개인정보 처리를 위한 법적 근거는 소속 회사의 적합성을 보장하고 관련 리스크를 효과적으로 관리하려는 정당한 이익입니다.
고객 및 파트너 소통에서의 인공지능 활용
상업적 및 운영적 활동을 지원하기 위해 생성형 AI를 포함한 AI 툴을 사용할 수 있습니다(예: 서신 작성 및 개인화, 회의 및 이메일 교환 내용 요약, 콘텐츠 번역, 계정 정보 분석, 지원 요청 분류 및 응답, 제안서 또는 계약서 작성 지원). 다만, 개인에게 중대한 영향을 미칠 수 있는 결과물의 경우 담당자의 검토를 거치게 됩니다. 관련 법령에 의해 허용되는 경우를 제외하고, 법적 효과 또는 이와 유사하게 중대한 영향을 미치는 어떠한 결정도 전적으로 자동화된 수단에 의해서만 내려지지 않습니다.
이벤트 등록 및 관리
당사 또는 파트너가 조직하고 참석하기로 결정한 세미나, 웨비나, 교육 세션, 가상 회의 및 기타 이벤트("이벤트")를 조직 및 진행하고 소통하기 위해 개인정보를 처리할 수 있습니다.
이 과정에서 개인정보를 공유하는 외부 제3자 제공업체(예: 화상 회의, 커뮤니케이션 제공업체)의 지원을 받을 수 있습니다.
경우에 따라, 이벤트를 녹화할 수도 있습니다. 자세한 내용은 다음의 시청각 콘텐츠 섹션을 참조하시기 바랍니다.
이벤트를 효과적으로 개선하고 확장하기 위해 수시로 설문조사를 발송할 수도 있으며, 설문 답변은 자율입니다.
이벤트가 가상이 아닌 대면 참석을 요하는 경우, 해당 특정 이벤트와 관련된 개인정보 처리 세부 사항은 별도로 제공되는 이벤트 개인정보 처리방침을 참조하시기 바랍니다.
관련 개인정보 항목: 연락처 정보(예: 성명, 이메일, 전화번호, 직책, 회사명), 회의명 또는 별칭, IP 주소, 기기/하드웨어 데이터(예: MAC 주소, 버전), 텍스트, 음향 및 동영상 데이터, 연결 데이터(예: 전화번호, 국가명, 시작 및 종료 시간) 및 등록 과정 또는 이벤트 기간 동안 자발적으로 제공하는 기타 데이터.
해당 개인정보 처리를 위한 법적 근거는 이벤트를 관리하고 활동을 홍보하는 것뿐만 아니라, 전반적인 이벤트 성과를 파악하고 평가하여 이를 개선할 수 있도록 설문조사를 발송하려는 정당한 이익입니다.
시청각 콘텐츠
당사 또는 파트너가 조직한 이벤트 기간 동안, 참가자의 사진을 촬영하거나 동영상을 녹화("시청각 콘텐츠")할 수 있습니다. 이러한 시청각 콘텐츠에는 개인 또는 단체, 발표자 또는 무대에 서는 사람의 모습이 촬영될 수 있습니다. 해당 자료를 웹사이트, 소셜 미디어 플랫폼 또는 기타 디지털 또는 인쇄 매체에 게시할 수 있습니다. 시청각 콘텐츠에 노출되기를 원하지 않는 경우, 녹화 또는 사진 촬영을 진행하는 담당자나 이벤트 주최자에게 알려주시기 바랍니다. 또한 대면 이벤트 중 사진 촬영이나 동영상 녹화가 진행될 때는 해당 구역에 진입하지 않도록 유의해 주시기 바랍니다.
참가자 개인의 시청각 콘텐츠를 촬영하는 경우 개인정보 처리 프로세스를 별도로 안내하고 촬영 전 동의를 구합니다.
이러한 처리에 반대하거나, 이전에 제공한 동의를 철회할 권리가 있습니다. 요청을 준수하기 위해 합리적인 노력을 기울일 것이나, 소셜 미디어 플랫폼을 포함하여 인터넷에 게시된 모든 정보는 전 세계적으로 접근 가능해지며, 연계되지 않거나 통제 범위를 벗어난 제3자에 의해 쉽게 복사 및 배포될 수 있음을 유의하시기 바랍니다. 이에 따라 해당 정보를 삭제한 후에도 인터넷에 계속 남아있을 수 있습니다. 이후의 추가 삭제 요청은 해당 인터넷 검색 엔진 또는 소셜 미디어 제공업체에 직접 제기해야 합니다.
사진이 인쇄물(예: 리플릿, 잡지, 뉴스레터)에 사용된 경우, 이를 제거하는 데 과도한 노력이 수반된다면 이미 인쇄된 부수가 소진될 때까지 해당 인쇄물이 계속 사용될 수 있습니다. 다만, 새로운 인쇄물에는 해당 사진이 일절 사용되지 않습니다.
관련 개인정보 항목: 사진, 동영상, 음성 녹음 및 수집되거나 공유되는 기타 생체 인식 데이터.
해당 개인정보 처리를 위한 법적 근거는 이벤트를 관리하고 활동을 홍보하려는 정당한 이익입니다. 다만, 개인의 시청각 콘텐츠를 촬영·제작하는 경우는 제외되며, 이 경우 동의에 기반합니다.
이벤트 기간 중 인공지능 활용
이벤트를 진행, 문서화 및 개선하기 위해 당사 또는 이벤트·화상 회의 제공업체가 제공하는 AI 기반 기능을 사용할 수 있습니다. 해당 기능은 실시간 또는 이벤트 후 스크립트 생성, 서면 요약본, 메모 및 하이라이트 제공, 실시간 자막 또는 번역 제공, 질의응답 및 채팅 지원, 취합된 형태의 참여도 분석 등에 활용됩니다. 스크립트 생성, 요약 또는 녹음 기능이 활성화되는 경우, 이벤트 시작 시 안내하고 필요한 경우 동의를 구합니다.
채용 기회와 관련하여 지원자로부터 직접 수령하거나, 공개적으로 접근 가능한 소스(예: 온라인 전문 네트워크, 소셜 미디어 사이트 또는 채용 게시판) 또는 제3자(예: 인사 서비스 제공업체, 대학, 고용/헤드헌팅 대행사, 추천인, 세무 및 사회보험 당국 또는 기타 관련 당국)를 통해 수령한 개인정보를 처리할 수 있습니다.
다음과 같은 목적으로 개인정보를 처리할 수 있습니다.
- 지원 시스템 내 계정 생성
- 이력서, 경력기술서 또는 제공한 기타 문서 평가 및 해당하는 경우 AI 시스템 활용을 통한 기술, 경력 및 자격 평가
- 인터뷰 일정 수립 및 평가 실시
- 법령에 의해 허용되거나 요구되는 경우, 채용 제안을 받기 위한 선결 조건으로서 신원 조회 또는 공개 소셜 미디어 확인 실시
- 지원 진행 상황과 관련한 연락 안내
- (해당하는 경우) 채용 과정에서 발생한 여비 상환
- 채용이 확정된 경우, 인사 파일용 지원서 보관 및 고용 관계 수립
- 관심사 및 기술을 기반으로 한 채용 기회 제공 및 채용 활동에 관한 최신 소식 안내
- 채용 프로세스 개선 등을 위한 설문조사 실시 등
채용 공고에 지원할 때, 해당 채용 직무와 관련된 데이터만 지원서에 포함해 주시기 바랍니다. 특정 채용의 경우, 고용 평등 기회 충족 및 법적 보고 요구사항을 준수하고자 자발적 참여를 바탕으로 특정 인구통계학적 정보(예: 성별, 인종/민족 및 국적)를 요청할 수 있습니다. 해당 정보는 선발 프로세스의 일부에 포함되지 않으며 채용 결정에 어떠한 영향도 미치지 않습니다.
일부 직무의 경우, 채용 프로세스를 지원하고자 제3자 제공업체가 제공하는 기술 기반 평가 및 채용 툴(예: 화상 인터뷰 플랫폼, 구조화된 평가, 직무 시뮬레이션, AI 지원 스크리닝 워크플로)을 사용할 수 있습니다. 이러한 툴은 지원 정보의 구조화된 수집, 인터뷰 또는 평가 일정 수립 및 진행, 직무 관련 기술 검증, 채용 담당자의 검토를 지원하기 위한 구조화된 요약본 또는 인사이트 생성 등에 활용됩니다. 직무 및 사용되는 툴에 따라 이력서 및 지원 자료 검토, 구조화된 질문(텍스트, 음성 및/또는 동영상 형태)에 대한 답변 요청, 채용 담당자용 요약본, 점수 또는 신뢰도 지표 생성 등이 포함될 수 있습니다. 이렇게 도출된 결과물은 결정을 돕는 지원 자료로 활용되며, 채용 담당자가 관련 정보를 검토하고 채용 결정을 내릴 최종 책임을 집니다. 특정 평가 단계가 자율적인 참여를 바탕으로 제공되는 경우에는 이를 명확히 안내하고, 가능한 경우 대체 경로를 제공합니다.
또한 공개 전문 네트워크 및 채용 게시판에서의 후보자 발굴, 인터뷰 일정 수립, 인터뷰 녹취 및 요약, 지원 자료 번역 및 채용 담당자 서신 초안 작성을 위해 AI를 사용할 수 있습니다. 이러한 결과물은 채용 담당자를 대체하는 것이 아니라 보조하는 용도로만 사용되며, 전적으로 자동화된 수단에 의해서만 채용 결정이 내려지지는 않습니다. AI가 지원한 결과에 대한 담당자의 검토를 채용 담당자에게 직접 요청하거나 "인공지능" 섹션의 세부 정보를 통해 요청할 수 있습니다.
계정을 생성한 후에는 포털 계정 대시보드 기능을 통해 개인정보 선호 설정 및 이메일 구독 설정을 변경할 수도 있습니다. 언제든지 iCIMS.help@softwareone.com으로 연락하면 이에 따라 지원을 받을 수 있습니다.
지원 전형에서 선발되지 않았으나, 향후 잠재적인 채용 기회를 위해 개인정보를 더 오래 보관하는 것에 동의한 경우, 해당 데이터는 추가로 2년 동안 보관되며 이후 절차에 따라 삭제됩니다. 연장된 보관 기간에 동의하지 않은 경우에는 관련 법령에 따라 지원 프로세스가 종료된 후 6개월 이내에 데이터를 삭제합니다. 다만, 이러한 보관 기간과 관계없이 "정보주체의 권리" 섹션에 따라 언제든지 당사에 데이터 삭제 요청을 제기할 수 있습니다.
관련 개인정보 항목: 연락처 정보(예: 성명, 이메일, 전화번호, 직책, 회사명), 이력서(제공한 사진 또는 이미지 포함), 자기소개서(지원동기서), 추천서, 자택 주소, 신원 확인 데이터(예: 생년월일, 국적, 주민등록증 또는 여권 등), 고용 데이터(예: 경력 사항, 근로계약서, 과거 고용 이력, 현재 고용 상태·유형, 직무 또는 필요한 경우 취업·체류 허가증 등), 교육·자격 데이터(예: 학위, 자격증, 이전 경력 사항, 부업 이력, 추천인, 전문 지식 및 경험을 입증하는 기타 관련 서류), 설문조사·평가 결과, 관련 법령에 의해 허용 및/또는 요구되는 경우의 건강 데이터, 은행 계좌 상세 정보(예: 합의된 경우 여비 상환용), 자율적으로 제공하는 기타 데이터.
해당 개인정보 처리를 위한 법적 근거는 다음과 같습니다.
- 공석인 채용 직무의 충원을 위한 계정 생성, 지원서 평가, 인터뷰 또는 평가 실시, 신원 조회 진행 및 채용 프로세스 전반의 관리에 대한 정당한 이익
- 채용 프로세스의 효과적인 개선 방안 모색 및 전반적인 성과·효율성 평가를 위해 설문조사를 발송하려는 정당한 이익
- 법적 청구 발생 시 당사 및 브랜드를 보호하기 위한 방어권과 권리 행사에 대한 정당한 이익
- 지원한 채용 기회에 선발되지 않은 경우, 향후 개인정보를 장기적으로 안전하게 보관하는 것에 대한 정보주체의 동의
- 지원 과정에서의 AI 툴 사용(예: AI 지원 평가 또는 화상 인터뷰)과 관련하여 필요 시 요구되는 정보주체의 동의
- 고용 관계 수립에 따른 계약상 근거
- 규제 요구사항 준수, 불만 또는 우려 사항 처리 및 필요한 경우 당사 보호를 위한 법적 의무 이행
기업 거래
사업 확장 및 성장 과정에서 다양한 기업 거래가 발생할 수 있습니다. 이에 따라 당사의 비즈니스, 자산 또는 주식의 전부 또는 일부에 대한 조직 개편, 매각, 합병, 통합, 합작 투자, 양도, 이전 또는 기타 처분(파산 또는 이와 유사한 절차와 관련된 경우 포함)이 제안되거나 실제 집행되는 경우, 관련 개인정보가 제3자에게 공개되거나 이전될 수 있습니다.
관련 개인정보 항목: 연락처 정보(예: 성명, 이메일, 전화번호, 직책, 회사명), 계정 인증 정보, 구매 및 거래 기록, 기업 거래를 원활하게 진행하는 데 필요한 기타 데이터.
해당 개인정보 처리를 위한 법적 근거는 기업 거래를 수행하고 비즈니스 연속성을 보장하려는 정당한 이익입니다.
분쟁 해결
법적 권리를 보호하고, 권리 행사 및 청구에 대한 방어를 수행하거나 법적 절차(제3자가 개입된 절차 포함)에 참여하기 위해 개인정보를 처리할 수 있습니다.
관련 개인정보 항목: 연락처 정보(예: 성명, 이메일, 전화번호, 직책, 회사명), 계약 문서, 서신, 사용 로그, 거래 이력, 분쟁 사안과 관련된 기타 데이터.
해당 개인정보 처리를 위한 법적 근거는 법적 권리를 방어하고 분쟁을 효율적으로 해결하려는 정당한 이익입니다.
규제 준수
관련 법령 및 규정상의 의무를 이행하기 위해, 공공 기관, 규제 기관 또는 사법 기관(예: 경찰, 법원)과 개인정보를 처리 및 공유해야 하거나 요구될 수 있습니다. 또한 준수 의무를 지원받고자 외부 감사인 또는 자문인을 선임할 수 있으며, 이 경우 필요한 범위 내에서 개인정보가 공유됩니다. 이는 법령에서 요구하는 바에 따라 기록 유지, 보고서 제출 또는 정보 공개 등을 포함할 수 있습니다. 일부 사례의 경우 관련 법령에 따라 개인정보 제공이 의무적이거나 공식 요청에 따를 수 있습니다. 반면, 규제 준수 목적으로 필요한 보고서를 선제적으로 제출할 수도 있습니다.
관련 개인정보 항목: 연락처 정보(예: 성명, 이메일, 전화번호, 직책, 회사명), 거래 기록, 서신 이력, 계정 활동, 규제 준수를 증명하는 데 필요한 기타 데이터.
해당 개인정보 처리를 위한 법적 근거는 법적 의무 준수입니다.
우려 사항 보고
SoftwareOne은 청렴성과 규제 준수의 최고 표준을 유지하기 위해 노력하고 있습니다. 그 일환으로 규제 준수, 윤리 경영 또는 잠재적 비위 행위 등과 관련된 우려 사항 제기를 위해 안전하고 기밀이 보장되는 보고 채널인 SoftwareOne Integrity Line을 운영하고 있습니다. SoftwareOne Integrity Line은 내부 임직원뿐만 아니라 우려 사항이나 위반 의심 사례를 보고하고자 하는 외부 이해관계자 누구나 이용할 수 있으며, 원하는 경우 익명으로도 보고할 수 있습니다. 모든 제보 및 보고 사항은 엄격한 기밀로 취급되며, 제출 시 공유되는 개인정보는 본 개인정보 처리방침, Integrity Line 내 개인정보 보호정책 및 관련 데이터 보호 법령에 따라 우려 사항 조사 및 해결 목적으로만 처리됩니다.
관련 개인정보: 신원이 공개된 경우에 한해 제보자/보고자의 연락처 정보 및 제보 내용의 일부로 제공된 기타 개인정보 일체가 포함됩니다. 또한, 제기된 혐의로 인해 영향을 받는 개인과 관련하여 제보 내용에 포함된 데이터(예: 성명, 이메일, 전화번호, 자택 주소 및 관련 증빙 서류)가 수집될 수 있으며, 아울러 제보 내용에 포함되거나 조사 과정에서 공개되는 경우, 특별 범주 개인정보도 수집될 수 있습니다.
해당 개인정보 처리를 위한 법적 근거는 다음과 같습니다.
- 안전한 내부 보고 채널 제공 의무를 포함한 법적 의무 준수
- 형사 범죄, 직무 위반 및 기타 위반 행위의 예방 및 탐지하고, 이 과정에서 내부 프로세스의 적법성을 검증하며, 청렴성을 수호하고 손해 및 책임 리스크를 방지하려는 회사의 정당한 이익
- 특별 범주 개인정보가 처리되는 경우, 제보 처리와 조사 수행에 필요한 경우에 한하며, 관련 데이터 보호 법령에 따라 허용되는 경우에만 해당 데이터를 처리
보안 분석
웹사이트, 플랫폼, 애플리케이션 또는 기타 제품 및 서비스의 보안을 유지하고, 이에 대한 사기 또는 오용 행위를 탐지하기 위해 개인정보를 처리할 수 있습니다. 이는 무단 접근을 탐지하고 예방하여 시스템 무결성을 보장하고, 사이버 위협으로부터 디지털 인프라를 보호하기 위함입니다. 여기에는 웹사이트, 플랫폼, 애플리케이션 또는 기타 제품·서비스의 기밀성, 무결성 및 가용성을 유지하기 위한 접근 로그, 사용 패턴 및 기타 기술적 요소의 모니터링이 포함됩니다.
관련 개인정보 항목: IP 주소, 로그인 인증 정보, 기기 식별자, 브라우저 유형, 운영체제, 접근 타임스탬프 및 활동 로그.
해당 개인정보 처리를 위한 법적 근거는 사기 및 오용 행위를 탐지하고, 웹사이트·플랫폼·애플리케이션 및 기타 제품·서비스가 본래의 의도된 목적으로 사용되도록 보장하며, 외부 침입 및 침해로부터 안전하게 보호하려는 정당한 이익에 기반합니다.
인공지능
내부 프로세스를 원활하게 하고, 서비스를 개선하며, 제공하는 디지털 제품 및 서비스 전반의 혁신을 지원하기 위해 비즈니스 특정 부문에서 머신러닝 및 생성형 AI를 포함한 AI를 활용하고 있습니다. AI 활용 방식은 상황에 따라 상이합니다. 경우에 따라 담당자의 검토를 거치는 권고 또는 보조를 제공하는 데만 AI가 활용되기도 하며, 다른 경우에는 특정 저위험 운영 업무의 자동화를 지원하기도 합니다. AI 활용이 개인과 관련될 수 있는 경우 투명성 확보를 최우선으로 하여 사안별로 명확한 정보를 제공하고 있습니다.
AI 활용에 대한 자세한 정보가 필요하거나 우려 사항, 안전하지 않은 결과물 또는 예기치 않은 AI 작동 등을 발견하는 경우 responsible-ai.global@softwareone.com으로 문의해 주시기 바랍니다.
개인정보 보유
개인정보 수집 목적 달성 또는 법적 의무 준수를 위해 필요한 기간 동안 해당 정보를 보유합니다. 보존 기간은 계약 기간, 법적 보고 의무, 분쟁 해결·사기 예방을 위한 필수 보존 기간 및 기타 규제 요구사항 등을 포함하며, 이에 국한되지 않습니다. 개인정보를 보유할 정당한 비즈니스적 필요성이 더 이상 없는 경우에는 특정 개인을 식별할 수 없도록 익명처리하거나, 관련 법령에 따라 안전하게 파기합니다.
개인정보를 제공받는 자
본 개인정보 처리방침에 명시된 목적을 달성하기 위해, 다음과 같이 외부 수신처에 개인정보를 공개하거나 제공할 수 있습니다.
SoftwareOne 계열사: 글로벌 그룹 구조상, 특정 부서 및 인원은 업무상 필요한 경우에 한해 제한적으로 개인정보를 처리합니다. 이러한 계열사 간 모든 개인정보 접근 및 이전에 대해서는 관련 데이터 보호 요구사항을 엄격히 준수하고 있습니다. SoftwareOne 그룹사에 관한 추가 정보는 여기에서 확인하실 수 있습니다.
IT 공급업체를 포함한 서비스 제공업체: 웹사이트, 플랫폼, 애플리케이션 또는 기타 제품 및 서비스를 지원하기 위해 IT 공급업체를 포함한 서비스 제공업체에 개인정보를 공개할 수 있습니다. 해당 업체들은 마케팅, 우편·이메일 발송, 세무·회계, 결제·청구 처리, 감사, 설문조사 수행, 이벤트 관리, 채용 프로세스, 고객 서비스, 데이터 고도화, 사기 예방, 영업, 웹 호스팅 또는 분석 서비스 등을 제공합니다. 이와 유사하게, 시스템 지원과 소프트웨어 및 데이터 저장을 목적으로 IT 공급업체와 개인정보를 공유할 수 있으며, 개인정보 보호에 요구되는 필수 안전 조치를 위해 서비스 제공업체와 별도의 계약을 체결하여 안전장치를 철저히 관리하고 있습니다. 개인정보 보호에 요구되는 필수 안전 조치를 위해 서비스 제공업체와 별도의 계약을 체결하여 안전장치를 철저히 관리하고 있습니다.
공공 기관 또는 정부 당국: 법적 의무·규정 또는 계약을 준수해야 하거나 법적으로 강제되는 법원의 명령, 행정·사법 절차에 대응하기 위해 법적 근거가 확보된 경우, 사법 당국, 데이터 보호 당국, 세무 당국, 신용 조회 기관, 채권 추심업체, 은행, 법원 또는 기타 관계 기관을 포함한 공공 기관 및 관련 단체에 개인정보를 공개하거나 제공할 수 있습니다.
법률 자문인 및 전문가 그룹: 분쟁, 청구 또는 소송 절차와 관련하여 자문을 제공받거나 대리할 필요가 있는 경우, 또는 규제 준수 의무를 지원받기 위해 관련 법률 전문가 등과 개인정보를 공유할 수도 있습니다.
공동 마케팅 파트너: 신청·등록한 이벤트, 웨비나 또는 경품 행사의 후원사, 또는 공동 마케팅 활동을 함께 진행하는 기타 협력사 등에 개인정보를 제공할 수 있습니다.
개인정보 이전
본 개인정보 처리방침에 명시된 목적을 달성하기 위해 필요하거나 요구되는 경우에 한하여, 법적 근거가 확보되고 적절한 이전 메커니즘이 이행된 범위 내에서만 개인정보를 제3국(예: 관련 개인정보 보호 규정에 따라 추가적인 안전조치가 요구되는 국가)으로 이전할 수 있습니다.
이러한 국외 이전을 수행할 때는 개인정보를 이전하기 전에 관련 법령에서 요구하는 적절한 안전조치(예: 개인정보를 이전하는 당사자 간에 체결된 표준계약조항 또는 개인정보 이전 계약 체결 등)가 마련되도록 보장합니다.
개인정보 보안
개인정보를 보호하기 위해 당사는 적절한 기술적·관리적 보호조치를 이행하고 있습니다. 아울러, 개인정보에 접근하는 당사 공급업체, 파트너 및 기타 수신처 역시 동일한 조치를 취하고 유사한 수준의 안전장치를 마련하도록 관리합니다. 다만, 어떠한 전자적 전송 및 저장 방식도 100% 안전할 수는 없으며, 절대적인 보안을 표준적으로 보장하기는 어렵다는 점을 유의하셔야 합니다. 웹사이트, 플랫폼, 애플리케이션 또는 기타 제품 및 서비스에 접근하기 위해 특정 인증 정보를 사용해야 하는 경우, 해당 인증 정보에 대한 기밀을 유지해야 하며 타인과 공유하지 않도록 철저히 관리해야 합니다.
당사와의 상호작용 과정이 더 이상 안전하지 않다고 의심되거나 개인정보가 침해되었을 가능성이 있는 경우, it.security@softwareone.com으로 즉시 연락해 주시기 바랍니다.
정보주체의 권리
개인정보 처리에 따라 다음과 같은 법적 권리를 행사할 수 있습니다.
- 개인정보 접근(열람) 및 해당 정보의 사본 수령
- 개인정보에 대한 정정 또는 삭제 요구
- 특정 조건하에 개인정보 처리 제한 요청
- 개인정보 이전 요구
- 개인정보 처리에 대한 반대(특히 당사의 정당한 이익에 기반하여 처리되는 경우)
- 개인정보 처리가 적용 가능한 데이터 보호 규정을 위반한다고 판단되는 경우, 감독 기관에 불만 제기(다만, 신속한 해결을 위해 감독 기관 접수 전 당사에 먼저 문의할 것을 권장)
이러한 권리는 절대적이지 않으며, 권리 행사가 제한되는 사례가 존재할 수 있습니다. 이 경우 항상 해당 사실을 통지하고 요청을 전적으로 이행할 수 없는 사유를 명확히 설명해 드립니다.
문의 정보
본 개인정보 처리방침 및 개인정보 보호 실무와 관련하여 문의 사항이 있거나, 추가 정보 요청 또는 불만 사항을 접수하고자 하는 경우 다음 연락처로 문의해 주시기 바랍니다.
SoftwareOne | 법무 - 개인정보 보호 부서
이메일: data-protection.eu@softwareone.com
EU/EEA, 스위스 및 영국 지역 담당 개인정보 보호 책임자:
FIRST PRIVACY GmbH
Konsul-Smidt-Straße 88
28217 Bremen, Germany
상기 언급된 국가 및 지역 이외의 개인정보 보호 책임자 연락처 정보는 여기에서 확인하실 수 있습니다.
Supplements
This Supplement applies to individuals located in Latin America and the Caribbean (“LATAM”), in addition to the above Privacy Notice, and provides additional clarifications to certain region specific processing activities and legal requirements.
Applicability of Local Data Protection Laws
In Brazil, when personal data is processed or relates to individuals located in Brazil, such processing is carried out in accordance with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais – “LGPD”, Law No. 13.709/2018).
In Mexico, the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) is the key regulation governing data processing by companies and individuals in Mexico. Under the new law of 2025, the Anti-Corruption and Good Governance Secretariat is the entity responsible for supervising and enforcing the law.
In Ecuador we will process and treat your Personal Data in accordance with the provisions of the Organic Law of Personal Data Protection (LOPDP) and other relevant regulations issued by the Superintendence of Personal Data Protection. The consent required by the (LOPDP) will be provided by you in the manner established in the Privacy Notice for each type of relationship.
In Chile, we will process your data in accordance with Law Nº 19.628: Sobre Protección de la Vida Privada.
In Puerto Rico, we process your personal data in accordance with applicable laws of the Commonwealth of Puerto Rico and relevant United States federal privacy and data security laws, including, where applicable, data breach notification and consumer protection regulations. SoftwareOne implements appropriate technical and organizational measures to ensure the security and confidentiality of personal data in line with generally accepted privacy standards.
In the Dominican Republic, we will process and handle your personal data in accordance with the provisions of Law No. 172-13 on the Protection of Personal Data, as well as other applicable regulations. The required consent under Law No. 172-13 will be obtained in the manner described in this Privacy Notice, depending on the nature of the relationship and the processing activities involved.
In Jamaica, when your personal data is processed or if you are located in Jamaica, we will process such data in accordance with the Data Protection Act, 2020, and any applicable regulations issued by the competent authority. SoftwareOne ensures that personal data is processed lawfully, fairly and transparently, and that appropriate safeguards are in place, including for international data transfers.
In Trinidad and Tobago, we will process your personal data in accordance with the Data Protection Act, 2011, and applicable regulations issued by the Office of the Information Commissioner. Personal data will be processed in a manner that ensures its confidentiality, integrity and security, and in line with the purposes described in this Privacy Notice.
Legal Basis – Regular Exercise of Rights (Brazil)
Where applicable, personal data may be processed for the regular exercise of rights in judicial, administrative or arbitration proceedings, in accordance with Article 7, item VI of the LGPD, including proceedings governed by the Brazilian Arbitration Law (Law No. 9,307 / 1996).
Communications (Brazil)
Individuals located in Brazil may submit privacy‑related requests and receive responses in Portuguese.
In accordance with ANPD Resolution No. 18 / 2024, SoftwareOne ensures that communications with data subjects and the Brazilian Data Protection Authority (ANPD) are carried out clearly and precisely in Portuguese.
Local Social Media Presence (Brazil)
In addition to global social media channels, SoftwareOne maintains local social media presences, as follows:
- LinkedIn: https://www.linkedin.com/company/softwareone-latam/
- X: https://x.com/softwareone_br
- Facebook: https://www.facebook.com/SoftwareOneBrasil/
- Instagram: https://www.instagram.com/softwareone_br/
- YouTube: https://www.youtube.com/@softwareonebrasil
Processing of personal data in this context is subject to the respective platforms’ local privacy policies:
- LinkedIn: https://br.linkedin.com/legal/privacy-policy
- X: https://x.com/pt/privacy
- Instagram: https://help.instagram.com/155833707900388
- YouTube: https://policies.google.com/privacy
International Data Transfers (Brazil and Ecuador)
Personal data may be transferred to third countries, provided that international treaties have been signed with those countries that allow the transfer of data and do not contravene local legislation.
International transfers of personal data originating from Brazil are conducted in accordance with the LGPD and ANPD Resolution CD/ANPD No. 19 of December 18, 2024 (Regulation of the International Transfer of Personal Data) and SoftwareOne relies on legal mechanisms that ensure an adequate level of protection for your personal data.
International Transfers of personal data originating from Ecuador will comply with the provisions of the LOPDP and SoftwareOne will only transfer personal data to countries and territories that comply with the standards of protection required by Ecuadorian laws and regulations.
Data Protection Rights (Brazil)
Individuals subject to the LGPD have the following rights:
- confirmation of the existence of processing;
- access to their data;
- rectification of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data or data processed in noncompliance with the LGPD;
- data portability upon express request;
- deletion of personal data processed with consent, to the extent permitted by law;
- information about public and private entities with which their personal data has been shared;
- information about the possibility of denying consent and its consequences;
- revocation of consent;
- upon request, obtain the full text of the clauses used to carry out an international data transfer, subject to trade and industrial secrets;
- lodge a complaint with a supervisory agency if they believe that the processing of their personal data infringes applicable data protection regulations.
In Brazil, the supervisory agency is the National Data Protection Agency (Agência Nacional de Proteção de Dados - ANPD).
Contact for data protection requests (Brazil and Ecuador)
In accordance with the LGPD and ANPD Resolution No. 18/2024, SoftwareOne has appointed a Data Protection Officer for Brazil. You may contact our DPO for any inquiries related to the processing of your personal data or to exercise your rights under the LGPD:
Vanessa Siqueira
data-protection.br@softwareone.com
The Data Protection Officer appointed for Ecuador (Encargado):
Nombre: Paul S Harris
Dirección: Ave. Naciones Unidas E699, Oficina 501. – Quito Ecuador
Teléfono: +593998325618
This Supplement applies to the handling of personal information of individuals located in Japan which is collected in Japan by SoftwareOne Japan K.K. or any other SoftwareOne entity with which you have established a relationship, as the case may be (individually or collectively, “SoftwareOne” or “we”) or a third party acting as a data processor on behalf of SoftwareOne, and supplements the above Privacy Notice. We comply with the Act on the Protection of Personal Information of Japan (Act No. 57 of 2003; the “APPI”).
Corporate Information
Under this Supplement, the entity responsible for handling your personal information is as follows:
Name: SoftwareOne Japan K.K.
Address: Hulic JP Akasaka Building 8F, 2-5-8 Akasaka, Minato-ku, Tokyo 107-0052
Representative: Kenji Hasegawa, CEO
Personal Information
“Personal information”, “personal data” and other related terms in this Supplement are to be interpreted as used in the APPI, unless otherwise defined herein; accordingly:
- “personal information” means information relating to a living individual which falls under any of the following items:
- information containing a name, date of birth, or other identifier or the equivalent (meaning all items (excluding individual identification codes) made by writing, recording, sound or motion, or other means, in a document, drawing, or electronic or magnetic record (this includes a record created in electronic or magnetic form (meaning electronic form, magnetic form, or any other form that cannot be perceived with the human senses; the same applies in the following item (ii)) which can be used to identify a specific individual (this includes any information that can be easily collated with other information and thereby used to identify that specific individual); and
- those containing an individual identification code; and
- “personal data” means personal information compiled in a personal information database or the equivalent.
Purposes of Use
We handle personal information solely within the scope necessary to achieve the purposes of use specified in the above Privacy Notice, except where otherwise permitted by the APPI or with your prior consent.
Proper Acquisition
We collect personal information in an appropriate manner and will not acquire any personal information through deception or other improper means.
Security Control Measures
We implement necessary and appropriate security control measures, including organizational, personnel, physical and technical safeguards, in order to prevent the leakage, loss or damage of any personal data we handle.
Joint Use
We may share and jointly use your personal data among our group companies.
- Items of Personal Data: As described in the “Relevant personal data” paragraph in each situation set forth in the above Privacy Notice.
- Scope of Joint Users: SoftwareOne AG and its consolidated subsidiaries.
- Purposes of Use: As described in Section 3 “Purposes of Use” above.
- Responsible Party for managing the personal data: SoftwareOne Japan K.K. (as identified in Section 1 above).
Cross Border Transfers
If we transfer your personal data to a third party outside Japan (excluding the EU and the UK), we will obtain your prior consent unless the recipient ensures an APPI-adequate level of protection or another legal exception under the APPI applies. Before seeking to obtain your prior consent, we will provide you with information on the name of the relevant foreign country, the personal information protection system of the foreign country, and the measures taken by the relevant third party to protect personal information.
Provision to Third Parties & Record-Keeping
We will not provide your personal data to any third party without your prior consent, except where permitted by the APPI or otherwise provided in this Supplement. When providing or receiving personal data from a third party, we will create and retain records in accordance with the APPI.
Your Rights under the APPI
In accordance with the APPI, you may request us for:
- notification of the purposes of use of the personal data we hold;
- disclosure of the content of your personal data we hold and the records we retain, or correction, addition or deletion of the content of your personal data we hold, if the content of such personal data is factual;
- suspension of use or erasure of your personal data we hold if the personal data has been obtained or is being handled in violation of the APPI; or
- cessation of third-party provision of your personal data we hold if the personal data is being provided to a third party in violation of the APPI.
You may also make a complaint about our handling of your personal data we hold, in accordance with the APPI. Such request or complaint must be made by submitting an inquiry to our contact point which can be found in Section 11. We will respond to such request or complaint in accordance with the APPI. Please note that we may collect the actual costs from you for taking the relevant measures in responding to your request for notification of the purposes of use of the personal data we hold or your request for disclosure of the content of the personal data we hold.
Sensitive Personal Information
We will not acquire any “sensitive personal information” as specified in the APPI (e.g., race, creed, social status, medical history, criminal record, the fact of having suffered damage by a crime) unless permitted under the APPI or with your prior consent.
Contact Point
To exercise your rights or for inquiries regarding our handling of personal data in Japan, please contact:
SoftwareONE Japan K.K.
Hulic JP Akasaka Building 8F, 2-5-8 Akasaka, Minato-ku, Tokyo 107-0052
+81 3 5005 2801
info.jp@softwareone.com
This Supplement applies where personal data is processed in the United Arab Emirates (“UAE”) or where the UAE Federal Decree Law No. 45 of 2021 on the Protection of Personal Data (“UAE PDPL”) is applicable. This Supplement shall be read together with the above Privacy Notice. Where any conflict arises, the provisions of this Supplement prevail for processing activities subject to the UAE PDPL.
Overseas Transfers (Articles 22–24 UAE PDPL)
SoftwareOne may transfer personal data outside the UAE only in accordance with the requirements of the UAE PDPL. Such transfers may take place where:
- The destination country appears on the UAE Data Office’s approved adequacy list;
- Appropriate contractual safeguards or legally recognized transfer mechanisms are implemented; or
- An exception under the UAE PDPL applies.
SoftwareOne ensures that all cross border transfers are supported by appropriate protection measures consistent with the UAE PDPL and the internal data protection standards.
Personal Data Breach Notification (Article 9 UAE PDPL)
In the event of a personal data breach that may pose a risk to the confidentiality, privacy, security or rights of individuals, SoftwareOne will:
- Notify the UAE Data Office without undue delay, and
- Notify affected individuals where the breach is likely to cause significant harm or impact.
SoftwareOne may maintains internal incident response processes to ensure timely detection, assessment, reporting, and mitigation of personal data breaches.
Data Protection Officer Requirement (Articles 10–11 UAE PDPL)
SoftwareOne appoints a Data Protection Officer (“DPO”) where required under the UAE PDPL, including scenarios involving:
- High risk processing operations, or
- Large scale processing of sensitive personal data.
The DPO supports ongoing compliance with the UAE PDPL, monitors internal controls, advises on data protection obligations and acts as a liaison with the UAE Data Office.
Rights of Individuals (Articles 13–20 UAE PDPL)
In addition to the rights outlined in the above Privacy Notice, individuals subject to the UAE PDPL may exercise the following rights:
- Right of access to personal data;
- Right to request correction or erasure;
- Right to restrict or stop processing;
- Right to data portability;
- Right to object to automated processing or automated decision making.
Requests may be submitted through the contact channels specified in the above Privacy Notice, and SoftwareOne will respond within the timelines mandated by the UAE PDPL.
Legal Basis for Processing (Article 4 UAE PDPL)
SoftwareOne processes personal data based on one or more legal bases recognized under the law, including:
- Consent;
- Necessity for performance of a contract;
- Compliance with legal obligations;
- Protection of public interest;
- Legitimate interests, to the extent permitted under the UAE PDPL.
Retention (Article 21 UAE PDPL)
Personal data subject to the UAE PDPL is retained only for the duration necessary to fulfil the purposes for which it was collected or as required by applicable legislation. SoftwareOne applies internal retention schedules aligned with the UAE PDPL’s data minimization and storage limitation principles.
Contact for UAE PDPL Requests
Individuals seeking to exercise their rights or raise concerns under the UAE PDPL may contact SoftwareOne at data-protection.me@softwareone.com.
This Supplement applies where personal data is processed within the State of Qatar or where the Qatar Personal Data Privacy Protection Law – Law No. 13 of 2016 (“Qatar PDPL”) is applicable. This Supplement shall be read together with the above Privacy Notice. Where any conflict arises, the provisions of this Supplement prevail for processing activities subject to the Qatar PDPL.
Overseas Data Transfers (Articles 15 & 16 Qatar PDPL)
SoftwareOne may transfer personal data outside the State of Qatar only in accordance with the requirements of the Qatar PDPL. Transfers may take place where:
- The receiving country provides an adequate level of protection;
- Explicit consent of the individual is obtained; or
- Appropriate safeguards or legally recognized transfer mechanisms are implemented.
SoftwareOne ensures that all cross border transfers follow the protection standards mandated under the Qatar PDPL.
Personal Data Breach Notification (Article 14 Qatar PDPL)
In the event of a personal data breach, SoftwareOne will:
- Notify the Ministry of Communications and Information Technology (MCIT) immediately, as required under the Qatar PDPL; and
- Notify affected individuals where the breach is likely to result in harm or adverse impact.
SoftwareOne maintains internal procedures to detect, assess and report breaches in accordance with statutory obligations.
Consent Requirements (Article 4 Qatar PDPL)
SoftwareOne obtains consent in accordance with the Qatar PDPL, ensuring that:
- Consent is explicit and informed;
- Consent is obtained prior to the processing of personal data;
- Additional safeguards are applied when processing sensitive personal data.
Where consent is withdrawn, SoftwareOne will cease processing activities unless another lawful basis under the Qatar PDPL applies.
Rights of Individuals (Articles 7–10 Qatar PDPL)
Individuals whose personal data is processed under the Qatar PDPL may exercise the following rights:
- Right of access to personal data;
- Right to request correction or erasure;
- Right to object to processing;
- Right to withdraw consent at any time.
Such rights can be exercised by reaching SoftwareOne at data-protection.me@softwareone.com. Replies will be received within the timelines specified under the Qatar PDPL.
This Supplement applies where personal data is processed within Australia or where the Privacy Act 1988 (Cth) (“Privacy Act”) is applicable. This Supplement shall be read together with the above Privacy Notice. Where any conflict arises, the provisions of this Supplement prevail for processing activities subject to the Privacy Act.
The type of personal data we use and what we do with that depends on the relationship we have with you. Therefore, some parts of this Supplement, as well as of the above Privacy Notice may not be relevant for you or more than one part of this Supplement, as well as of the above Privacy Notice may apply to you.
The meaning of the term “personal data” in this Supplement, as well as in the above Privacy Notice, has the same meaning as set out in the Privacy Act.
This Supplement, as well as the above Privacy Notice may be replaced or supplemented in order to fulfil legal requirements, as well as to provide you with all necessary information on how we process your personal data.
Why we collect personal data
We collect personal data so that we can provide our services to you and your service provider, as well as reasonable associated purposes. These purposes include but are not limited to the purposes already reflected in the above Privacy Notice.
We may also collect your personal information for a purpose which is additional to the original purpose pursuant to which we originally received or collected the personal data.
Personal data we collect
The types of personal data we may receive or collect include the following:
- Name or alias;
- Contact details (such as address, postal address, email, phone number);
- Date of birth;
- Sex, gender, or gender identity;
- Nationality or proof of residence (such as residence permits, work right permits or visa);
- Employment data (such as current employment, past employment or other work history);
- Educational qualifications (such as degrees, accreditations, occupational permits or occupational licences);
- Identification documents (such as passport, driver’s licence, identity card or other similar documentation);
- Pictures (such as head shots);
- Transaction and bank account details;
- Any personal information that is inherently disclosed when you or your service provider communicate with us (such as metadata); and
- Criminal history.
In limited circumstances we may need to obtain health information from you. In such circumstances we will make an express request and will treat any information as strictly confidential.
Further details about the personal data we collect and how it is processed or used depending on our relationship with you can be found in the above Privacy Notice.
How we collect personal data
We receive or collect personal data directly from your or your service provider’s in interactions with us, such as when you create a user account, sign up for our services, submit queries or engage with the services we provide. In addition to this, any personal data that you provide to us will constitute the collection of personal data for the purposes of this Supplement, as well as the above Privacy Notice.
Personal data may also be collected via our website, forms, phone calls, emails or through third-party providers with your consent or to the extent necessary to provide the services to you.
How we hold and protect personal data
We will only retain your personal data only so long as is necessary to provide our services, after which time we will destroy it, unless we:
- are required by law to retain it; or
- are required to preserve it for the purposes of providing services to another customer; or
- have agreed to a request by you or your service provider to preserve that personal information; or
- have a legitimate purpose for retaining it.
We take all reasonable steps to protect all information we hold, including personal data.
Cookies and other similar technologies
We may use cookies and similar technologies (for simplicity reasons, hereinafter referred to as “Cookies”), when you use our websites, platforms, applications as well as other products and services.
Our Cookie Banner and consent management system show you a list of the Cookies we use, including their provider, purpose, description and other relevant information. In the default setting, only the essential Cookies are enabled. Via the consent management system, you can determine whether you allow the setting of additional Cookies or not. You can adjust your preferences at any time via the consent management system.
Further information about the ways that we may track your personal information including on social media (e.g., Facebook) can be found in the above Privacy Notice.
Disclosure to third parties
We may disclose your personal data to parties to fulfil the purposes described above, including to provide services to you or your service provider. Due to SoftwareOne’s international group structure, personal data will be disclosed to certain departments and persons on a need-to-know basis to process personal data so that we can provide our services. For all intragroup personal data access and transfers, we comply with the provisions of the Privacy Act.
Third party service providers contracted by SoftwareOne may also receive personal data to provide or facilitate the provision of our services. These include, service providers who support us with order fulfilment, payment / billing, customer service, finance, auditing, fraud detection, IT services, communication, hosting, logistics, email delivery, marketing, sales, data analysis, event management, training, surveys, printing, archive, advisory and consulting services.
We may disclose your personal data to further recipients, such as private as well as public entities and institutions, including law enforcement, data protection authorities, tax authorities, credit agencies, debt collectors, banks, courts, hotels or other companies insofar as there is a legal basis for such disclosure.
Disclosure overseas
As we operate in a number of countries it is possible that your personal data may need to be transferred outside of Australia to countries in which we operate including the European Union, the United Kingdom and Switzerland, in order to provide our services. We will take reasonable steps to ensure that such recipients comply with the Privacy Act and maintain the confidentiality and security of your personal information.
Accessing or correcting personal data
You may contact us to access your personal data we hold about you and to request corrections if any details are inaccurate or incomplete. We may refuse to provide access you with to your personal data if:
- we are legally permitted to do so and consider it appropriate; or
- are required by law to deny the request.
Questions and complaints
If you have any requests, comments, queries or complaints in relation to your personal data, our handling of your personal data or how we handle personal data generally, please contact our information officer at data-protection.apac@softwareone.com.
We will respond to any requests or complaints within a reasonable period (usually 30 days).
If you disagree with our response or any decision that we make in respect of your personal data, including in respect of any complaint that you have made, you may refer your complaint to the Office of the Australian Information Commissioner by visiting www.oaic.gov.au, calling 1300 363 992 or by emailing enquiries@oaic.gov.au.
This Supplement applies where personal data is processed within New Zealand or where the Privacy Act 2020 (“Privacy Act”) is applicable. This Supplement shall be read together with the above Privacy Notice.
The type of personal data we use and what we do with that depends on the relationship we have with you. Therefore, some parts of this Supplement, as well as of the above Privacy Notice may not be relevant for you or more than one part of this Supplement, as well as of the above Privacy Notice may apply to you.
The meaning of the term “personal data” in this Supplement, as well as in the above Privacy Notice has the same meaning as set out in the Privacy Act.
This Supplement, as well as the above Privacy Notice may be replaced or supplemented in order to fulfil legal requirements, as well as to provide you with all necessary information on how we process your personal data.
Why we collect personal information
We collect personal data so that we can provide our services to you and your service provider, as well as reasonable associated purposes. These purposes include but are not limited to the following:
- communicate with you and your service provider, process requests and respond to requests;
- process comments or posts;
- register and send newsletters to you which you subscribe to;
- marketing purposes;
- registration, authentication and administration of user accounts;
- license monitoring purposes;
- provision of demo products and services as well as trials (also from third parties);
- analysis purposes in order to improve our products and services;
- tailor our website content and experience to your interests;
- maintain the security of our websites, platforms, applications as well other products and services;
- comply with legal and regulatory requirements and requests; and
- establish, exercise and defend legal claims.
We may also collect your personal data for a purpose which is additional to the original purpose pursuant to which we originally received or collected the personal data.
You are not required to give us your personal data, however, if you choose not to we may be unable to provide, in whole or in part, our services to you and your service provider.
Further details about the personal data we collect and how it is processed or used depending on our relationship with you can be found in the above Privacy Notice.
Personal data we collect
The types of personal data we may receive or collect include the following:
- Name or alias;
- Contact details (such as address, postal address, email and phone number);
- Date of birth;
- Sex, gender or gender identity;
- Nationality or proof of residence (such as residence permits, work right permits or visa);
- Employment data (such as current employment, past employment or other work history);
- Educational qualifications (such as degrees, accreditations, occupational permits or occupational licences);
- Identification documents (such as passport, driver’s licence, identity card or other similar documentation);
- Pictures (such as head shots);
- Transaction and bank account details;
- Any personal data that is inherently disclosed when you or your service provider communicate with us (such as metadata); and
- Criminal history.
During the course of providing services to you or your service provider we may create information about you which constitutes personal data including things such as emails, letters or other internal records.
Further details about the personal data we collect and how it is processed or used depending on our relationship with you can be found in the above Privacy Notice.
How we collect personal data
We receive or collect personal data directly from your or your service provider’s in interactions with us, such as when you create a user account, sign up for our services, submit queries or engage with the services we provide. In addition to this, any personal data that you provide to us will constitute the collection of personal data for the purposes of this Supplement, as well as the above Privacy Notice.
Information which we create as a result of providing services to you or your service provider which constitutes personal data will also constitute the collection of personal data for the purposes of this Supplement, as well as the above Privacy Notice.
Personal data may also be collected via our website, forms, phone calls, emails or through third-party providers with your consent or to the extent necessary to provide the services to you.
How we hold and protect personal data
We will only retain your personal data only so long as is necessary to provide our services, after which time we will destroy it unless we:
- are required by law to retain it; or
- are required to preserve it for the purposes of providing services to another customer; or
- have agreed to a request by you or your service provider to preserve that personal data; or
- have a legitimate purpose for retaining it.
We take all reasonable steps to protect all information we hold, including personal data.
Cookies and other similar technologies
We may use cookies and similar technologies (for simplicity reasons, hereinafter referred to as “Cookies”), when you use our websites, platforms, applications as well as other products and services.
Our Cookie Banner and consent management system show you a list of the Cookies we use, including their provider, purpose, description and other relevant information. In the default setting, only the essential Cookies are enabled. Via the consent management system, you can determine whether you allow the setting of additional Cookies or not. You can adjust your preferences at any time via the consent management system.
Further information about the ways that we may track your personal data including on social media (e.g., Facebook) can be found in the above Privacy Notice.
Disclosure to third parties
We may disclose your personal data to parties to fulfil the purposes described above including to provide services to you or your service provider. Due to SoftwareOne’s international group structure, personal data will be disclosed to certain departments and persons on a need-to-know basis to process personal data so that we can provide our services. For all intragroup data access and transfers, we comply with the provisions of the Privacy Act.
Third party service providers contracted by SoftwareOne may also receive personal data to provide or facilitate the provision of our services. These include, service providers who support us with order fulfilment, payment / billing, customer service, finance, auditing, fraud detection, IT services, communication, hosting, logistics, email delivery, marketing, sales, data analysis, event management, training, surveys, printing, archive, advisory and consulting services.
We may disclose your personal data to further recipients to the extent required to fulfil the purpose, such as private as well as public entities and institutions, including law enforcement, data protection authorities, tax authorities, credit agencies, debt collectors, banks, courts, hotels or other companies insofar as there is a legal basis for such disclosure.
Disclosure overseas
As we operate in a number of countries it is possible that your personal data may need to be transferred outside of New Zealand to countries in which we operate including the European Union, the United Kingdom and Switzerland, in order to provide our services. We will take reasonable steps to ensure that such recipients comply with the Privacy Act and maintain the confidentiality and security of your personal data.
Accessing or correcting personal data
You may contact us to access your personal data we hold about you and to request corrections if any details are inaccurate or incomplete. We may refuse to provide access you with to your personal data if:
- we are legally permitted to do so and consider it appropriate; or
- are required by law to deny the request.
Questions and complaints
If you have any requests, comments, queries or complaints in relation to your personal data, our handling of your personal data or how we handle personal data generally, please contact our information officer at data-protection.apac@softwareone.com.
We will respond to any requests or complaints within a reasonable period (usually 30 days).
If you disagree with our response or any decision that we make in respect of your personal data including in respect of any complaint that you have made, you may refer your complaint to the Privacy Commissioner (Te Mana Matapono Matatapu) by visiting www.privacy.org.nz, calling 0800 803 909 or by emailing enquiries@privacy.org.nz.
Applicability
This Supplement forms an integral part of the above Privacy Notice and applies solely to Data Principals located in India.
This Supplement governs the processing of digital personal data by SoftwareOne in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made thereunder ("DPDP Rules"), including:
- personal data collected in digital form within India;
- personal data collected in non-digital form and subsequently digitized; and
- processing of digital personal data carried out outside India in connection with the offering of goods or services to Data Principals within India, in accordance with Section 3 of the DPDP Act.
In the event of any inconsistency between this Supplement and the above Privacy Notice, the provisions of this Supplement shall prevail to the extent of such inconsistency for processing governed by Indian law.
Definitions
Unless otherwise defined herein, capitalized terms used in this Supplement shall have the meanings ascribed to them under the DPDP Act and the DPDP Rules.
For the purposes of this Supplement:
- "Board" means the Data Protection Board of India established under the DPDP Act;
- "Data Principal" means the individual to whom the personal data relates and where such individual is
- a child, includes the parents or lawful guardian of such child; or
- a person with disability, includes her lawful guardian acting on her behalf.
- "SoftwareOne" means the relevant SoftwareOne entity acting as a Data Fiduciary in relation to the processing of personal data under Indian law.
Notice to Data Principals
Consent to the processing of personal data by SoftwareOne shall be obtained only upon the Data Principal’s acceptance of this Supplement and the above Privacy Notice.
Contact for Data Protection Requests
Any request for withdrawal of consent, request for access to information, correction, erasure, grievance or any other communication under the DPDP Act may be addressed to:
Designation / Department: Regional General Counsel
Email ID: data-protection.apac@softwareone.com
Alternately, the Data Principal may communicate his request at: Shweta.Sinha@softwareone.com.
Grievance Redressal Mechanism
SoftwareOne has established an effective grievance redressal mechanism to address grievances raised by Data Principals in relation to the processing of their personal data.
A Data Principal may submit a grievance by contacting the Grievance Officer at:
Name: Regional General Counsel
Designation: Grievance Officer – India
Email ID: data-protection.apac@softwareone.com
Postal Address: 7th Floor, Tower 1A, International Tech Park, Near Sector 59, Behrampur, Gurugram, Haryana-122101.
SoftwareOne shall acknowledge the grievance and endeavor to resolve it within 30 days from the date of receipt.
A Data Principal shall exhaust the grievance redressal mechanism provided herein before approaching the Board, in accordance with Section 13 of the DPDP Act.
Nomination
A Data Principal may nominate one or more individuals to exercise her rights under the DPDP Act in the event of her death or incapacity.
Such nomination may be made by:
- submitting a request through the user account or digital interface made available by SoftwareOne; or
- submitting a written request to SoftwareOne using the contact details provided in this Supplement, along with such information and verification details as may be reasonably required by SoftwareOne.
Processing and Transfer of Personal Data Outside India
SoftwareOne may transfer personal data outside the territory of India only in accordance with:
- any restrictions notified by the Central Government on the transfer of personal data to specified countries or territories; and
- the conditions and safeguards specified by the Central Government through general or special orders.
Where such transfers occur, SoftwareOne shall ensure compliance with all applicable requirements under the DPDP Act, the DPDP Rules, and other applicable Indian laws.
Updates to this Supplement
This Supplement may be updated from time to time to reflect changes in applicable law, including amendments to the DPDP Act or the DPDP Rules, or guidance, directions or orders issued by the Government of India or the Data Protection Board of India. Material changes shall be notified to Data Principals through appropriate and reasonable means.
Children’s Personal Data
SoftwareOne does not knowingly process personal data of children, as defined under the DPDP Act.
Where processing of personal data of a child becomes necessary under applicable law, SoftwareOne shall ensure compliance with the requirements relating to verifiable parental consent and other safeguards prescribed under the DPDP Act and the DPDP Rules.
Additional DPDP-Specific Disclosures
Right to Withdraw Consent: Withdrawal of consent shall not affect the legality of processing carried out prior to such withdrawal.
Data Retention: SoftwareOne shall retain personal data only for such period as is necessary to fulfil the specified purpose or to comply with applicable law, after which such data shall be erased in accordance with the DPDP Act and the DPDP Rules.
본 개인정보 처리방침의 변경
당사는 관련 법령, 실무 및 서비스의 변경 사항을 반영하거나 투명성을 향상시키기 위해 본 개인정보 처리방침을 수시로 업데이트할 수 있습니다. 중대한 변경이 발생하는 경우, 본 방침 최상단의 시행일을 업데이트하여 변경 사실을 공지합니다. 따라서 개인정보를 어떻게 수집, 사용 및 보호하는지 지속적으로 파악할 수 있도록 본 개인정보 처리방침을 정기적으로 검토할 것을 권장합니다.
SoftwareOne과 Crayon 간의 합병에 따라, 본 개인정보 처리방침의 시행일 이전에 수집된 개인정보에 대해서는 양사의 이전 개인정보 처리방침이 계속 적용될 수 있음을 유의하시기 바랍니다.
- 시행일 이전에 SoftwareOne이 수집한 개인정보는 여기에서 제공되는 이전 개인정보 처리방침을 참조해 주시기 바랍니다.
- 시행일 이전에 Crayon이 수집한 개인정보는 여기에서 제공되는 이전 개인정보 처리방침을 참.
개정 이력
| 버전 | 날짜 |
|---|---|
| 1.0 | 2020년 6월 |
| 2.0 | 2021년 9월 |
| 3.0 | 발효일: 2026년 8월 |