隐私声明
我们非常重视隐私保护
隐私声明
生效日期:2026 年 8 月
您的隐私对于 SoftwareOne 及其关联公司(以下统称 “SoftwareOne”、“我们”、“我方”)至关重要。本隐私声明将说明我们可能收集您的哪些个人数据、个人数据使用方式,以及您享有的数据保护权利。
我们使用的个人数据类型及使用方式取决于我们与您之间的关系。因此,本隐私声明中的某些部分可能与您无关,或者有多个部分可能适用于您。
请注意:若我们作为数据处理方代表客户处理个人数据,本隐私声明不适用。该类场景下的个人数据处理规则,由我方与作为数据控制方的客户另行签订协议约定。
若本隐私声明中含有可跳转至非我方运营或管控网站的链接,请知悉:该网站运营方将负责处理您在其平台提交的个人数据,建议您查阅对应平台的隐私声明。在这种情况下,我方无法管控第三方网站对您个人数据的使用与处理行为,亦不对第三方的相关操作承担责任。
我们是谁
负责处理您个人数据的主体是与您建立业务关系的 SoftwareOne 实体(即数据控制方),例如您访问其网站、使用其服务、报名活动或应聘岗位对应的主体。点击此处可查看各 SoftwareOne 实体详情。
无论个人数据是由您本人、您所代表的企业直接提供,还是从其他第三方获取,我们均会依据下述目的及法律依据开展数据处理工作。
创建和管理用户账户
如需安全访问并使用我方网站、平台、应用及其他产品和服务,您需要在我方注册并维护个人账户。我们会在您注册账户,以及进行身份验证、账户管理与维护的过程中处理您的个人数据。
若您注册试用账户体验我方网站、平台、应用及其他产品和服务,我们将收集您的个人数据,用于身份核验、开通临时服务、监测使用情况,并就试用账户相关事宜与您沟通。
若我方网站、平台、应用及其他产品和服务附带独立隐私声明,对个人数据的收集与使用规则另行作出说明,请您以该声明为准。
涉及个人数据:联系方式(姓名、电子邮箱、电话号码、职位、公司名称等)、注册时间、登录记录、使用数据、操作行为数据。
关于您的此类个人数据的处理法律依据:履行与您订立的合同,完成账户的开设、管理及维护。
响应请求
我们会收集您的个人数据,通过在线聊天窗口、联系表单及其他方式接收并处理您向我方递交的请求。
涉及个人数据:联系方式(姓名、电子邮箱、电话号码、职位、公司名称等)、通讯地址、所在国家、请求内容、请求提交时间,以及您可能自愿提供的其他信息。
关于您的此类个人数据的处理法律依据:适用情形下,为履行法定义务或合同约定;其余情形基于我方合法权益,包括维护双方沟通、为您提供优质服务与使用体验。
帖子和评论
您可以在我们的网站、平台、应用以及其他产品和服务上发布帖子和评论。在此情况下,您发布的内容可能可以公开访问。请注意,在您的帖子和评论发布之前,我们可能还会进行手动审核,从而导致发布延迟。如果您提供姓名或别名,该名称将出现在您的帖子或评论旁边。
涉及个人数据:姓名/昵称、帖子及评论内容、发布日期和时间,以及您可能自愿提供的其他信息。
关于您的此类个人数据的处理法律依据:基于我方合法权益,用于维护用户互动、优化产品与服务。
时事通讯
您可以订阅我方时事通讯,内容涵盖 IT 行业前沿动态、重点资讯、新品与服务介绍、近期活动、优惠活动以及行业决策者关注的重要事项。
订阅时,我们需要您提供电子邮箱地址。在某些地区,您在提交订阅表后将收到一封确认信。在此情况下,订阅将在您点击确认信中的链接后生效。
订阅后,我们可能会在时事通讯中嵌入个体跟踪技术,以便识别您查看或打开时事通讯的时间,并对通讯中的链接进行个性化处理,以便了解您点击通讯中的哪些链接及点击时间。
您可以随时取消订阅时事通讯。如需取消订阅,可使用每封邮件末尾的取消订阅链接,或发送邮件至 info.global@softwareone.com。
涉及个人数据:联系方式(姓名、电子邮箱、电话号码、职位、公司名称等)、所在国家、互动数据(时事通讯是否打开、打开时间、访问次数、点击的链接等)。
关于您的此类个人数据的处理法律依据:您同意接收时事通讯。
营销推广
当您以客户、合作伙伴(含潜在客户)身份与我方对接时,我们会收集您的个人数据。同时,我方也可从具备合法授权的正规第三方机构获取个人数据,用于开展营销活动,包括但不限于向您推送活动预告、产品、服务及优惠资讯。
此外,我们会借助追踪技术自动采集 IP 地址、邮件打开及链接点击等互动数据,用于统计推广效果,提升营销内容的相关性与投放成效。
涉及个人数据:联系方式(姓名、电子邮箱、电话号码、职位、公司名称等),以及您提供的其他信息。
关于您的此类个人数据的处理法律依据:您同意接收营销信息,或我方开展营销活动的合法权益。
许可与技术使用分析
基于与客户的合作关系,我们会处理软件许可及技术使用环境相关数据,在全合作周期内充分了解、管理并响应客户需求。
若客户授权我方访问其技术环境,或使用我方及经认可的第三方工具,我方将在对应平台或技术的授权范围内,查看许可类型、分配情况及使用数据,其中包括通过我方获取的以及从其他供应商处获取的且经授权查看的许可。
我们使用上述数据优化许可配置与使用、核验服务资格、按用户或许可数量结算并提供对应服务,同时分析全体客户的整体使用趋势。相关分析结果也将用于新品研发、现有服务升级及挖掘商业机会。
我方仅在客户授权范围及合同约定内,访问或处理许可/使用数据。
涉及个人数据:用户/设备标识、许可分配及使用数据、服务使用指标、相关技术元数据。
个人数据处理法律依据:基于我方合法权益,对产品和服务进行管理与拓展,在合作全周期内为客户提供支持、开展经营活动,以及在适用情况下履行合同义务。
Cookie 和其他类似技术
您使用我方网站、平台、应用及其他产品和服务时,我们可能会使用 Cookie 及同类技术。Cookie 是网站存储在您设备中的小型文本文件,可记录您的使用偏好、登录信息及浏览行为,为您打造个性化、高效且流畅的使用体验。该技术也常用于网站流量统计、会话管理及内容精准推送。
必要 Cookie
保障网站基础运行,无法禁用。
功能型 Cookie
实现拓展功能,加载字体、视频、地图、社交插件及嵌入式服务等第三方内容。
分析及营销 Cookie
统计用户与网站的互动,支撑广告投放与营销活动开展。
我们使用此类 Cookie 分析使用数据,研究您使用我方网站、平台、应用及其他产品和服务的行为,以此优化使用体验。同时,我们会借助第三方工具生成匿名会话记录,分析网站使用情况、优化功能。记录中不含任何个人数据,敏感字段均已做脱敏处理,以保护您的隐私。
我方还会使用跨设备追踪技术,在站外投放定向广告并评估广告效果。若您开启非必要 Cookie,Cookie 提示栏中列明的第三方服务商可访问您的浏览器与设备、分析您的 IP 地址、存储或读取设备识别标识、调用追踪像素,并凭借相关标识跨网站识别您的设备。若您使用个人账户登录第三方平台,不同设备(电脑、手机、平板)的识别标识可能被关联,供第三方开展跨设备广告投放。
我们也会使用网站分析工具优化页面设计、识别回访用户。此类工具依托匿名标识生成使用日志,并结合 Cookie 运行,相关说明详见Cookie 提示栏。
对于某些未存储于服务器上的服务,我们还会将其嵌入到我们的网站中。例如,您可以使用地图查看 SoftwareOne 实体的确切位置,也可以观看视频。在某些地区,我们可能会确保您访问我方网站、平台、应用或其他带有嵌入式内容的产品和服务时不会自动向第三方供应商提供任何信息,我们仅显示本地存储的缩略图。在此情况下,仅当您通过Cookie 提示栏表示同意时,才会加载来自第三方供应商的内容。当您查看内容时,第三方供应商会接收到相关信息,显示您曾访问我们的网站,以及在此方面提供服务所需的使用数据。如果第三方供应商进行进一步的数据处理,我们无法施加任何影响。
我方Cookie 提示栏由第三方提供,会列明我方使用的 Cookie 及对应服务商。默认设置下,仅启用必要 Cookie。您可以随时通过Cookie 提示栏选择是否启用其他 Cookie,并调整偏好设置。您可以随时通过Cookie 提示栏调整您的偏好设置。
相关个人数据:IP 地址、设备及浏览器信息、安全与反爬识别数据、Cookie 授权偏好、网站互动数据(视频播放、地图使用、嵌入式内容操作等)、基于 IP 解析的大致地理位置、网络请求与性能数据、浏览页面及行为轨迹(点击、滑动、访问路径等)、页面停留时长与会话时长、Cookie 标识及广告标识、转化与互动事件(表单提交、功能操作等)、营销活动数据。
关于您的此类个人数据的处理法律依据:对于必要 Cookie,基于我方合法权益,保障网站正常展示;对于非必要 Cookie 及同类技术,以您的同意为依据。
数字产品与服务中的人工智能应用
我方会使用人工智能(下称“AI”)工具(含生成式 AI)优化您的网站、平台、应用及其他产品与服务的使用体验,例如搭载智能客服、完成内容翻译与摘要、推送个性化内容、审核帖子与评论、迭代产品功能等。若人工智能输出内容可能对您产生实质性影响,我方将安排人工复核。
当您访问我们的主要社交媒体(账户链接如下)页面时,我们可能会处理您的个人数据:
- LinkedIn:https://www.linkedin.com/company/SoftwareOne
- X:https://x.com/SoftwareOne,https://x.com/SWO_Careers
- Facebook:https://www.facebook.com/Softwareone/,https://www.facebook.com/softwareonecareers
- Instagram:https://www.instagram.com/softwareone/,https://www.instagram.com/swocareers/
- YouTube:https://www.youtube.com/SoftwareOne-global
- Tik Tok:https://www.tiktok.com/@swocareers?_r=1&_t=ZN-94SU63n1PIl
我方与对应社交媒体平台运营方共同承担个人数据处理责任。平台方主导个人数据处理的目的与方式,我方仅能有限干预。
您在我方社交媒体页面发布的评论、视频、图片、点赞、公开留言等内容,将由平台方对外展示,我方不会将其挪作他用,但保留必要时删除相关内容的权利。如果社交媒体页面具有相关功能,我们可能会将您的内容分享在我们的网站上,并通过社交媒体页面与您沟通。
如果您在我们的其中一个社交媒体页面上向我们提交请求,则根据您请求的内容,我们也可能会考虑使用其他能够确保机密性的安全通信渠道。您可以随时通过其他提供的渠道向我们发送机密请求。若您对个人数据处理行为提出异议,请按照“联系方式”一节中的说明联系我方。我方将核查您的诉求,判断能否受理及干预相关处理行为;超出我方权责范围的,需要您直接联系对应社交平台运营方。
我们可能会使用社交媒体页面进行广告宣传。为此,我们可能会使用由相应社交媒体页面提供商提供的人口统计信息以及基于兴趣、行为或位置的目标群体特征信息。我们只能在有限的范围内对数据处理施加影响,无法禁用相应社交媒体页面提供商向我们提供的统计数据。
我们为各个社交媒体渠道使用转化跟踪选项。为此,我们在网站上加入了相应的像素或便签,以便收集转化数据。您可以通过Cookie 提示栏选择是否启用此类非必要 Cookie,并随时调整偏好设置。
我方使用人工智能工具(含生成式 AI)运营社交账户,例如撰写、翻译文案,制作、编辑视觉内容,审核主页评论,汇总分析互动数据,所有对外发布内容均经过人工审核。社交媒体平台自身搭载的 AI 功能,适用其独立隐私声明。
由社交媒体提供商进行数据处理
社交媒体提供商可能会使用网络跟踪方法。无论您是否在社交媒体平台上登录,提供商都可以执行网络跟踪。如前所述,社交媒体页面的网络追踪技术不受我方管控,我方也无法关闭此类功能。请注意,相关社交媒体页面方可能会结合您的账户信息与行为数据,分析您的使用习惯、社交关系及个人偏好。如果相关社交媒体页面提供商对您的数据进行处理,我们无法施加任何影响。
有关在社交媒体页面上处理个人数据的更多信息,请访问下面列出的相应提供商的隐私声明:
- LinkedIn:https://www.linkedin.com/legal/privacy-policy
- X:https://x.com/en/privacy
- Facebook:https://www.facebook.com/privacy/explanation
- Instagram:https://help.instagram.com/155833707900388
- YouTube:https://policies.google.com/privacy?hl=en
- TikTok:https://www.tiktok.com/legal/page/us/privacy-policy/en
相关个人数据:姓名、所属企业、电子邮箱、所在国家,以及您主动向我方提供的其他信息。
关于您的此类个人数据的处理法律依据:基于我方合法权益,在社交平台开展品牌、服务及产品宣传推广,提升营销活动的成效与相关性,优化整体营销表现,同时服务于公关与对外沟通工作。非必要 Cookie 的启用以您的同意为依据,您可以随时通过Cookie 提示栏调整设置。
产品或服务的购买与使用
为了帮助您购买和使用我们的产品或服务,我们可能需要处理您的个人数据。相关个人数据可由您本人、您所代表的企业、合作供应商或商业伙伴直接提供。
根据所提供产品与服务的不同,我们分为两种身份处理个人数据:
- 针对部分产品和服务,我方独立确定个人数据的处理目的与方式;
- 针对其余产品与服务,我方作为数据处理方代表客户开展工作。该类场景下的具体处理规则,详见我方与客户签订的数据处理协议。
该等相关数据处理工作用于维护我方与您及您所代表企业的合作关系,包括协议洽谈、签署及报价对接。
在提供部分产品与服务的过程中,我们会处理相关数据,用于检测、排查及应对网络安全威胁,包括系统监控、安全事件分析,以及应对影响客户环境的潜在安全事故。
若您在采购前注册试用账户体验我方产品与服务,我们将收集您的个人数据,用于身份核验、开通临时服务、监测产品使用情况,并就试用账户相关事宜与您沟通。
我们有时会开展市场调研与满意度调查,以此了解您对我方产品、服务的体验、诉求与建议,持续优化产品服务及与客户、合作伙伴、意向方的合作关系。在此情况下,您有权反对此等处理。如需详细了解如何行使您的权利,请参见下文“联系方式”。
相关个人数据:联系方式(姓名、电子邮箱、电话号码、职位、公司名称等)、登录凭证、注册时间、使用数据、系统及安全日志(身份验证日志、网络流量元数据、终端监测数据等)、IP 地址、设备标识、设备及应用数据(主机名、操作系统、应用使用元数据等)、安全事件相关数据(疑似恶意行为对应的文件、内存数据、日志等),以及您在采购和使用产品服务过程中主动提供的其他信息。
关于您的此类个人数据的处理法律依据:基于我方合法权益,与您所代表的法人主体洽谈、签订并履行合同,完成产品销售与服务交付。开展市场调研、问卷调查及开通试用账户,亦基于该合法权益,向作为潜在客户代表的您展示我方产品或服务。
产品与服务优化
您在使用我方产品与服务期间,我们会处理您的个人数据,用于数据统计及产品服务优化。
相关个人数据:姓名、电子邮箱、IP 地址、浏览内容、访问时间、数据传输量、访问状态、浏览器及操作系统、跳转来源链接。
关于您的此类个人数据的处理法律依据:基于我方合法权益,统计整体运营情况、优化产品与服务,最终提升您的使用体验。
客户资信核验
签订合作协议前,我们会处理个人数据开展客户资信审查,管控合作全周期内的财务风险,包括在企业资源规划 (ERP) 系统中核验客户信息、授信额度,完成交易前置审核。
相关个人数据:联系方式(姓名、电子邮箱、电话号码、职位、公司名称等)、财务记录、信用评分、付款记录、未结清欠款、证件编号(增值税号、企业注册号等)、征信机构提供的与您个人相关的信息。
关于您的此类个人数据的处理法律依据:基于我方合法权益,评估客户资信状况、降低财务风险。
尽职调查与背景审核
开展合作前,若您代表客户、合作伙伴或意向方与我方对接,我们会处理您的个人数据,完成尽职调查与背景审核。在符合法律法规要求的前提下,尽职调查与背景审核包括安全、隐私及资质核验。
涉及个人数据:联系方式(姓名、电子邮箱、电话号码、职位、公司名称等),以及您自愿提供的其他信息。
关于您的此类个人数据的处理法律依据:基于我方合法权益,核查合作方资质、管控合作风险。
客户与合作伙伴对接中的人工智能应用
我方会使用 AI 工具(含生成式 AI)开展经营与运营工作,例如撰写、定制沟通文案,整理会议及邮件内容,翻译文档,分析账户信息,分流、响应服务诉求,协助拟定方案与合同等。若 AI 输出内容可能对您产生实质性影响,我方将安排人工复核。除法律另有规定外,我方不会仅凭自动化系统作出具备法律效力或重大影响的决策。
活动报名与管理
若您报名参加我方或合作方举办的研讨会、网络研讨会、培训课程、线上会议及其他活动(以下统称“活动”),我们会处理您的个人数据信息,用于沟通对接、活动组织及落地执行。
活动举办过程中,我们可能委托第三方服务商(如视频会议、通讯服务提供商)协助开展工作,并向其共享您的个人数据。
部分活动会进行录制,详情请参见下文“音视频内容”板块。
我们有时会推送活动调研问卷,您可自愿填写,帮助我方优化活动形式与内容。
若活动为线下形式,需要您亲临现场,请参阅单独发布的活动隐私声明,其中详述了我们针对该特定活动处理您个人数据的相关细则。
涉及个人数据:联系方式(姓名、电子邮箱、电话号码、职位、公司名称等)、会议昵称、IP 地址、设备/硬件信息(MAC 地址、设备版本等)、文字、音频、视频数据、通讯数据(电话号码、所在国家、活动起止时间等),以及您在报名及活动过程中自愿提供的其他信息。
关于您的此类个人数据的处理法律依据:基于我方合法权益,开展活动运营、品牌宣传,推送调研问卷以评估并优化活动效果。
音视频内容
我方及合作方举办活动期间,可能拍摄照片、录制视频(以下统称“音视频内容”)。音视频内容可能包含参会人员、发言嘉宾及台上人员影像。我方可能将相关素材发布至官网、社交平台及其他数字或纸质载体。若您不希望出现在音视频内容中,请及时告知拍摄人员或活动主办方。同时,我们建议您在参与线下活动时,留意避开拍摄画面,避免被拍照或录像。
若需单独拍摄参会人员个人音视频内容,我方会提前告知并征得您的同意后再执行。
您有权拒绝相关信息处理,或撤回已作出的同意。尽管我们会尽力配合您的要求,但众所周知,发布在互联网(包括社交媒体平台)上的任何信息都会被全球用户查看,且极易被不受我方控制、无关联的第三方复制和传播。即便我方删除相关内容,也无法保证全网彻底清除,您如需进一步处理,需联系对应搜索引擎或平台运营方。
若您的影像已用于印刷品(宣传册、刊物、时事通讯等),且撤回诉求导致整改成本过高,现有印刷品可继续使用直至消耗完毕,我方不会在新印刷品中继续使用您的影像。
涉及个人数据:照片、视频、录音,以及收集或共享的其他生物特征信息。
关于您的此类个人数据的处理法律依据:对于集体活动音视频内容的处理,基于我方合法权益,用于活动运营与品牌宣传;对于个人专属音视频内容的处理,以您的同意为依据。
活动中的人工智能应用
为保障活动开展、留存活动资料及优化活动体验,我方及活动、会议服务商提供的 AI 功能,可用于实时录制及会后整理文稿、撰写摘要、生成要点、实时字幕、即时翻译、问答及互动管理、汇总分析参与数据。若活动开启转录、摘要或录制功能,我方会在活动开始前告知您;如需授权,将征得您的同意。
我们会处理您的个人数据,信息来源包括您本人主动提交、公开渠道(职场平台、社交平台、招聘网站等)及第三方机构(人力资源服务商、院校、招聘中介、推荐人、税务及社保机构等)。
个人数据处理用途如下:
- 在我们的招聘系统中为您创建账户;
- 审阅您提交的简历及相关材料,必要时借助 AI 系统评估您的技能、从业经验与资质;
- 安排面试及综合测评;
- 符合法律许可或要求的前提下,开展背景调查及社交信息核查,作为录用参考;
- 同步招聘进度;
- 依法报销应聘期间产生的差旅费用;
- 归档应聘资料,应聘成功后建立劳动关系;
- 结合您的兴趣与技能推送岗位信息,同步招聘动态;
- 发放调研问卷,优化招聘流程等。
应聘岗位时,请仅提交与应聘岗位相关的信息。部分岗位可自愿填写人口统计信息(性别、种族、国籍等),用于落实平等就业政策及法定报备要求。此类信息不参与招聘筛选,不会影响录用结果。
针对部分岗位,我方会使用第三方测评及招聘工具(视频面试平台、标准化测评、岗位模拟、AI 辅助筛选等)推进招聘工作。相关工具可结构化收集应聘信息、安排面试测评、核验岗位技能、生成分析报告,供招聘人员参考。根据岗位及所用工具的不同,相关环节可能包括审阅您的简历与应聘材料、邀请您作答标准化问题(文字、音频、视频形式均可),并生成供招聘人员查看的总结、评分或可信度指标。我方仅将以上结果作为决策辅助,最终审核及录用决定均由招聘人员作出。若测评环节为自愿参与,我方会明确说明,并尽可能提供替代方案。
我方也会使用 AI 筛选职场平台及招聘网站的候选人、安排面试、转录并总结面试内容、翻译应聘材料、撰写招聘沟通文案。AI 输出内容仅作辅助,不会替代招聘人员工作,我方不会仅凭自动化系统作出录用决定。您可直接向招聘人员,或按照“人工智能”板块中的联系方式,申请人工复核 AI 处理结果。
在您注册我方账户后,您可以修改个人数据偏好及邮件订阅设置,相关功能均位于您的账户后台面板中。您也可以随时发送邮件至 iCIMS.help@softwareone.com 寻求协助。
若您求职未成功,且已同意我们延长保存您的个人信息(以便后续有合适职位机会时联系您),我们将继续保存该信息两年,期满后将予以删除。若您未同意延长留存期限,我方会在招聘流程结束后六个月内删除相关信息,具体遵照法律法规执行。您也可随时依据“您的权利”板块内容,申请删除个人数据。
涉及个人数据:联系方式(姓名、电子邮箱、电话号码、职位、公司名称等)、简历(含本人照片)、求职信、推荐信、居住地址、身份信息(出生日期、国籍、身份证件、护照等)、从业信息(工作履历、劳动合同、在职状态、岗位信息、工作/居留许可等)、学历及资质信息(学位、证书、从业经历、兼职信息、推荐人、其他资质证明材料等)、问卷及测评结果、法律许可范围内收集的健康信息、银行账户信息(用于报销差旅费用),以及您自愿提供的其他信息。
关于您的此类个人数据的处理法律依据:
- 基于我方合法权益,创建应聘账户、审阅简历、安排面试测评、背景调查及整体招聘工作;
- 基于我方合法权益,发放调研问卷,优化招聘流程与整体工作效率;
- 基于我方合法权益,应对法律纠纷、维护品牌权益;
- 若您应聘未果,经您同意后,延长个人数据的安全留存期限;
- 如需在应聘流程中使用 AI 工具(例如 AI 辅助测评、视频面试),以您的同意为依据;
- 履行合同:应聘成功后建立劳动关系;
- 履行法定义务:遵守监管要求、处理投诉、应对法律纠纷。
企业交易
随着业务发展,我方可能开展各类企业交易。若我方全部或部分业务、资产、股权发生重组、出售、合并、整合、合资、转让、处置(含破产及类似程序),您的个人数据可能会向相关第三方披露或移交。
涉及个人数据:联系方式(姓名、电子邮箱、电话号码、职位、公司名称等)、账户凭证、采购及交易记录、推进企业交易所需的其他信息。
关于您的此类个人数据的处理法律依据:基于我方合法权益,推进企业交易、保障业务持续运营。
纠纷处理
为维护合法权益、提出及应诉、参与法律程序(含涉及第三方的相关流程),我们会处理您的个人数据。 涉及个人数据:联系方式(姓名、电子邮箱、电话号码、职位、公司名称等)、合同文件、往来沟通记录、使用日志、交易记录,以及与纠纷相关的其他信息。 关于您的此类个人数据的处理法律依据:基于我方合法权益,维护自身法律权益、高效处理纠纷。合规履职
为履行法律法规规定的义务,我方可能需要向公共机构、监管部门、执法机关(公安、法院等)提交或共享您的个人数据。我方也可能聘请外部审计、咨询机构协助完成合规工作,并按需共享相关信息。工作内容包括留存记录、提交报表、依法披露信息。部分场景下,提交个人数据为法定义务,或需配合官方要求;其余场景下,我方会主动提交合规所需报表。
涉及个人数据:联系方式(姓名、电子邮箱、电话号码、职位、公司名称等)、交易记录、沟通记录、账户操作记录,以及证明合规情况所需的其他信息。
关于您的此类个人数据的处理法律依据:履行法定义务。
问题举报
SoftwareOne 始终恪守高水准的职业操守与合规要求。为此,我方开通了 SoftwareOne Integrity Line,作为安全、保密的反馈入口,受理合规、职业道德及其他违规行为相关举报。SoftwareOne Integrity Line 对内、对外均开放,任何人均可通过该渠道反映问题或举报疑似违规行为,也可选择匿名举报。所有举报信息均严格保密,举报提交的个人数据仅用于核查及处理举报事项,处理规则遵循本隐私声明、Integrity Line 专属隐私政策及数据保护相关法律法规。
涉及个人数据:举报人信息(实名举报时),包括联系方式及举报时提供的其他个人数据。举报内容中涉及被举报人员的相关信息(例如姓名、电子邮箱、电话号码、地址及各类佐证材料)。若举报内容或调查过程中涉及特殊类别个人数据,我方也将一并收集。
关于此类个人数据的处理法律依据:
- 履行法定义务,包括开通内部安全举报渠道;
- 基于我方合法权益,预防、查处违法违纪及违规行为,核查内部流程合规性,维护企业信誉、规避法律风险;
- 特殊类别个人数据,仅在处理举报、开展调查确有必要,且符合数据保护法律法规要求时进行处理。
安全分析
为维护我方网站、平台、应用及其他产品和服务的安全,识别欺诈或违规使用行为,我们可能处理您的个人数据。此举旨在检测并阻止非法访问、保障系统完整性、抵御网络威胁,从而保护我方数字基础设施。相关工作包括监控访问日志、使用行为及其他技术数据,以维护我方网站、平台、应用及其他产品和服务的保密性、完整性与可用性。
涉及个人数据:IP 地址、登录凭证、设备标识、浏览器类型、操作系统、访问时间戳、操作日志。
关于您的此类个人数据的处理法律依据:基于我方合法权益,防范欺诈与违规使用行为,保障网站、平台、应用或其他产品与服务合规使用、抵御网络入侵与破坏。
人工智能
我方在部分业务环节使用 AI 技术(含机器学习、生成式 AI),用于优化内部流程、升级服务、推动数字产品与服务创新。我们对 AI 的使用方式视具体场景而定。部分场景中,AI 仅用于提供建议或辅助支持,相关内容均需经过人工审核;其余场景下,AI 可协助自动化处理部分低风险运营工作。若 AI 的使用会对个人产生影响,我们将秉持透明原则,分场景提供清晰说明。
有关更多 AI 使用细节,或发现 AI 输出内容存在问题、异常行为,请发送邮件至 responsible-ai.global@softwareone.com。
数据保留
我们将在收集目的达成、或法律法规要求的留存期限内保存您的个人数据,包括但不限于合同有效期、法定报备周期、纠纷处理及反欺诈所需留存时长,以及其他监管要求。当个人数据不再具备合法业务留存需求时,我方会对信息做匿名化处理(使其无法关联至个人),或按照法律法规要求安全删除。
数据接收者
为实现本隐私声明载明的使用目的,我方可能向以下主体披露您的个人数据:
SoftwareOne 关联公司:基于集团架构,相关岗位人员会在最小必要范围内处理您的个人数据。集团内部所有信息的访问与流转,均严格遵守数据保护相关法规。点击此处可查看 SoftwareOne 集团旗下公司详情。
服务提供商(含 IT 服务商):我方会向合作服务商共享信息,保障网站、平台、应用及其他产品和服务正常运行,服务提供商业务涵盖营销、邮件、财税、支付结算、审计、调研、活动执行、招聘、客户服务、数据优化、反欺诈、销售、服务器托管、数据分析等。同样,为保障系统运行以及满足软件和数据存储需求,我们可能会向 IT 服务商共享您的个人数据。我方与所有服务商签订正式协议,明确个人数据保护义务与安全保障措施。我方与所有服务商签订正式协议,明确个人数据保护义务与安全保障措施。
公共机构与政府部门:我们可能会向公共机构及部门披露您的信息,包括执法机关、数据保护机构、税务机关、征信机构、催收机构、银行、法院及其他企业;前提是该披露具备合法依据,且我们需履行法定义务、遵守法规或合同约定,或是遵照具有法律强制力的法院指令、行政及司法程序执行。
法律顾问及相关专业机构:如因纠纷、索赔、诉讼事宜需要协助、提供法律意见或代理我方,或是为配合合规工作,我们可能会向相关法律专业人士共享您的个人数据。
联合营销合作方:向您报名的活动、线上研讨会、抽奖活动主办方,及其他联合营销合作方共享信息。
数据传输
仅在实现本隐私声明载明的目的确有必要、具备合法传输依据、且落实完备保障措施的前提下,我方会将您的个人数据传输至其他国家/地区(依据数据保护法规,该类地区需额外加强安全防护)。
进行此类跨境数据传输时,我们会在传输个人数据前,依法落实相应安全保障措施(例如与个人数据传输方签订标准合同条款或数据传输协议)。
数据安全
为保护您的个人数据,我们将采取相应的技术和组织措施。我们将确保代表我方访问您个人数据的供应商、合作方及其他接收方采取同等措施,并落实相应的安全保障。但您须知晓,任何电子传输和存储方式都无法做到百分之百安全,不存在绝对安全的标准保障。若您需要使用特定凭证访问我方网站、平台、应用及其他产品和服务,请务必妥善保管该凭证,切勿向他人泄露。
如您怀疑与我方的交互不再安全,或您的个人数据可能已遭到泄露,请立即发送邮件至 it.security@softwareone.com 联系我们。
您的权利
在我们处理您的个人数据过程中,您可依法行使以下权利:
- 查阅您的个人数据并获取个人数据副本;
- 要求我们更正或删除您的个人数据;
- 在特定条件下,请求限制对您个人数据的处理;
- 请求转移个人信息;
- 对您个人数据的处理提出反对,尤其是基于我方合法权益开展的数据处理;
- 若您认为个人数据处理行为违反现行数据保护法规,可向监管机构提出投诉。我们建议您在联系监管机构前先向我们反馈问题,请优先与我们取得联系。
请注意,上述权利并非绝对,部分情形下权利的行使会受到限制。如遇此类情况,我们将及时告知您,并说明无法完全满足您诉求的原因。
联系方式
如您对本隐私声明、我们的个人数据处理规则存在疑问,或是需要咨询、提交投诉,请通过以下方式联系我们:
SoftwareOne | 法务部 - 数据保护部门
电子邮箱:data-protection.eu@softwareone.com
欧盟/欧洲经济区、瑞士及英国地区的数据保护官信息如下:
FIRST PRIVACY GmbH
Konsul-Smidt-Straße 88
28217 Bremen, Germany
如需了解上述国家及地区以外的数据保护官联系方式,请点击此处。
Supplements
This Supplement applies to individuals located in Latin America and the Caribbean (“LATAM”), in addition to the above Privacy Notice, and provides additional clarifications to certain region specific processing activities and legal requirements.
Applicability of Local Data Protection Laws
In Brazil, when personal data is processed or relates to individuals located in Brazil, such processing is carried out in accordance with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais – “LGPD”, Law No. 13.709/2018).
In Mexico, the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) is the key regulation governing data processing by companies and individuals in Mexico. Under the new law of 2025, the Anti-Corruption and Good Governance Secretariat is the entity responsible for supervising and enforcing the law.
In Ecuador we will process and treat your Personal Data in accordance with the provisions of the Organic Law of Personal Data Protection (LOPDP) and other relevant regulations issued by the Superintendence of Personal Data Protection. The consent required by the (LOPDP) will be provided by you in the manner established in the Privacy Notice for each type of relationship.
In Chile, we will process your data in accordance with Law Nº 19.628: Sobre Protección de la Vida Privada.
In Puerto Rico, we process your personal data in accordance with applicable laws of the Commonwealth of Puerto Rico and relevant United States federal privacy and data security laws, including, where applicable, data breach notification and consumer protection regulations. SoftwareOne implements appropriate technical and organizational measures to ensure the security and confidentiality of personal data in line with generally accepted privacy standards.
In the Dominican Republic, we will process and handle your personal data in accordance with the provisions of Law No. 172-13 on the Protection of Personal Data, as well as other applicable regulations. The required consent under Law No. 172-13 will be obtained in the manner described in this Privacy Notice, depending on the nature of the relationship and the processing activities involved.
In Jamaica, when your personal data is processed or if you are located in Jamaica, we will process such data in accordance with the Data Protection Act, 2020, and any applicable regulations issued by the competent authority. SoftwareOne ensures that personal data is processed lawfully, fairly and transparently, and that appropriate safeguards are in place, including for international data transfers.
In Trinidad and Tobago, we will process your personal data in accordance with the Data Protection Act, 2011, and applicable regulations issued by the Office of the Information Commissioner. Personal data will be processed in a manner that ensures its confidentiality, integrity and security, and in line with the purposes described in this Privacy Notice.
Legal Basis – Regular Exercise of Rights (Brazil)
Where applicable, personal data may be processed for the regular exercise of rights in judicial, administrative or arbitration proceedings, in accordance with Article 7, item VI of the LGPD, including proceedings governed by the Brazilian Arbitration Law (Law No. 9,307 / 1996).
Communications (Brazil)
Individuals located in Brazil may submit privacy‑related requests and receive responses in Portuguese.
In accordance with ANPD Resolution No. 18 / 2024, SoftwareOne ensures that communications with data subjects and the Brazilian Data Protection Authority (ANPD) are carried out clearly and precisely in Portuguese.
Local Social Media Presence (Brazil)
In addition to global social media channels, SoftwareOne maintains local social media presences, as follows:
- LinkedIn: https://www.linkedin.com/company/softwareone-latam/
- X: https://x.com/softwareone_br
- Facebook: https://www.facebook.com/SoftwareOneBrasil/
- Instagram: https://www.instagram.com/softwareone_br/
- YouTube: https://www.youtube.com/@softwareonebrasil
Processing of personal data in this context is subject to the respective platforms’ local privacy policies:
- LinkedIn: https://br.linkedin.com/legal/privacy-policy
- X: https://x.com/pt/privacy
- Instagram: https://help.instagram.com/155833707900388
- YouTube: https://policies.google.com/privacy
International Data Transfers (Brazil and Ecuador)
Personal data may be transferred to third countries, provided that international treaties have been signed with those countries that allow the transfer of data and do not contravene local legislation.
International transfers of personal data originating from Brazil are conducted in accordance with the LGPD and ANPD Resolution CD/ANPD No. 19 of December 18, 2024 (Regulation of the International Transfer of Personal Data) and SoftwareOne relies on legal mechanisms that ensure an adequate level of protection for your personal data.
International Transfers of personal data originating from Ecuador will comply with the provisions of the LOPDP and SoftwareOne will only transfer personal data to countries and territories that comply with the standards of protection required by Ecuadorian laws and regulations.
Data Protection Rights (Brazil)
Individuals subject to the LGPD have the following rights:
- confirmation of the existence of processing;
- access to their data;
- rectification of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data or data processed in noncompliance with the LGPD;
- data portability upon express request;
- deletion of personal data processed with consent, to the extent permitted by law;
- information about public and private entities with which their personal data has been shared;
- information about the possibility of denying consent and its consequences;
- revocation of consent;
- upon request, obtain the full text of the clauses used to carry out an international data transfer, subject to trade and industrial secrets;
- lodge a complaint with a supervisory agency if they believe that the processing of their personal data infringes applicable data protection regulations.
In Brazil, the supervisory agency is the National Data Protection Agency (Agência Nacional de Proteção de Dados - ANPD).
Contact for data protection requests (Brazil and Ecuador)
In accordance with the LGPD and ANPD Resolution No. 18/2024, SoftwareOne has appointed a Data Protection Officer for Brazil. You may contact our DPO for any inquiries related to the processing of your personal data or to exercise your rights under the LGPD:
Vanessa Siqueira
data-protection.br@softwareone.com
The Data Protection Officer appointed for Ecuador (Encargado):
Nombre: Paul S Harris
Dirección: Ave. Naciones Unidas E699, Oficina 501. – Quito Ecuador
Teléfono: +593998325618
This Supplement applies to the handling of personal information of individuals located in Japan which is collected in Japan by SoftwareOne Japan K.K. or any other SoftwareOne entity with which you have established a relationship, as the case may be (individually or collectively, “SoftwareOne” or “we”) or a third party acting as a data processor on behalf of SoftwareOne, and supplements the above Privacy Notice. We comply with the Act on the Protection of Personal Information of Japan (Act No. 57 of 2003; the “APPI”).
Corporate Information
Under this Supplement, the entity responsible for handling your personal information is as follows:
Name: SoftwareOne Japan K.K.
Address: Hulic JP Akasaka Building 8F, 2-5-8 Akasaka, Minato-ku, Tokyo 107-0052
Representative: Kenji Hasegawa, CEO
Personal Information
“Personal information”, “personal data” and other related terms in this Supplement are to be interpreted as used in the APPI, unless otherwise defined herein; accordingly:
- “personal information” means information relating to a living individual which falls under any of the following items:
- information containing a name, date of birth, or other identifier or the equivalent (meaning all items (excluding individual identification codes) made by writing, recording, sound or motion, or other means, in a document, drawing, or electronic or magnetic record (this includes a record created in electronic or magnetic form (meaning electronic form, magnetic form, or any other form that cannot be perceived with the human senses; the same applies in the following item (ii)) which can be used to identify a specific individual (this includes any information that can be easily collated with other information and thereby used to identify that specific individual); and
- those containing an individual identification code; and
- “personal data” means personal information compiled in a personal information database or the equivalent.
Purposes of Use
We handle personal information solely within the scope necessary to achieve the purposes of use specified in the above Privacy Notice, except where otherwise permitted by the APPI or with your prior consent.
Proper Acquisition
We collect personal information in an appropriate manner and will not acquire any personal information through deception or other improper means.
Security Control Measures
We implement necessary and appropriate security control measures, including organizational, personnel, physical and technical safeguards, in order to prevent the leakage, loss or damage of any personal data we handle.
Joint Use
We may share and jointly use your personal data among our group companies.
- Items of Personal Data: As described in the “Relevant personal data” paragraph in each situation set forth in the above Privacy Notice.
- Scope of Joint Users: SoftwareOne AG and its consolidated subsidiaries.
- Purposes of Use: As described in Section 3 “Purposes of Use” above.
- Responsible Party for managing the personal data: SoftwareOne Japan K.K. (as identified in Section 1 above).
Cross Border Transfers
If we transfer your personal data to a third party outside Japan (excluding the EU and the UK), we will obtain your prior consent unless the recipient ensures an APPI-adequate level of protection or another legal exception under the APPI applies. Before seeking to obtain your prior consent, we will provide you with information on the name of the relevant foreign country, the personal information protection system of the foreign country, and the measures taken by the relevant third party to protect personal information.
Provision to Third Parties & Record-Keeping
We will not provide your personal data to any third party without your prior consent, except where permitted by the APPI or otherwise provided in this Supplement. When providing or receiving personal data from a third party, we will create and retain records in accordance with the APPI.
Your Rights under the APPI
In accordance with the APPI, you may request us for:
- notification of the purposes of use of the personal data we hold;
- disclosure of the content of your personal data we hold and the records we retain, or correction, addition or deletion of the content of your personal data we hold, if the content of such personal data is factual;
- suspension of use or erasure of your personal data we hold if the personal data has been obtained or is being handled in violation of the APPI; or
- cessation of third-party provision of your personal data we hold if the personal data is being provided to a third party in violation of the APPI.
You may also make a complaint about our handling of your personal data we hold, in accordance with the APPI. Such request or complaint must be made by submitting an inquiry to our contact point which can be found in Section 11. We will respond to such request or complaint in accordance with the APPI. Please note that we may collect the actual costs from you for taking the relevant measures in responding to your request for notification of the purposes of use of the personal data we hold or your request for disclosure of the content of the personal data we hold.
Sensitive Personal Information
We will not acquire any “sensitive personal information” as specified in the APPI (e.g., race, creed, social status, medical history, criminal record, the fact of having suffered damage by a crime) unless permitted under the APPI or with your prior consent.
Contact Point
To exercise your rights or for inquiries regarding our handling of personal data in Japan, please contact:
SoftwareONE Japan K.K.
Hulic JP Akasaka Building 8F, 2-5-8 Akasaka, Minato-ku, Tokyo 107-0052
+81 3 5005 2801
info.jp@softwareone.com
This Supplement applies where personal data is processed in the United Arab Emirates (“UAE”) or where the UAE Federal Decree Law No. 45 of 2021 on the Protection of Personal Data (“UAE PDPL”) is applicable. This Supplement shall be read together with the above Privacy Notice. Where any conflict arises, the provisions of this Supplement prevail for processing activities subject to the UAE PDPL.
Overseas Transfers (Articles 22–24 UAE PDPL)
SoftwareOne may transfer personal data outside the UAE only in accordance with the requirements of the UAE PDPL. Such transfers may take place where:
- The destination country appears on the UAE Data Office’s approved adequacy list;
- Appropriate contractual safeguards or legally recognized transfer mechanisms are implemented; or
- An exception under the UAE PDPL applies.
SoftwareOne ensures that all cross border transfers are supported by appropriate protection measures consistent with the UAE PDPL and the internal data protection standards.
Personal Data Breach Notification (Article 9 UAE PDPL)
In the event of a personal data breach that may pose a risk to the confidentiality, privacy, security or rights of individuals, SoftwareOne will:
- Notify the UAE Data Office without undue delay, and
- Notify affected individuals where the breach is likely to cause significant harm or impact.
SoftwareOne may maintains internal incident response processes to ensure timely detection, assessment, reporting, and mitigation of personal data breaches.
Data Protection Officer Requirement (Articles 10–11 UAE PDPL)
SoftwareOne appoints a Data Protection Officer (“DPO”) where required under the UAE PDPL, including scenarios involving:
- High risk processing operations, or
- Large scale processing of sensitive personal data.
The DPO supports ongoing compliance with the UAE PDPL, monitors internal controls, advises on data protection obligations and acts as a liaison with the UAE Data Office.
Rights of Individuals (Articles 13–20 UAE PDPL)
In addition to the rights outlined in the above Privacy Notice, individuals subject to the UAE PDPL may exercise the following rights:
- Right of access to personal data;
- Right to request correction or erasure;
- Right to restrict or stop processing;
- Right to data portability;
- Right to object to automated processing or automated decision making.
Requests may be submitted through the contact channels specified in the above Privacy Notice, and SoftwareOne will respond within the timelines mandated by the UAE PDPL.
Legal Basis for Processing (Article 4 UAE PDPL)
SoftwareOne processes personal data based on one or more legal bases recognized under the law, including:
- Consent;
- Necessity for performance of a contract;
- Compliance with legal obligations;
- Protection of public interest;
- Legitimate interests, to the extent permitted under the UAE PDPL.
Retention (Article 21 UAE PDPL)
Personal data subject to the UAE PDPL is retained only for the duration necessary to fulfil the purposes for which it was collected or as required by applicable legislation. SoftwareOne applies internal retention schedules aligned with the UAE PDPL’s data minimization and storage limitation principles.
Contact for UAE PDPL Requests
Individuals seeking to exercise their rights or raise concerns under the UAE PDPL may contact SoftwareOne at data-protection.me@softwareone.com.
This Supplement applies where personal data is processed within the State of Qatar or where the Qatar Personal Data Privacy Protection Law – Law No. 13 of 2016 (“Qatar PDPL”) is applicable. This Supplement shall be read together with the above Privacy Notice. Where any conflict arises, the provisions of this Supplement prevail for processing activities subject to the Qatar PDPL.
Overseas Data Transfers (Articles 15 & 16 Qatar PDPL)
SoftwareOne may transfer personal data outside the State of Qatar only in accordance with the requirements of the Qatar PDPL. Transfers may take place where:
- The receiving country provides an adequate level of protection;
- Explicit consent of the individual is obtained; or
- Appropriate safeguards or legally recognized transfer mechanisms are implemented.
SoftwareOne ensures that all cross border transfers follow the protection standards mandated under the Qatar PDPL.
Personal Data Breach Notification (Article 14 Qatar PDPL)
In the event of a personal data breach, SoftwareOne will:
- Notify the Ministry of Communications and Information Technology (MCIT) immediately, as required under the Qatar PDPL; and
- Notify affected individuals where the breach is likely to result in harm or adverse impact.
SoftwareOne maintains internal procedures to detect, assess and report breaches in accordance with statutory obligations.
Consent Requirements (Article 4 Qatar PDPL)
SoftwareOne obtains consent in accordance with the Qatar PDPL, ensuring that:
- Consent is explicit and informed;
- Consent is obtained prior to the processing of personal data;
- Additional safeguards are applied when processing sensitive personal data.
Where consent is withdrawn, SoftwareOne will cease processing activities unless another lawful basis under the Qatar PDPL applies.
Rights of Individuals (Articles 7–10 Qatar PDPL)
Individuals whose personal data is processed under the Qatar PDPL may exercise the following rights:
- Right of access to personal data;
- Right to request correction or erasure;
- Right to object to processing;
- Right to withdraw consent at any time.
Such rights can be exercised by reaching SoftwareOne at data-protection.me@softwareone.com. Replies will be received within the timelines specified under the Qatar PDPL.
This Supplement applies where personal data is processed within Australia or where the Privacy Act 1988 (Cth) (“Privacy Act”) is applicable. This Supplement shall be read together with the above Privacy Notice. Where any conflict arises, the provisions of this Supplement prevail for processing activities subject to the Privacy Act.
The type of personal data we use and what we do with that depends on the relationship we have with you. Therefore, some parts of this Supplement, as well as of the above Privacy Notice may not be relevant for you or more than one part of this Supplement, as well as of the above Privacy Notice may apply to you.
The meaning of the term “personal data” in this Supplement, as well as in the above Privacy Notice, has the same meaning as set out in the Privacy Act.
This Supplement, as well as the above Privacy Notice may be replaced or supplemented in order to fulfil legal requirements, as well as to provide you with all necessary information on how we process your personal data.
Why we collect personal data
We collect personal data so that we can provide our services to you and your service provider, as well as reasonable associated purposes. These purposes include but are not limited to the purposes already reflected in the above Privacy Notice.
We may also collect your personal information for a purpose which is additional to the original purpose pursuant to which we originally received or collected the personal data.
Personal data we collect
The types of personal data we may receive or collect include the following:
- Name or alias;
- Contact details (such as address, postal address, email, phone number);
- Date of birth;
- Sex, gender, or gender identity;
- Nationality or proof of residence (such as residence permits, work right permits or visa);
- Employment data (such as current employment, past employment or other work history);
- Educational qualifications (such as degrees, accreditations, occupational permits or occupational licences);
- Identification documents (such as passport, driver’s licence, identity card or other similar documentation);
- Pictures (such as head shots);
- Transaction and bank account details;
- Any personal information that is inherently disclosed when you or your service provider communicate with us (such as metadata); and
- Criminal history.
In limited circumstances we may need to obtain health information from you. In such circumstances we will make an express request and will treat any information as strictly confidential.
Further details about the personal data we collect and how it is processed or used depending on our relationship with you can be found in the above Privacy Notice.
How we collect personal data
We receive or collect personal data directly from your or your service provider’s in interactions with us, such as when you create a user account, sign up for our services, submit queries or engage with the services we provide. In addition to this, any personal data that you provide to us will constitute the collection of personal data for the purposes of this Supplement, as well as the above Privacy Notice.
Personal data may also be collected via our website, forms, phone calls, emails or through third-party providers with your consent or to the extent necessary to provide the services to you.
How we hold and protect personal data
We will only retain your personal data only so long as is necessary to provide our services, after which time we will destroy it, unless we:
- are required by law to retain it; or
- are required to preserve it for the purposes of providing services to another customer; or
- have agreed to a request by you or your service provider to preserve that personal information; or
- have a legitimate purpose for retaining it.
We take all reasonable steps to protect all information we hold, including personal data.
Cookies and other similar technologies
We may use cookies and similar technologies (for simplicity reasons, hereinafter referred to as “Cookies”), when you use our websites, platforms, applications as well as other products and services.
Our Cookie Banner and consent management system show you a list of the Cookies we use, including their provider, purpose, description and other relevant information. In the default setting, only the essential Cookies are enabled. Via the consent management system, you can determine whether you allow the setting of additional Cookies or not. You can adjust your preferences at any time via the consent management system.
Further information about the ways that we may track your personal information including on social media (e.g., Facebook) can be found in the above Privacy Notice.
Disclosure to third parties
We may disclose your personal data to parties to fulfil the purposes described above, including to provide services to you or your service provider. Due to SoftwareOne’s international group structure, personal data will be disclosed to certain departments and persons on a need-to-know basis to process personal data so that we can provide our services. For all intragroup personal data access and transfers, we comply with the provisions of the Privacy Act.
Third party service providers contracted by SoftwareOne may also receive personal data to provide or facilitate the provision of our services. These include, service providers who support us with order fulfilment, payment / billing, customer service, finance, auditing, fraud detection, IT services, communication, hosting, logistics, email delivery, marketing, sales, data analysis, event management, training, surveys, printing, archive, advisory and consulting services.
We may disclose your personal data to further recipients, such as private as well as public entities and institutions, including law enforcement, data protection authorities, tax authorities, credit agencies, debt collectors, banks, courts, hotels or other companies insofar as there is a legal basis for such disclosure.
Disclosure overseas
As we operate in a number of countries it is possible that your personal data may need to be transferred outside of Australia to countries in which we operate including the European Union, the United Kingdom and Switzerland, in order to provide our services. We will take reasonable steps to ensure that such recipients comply with the Privacy Act and maintain the confidentiality and security of your personal information.
Accessing or correcting personal data
You may contact us to access your personal data we hold about you and to request corrections if any details are inaccurate or incomplete. We may refuse to provide access you with to your personal data if:
- we are legally permitted to do so and consider it appropriate; or
- are required by law to deny the request.
Questions and complaints
If you have any requests, comments, queries or complaints in relation to your personal data, our handling of your personal data or how we handle personal data generally, please contact our information officer at data-protection.apac@softwareone.com.
We will respond to any requests or complaints within a reasonable period (usually 30 days).
If you disagree with our response or any decision that we make in respect of your personal data, including in respect of any complaint that you have made, you may refer your complaint to the Office of the Australian Information Commissioner by visiting www.oaic.gov.au, calling 1300 363 992 or by emailing enquiries@oaic.gov.au.
This Supplement applies where personal data is processed within New Zealand or where the Privacy Act 2020 (“Privacy Act”) is applicable. This Supplement shall be read together with the above Privacy Notice.
The type of personal data we use and what we do with that depends on the relationship we have with you. Therefore, some parts of this Supplement, as well as of the above Privacy Notice may not be relevant for you or more than one part of this Supplement, as well as of the above Privacy Notice may apply to you.
The meaning of the term “personal data” in this Supplement, as well as in the above Privacy Notice has the same meaning as set out in the Privacy Act.
This Supplement, as well as the above Privacy Notice may be replaced or supplemented in order to fulfil legal requirements, as well as to provide you with all necessary information on how we process your personal data.
Why we collect personal information
We collect personal data so that we can provide our services to you and your service provider, as well as reasonable associated purposes. These purposes include but are not limited to the following:
- communicate with you and your service provider, process requests and respond to requests;
- process comments or posts;
- register and send newsletters to you which you subscribe to;
- marketing purposes;
- registration, authentication and administration of user accounts;
- license monitoring purposes;
- provision of demo products and services as well as trials (also from third parties);
- analysis purposes in order to improve our products and services;
- tailor our website content and experience to your interests;
- maintain the security of our websites, platforms, applications as well other products and services;
- comply with legal and regulatory requirements and requests; and
- establish, exercise and defend legal claims.
We may also collect your personal data for a purpose which is additional to the original purpose pursuant to which we originally received or collected the personal data.
You are not required to give us your personal data, however, if you choose not to we may be unable to provide, in whole or in part, our services to you and your service provider.
Further details about the personal data we collect and how it is processed or used depending on our relationship with you can be found in the above Privacy Notice.
Personal data we collect
The types of personal data we may receive or collect include the following:
- Name or alias;
- Contact details (such as address, postal address, email and phone number);
- Date of birth;
- Sex, gender or gender identity;
- Nationality or proof of residence (such as residence permits, work right permits or visa);
- Employment data (such as current employment, past employment or other work history);
- Educational qualifications (such as degrees, accreditations, occupational permits or occupational licences);
- Identification documents (such as passport, driver’s licence, identity card or other similar documentation);
- Pictures (such as head shots);
- Transaction and bank account details;
- Any personal data that is inherently disclosed when you or your service provider communicate with us (such as metadata); and
- Criminal history.
During the course of providing services to you or your service provider we may create information about you which constitutes personal data including things such as emails, letters or other internal records.
Further details about the personal data we collect and how it is processed or used depending on our relationship with you can be found in the above Privacy Notice.
How we collect personal data
We receive or collect personal data directly from your or your service provider’s in interactions with us, such as when you create a user account, sign up for our services, submit queries or engage with the services we provide. In addition to this, any personal data that you provide to us will constitute the collection of personal data for the purposes of this Supplement, as well as the above Privacy Notice.
Information which we create as a result of providing services to you or your service provider which constitutes personal data will also constitute the collection of personal data for the purposes of this Supplement, as well as the above Privacy Notice.
Personal data may also be collected via our website, forms, phone calls, emails or through third-party providers with your consent or to the extent necessary to provide the services to you.
How we hold and protect personal data
We will only retain your personal data only so long as is necessary to provide our services, after which time we will destroy it unless we:
- are required by law to retain it; or
- are required to preserve it for the purposes of providing services to another customer; or
- have agreed to a request by you or your service provider to preserve that personal data; or
- have a legitimate purpose for retaining it.
We take all reasonable steps to protect all information we hold, including personal data.
Cookies and other similar technologies
We may use cookies and similar technologies (for simplicity reasons, hereinafter referred to as “Cookies”), when you use our websites, platforms, applications as well as other products and services.
Our Cookie Banner and consent management system show you a list of the Cookies we use, including their provider, purpose, description and other relevant information. In the default setting, only the essential Cookies are enabled. Via the consent management system, you can determine whether you allow the setting of additional Cookies or not. You can adjust your preferences at any time via the consent management system.
Further information about the ways that we may track your personal data including on social media (e.g., Facebook) can be found in the above Privacy Notice.
Disclosure to third parties
We may disclose your personal data to parties to fulfil the purposes described above including to provide services to you or your service provider. Due to SoftwareOne’s international group structure, personal data will be disclosed to certain departments and persons on a need-to-know basis to process personal data so that we can provide our services. For all intragroup data access and transfers, we comply with the provisions of the Privacy Act.
Third party service providers contracted by SoftwareOne may also receive personal data to provide or facilitate the provision of our services. These include, service providers who support us with order fulfilment, payment / billing, customer service, finance, auditing, fraud detection, IT services, communication, hosting, logistics, email delivery, marketing, sales, data analysis, event management, training, surveys, printing, archive, advisory and consulting services.
We may disclose your personal data to further recipients to the extent required to fulfil the purpose, such as private as well as public entities and institutions, including law enforcement, data protection authorities, tax authorities, credit agencies, debt collectors, banks, courts, hotels or other companies insofar as there is a legal basis for such disclosure.
Disclosure overseas
As we operate in a number of countries it is possible that your personal data may need to be transferred outside of New Zealand to countries in which we operate including the European Union, the United Kingdom and Switzerland, in order to provide our services. We will take reasonable steps to ensure that such recipients comply with the Privacy Act and maintain the confidentiality and security of your personal data.
Accessing or correcting personal data
You may contact us to access your personal data we hold about you and to request corrections if any details are inaccurate or incomplete. We may refuse to provide access you with to your personal data if:
- we are legally permitted to do so and consider it appropriate; or
- are required by law to deny the request.
Questions and complaints
If you have any requests, comments, queries or complaints in relation to your personal data, our handling of your personal data or how we handle personal data generally, please contact our information officer at data-protection.apac@softwareone.com.
We will respond to any requests or complaints within a reasonable period (usually 30 days).
If you disagree with our response or any decision that we make in respect of your personal data including in respect of any complaint that you have made, you may refer your complaint to the Privacy Commissioner (Te Mana Matapono Matatapu) by visiting www.privacy.org.nz, calling 0800 803 909 or by emailing enquiries@privacy.org.nz.
Applicability
This Supplement forms an integral part of the above Privacy Notice and applies solely to Data Principals located in India.
This Supplement governs the processing of digital personal data by SoftwareOne in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made thereunder ("DPDP Rules"), including:
- personal data collected in digital form within India;
- personal data collected in non-digital form and subsequently digitized; and
- processing of digital personal data carried out outside India in connection with the offering of goods or services to Data Principals within India, in accordance with Section 3 of the DPDP Act.
In the event of any inconsistency between this Supplement and the above Privacy Notice, the provisions of this Supplement shall prevail to the extent of such inconsistency for processing governed by Indian law.
Definitions
Unless otherwise defined herein, capitalized terms used in this Supplement shall have the meanings ascribed to them under the DPDP Act and the DPDP Rules.
For the purposes of this Supplement:
- "Board" means the Data Protection Board of India established under the DPDP Act;
- "Data Principal" means the individual to whom the personal data relates and where such individual is
- a child, includes the parents or lawful guardian of such child; or
- a person with disability, includes her lawful guardian acting on her behalf.
- "SoftwareOne" means the relevant SoftwareOne entity acting as a Data Fiduciary in relation to the processing of personal data under Indian law.
Notice to Data Principals
Consent to the processing of personal data by SoftwareOne shall be obtained only upon the Data Principal’s acceptance of this Supplement and the above Privacy Notice.
Contact for Data Protection Requests
Any request for withdrawal of consent, request for access to information, correction, erasure, grievance or any other communication under the DPDP Act may be addressed to:
Designation / Department: Regional General Counsel
Email ID: data-protection.apac@softwareone.com
Alternately, the Data Principal may communicate his request at: Shweta.Sinha@softwareone.com.
Grievance Redressal Mechanism
SoftwareOne has established an effective grievance redressal mechanism to address grievances raised by Data Principals in relation to the processing of their personal data.
A Data Principal may submit a grievance by contacting the Grievance Officer at:
Name: Regional General Counsel
Designation: Grievance Officer – India
Email ID: data-protection.apac@softwareone.com
Postal Address: 7th Floor, Tower 1A, International Tech Park, Near Sector 59, Behrampur, Gurugram, Haryana-122101.
SoftwareOne shall acknowledge the grievance and endeavor to resolve it within 30 days from the date of receipt.
A Data Principal shall exhaust the grievance redressal mechanism provided herein before approaching the Board, in accordance with Section 13 of the DPDP Act.
Nomination
A Data Principal may nominate one or more individuals to exercise her rights under the DPDP Act in the event of her death or incapacity.
Such nomination may be made by:
- submitting a request through the user account or digital interface made available by SoftwareOne; or
- submitting a written request to SoftwareOne using the contact details provided in this Supplement, along with such information and verification details as may be reasonably required by SoftwareOne.
Processing and Transfer of Personal Data Outside India
SoftwareOne may transfer personal data outside the territory of India only in accordance with:
- any restrictions notified by the Central Government on the transfer of personal data to specified countries or territories; and
- the conditions and safeguards specified by the Central Government through general or special orders.
Where such transfers occur, SoftwareOne shall ensure compliance with all applicable requirements under the DPDP Act, the DPDP Rules, and other applicable Indian laws.
Updates to this Supplement
This Supplement may be updated from time to time to reflect changes in applicable law, including amendments to the DPDP Act or the DPDP Rules, or guidance, directions or orders issued by the Government of India or the Data Protection Board of India. Material changes shall be notified to Data Principals through appropriate and reasonable means.
Children’s Personal Data
SoftwareOne does not knowingly process personal data of children, as defined under the DPDP Act.
Where processing of personal data of a child becomes necessary under applicable law, SoftwareOne shall ensure compliance with the requirements relating to verifiable parental consent and other safeguards prescribed under the DPDP Act and the DPDP Rules.
Additional DPDP-Specific Disclosures
Right to Withdraw Consent: Withdrawal of consent shall not affect the legality of processing carried out prior to such withdrawal.
Data Retention: SoftwareOne shall retain personal data only for such period as is necessary to fulfil the specified purpose or to comply with applicable law, after which such data shall be erased in accordance with the DPDP Act and the DPDP Rules.
隐私声明修订
我们可能会不定期更新本隐私声明,以适配现行法律、业务操作、服务内容及合规要求,同时提升信息透明度。若进行重大内容变更,我们将通过更新本隐私声明顶部的生效日期进行告知。因此建议您定期查阅本声明,及时了解我们收集、使用和保护个人数据的相关规则。
请注意:SoftwareOne 与 Crayon 完成合并后,本声明生效日前收集的个人数据,仍适用双方原有隐私声明。
版本历史
| 版本 | 日期 |
|---|---|
| 1.0 | 2020 年 6 月 |
| 2.0 | 2021 年 9 月 |
| 3.0 | 2026 年 8 月 |