我們高度重視您的隱私
我們高度重視您的隱私
隱私權聲明
生效日期:2026 年 8 月
您的隱私對於 SoftwareOne 及其關係企業 (以下統稱為「SoftwareOne」、「我們」、「我們的」) 非常重要。本隱私權聲明說明我們可能使用關於您的個人資料類型、可能的使用方式,以及您所擁有的資料保護權為何。
我們使用的個人資料類型以及我們如何處理這些資料,將視我們與您的關係而定。因此,本隱私權聲明的某些部分可能與您無關,或者本隱私權聲明的多個部分可能適用於您。
請注意,本隱私權聲明不適用於我們作為資料處理者代表客戶處理個人資料的情況。如果遇到此類情況,個人資料的處理將受到我們與客戶 (即資料控制者) 之間的個別協議所約束。
倘若本隱私權聲明包含會將您重新導向至並非由我們經營或控制的其他網站的參考資料,請注意,該網站的提供者將負責處理您在該網站上提供的任何個人資料,同時我們建議您相應地查看其隱私權聲明。如果遇到此類情況,我們將無法控制您個人資料的使用與處理方式,同時對於該提供者使用您個人資料的情況也不會承擔任何責任。
我們是誰
負責處理您個人資料的實體是 SoftwareOne 實體 (「資料控制者」),您已與該實體建立關係,例如造訪其網站、使用其服務、報名參加活動或應徵工作機會。如需瞭解更多有關不同 SoftwareOne 實體的資訊,請按此處。
當我們收到您的個人資料 (直接透過您收到、透過您所代表的公司收到,或是在其他情況下透過第三方收到),我們可能會基於以下目的和法律依據處理您的資料。
使用者帳戶與建立與管理
為了能夠安全地存取和使用我們的網站、平台、應用程式或其他產品與服務,您可能需要向我們註冊並維護一個使用者帳戶。當您註冊這些帳戶,以及我們針對這些帳戶進行身份驗證、管理和維護期間,我們都會處理您的個人資料。
如果您選擇建立示範或試用帳戶來探索我們的網站、平台、應用程式或其他產品和服務,我們可能會收集您的個人資料,並且利用該資料來驗證您的存取權限、提供臨時服務功能、監看您的使用情況,以及針對有關示範或試用帳戶的資訊與您溝通。
如果我們的網站、平台、應用程式或其他產品和服務引用了不同的隱私權聲明,說明收集和處理個人資料的原因和方式,我們建議您參考該隱私權聲明。
相關個人資料:聯絡人詳細資料 (例如姓名、電子郵件、電話號碼、職位、公司名稱)、註冊時間和日期、登入資訊、使用資料、活動資料。
我們處理您個人資料的法律依據是我們與您締結的合約,以便我們能夠建立、管理和維護您的帳戶。
回應請求
我們可能會收集您的個人資料,以便與您溝通並處理您透過聊天功能、聯絡表單或其他方式向我們提出的請求。
相關個人資料:聯絡人詳細資料 (例如姓名、電子郵件、電話號碼、職位、公司名稱)、郵寄地址、國家、請求內容、請求日期、您可能自願向我們揭露的其他資料。
在適用情況下,我們處理您個人資料的法律依據乃是履行我們對您的法律義務或合約承諾;除此之外,我們處理您個人資料的法律依據是管理我們與您的互動以及為您提供滿意服務與體驗的合法權益。
貼文與評論
您可以針對我們的網站、平台、應用程式以及其他產品和服務發表貼文與評論。在這種情況下,一般大眾可以取得您的內容。請注意,我們仍有可能會在發佈前人工審核您的貼文或評論,這樣可能會導致其顯示延遲。如果您提供姓名或別名,這個名字會公佈在貼文與評論的旁邊。
相關個人資料:姓名或別名、貼文與評論內容、時間與日期、您可能自願向我們揭露的其他資料。
我們處理您個人資料的法律依據乃是我們管理與您的互動以及改善我們產品與服務的合法權益。
電子報
您可以註冊我們的電子報,內容為您提供有關 IT 產業當前的趨勢與亮點、新產品或服務、即將舉行的活動、特別優惠以及 IT 決策者需要關注的重要日期等資訊。
我們需要您在註冊時提供電子郵件地址。在某些地區,您填寫完註冊表後,我們可能會向您傳送一封確認電子郵件。如果是這種情況,您必須點擊確認電子郵件中的連結,註冊才會啟動。
如果您註冊我們的電子報,我們可能會在電子報中加入個別的追蹤技術,藉此識別您何時存取或開啟傳送給您的電子報,並且對電子報中的連結進行個人化設置,確定您在何時點擊了哪個連結。
您可以隨時取消訂閱我們的電子報。只需點擊我們通訊內容最後的取消訂閱連結即可,或是傳送電子郵件至 info.global@softwareone.com。
相關個人資料:聯絡人詳細資料 (例如姓名、電子郵件、電話號碼、職位、公司名稱)、國家、參與度指標 (例如是否有開啟電子報、開啟日期 / 時間、存取電子報的次數、點擊的連結)。
我們處理您個人資料的法律依據乃是您同意收到電子報。
行銷
基於行銷目的,當您代表我們的客戶或合作夥伴 (包括潛在客戶) 與我們互動時,我們會收集您的個人資料。我們也可能透過通過驗證,獲得合法授權,可以共用此類資訊作為行銷傳播用途的第三方提供者收到個人資料。我們將基於行銷目的處理此類個人資料,包括但不限於告知您可能感興趣,並且即將舉行的活動、產品、服務和優惠。
此外,我們可能會使用個人追蹤技術,自動收集 IP 位址資料和參與度指標 (例如電子郵件開啟和連結點擊),以協助我們監控績效並提高行銷活動的相關性和有效性。
相關個人資料:聯絡人詳細資料 (例如姓名、電子郵件、電話號碼、職位、公司名稱),以及您提供給我們的任何其他資料。
我們處理您個人資料的法律依據是您的同意或我們向您傳送行銷傳播的合法權益。
授權與技術使用分析
在與客戶的商業關係中,我們可能會處理與軟體授權和技術使用環境相關的資訊,以便更精準地掌握、管理和支援客戶在整個合作關係生命週期中的需求。
如果客戶已授予我們存取其技術環境的權限,或是已經著手使用我們或核准的第三方工具,我們可能會了解相關平台或技術範圍內的授權類型、分配與使用情況。其中可能包括透過我們獲得的授權,以及透過其他提供者獲得的授權 (前提是此類存取已獲得授權)。
我們利用此資訊以支援授權和使用最佳化、驗證服務資格、管理按使用者或按授權定價或提供的服務,以及分析我們客戶群的彙總趨勢。這些分析還可以提供有關新產品和服務的開發、現有產品的改良以及確認相關商機等資訊。
如果授權或使用資料超出客戶授予的存取權限或適用合約安排範圍,我們不會進行存取或處理。
相關個人資料:使用者或裝置識別碼、授權分配和使用資料、服務使用指標以及相關技術中繼資料。
此類個人資料處理的法律依據是我們基於以下方面的合法權益:管理和開發我們的產品與服務、在合作關係的整個生命週期內為客戶提供支援、開展我們的商業活動,以及在適用情況下履行合約義務。
Cookie 以及其他類似技術
當您使用我們的網站、平台、應用程式以及其他產品和服務時,我們可能會使用 cookie 以及類似技術。Cookie 是您造訪的網站儲存在您裝置上的小型文字檔案。它們可協助網站記住您的偏好、登入資訊和瀏覽活動,進而提供更個人化、高效和流暢的線上體驗,通常用於分析網站流量、管理使用者作業階段以及根據您的興趣自訂內容。
必要性 cookie
這些 cookie 是網站運作所必須,無法停用。
功能性 cookie
這些 cookie 可啟用其他功能和第三方內容,例如字型、影片、地圖、社群外掛程式和嵌入式服務。
分析與行銷 cookie
這些 cookie 可以幫助我們瞭解使用者與網站的互動方式,並且支援廣告與行銷活動。
我們使用它的目的之一是處理您的使用資料,以便分析您如何使用我們的網站、平台、應用程式或其他產品和服務,以及與它們的互動方式,進而改善您的線上體驗。此外,我們可能會使用第三方工具建立匿名作業階段記錄,協助我們分析網站使用情況並改善功能。這些記錄並不會包含任何個人資料,同時敏感欄位均已屏蔽,以確保您的隱私。
我們也可能使用跨裝置追蹤技術在我們的網站之外顯示針對性廣告,並評估廣告成效。在我們 cookie 橫幅中所列出的第三方提供者 (如果已經啟用非必要性 cookie) 可能會存取您的瀏覽器或裝置、分析您的 IP 位址、儲存或讀取識別特徵或存取追蹤像素。這些特徵可能用於在其他網站上識別您的裝置。如果使用您的使用者資料向第三方提供者註冊,則不同裝置 (例如筆記型電腦、智慧型手機、平板電腦) 上的識別特徵可能會關聯起來。如此將可讓服務供應商能夠跨裝置管理廣告活動。
我們還可能會使用網站分析工具適當地設計我們的網站並且識別回訪者。這些工具會根據化名產生使用檔案並且依賴 cookie 的使用,如同Cookie 橫幅中所述。
我們還在網站中嵌入了並未儲存在我們伺服器上的某些服務。舉例來說,您可以使用地圖或者可以觀看影片找到 SoftwareOne 實體的正確位置。在某些地區,我們可能會確保對於我們包含嵌入式內容的網站、平台、應用程式或其他產品和服務的存取,不會自動向第三方提供者提供任何資訊,我們只會顯示本地儲存的縮圖。在此情況下,只有在您透過Cookie 橫幅表示同意之後,才會載入來自第三方提供者的內容。當您查看內容時,第三方提供者會收到您存取我們網站的消息,以及他們提供服務所需的相關使用資料。我們不會介入第三方提供者所執行的後續資料處理工作。
我們的 Cookie 橫幅係由第三方提供,並且會顯示我們所使用的 cookie 清單,包括其提供者。根據預設設定,只有必要性 cookie 才會啟用。透過 Cookie 橫幅,您可以決定是否允許設定其他 cookie。您可以隨時透過 Cookie 橫幅調整您的偏好設定。
相關個人資料:IP 位址、裝置和瀏覽器資訊、安全性和機器人偵測訊號、Cookie 同意偏好設定、網站互動資料 (例如影片觀看次數、地圖使用、嵌入式內容互動)、根據 IP 位址推斷的大致位置、技術請求和績效資料、造訪的頁面和瀏覽行為 (例如點擊次數、捲動次數、瀏覽路徑)、瀏覽網頁的時間以及階段作業持續期間、Cookie 識別碼以及廣告 ID、轉換和參與活動 (例如表單提交、互動) 以及行銷和活動成效資料。
必要性 cookie 處理您個人資料的法律依據乃是我們向您展示網站、平台和應用程式的合法權益。對於非必要性 cookie 和類似技術,其法律依據則是您的同意。
在我們的數位產品與服務中使用人工智慧
我們也可能會使用人工智慧 (「AI」) 工具 (包括生成式 AI) 以支援您與我們網站、平台、應用程式和其他產品或服務的互動 (例如,為聊天助理提供支援、翻譯或總結內容、根據個人喜好顯示內容、審核貼文和評論以及提供或改良產品功能),並在輸出結果可能對您產生有意義的影響時進行人工審核。
當您造訪我們的主要社群媒體網頁 (主要社群媒體茲列於下方) 時,我們可能會處理您的個人資料:
- LinkedIn:https://www.linkedin.com/company/SoftwareOne
- X:https://x.com/SoftwareOne,https://x.com/SWO_Careers
- Facebook:https://www.facebook.com/Softwareone/,https://www.facebook.com/softwareonecareers
- Instagram:https://www.instagram.com/softwareone/,https://www.instagram.com/swocareers/
- YouTube:https://www.youtube.com/SoftwareOne-global
- Tik Tok:https://www.tiktok.com/@swocareers?_r=1&_t=ZN-94SU63n1PIl
我們與相應社群媒體網頁的提供者共同負責處理您的個人資料。社群媒體頁面提供者在此方面也決定了您個人資料處理活動的目的與方式,而我們只能在有限程度上對其進行影響。
您在我們的社群媒體網頁上輸入的資料,例如評論、影片、圖片、按讚、公開訊息等,均由社群媒體網頁提供者發布,我們不會將其用於任何其他目的。我們仍保留在必要時刪除內容的權利。如果此為社群媒體動態功能,我們可能會在我們的網站上分享您的內容,並且透過社群媒體網頁向您傳達消息。
如果您透過社群媒體網頁向我們提出要求,我們也可能會根據您的要求,尋求其他能夠保證機密性的安全溝通管道。您始終可以透過提供的其他管道向我們傳送保密要求。如果您反對針對您的個人資料進行特定處理活動,請根據「聯絡資訊」一節中所述的方式與我們聯絡。我們將審查您的請求,同時判定我們是否能夠給予回應,以及我們對於此類處理活動是否會產生任何影響。否則,您可能需要直接聯絡社群媒體網頁提供者。
我們可能會基於廣告目的使用我們的社群媒體網頁。使用社群媒體網頁時,我們可能會使用由相應社群媒體網頁提供者所提供,根據人口統計、興趣、行為或位置的目標群體特徵。我們只會在有限程度上影響資料處理,同時我們無法停用相應社群媒體網頁提供者向我們提供的統計資料。
我們針對各個社群媒體管道會使用轉換追蹤選項。為使用該選項,我們在網站上加入了相應的像素或標籤,以便收集轉換資料。透過 Cookie 橫幅,您可以決定是否允許使用此類非必要性 cookie,並且調整您的偏好設定。
我們可能會使用 AI 工具 (包括生成式 AI) 以支援我們的社群媒體活動 (例如,撰寫或翻譯標題、生成或改編視覺內容、審核公司自己網頁上的評論以及以彙總形式分析參與情況),內容在發布前由我們的團隊進行審核。由社群媒體供應商自行經營的 AI 功能仍受其各自隱私權聲明約束管理。
社群媒體網頁提供者進行的資料處理
社群媒體網頁提供者可能會使用網頁追蹤方法。無論您是否已經登入社群媒體平台的帳戶,都可以進行網頁追蹤。如前所述,社群媒體網頁的網頁追蹤方法超出我們的控制範圍,我們無法停用這些功能。請注意,相關社群媒體網頁的提供者可能會使用您的個人資料和行為資料來評估您的習慣、人際關係和偏好。我們無法介入相關社群媒體網頁提供者對您資料的處理。
如需更多有關在社群媒體網頁上處理您個人資料的資訊,請造訪各自提供者的隱私權聲明,如下所列:
- LinkedIn:https://www.linkedin.com/legal/privacy-policy
- X:https://x.com/en/privacy
- Facebook:https://www.facebook.com/privacy/explanation
- Instagram:https://help.instagram.com/155833707900388
- YouTube:https://policies.google.com/privacy?hl=en
- TikTok:https://www.tiktok.com/legal/page/us/privacy-policy/en
相關個人資料:姓名、公司、電子郵件地址、國家以及您自願向我們提供的任何其他資訊。
我們處理您個人資料的法律依據是我們在社群媒體平台上宣傳與推廣我們的品牌、服務和產品的合法權益,以及提高我們行銷活動的有效性和相關性,進而提升整體行銷績效;同樣地,我們處理您的個人資料也是為了我們公共關係與傳播的利益。此外,我們還需徵得您的同意才能部署非必要性 cookie,您可以隨時透過 Cookie 橫幅進行調整。
購買和使用我們的產品或服務
為了方便您購買和使用我們的產品或服務,我們可能會處理您的個人資料。此類個人資料可能由您直接提供給我們,也可能由相關的客戶、供應商或業務合作夥伴提供給我們。
我們根據所提供的產品或服務,以兩種不同的方式處理個人資料:
- 對於某些產品或服務,我們會單獨決定處理個人資料的目的和方式;
- 對於其他產品或服務,我們會以資料處理者的身分代表客戶行事。在這些情況下,具體的處理活動會在我們與客戶之間簽訂的適用資料處理協議中詳細說明。
這項處理讓我們能夠管理和維護與您及您所代表的公司的關係,包括協商和最終確定協議,以及提供定價資訊。
同樣地,在提供我們的某些產品或服務時,我們可能會處理某些特定資料,以偵測、調查和因應網路安全威脅。其中包括監控系統、分析安全事件以及因應可能影響我們客戶環境的潛在事件。
如果您選擇先建立示範或試用帳戶以探索我們的產品和服務,之後再進行購買,我們可能會收集您的個人資料,並且利用該資料來驗證您的存取權限、提供臨時服務功能、監看您對於產品或服務的使用情況,以及針對有關示範或試用帳戶的資訊與您溝通。
我們有時會進行市場調查和滿意度調查,這是因為我們持續尋求更深入瞭解您對我們產品或服務的體驗、興趣與反饋意見,同時也努力加以改進,以及改善我們與客戶、業務合作夥伴和任何其他相關方的關係。遇到這種情況,您有權反對此類處理。如需瞭解更多有關如何行使權利的資訊,請參考「聯絡資訊」一節。
相關個人資料:聯絡人詳細資料 (例如姓名、電子郵件、電話號碼、職位、公司名稱)、登入憑證、註冊時間與日期、使用資料、系統與安全日誌 (例如驗證日誌、網路流量中繼資料、端點遙測)、IP 位址、裝置識別碼、裝置與應用程式資料 (例如主機名稱、作業系統詳細資料、應用程式使用中繼資料)、事件相關資料 (例如檔案、記憶體資料,或是與疑似惡意活動相關的日誌),以及您在購買和使用我們的產品或服務時,自願向我們提供的其他資料。
處理您個人資料的法律依據乃是我們透過管理、訂立和履行與您合法代表的實體簽訂的協議,同時銷售我們的產品或服務的合法權益。我們在進行市場調查或研究以及建立您的演示帳戶時,都依據相同的法律依據,以便我們能夠為您 (作為潛在客戶的合法代表) 提供我們產品或服務的預先展示。
產品與服務改善
在使用我們的產品或服務時,我們可能會處理您的個人資料,以便對其進行分析並用於統計和改善目的。
相關個人資料:姓名、電子郵件、IP 地址、造訪過的內容、造訪日期和時間、傳輸的資料量、存取狀態、網頁瀏覽器與作業系統、指出您是從哪個網站造訪的推薦連結。
我們處理您個人資料的法律依據乃是我們在了解我們的整體表現並改善我們的產品或服務,最終提升您與我們互動時的體驗。
客戶信用驗證
我們可能會處理個人資料,以便在與客戶簽訂協議之前進行信用查核,進而管理我們持續業務關係中的財務風險。其中可能還包括在啟用交易之前,在我們企業資源規劃 (ERP) 系統中對客戶資訊和信用額度進行內部驗證。
相關個人資料:聯絡人詳細資料 (例如姓名、電子郵件、電話號碼、職位、公司名稱)、金融交易記錄、信用評分、支付行為、未償債務、識別號碼 (例如增值稅編號或公司註冊證編號)、透過信用參考機構收到的資料 (如果與您個人相關)。
我們處理您個人資料的法律依據是我們評估信用狀況和最大限度降低財務風險的合法權益。
盡職調查與篩檢
在開展業務之前,當您代表我們的客戶、業務合作夥伴或任何相關方與我們聯絡時,我們可能會處理您的個人資料,以便我們能夠進行盡職調查或篩檢。在適用法律允許的範圍內,我們的盡職調查或篩檢活動可能包括安全、隱私和誠信查核。
相關個人資料:聯絡人詳細資料 (例如姓名、電子郵件、電話號碼、職位、公司名稱),您自願提供給我們的其他資料。
我們處理您個人資料的法律依據是我們為確保貴公司符合要求以及有效管理任何相關風險所享有的合法權益。
在客戶和合作夥伴關係方面運用人工智慧
我們可能會使用 AI 工具 (包括生成式 AI) 以支援我們的商業和營運活動 (例如起草和個人化通訊內容、總結會議和電子郵件交流、翻譯內容、分析帳戶資訊、分類和回覆支援要求以及協助準備提案或合約),任何可能對您產生重大影響的輸出結果都將經過人工審核。除非適用法律允許,否則不得僅憑自動化方式作出任何產生法律效力或類似重大影響的決定。
活動註冊和管理
我們可能會處理您的個人資料,以便與您溝通、組織和舉辦研討會、網路研討會、培訓課程、網路會議和其他活動 (以下稱為「活動」),這些活動由我們或我們的任何合作夥伴負責組織,同時您決定出席這些活動。
在此過程中,我們可能會得到外部第三方提供者 (例如視訊會議、通訊供應商) 的支援,我們會與他們分享您的個人資料。
在某些情況下,我們可能也會記錄我們的活動。請查看以下有關影音內容一節的說明以瞭解更多資訊。
我們有時也可能會向您發送調查,您可以自由選擇是否回答,以便我們評估如何有效地改善或擴展我們的活動。
如果活動並非線上活動,而是需要您親自參加,我們將另行提供活動隱私權聲明,其中包含有關我們如何處理與該特定活動相關,關於您個人資料的詳細資訊。
相關個人資料:聯絡人詳細資料 (例如姓名、電子郵件、電話號碼、職位、公司名稱)、會議名稱或別名、IP 位址、裝置/ 硬體資料 (例如 MAC 位址、版本)、文字、音訊與視訊資料、連線資料 (例如電話號碼、國家名稱、開始與結束時間)、您在註冊過程中或活動期間自願提供給我們的其他資料。
我們處理您個人資料的法律依據乃是我們管理活動、宣傳推廣以及向您傳送調查內容的合法權益,以便我們了解、評估和改進活動的整體表現。
影音內容
在我們或我們任何的合作夥伴所安排的活動中,我們可能會拍攝參與者的照片或錄製影片 (「影音內容」)。此類「影音內容」可能會拍到您、一群人,或是在台上演講或出席的任何人。我們可能會將這些素材發佈在我們的網站、社群媒體平台或是任何其他數位或印刷媒體上。如果您不希望自己出現在此類「影音內容」中,請告知錄製或拍攝照片的人員或活動安排者。此外,我們建議您在親自參加活動時請留意,不要出現於正在拍攝或錄影的照片 / 影片中。
對於參與者的個人「影音內容」,我們會另行告知您個人資料處理的相關事宜,並在處理前徵得您的同意。
您有權反對此類處理,或是撤回先前已經向您徵得的同意。儘管我們將盡力滿足您的要求,不過眾所周知的是,任何發佈在網際網路 (包括社群媒體平台) 上的資訊都可能被全球存取,並且可能被與我們沒有聯繫或是不受我們控制的第三方輕易複製與散佈。因此,即使我們已刪除該資訊,在網際網路上仍然可能找到它們。此時應該直接向相應的網路搜尋引擎或社群媒體供應商提出進一步的刪除要求。
如果您的照片已經被用於印刷材料 (例如傳單、雜誌、業務通訊),而將照片從這些材料中移除需要付出不成比例的努力,那麼可能會繼續使用這些印刷材料,直到印刷版本用完為止。不過,您的照片不會用於任何新的印刷材料。
相關個人資料:收集而來或是與我們分享的圖片、影片、錄音、其他生物辨識資料。
處理您個人資料的法律依據是我們管理活動和宣傳活動的合法權益,但是在我們製作個人視聽內容的情況除外,在此情況時,我們將取得您的同意後再進行。
在我們的活動中使用人工智慧
為了舉辦、記錄以及改進我們的活動,我們可能會使用 AI 功能 (由我們或我們的活動和視訊會議提供者提供) 以產生活動現場或活動後的文字記錄、書面摘要、備忘錄和重點,提供即時字幕或即時翻譯、支援問題與解答以及聊天,並以彙總形式分析參與程度。如果啟用轉錄、摘要或錄音功能,我們將在活動開始時通知您,並在必要時徵求您的同意。
我們可能會處理您的個人資料,這些資料可能直接來自於您、來自可公開取得的管道 (例如線上專業網路、社交媒體網站或人才招募網站) 或來自第三方 (例如人事服務提供者、大學、就業 / 招聘機構、推薦人、稅務和社會保險機構或其他相關機構),以便用於提供就業機會。
我們可能會基於以下目的處理您的個人資料:
- 在我們的應徵系統中為您建立一個帳戶;
- 透過使用 AI 系統,評估您提供給我們的簡歷、履歷或其他文件,以及評估您的技能、經驗和資格 (如果適用);
- 安排面試並進行評估;
- 在法律允許或規定的情況下,進行背景調查或公共社群查核,作為獲得工作機會的先決條件;
- 針對您的應徵進度與您聯絡;
- 在情況允許的情況下,給付招募過程中產生的差旅費用;
- 將您的應徵資料保存至人事檔案,並在應徵成功後與您建立僱傭關係;
- 根據您的興趣和技能為您提供工作機會,並且告知您最新的招募資訊;
- 進行調查以改善我們的招募流程等。
應徵我們的職缺時,請您僅在應徵資料中加入與該職位相關的資訊。對於某些應徵,我們可能會在自願的基礎上要求提供某些人口統計資訊 (例如性別、種族/民族和國籍),以符合平等就業機會和法律報告要求。此資訊不屬於遴選過程的一部分,也不會對招募決定產生任何影響。
對於某些職位,我們可能會使用第三方提供者提供的技術輔助評估與招募工具 (例如視訊面試平台、結構化評估、工作模擬、AI 輔助篩選工作流程) 以支援部分招募流程。這些工具可以協助我們以結構化的方式收集應徵資訊、安排和進行面試或評估、驗證與工作相關的技能,並產生結構化的摘要或分析報告,支援招募人員的審核工作。根據職位和所用工具的不同,這可能包括審核您的履歷和應徵資料,邀請您回答結構化問題 (以文字、音訊和 / 或視訊形式),並產生招募人員的總結、評分或信心指標。我們將這些輸出結果作為決策支援,我們的招募人員仍然負責審查相關資訊並做出招募決定。如果某個特定評估步驟是自願提供的,我們會明確說明,並在可行的情況下提供替代途徑。
我們也可能使用 AI 協助我們從公共專業網路和招聘網站尋找應徵者、安排面試、轉錄以及彙總面試內容、翻譯應徵資料以及撰寫招聘人員的溝通文稿。這些產出結果旨在為我們的招募人員提供支援 (而非取代),任何招募決定都不會完全由自動化方式做出。您可以直接聯絡招募人員或是透過「人工智慧」一節中的詳細資料,要求人工審核任何由 AI 產生的結果。
建立好自己的帳戶後,您還可以透過入口網站帳戶儀表板變更您的個人資料偏好設定以及電子郵件訂閱。當然,您也可以隨時透過 iCIMS.help@softwareone.com 與我們聯絡,我們將據此為您提供相應的支援。
如果您的求職申請未獲成功,同時您已同意我們將您的個人資料保留較長時間 (因為這些資料可能對您未來的潛在機會有所幫助),我們將再保留兩年,兩年之後我們會將其刪除。如果您未同意延長資料保留期限,我們將根據適用法律的要求,在應徵流程結束後六個月內刪除您的資料。當然,您可以依照「您的權利」一節所述,隨時向我們提出資料刪除要求。
相關個人資料:聯絡人詳細資料 (例如姓名、電子郵件、電話號碼、職位、公司名稱)、簡歷 (包括您提供的相片或影像)、求職信、推薦信、住家地址、身分資料 (例如出生日期、國籍、身分證或護照等)、就業資料 (例如工作經驗、僱傭合約、過往工作經驗、目前工作狀況、工作類型、職能、工作證或居留證(如有必要)等)、教育程度以及資歷資料 (例如學位、證書、過往工作經驗、第二職業、推薦信以及其他能夠證明您的專業技能和經驗的相關文件)、問卷調查與評估結果、適用法律允許和 / 或要求提供的健康資料、銀行帳戶詳細資料 (例如,經同意後報銷差旅費用);您自願提供給我們的其他資料。
我們處理您個人資料的法律依據乃是:
- 我們基於合法權益建立您的帳戶、評估您的應徵、進行面試或評估、背景調查以及全面管理招聘流程,以填補我們的空缺職位;
- 我們基於合法權益向您傳送調查問卷,以便我們瞭解與評估如何更好地改善我們的招募流程以及整體績效和效率;
- 我們基於合法權益在發生法律訴訟時維護自身權益,並且行使任何權利以保護自身以及我們的品牌;
- 如果您未能順利應徵到工作,您同意我們將您的個人資料安全地保存較長時間;
- 在必要時徵得您的同意,在您的應徵過程中使用 AI 工具 (例如 AI 支援的評估或視訊面試);
- 基於合約目的,與您建立僱傭關係;
- 基於法律義務遵守法規要求、處理投訴或疑慮,並在必要時維護自身權益。
公司交易
隨著我們業務的持續發展,我們可能會進行各種公司交易,因此,如果發生任何擬議或實際的重組、出售、合併、整合、合資、轉讓、轉移或以其他方式處置我們全部或部分業務、資產或股份 (包括與任何破產或類似程序有關的情況),您的個人資料可能會被揭露或轉移給相關的第三方。
相關個人資料:聯絡人詳細資料 (例如姓名、電子郵件、電話號碼、職位、公司名稱)、帳戶憑證、購買與交易記錄、促成公司交易所需的其他資料。
處理您個人資料的法律依據乃是我們開展公司交易和確保業務連續性的合法權益。
爭端解決
我們可能會處理您的個人資料以保護我們的合法權益、行使和抗辯索賠或參與法律訴訟 (包括涉及第三方的訴訟)。
相關個人資料:聯絡人詳細資料 (例如姓名、電子郵件、電話號碼、職位、公司名稱)、合約文件、信函、使用日誌、交易記錄、與爭議事項相關的其他資料。
我們處理您個人資料的法律依據乃是我們維護自身法定權利與有效解決爭端的合法權益。
法規遵循
為了履行適用法律法規規定的義務,我們可能需要或被要求處理您的個人資料並與公共機構、監管機構或執法機關 (例如警察、法院) 共用該資料。我們也可能會聘請外部稽核人員或顧問協助履行合規義務,並會在必要範圍內與他們分享個人資料。其中可能包括維護記錄、提交報告或根據法律要求揭露資訊。在某些情況下,根據適用法律,提供個人資料具有強制性質,或者可能根據官方要求提供。在其他情況下,我們可能會主動提交必要的合規報告。
相關個人資料:聯絡人詳細資料 (例如姓名、電子郵件、電話號碼、職位、公司名稱)、交易記錄、通訊歷程記錄、帳戶活動、證明合規所需的其他資料。
我們處理您個人資料的法律依據乃是我們對於法律義務的遵守。
舉報疑慮
在 SoftwareOne,我們致力於維護最高的誠信和合規標準。為了對這項承諾給予大力支持,我們提供 SoftwareOne Integrity Line (SoftwareOne 正直熱線),這是一個安全保密的舉報管道,與合規性、道德行為或其他潛在不當行為相關的任何疑慮皆可提出。SoftwareOne Integrity Line (SoftwareOne 正直熱線) 可供內部人員使用,也可供任何希望舉報疑慮或懷疑違規行為的外部人員使用 (如果願意,也可以匿名方式進行舉報)。所有舉報均嚴格保密,提交報告時共用的個人資料僅用於調查和解決問題,並遵守本隱私權聲明、「正直熱線」中的隱私權政策以及適用的資料保護法。
相關個人資料:檢舉人 / 舉報人個人資料 (其身分已經公開),包括聯絡人詳細資訊以及報告中提供的任何其他個人資料。報告中包含與所提出指控之個人相關的資料 (例如姓名、電子郵件、電話號碼、地址以及任何佐證文件)。如果已經包括在報告中或是在調查過程中揭露,也可能收集特殊的個人資料。
我們處理個人資料的法律依據乃是:
- 遵守法律義務,包括提供安全的內部通報管道的義務;
- 我們有權預防和偵查犯罪行為、違反職責和其他違法行為,並在此過程中核實內部流程的合法性,維護我們的誠信,防範損害和責任風險;
- 如果涉及特殊類別的個人資料,我們將僅在處理報告和進行調查所需情況,並且僅在適用資料保護法律允許的情況下處理這些資料。
安全分析
為維護我們網站、平台、應用程式或其他產品和服務的安全,以及偵測詐騙或濫用行為,我們可能會處理您的個人資料。我們這麼做的目的是為了保護我們的數位基礎設施,透過偵測和阻止未經授權的存取,確保系統完整性並抵禦網路威脅。其中包括監控存取日誌、使用模式和其他技術要素,以維護我們網站、平台、應用程式或其他產品和服務的機密性、完整性和可用性。
相關個人資料:IP 位址、登入憑證、裝置識別碼、瀏覽器類型、作業系統、存取時間戳記、活動日誌。
我們處理您個人資料的法律依據是我們在偵測詐騙與濫用行為方面的合法權益,確保我們的網站、平台、應用程式或其他產品和服務用於預期目的,同時免於遭受入侵和破壞。
人工智慧
我們在業務的某些部分會使用到 AI (包括機器學習以及生成式 AI),例如加速內部流程、改善服務,同時支持我們在提供數位產品和服務方面的創新。我們使用 AI 的方式取決於具體情況。在某些情況下,AI 僅用於提供由人工審核的建議或協助;在其他情況下,AI 可以協助自動化某些低風險的操作任務。在 AI 運用可能與個人產生關聯方面,我們致力於保持公開透明,並且將會根據‑逐案‑情況提供明確的資訊。
如果您想了解更多關於我們使用 AI 的資訊,或是遇到任何問題、不安全輸出或是意外的 AI 行為,請透過 responsible-ai.global@softwareone.com 與我們聯絡。
資料保留
我們會將您的資料保留至達成收集目的或履行法律義務所需的時間。其中包括但不限於合約期限、法律報告義務、解決爭議和防止詐騙所需的保留期限,以及任何其他監管要求。一旦我們不再有正當的業務需要保留您的個人資料,我們將對其進行匿名化處理,使其不再與您關聯,或根據適用的法律將其安全地刪除。
資料接收者
為了實現本隱私權聲明中所述目的,我們可能會將您的個人資料揭露給其他接收方,具體對象如下所述:
SoftwareOne 關係企業:由於我們集團的國際化結構,某些部門和人員需要按「 有需要知道」的原則處理您的個人資料。對於集團內部所有個人資料的存取和傳輸,我們遵守適用的資料保護要求。有關 SoftwareOne 集團公司的進一步資訊,請按此處查詢。
服務提供者,包括 IT 供應商:我們會將您的個人資料揭露給我們用於支援我們網站、平台、應用程式或其他產品和服務的服務供應商,包括 IT 供應商。這些公司提供的服務包括:行銷、郵寄或電子郵件、稅務和會計、支付或帳單處理、稽核、進行調查、活動管理、招聘流程、客戶服務、資料增強服務、詐騙預防、銷售、網站託管或分析服務。同樣地,為支援我們的系統以及基於軟體和資料儲存的目的,我們可能會將您的個人資料與 IT 供應商共用。我們與服務提供者簽訂專屬合約,其中包含保護您個人資料所需的安全保障措施。我們與服務提供者簽訂專屬合約,其中包含保護您個人資料所需的安全保障措施。
公共或政府機構:我們可能會向公共實體和機構揭露您的資料,包括執法部門、資料保護機構、稅務機關、信用機構、債務催收機構、銀行、法院或其他公司,惟前提是已存在有此類揭露的法律依據,同時我們必須遵守我們的法律義務、法規或合約,或者為了回應我們依法必須遵守的法院命令、行政或司法程序。
法律顧問或類似專業人士:在需要提供支援、向我們提供建議或代表我們處理爭議、索賠或訴訟,或協助我們遵守規範時,我們也可能會將您的個人資料與相關的法律專業人士分享。
聯合行銷夥伴 :我們可能會將您的個人資料提供給您註冊的活動、網路研討會或抽獎活動的贊助商,或是提供給與我們進行聯合行銷活動的其他各方。資料傳輸
我們可能會將您的個人資料傳輸至第三國 (例如,根據適用的資料保護法規要求採取額外保障措施的國家),惟僅限於為實現本隱私權聲明中所述目的所必需或要求的情況,同時資料轉移有法律依據並且已實施適當的傳輸機制。
在進行這些國際傳輸時,我們將確保在傳輸個人資料之前按照適用法律的規定採取適當的保障措施 (例如,透過納入標準合約條款或傳輸個人資料的各方之間制定的資料傳輸協議)。
資料安全
為保護您的個人資料,我們將實施適當的技術與組織措施。我們將確保代表我們存取您個人資料的供應商、合作夥伴和其他資料接收者也會做相同的事情,實施類似的保障措施。然而您必須清楚是,沒有任何一種電子傳輸與儲存方法是 100% 安全的,同時也沒有絕對安全的保障標準。當您需要使用某些憑證來存取我們的網站、平台、應用程式或其他產品和服務時,您必須確保對這些憑證保密,同時不會與任何其他人分享。
如果您懷疑您與我們的互動不再安全,或者您的個人資料可能已洩露,請立即透過以下管道與我們聯絡:it.security@softwareone.com。
您的權利
在我們處理您的個人資料後,您將享有某些合法權利,具體包括:
- 存取您的個人資料並取得您的個人資料副本;
- 要求我們更正或刪除您的個人資料;
- 在某些情況下,要求限制對您個人資料的處理;
- 要求實現個人資料可攜性;
- 反對處理您的個人資料,尤其是當個人資料是根據我們的合法權益進行處理時;
- 如果認為對您個人資料的處理違反適用的資料保護法規,向監管機構提出申訴。然而,我們希望在您聯絡監管機構之前解決您的問題,因此請先與我們聯絡。
請注意,這些並非是絕對權利,在某些情況下,這些權利的行使可能會受到限制。倘若發生這種情況,我們一定會及時通知您,並且說明無法完全滿足您要求的原因。
聯絡資訊
如果您對本隱私權聲明、我們的資料保護措施有任何疑問,或者想透過我們獲得更多資訊或提出投訴,請透過以下方式與我們聯絡:
SoftwareOne | 法律 - 資料保護部
電子郵件:data-protection.eu@softwareone.com
我們負責歐盟/歐洲經濟區、瑞士與英國地區的資料保護官為:
FIRST PRIVACY GmbH
Konsul-Smidt-Straße 88
28217 Bremen, Germany
如需上述國家和地區以外的資料保護官的詳細聯絡資訊,請按一下此處。
Supplements
This Supplement applies to individuals located in Latin America and the Caribbean (“LATAM”), in addition to the above Privacy Notice, and provides additional clarifications to certain region specific processing activities and legal requirements.
Applicability of Local Data Protection Laws
In Brazil, when personal data is processed or relates to individuals located in Brazil, such processing is carried out in accordance with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados Pessoais – “LGPD”, Law No. 13.709/2018).
In Mexico, the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) is the key regulation governing data processing by companies and individuals in Mexico. Under the new law of 2025, the Anti-Corruption and Good Governance Secretariat is the entity responsible for supervising and enforcing the law.
In Ecuador we will process and treat your Personal Data in accordance with the provisions of the Organic Law of Personal Data Protection (LOPDP) and other relevant regulations issued by the Superintendence of Personal Data Protection. The consent required by the (LOPDP) will be provided by you in the manner established in the Privacy Notice for each type of relationship.
In Chile, we will process your data in accordance with Law Nº 19.628: Sobre Protección de la Vida Privada.
In Puerto Rico, we process your personal data in accordance with applicable laws of the Commonwealth of Puerto Rico and relevant United States federal privacy and data security laws, including, where applicable, data breach notification and consumer protection regulations. SoftwareOne implements appropriate technical and organizational measures to ensure the security and confidentiality of personal data in line with generally accepted privacy standards.
In the Dominican Republic, we will process and handle your personal data in accordance with the provisions of Law No. 172-13 on the Protection of Personal Data, as well as other applicable regulations. The required consent under Law No. 172-13 will be obtained in the manner described in this Privacy Notice, depending on the nature of the relationship and the processing activities involved.
In Jamaica, when your personal data is processed or if you are located in Jamaica, we will process such data in accordance with the Data Protection Act, 2020, and any applicable regulations issued by the competent authority. SoftwareOne ensures that personal data is processed lawfully, fairly and transparently, and that appropriate safeguards are in place, including for international data transfers.
In Trinidad and Tobago, we will process your personal data in accordance with the Data Protection Act, 2011, and applicable regulations issued by the Office of the Information Commissioner. Personal data will be processed in a manner that ensures its confidentiality, integrity and security, and in line with the purposes described in this Privacy Notice.
Legal Basis – Regular Exercise of Rights (Brazil)
Where applicable, personal data may be processed for the regular exercise of rights in judicial, administrative or arbitration proceedings, in accordance with Article 7, item VI of the LGPD, including proceedings governed by the Brazilian Arbitration Law (Law No. 9,307 / 1996).
Communications (Brazil)
Individuals located in Brazil may submit privacy‑related requests and receive responses in Portuguese.
In accordance with ANPD Resolution No. 18 / 2024, SoftwareOne ensures that communications with data subjects and the Brazilian Data Protection Authority (ANPD) are carried out clearly and precisely in Portuguese.
Local Social Media Presence (Brazil)
In addition to global social media channels, SoftwareOne maintains local social media presences, as follows:
- LinkedIn: https://www.linkedin.com/company/softwareone-latam/
- X: https://x.com/softwareone_br
- Facebook: https://www.facebook.com/SoftwareOneBrasil/
- Instagram: https://www.instagram.com/softwareone_br/
- YouTube: https://www.youtube.com/@softwareonebrasil
Processing of personal data in this context is subject to the respective platforms’ local privacy policies:
- LinkedIn: https://br.linkedin.com/legal/privacy-policy
- X: https://x.com/pt/privacy
- Instagram: https://help.instagram.com/155833707900388
- YouTube: https://policies.google.com/privacy
International Data Transfers (Brazil and Ecuador)
Personal data may be transferred to third countries, provided that international treaties have been signed with those countries that allow the transfer of data and do not contravene local legislation.
International transfers of personal data originating from Brazil are conducted in accordance with the LGPD and ANPD Resolution CD/ANPD No. 19 of December 18, 2024 (Regulation of the International Transfer of Personal Data) and SoftwareOne relies on legal mechanisms that ensure an adequate level of protection for your personal data.
International Transfers of personal data originating from Ecuador will comply with the provisions of the LOPDP and SoftwareOne will only transfer personal data to countries and territories that comply with the standards of protection required by Ecuadorian laws and regulations.
Data Protection Rights (Brazil)
Individuals subject to the LGPD have the following rights:
- confirmation of the existence of processing;
- access to their data;
- rectification of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data or data processed in noncompliance with the LGPD;
- data portability upon express request;
- deletion of personal data processed with consent, to the extent permitted by law;
- information about public and private entities with which their personal data has been shared;
- information about the possibility of denying consent and its consequences;
- revocation of consent;
- upon request, obtain the full text of the clauses used to carry out an international data transfer, subject to trade and industrial secrets;
- lodge a complaint with a supervisory agency if they believe that the processing of their personal data infringes applicable data protection regulations.
In Brazil, the supervisory agency is the National Data Protection Agency (Agência Nacional de Proteção de Dados - ANPD).
Contact for data protection requests (Brazil and Ecuador)
In accordance with the LGPD and ANPD Resolution No. 18/2024, SoftwareOne has appointed a Data Protection Officer for Brazil. You may contact our DPO for any inquiries related to the processing of your personal data or to exercise your rights under the LGPD:
Vanessa Siqueira
data-protection.br@softwareone.com
The Data Protection Officer appointed for Ecuador (Encargado):
Nombre: Paul S Harris
Dirección: Ave. Naciones Unidas E699, Oficina 501. – Quito Ecuador
Teléfono: +593998325618
This Supplement applies to the handling of personal information of individuals located in Japan which is collected in Japan by SoftwareOne Japan K.K. or any other SoftwareOne entity with which you have established a relationship, as the case may be (individually or collectively, “SoftwareOne” or “we”) or a third party acting as a data processor on behalf of SoftwareOne, and supplements the above Privacy Notice. We comply with the Act on the Protection of Personal Information of Japan (Act No. 57 of 2003; the “APPI”).
Corporate Information
Under this Supplement, the entity responsible for handling your personal information is as follows:
Name: SoftwareOne Japan K.K.
Address: Hulic JP Akasaka Building 8F, 2-5-8 Akasaka, Minato-ku, Tokyo 107-0052
Representative: Kenji Hasegawa, CEO
Personal Information
“Personal information”, “personal data” and other related terms in this Supplement are to be interpreted as used in the APPI, unless otherwise defined herein; accordingly:
- “personal information” means information relating to a living individual which falls under any of the following items:
- information containing a name, date of birth, or other identifier or the equivalent (meaning all items (excluding individual identification codes) made by writing, recording, sound or motion, or other means, in a document, drawing, or electronic or magnetic record (this includes a record created in electronic or magnetic form (meaning electronic form, magnetic form, or any other form that cannot be perceived with the human senses; the same applies in the following item (ii)) which can be used to identify a specific individual (this includes any information that can be easily collated with other information and thereby used to identify that specific individual); and
- those containing an individual identification code; and
- “personal data” means personal information compiled in a personal information database or the equivalent.
Purposes of Use
We handle personal information solely within the scope necessary to achieve the purposes of use specified in the above Privacy Notice, except where otherwise permitted by the APPI or with your prior consent.
Proper Acquisition
We collect personal information in an appropriate manner and will not acquire any personal information through deception or other improper means.
Security Control Measures
We implement necessary and appropriate security control measures, including organizational, personnel, physical and technical safeguards, in order to prevent the leakage, loss or damage of any personal data we handle.
Joint Use
We may share and jointly use your personal data among our group companies.
- Items of Personal Data: As described in the “Relevant personal data” paragraph in each situation set forth in the above Privacy Notice.
- Scope of Joint Users: SoftwareOne AG and its consolidated subsidiaries.
- Purposes of Use: As described in Section 3 “Purposes of Use” above.
- Responsible Party for managing the personal data: SoftwareOne Japan K.K. (as identified in Section 1 above).
Cross Border Transfers
If we transfer your personal data to a third party outside Japan (excluding the EU and the UK), we will obtain your prior consent unless the recipient ensures an APPI-adequate level of protection or another legal exception under the APPI applies. Before seeking to obtain your prior consent, we will provide you with information on the name of the relevant foreign country, the personal information protection system of the foreign country, and the measures taken by the relevant third party to protect personal information.
Provision to Third Parties & Record-Keeping
We will not provide your personal data to any third party without your prior consent, except where permitted by the APPI or otherwise provided in this Supplement. When providing or receiving personal data from a third party, we will create and retain records in accordance with the APPI.
Your Rights under the APPI
In accordance with the APPI, you may request us for:
- notification of the purposes of use of the personal data we hold;
- disclosure of the content of your personal data we hold and the records we retain, or correction, addition or deletion of the content of your personal data we hold, if the content of such personal data is factual;
- suspension of use or erasure of your personal data we hold if the personal data has been obtained or is being handled in violation of the APPI; or
- cessation of third-party provision of your personal data we hold if the personal data is being provided to a third party in violation of the APPI.
You may also make a complaint about our handling of your personal data we hold, in accordance with the APPI. Such request or complaint must be made by submitting an inquiry to our contact point which can be found in Section 11. We will respond to such request or complaint in accordance with the APPI. Please note that we may collect the actual costs from you for taking the relevant measures in responding to your request for notification of the purposes of use of the personal data we hold or your request for disclosure of the content of the personal data we hold.
Sensitive Personal Information
We will not acquire any “sensitive personal information” as specified in the APPI (e.g., race, creed, social status, medical history, criminal record, the fact of having suffered damage by a crime) unless permitted under the APPI or with your prior consent.
Contact Point
To exercise your rights or for inquiries regarding our handling of personal data in Japan, please contact:
SoftwareONE Japan K.K.
Hulic JP Akasaka Building 8F, 2-5-8 Akasaka, Minato-ku, Tokyo 107-0052
+81 3 5005 2801
info.jp@softwareone.com
This Supplement applies where personal data is processed in the United Arab Emirates (“UAE”) or where the UAE Federal Decree Law No. 45 of 2021 on the Protection of Personal Data (“UAE PDPL”) is applicable. This Supplement shall be read together with the above Privacy Notice. Where any conflict arises, the provisions of this Supplement prevail for processing activities subject to the UAE PDPL.
Overseas Transfers (Articles 22–24 UAE PDPL)
SoftwareOne may transfer personal data outside the UAE only in accordance with the requirements of the UAE PDPL. Such transfers may take place where:
- The destination country appears on the UAE Data Office’s approved adequacy list;
- Appropriate contractual safeguards or legally recognized transfer mechanisms are implemented; or
- An exception under the UAE PDPL applies.
SoftwareOne ensures that all cross border transfers are supported by appropriate protection measures consistent with the UAE PDPL and the internal data protection standards.
Personal Data Breach Notification (Article 9 UAE PDPL)
In the event of a personal data breach that may pose a risk to the confidentiality, privacy, security or rights of individuals, SoftwareOne will:
- Notify the UAE Data Office without undue delay, and
- Notify affected individuals where the breach is likely to cause significant harm or impact.
SoftwareOne may maintains internal incident response processes to ensure timely detection, assessment, reporting, and mitigation of personal data breaches.
Data Protection Officer Requirement (Articles 10–11 UAE PDPL)
SoftwareOne appoints a Data Protection Officer (“DPO”) where required under the UAE PDPL, including scenarios involving:
- High risk processing operations, or
- Large scale processing of sensitive personal data.
The DPO supports ongoing compliance with the UAE PDPL, monitors internal controls, advises on data protection obligations and acts as a liaison with the UAE Data Office.
Rights of Individuals (Articles 13–20 UAE PDPL)
In addition to the rights outlined in the above Privacy Notice, individuals subject to the UAE PDPL may exercise the following rights:
- Right of access to personal data;
- Right to request correction or erasure;
- Right to restrict or stop processing;
- Right to data portability;
- Right to object to automated processing or automated decision making.
Requests may be submitted through the contact channels specified in the above Privacy Notice, and SoftwareOne will respond within the timelines mandated by the UAE PDPL.
Legal Basis for Processing (Article 4 UAE PDPL)
SoftwareOne processes personal data based on one or more legal bases recognized under the law, including:
- Consent;
- Necessity for performance of a contract;
- Compliance with legal obligations;
- Protection of public interest;
- Legitimate interests, to the extent permitted under the UAE PDPL.
Retention (Article 21 UAE PDPL)
Personal data subject to the UAE PDPL is retained only for the duration necessary to fulfil the purposes for which it was collected or as required by applicable legislation. SoftwareOne applies internal retention schedules aligned with the UAE PDPL’s data minimization and storage limitation principles.
Contact for UAE PDPL Requests
Individuals seeking to exercise their rights or raise concerns under the UAE PDPL may contact SoftwareOne at data-protection.me@softwareone.com.
This Supplement applies where personal data is processed within the State of Qatar or where the Qatar Personal Data Privacy Protection Law – Law No. 13 of 2016 (“Qatar PDPL”) is applicable. This Supplement shall be read together with the above Privacy Notice. Where any conflict arises, the provisions of this Supplement prevail for processing activities subject to the Qatar PDPL.
Overseas Data Transfers (Articles 15 & 16 Qatar PDPL)
SoftwareOne may transfer personal data outside the State of Qatar only in accordance with the requirements of the Qatar PDPL. Transfers may take place where:
- The receiving country provides an adequate level of protection;
- Explicit consent of the individual is obtained; or
- Appropriate safeguards or legally recognized transfer mechanisms are implemented.
SoftwareOne ensures that all cross border transfers follow the protection standards mandated under the Qatar PDPL.
Personal Data Breach Notification (Article 14 Qatar PDPL)
In the event of a personal data breach, SoftwareOne will:
- Notify the Ministry of Communications and Information Technology (MCIT) immediately, as required under the Qatar PDPL; and
- Notify affected individuals where the breach is likely to result in harm or adverse impact.
SoftwareOne maintains internal procedures to detect, assess and report breaches in accordance with statutory obligations.
Consent Requirements (Article 4 Qatar PDPL)
SoftwareOne obtains consent in accordance with the Qatar PDPL, ensuring that:
- Consent is explicit and informed;
- Consent is obtained prior to the processing of personal data;
- Additional safeguards are applied when processing sensitive personal data.
Where consent is withdrawn, SoftwareOne will cease processing activities unless another lawful basis under the Qatar PDPL applies.
Rights of Individuals (Articles 7–10 Qatar PDPL)
Individuals whose personal data is processed under the Qatar PDPL may exercise the following rights:
- Right of access to personal data;
- Right to request correction or erasure;
- Right to object to processing;
- Right to withdraw consent at any time.
Such rights can be exercised by reaching SoftwareOne at data-protection.me@softwareone.com. Replies will be received within the timelines specified under the Qatar PDPL.
This Supplement applies where personal data is processed within Australia or where the Privacy Act 1988 (Cth) (“Privacy Act”) is applicable. This Supplement shall be read together with the above Privacy Notice. Where any conflict arises, the provisions of this Supplement prevail for processing activities subject to the Privacy Act.
The type of personal data we use and what we do with that depends on the relationship we have with you. Therefore, some parts of this Supplement, as well as of the above Privacy Notice may not be relevant for you or more than one part of this Supplement, as well as of the above Privacy Notice may apply to you.
The meaning of the term “personal data” in this Supplement, as well as in the above Privacy Notice, has the same meaning as set out in the Privacy Act.
This Supplement, as well as the above Privacy Notice may be replaced or supplemented in order to fulfil legal requirements, as well as to provide you with all necessary information on how we process your personal data.
Why we collect personal data
We collect personal data so that we can provide our services to you and your service provider, as well as reasonable associated purposes. These purposes include but are not limited to the purposes already reflected in the above Privacy Notice.
We may also collect your personal information for a purpose which is additional to the original purpose pursuant to which we originally received or collected the personal data.
Personal data we collect
The types of personal data we may receive or collect include the following:
- Name or alias;
- Contact details (such as address, postal address, email, phone number);
- Date of birth;
- Sex, gender, or gender identity;
- Nationality or proof of residence (such as residence permits, work right permits or visa);
- Employment data (such as current employment, past employment or other work history);
- Educational qualifications (such as degrees, accreditations, occupational permits or occupational licences);
- Identification documents (such as passport, driver’s licence, identity card or other similar documentation);
- Pictures (such as head shots);
- Transaction and bank account details;
- Any personal information that is inherently disclosed when you or your service provider communicate with us (such as metadata); and
- Criminal history.
In limited circumstances we may need to obtain health information from you. In such circumstances we will make an express request and will treat any information as strictly confidential.
Further details about the personal data we collect and how it is processed or used depending on our relationship with you can be found in the above Privacy Notice.
How we collect personal data
We receive or collect personal data directly from your or your service provider’s in interactions with us, such as when you create a user account, sign up for our services, submit queries or engage with the services we provide. In addition to this, any personal data that you provide to us will constitute the collection of personal data for the purposes of this Supplement, as well as the above Privacy Notice.
Personal data may also be collected via our website, forms, phone calls, emails or through third-party providers with your consent or to the extent necessary to provide the services to you.
How we hold and protect personal data
We will only retain your personal data only so long as is necessary to provide our services, after which time we will destroy it, unless we:
- are required by law to retain it; or
- are required to preserve it for the purposes of providing services to another customer; or
- have agreed to a request by you or your service provider to preserve that personal information; or
- have a legitimate purpose for retaining it.
We take all reasonable steps to protect all information we hold, including personal data.
Cookies and other similar technologies
We may use cookies and similar technologies (for simplicity reasons, hereinafter referred to as “Cookies”), when you use our websites, platforms, applications as well as other products and services.
Our Cookie Banner and consent management system show you a list of the Cookies we use, including their provider, purpose, description and other relevant information. In the default setting, only the essential Cookies are enabled. Via the consent management system, you can determine whether you allow the setting of additional Cookies or not. You can adjust your preferences at any time via the consent management system.
Further information about the ways that we may track your personal information including on social media (e.g., Facebook) can be found in the above Privacy Notice.
Disclosure to third parties
We may disclose your personal data to parties to fulfil the purposes described above, including to provide services to you or your service provider. Due to SoftwareOne’s international group structure, personal data will be disclosed to certain departments and persons on a need-to-know basis to process personal data so that we can provide our services. For all intragroup personal data access and transfers, we comply with the provisions of the Privacy Act.
Third party service providers contracted by SoftwareOne may also receive personal data to provide or facilitate the provision of our services. These include, service providers who support us with order fulfilment, payment / billing, customer service, finance, auditing, fraud detection, IT services, communication, hosting, logistics, email delivery, marketing, sales, data analysis, event management, training, surveys, printing, archive, advisory and consulting services.
We may disclose your personal data to further recipients, such as private as well as public entities and institutions, including law enforcement, data protection authorities, tax authorities, credit agencies, debt collectors, banks, courts, hotels or other companies insofar as there is a legal basis for such disclosure.
Disclosure overseas
As we operate in a number of countries it is possible that your personal data may need to be transferred outside of Australia to countries in which we operate including the European Union, the United Kingdom and Switzerland, in order to provide our services. We will take reasonable steps to ensure that such recipients comply with the Privacy Act and maintain the confidentiality and security of your personal information.
Accessing or correcting personal data
You may contact us to access your personal data we hold about you and to request corrections if any details are inaccurate or incomplete. We may refuse to provide access you with to your personal data if:
- we are legally permitted to do so and consider it appropriate; or
- are required by law to deny the request.
Questions and complaints
If you have any requests, comments, queries or complaints in relation to your personal data, our handling of your personal data or how we handle personal data generally, please contact our information officer at data-protection.apac@softwareone.com.
We will respond to any requests or complaints within a reasonable period (usually 30 days).
If you disagree with our response or any decision that we make in respect of your personal data, including in respect of any complaint that you have made, you may refer your complaint to the Office of the Australian Information Commissioner by visiting www.oaic.gov.au, calling 1300 363 992 or by emailing enquiries@oaic.gov.au.
This Supplement applies where personal data is processed within New Zealand or where the Privacy Act 2020 (“Privacy Act”) is applicable. This Supplement shall be read together with the above Privacy Notice.
The type of personal data we use and what we do with that depends on the relationship we have with you. Therefore, some parts of this Supplement, as well as of the above Privacy Notice may not be relevant for you or more than one part of this Supplement, as well as of the above Privacy Notice may apply to you.
The meaning of the term “personal data” in this Supplement, as well as in the above Privacy Notice has the same meaning as set out in the Privacy Act.
This Supplement, as well as the above Privacy Notice may be replaced or supplemented in order to fulfil legal requirements, as well as to provide you with all necessary information on how we process your personal data.
Why we collect personal information
We collect personal data so that we can provide our services to you and your service provider, as well as reasonable associated purposes. These purposes include but are not limited to the following:
- communicate with you and your service provider, process requests and respond to requests;
- process comments or posts;
- register and send newsletters to you which you subscribe to;
- marketing purposes;
- registration, authentication and administration of user accounts;
- license monitoring purposes;
- provision of demo products and services as well as trials (also from third parties);
- analysis purposes in order to improve our products and services;
- tailor our website content and experience to your interests;
- maintain the security of our websites, platforms, applications as well other products and services;
- comply with legal and regulatory requirements and requests; and
- establish, exercise and defend legal claims.
We may also collect your personal data for a purpose which is additional to the original purpose pursuant to which we originally received or collected the personal data.
You are not required to give us your personal data, however, if you choose not to we may be unable to provide, in whole or in part, our services to you and your service provider.
Further details about the personal data we collect and how it is processed or used depending on our relationship with you can be found in the above Privacy Notice.
Personal data we collect
The types of personal data we may receive or collect include the following:
- Name or alias;
- Contact details (such as address, postal address, email and phone number);
- Date of birth;
- Sex, gender or gender identity;
- Nationality or proof of residence (such as residence permits, work right permits or visa);
- Employment data (such as current employment, past employment or other work history);
- Educational qualifications (such as degrees, accreditations, occupational permits or occupational licences);
- Identification documents (such as passport, driver’s licence, identity card or other similar documentation);
- Pictures (such as head shots);
- Transaction and bank account details;
- Any personal data that is inherently disclosed when you or your service provider communicate with us (such as metadata); and
- Criminal history.
During the course of providing services to you or your service provider we may create information about you which constitutes personal data including things such as emails, letters or other internal records.
Further details about the personal data we collect and how it is processed or used depending on our relationship with you can be found in the above Privacy Notice.
How we collect personal data
We receive or collect personal data directly from your or your service provider’s in interactions with us, such as when you create a user account, sign up for our services, submit queries or engage with the services we provide. In addition to this, any personal data that you provide to us will constitute the collection of personal data for the purposes of this Supplement, as well as the above Privacy Notice.
Information which we create as a result of providing services to you or your service provider which constitutes personal data will also constitute the collection of personal data for the purposes of this Supplement, as well as the above Privacy Notice.
Personal data may also be collected via our website, forms, phone calls, emails or through third-party providers with your consent or to the extent necessary to provide the services to you.
How we hold and protect personal data
We will only retain your personal data only so long as is necessary to provide our services, after which time we will destroy it unless we:
- are required by law to retain it; or
- are required to preserve it for the purposes of providing services to another customer; or
- have agreed to a request by you or your service provider to preserve that personal data; or
- have a legitimate purpose for retaining it.
We take all reasonable steps to protect all information we hold, including personal data.
Cookies and other similar technologies
We may use cookies and similar technologies (for simplicity reasons, hereinafter referred to as “Cookies”), when you use our websites, platforms, applications as well as other products and services.
Our Cookie Banner and consent management system show you a list of the Cookies we use, including their provider, purpose, description and other relevant information. In the default setting, only the essential Cookies are enabled. Via the consent management system, you can determine whether you allow the setting of additional Cookies or not. You can adjust your preferences at any time via the consent management system.
Further information about the ways that we may track your personal data including on social media (e.g., Facebook) can be found in the above Privacy Notice.
Disclosure to third parties
We may disclose your personal data to parties to fulfil the purposes described above including to provide services to you or your service provider. Due to SoftwareOne’s international group structure, personal data will be disclosed to certain departments and persons on a need-to-know basis to process personal data so that we can provide our services. For all intragroup data access and transfers, we comply with the provisions of the Privacy Act.
Third party service providers contracted by SoftwareOne may also receive personal data to provide or facilitate the provision of our services. These include, service providers who support us with order fulfilment, payment / billing, customer service, finance, auditing, fraud detection, IT services, communication, hosting, logistics, email delivery, marketing, sales, data analysis, event management, training, surveys, printing, archive, advisory and consulting services.
We may disclose your personal data to further recipients to the extent required to fulfil the purpose, such as private as well as public entities and institutions, including law enforcement, data protection authorities, tax authorities, credit agencies, debt collectors, banks, courts, hotels or other companies insofar as there is a legal basis for such disclosure.
Disclosure overseas
As we operate in a number of countries it is possible that your personal data may need to be transferred outside of New Zealand to countries in which we operate including the European Union, the United Kingdom and Switzerland, in order to provide our services. We will take reasonable steps to ensure that such recipients comply with the Privacy Act and maintain the confidentiality and security of your personal data.
Accessing or correcting personal data
You may contact us to access your personal data we hold about you and to request corrections if any details are inaccurate or incomplete. We may refuse to provide access you with to your personal data if:
- we are legally permitted to do so and consider it appropriate; or
- are required by law to deny the request.
Questions and complaints
If you have any requests, comments, queries or complaints in relation to your personal data, our handling of your personal data or how we handle personal data generally, please contact our information officer at data-protection.apac@softwareone.com.
We will respond to any requests or complaints within a reasonable period (usually 30 days).
If you disagree with our response or any decision that we make in respect of your personal data including in respect of any complaint that you have made, you may refer your complaint to the Privacy Commissioner (Te Mana Matapono Matatapu) by visiting www.privacy.org.nz, calling 0800 803 909 or by emailing enquiries@privacy.org.nz.
Applicability
This Supplement forms an integral part of the above Privacy Notice and applies solely to Data Principals located in India.
This Supplement governs the processing of digital personal data by SoftwareOne in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made thereunder ("DPDP Rules"), including:
- personal data collected in digital form within India;
- personal data collected in non-digital form and subsequently digitized; and
- processing of digital personal data carried out outside India in connection with the offering of goods or services to Data Principals within India, in accordance with Section 3 of the DPDP Act.
In the event of any inconsistency between this Supplement and the above Privacy Notice, the provisions of this Supplement shall prevail to the extent of such inconsistency for processing governed by Indian law.
Definitions
Unless otherwise defined herein, capitalized terms used in this Supplement shall have the meanings ascribed to them under the DPDP Act and the DPDP Rules.
For the purposes of this Supplement:
- "Board" means the Data Protection Board of India established under the DPDP Act;
- "Data Principal" means the individual to whom the personal data relates and where such individual is
- a child, includes the parents or lawful guardian of such child; or
- a person with disability, includes her lawful guardian acting on her behalf.
- "SoftwareOne" means the relevant SoftwareOne entity acting as a Data Fiduciary in relation to the processing of personal data under Indian law.
Notice to Data Principals
Consent to the processing of personal data by SoftwareOne shall be obtained only upon the Data Principal’s acceptance of this Supplement and the above Privacy Notice.
Contact for Data Protection Requests
Any request for withdrawal of consent, request for access to information, correction, erasure, grievance or any other communication under the DPDP Act may be addressed to:
Designation / Department: Regional General Counsel
Email ID: data-protection.apac@softwareone.com
Alternately, the Data Principal may communicate his request at: Shweta.Sinha@softwareone.com.
Grievance Redressal Mechanism
SoftwareOne has established an effective grievance redressal mechanism to address grievances raised by Data Principals in relation to the processing of their personal data.
A Data Principal may submit a grievance by contacting the Grievance Officer at:
Name: Regional General Counsel
Designation: Grievance Officer – India
Email ID: data-protection.apac@softwareone.com
Postal Address: 7th Floor, Tower 1A, International Tech Park, Near Sector 59, Behrampur, Gurugram, Haryana-122101.
SoftwareOne shall acknowledge the grievance and endeavor to resolve it within 30 days from the date of receipt.
A Data Principal shall exhaust the grievance redressal mechanism provided herein before approaching the Board, in accordance with Section 13 of the DPDP Act.
Nomination
A Data Principal may nominate one or more individuals to exercise her rights under the DPDP Act in the event of her death or incapacity.
Such nomination may be made by:
- submitting a request through the user account or digital interface made available by SoftwareOne; or
- submitting a written request to SoftwareOne using the contact details provided in this Supplement, along with such information and verification details as may be reasonably required by SoftwareOne.
Processing and Transfer of Personal Data Outside India
SoftwareOne may transfer personal data outside the territory of India only in accordance with:
- any restrictions notified by the Central Government on the transfer of personal data to specified countries or territories; and
- the conditions and safeguards specified by the Central Government through general or special orders.
Where such transfers occur, SoftwareOne shall ensure compliance with all applicable requirements under the DPDP Act, the DPDP Rules, and other applicable Indian laws.
Updates to this Supplement
This Supplement may be updated from time to time to reflect changes in applicable law, including amendments to the DPDP Act or the DPDP Rules, or guidance, directions or orders issued by the Government of India or the Data Protection Board of India. Material changes shall be notified to Data Principals through appropriate and reasonable means.
Children’s Personal Data
SoftwareOne does not knowingly process personal data of children, as defined under the DPDP Act.
Where processing of personal data of a child becomes necessary under applicable law, SoftwareOne shall ensure compliance with the requirements relating to verifiable parental consent and other safeguards prescribed under the DPDP Act and the DPDP Rules.
Additional DPDP-Specific Disclosures
Right to Withdraw Consent: Withdrawal of consent shall not affect the legality of processing carried out prior to such withdrawal.
Data Retention: SoftwareOne shall retain personal data only for such period as is necessary to fulfil the specified purpose or to comply with applicable law, after which such data shall be erased in accordance with the DPDP Act and the DPDP Rules.
本隱私權聲明的變更
我們可能會不時更新本隱私權聲明,以反映適用法律、我們的做法與服務、法律要求的變動或是提高透明度。如果我們做出重大變更,會透過更新本隱私權聲明頂端的生效日期通知您。因此,我們建議您定期查看本隱私權聲明,以便隨時了解我們如何收集、使用和保護您的個人資料。
請注意,SoftwareOne 和 Crayon 合併後,兩家公司先前的隱私權聲明可能仍然適用於本隱私權聲明生效日期之前收集的個人資料。
版本歷程記錄
| 版本 | 日期 |
| 1.0 | 2020 年 6 月 |
| 2.0 | 2021 年 9 月 |
| 3.0 | 2026 年 8 月 |