Privacy Policy
Introduction
Hitachi East Asia Limited (hereinafter referred to as "HEA" or "we"), fully understands the importance of personal data to you, and is committed to protecting your personal data. To explain how we collect, use, share, and protect your personal data and other related Data, we have established this personal data protection policy ("this Policy"), please be sure to read it carefully and make the decisions you consider appropriate.
HEA protects personal data primarily in the following ways:
1、Collection, Use, and Provision of Personal Data
HEA has established personal data protection management systems, while adhering to the principles of legality, legitimacy, and necessity in the collection, use, and provision of personal data in the course of our business operations.
2、Implementing Security Policies and Measures
In handling personal data, HEA always complies with applicable personal data protection laws and regulations (including the Personal Data (Privacy Data) Ordinance (Chapter 486)). To ensure the security of personal data, HEA will implement Data security safeguards in accordance with established standards, and manage personal data, restrict channels of personal data disclosure, and prevent unauthorized access, while striving to prevent personal data leakage incidents.
3、Respect for the rights of data subjects.
When you request to access, correct, or delete your personal data, or request to reject the use or provision of your personal data, HEA will, in accordance with applicable laws and regulations, respect the rights of data subjects and respond to and handle such requests as soon as possible.
4、Establishing and continuously improving personal data management systems
HEA’s management and employees all understand the importance of personal data protection. HEA has established and implemented relevant personal data management systems internally to ensure the personal data is used and protected appropriately. Such management systems will be fully implemented and continuously improved.
Definition of Personal Data
Personal data refers to Data related to a natural person, recorded electronically or by other means, and that can be used to/or identify of a specific natural person. Examples include name, date of birth, personal identification number, photograph or voice recording, type of work/ job title, and other related Data (including data that cannot identify a specific individual when used alone, but can identify a specific natural person when combined with other data).
Sensitive Personal Data refers to personal data which, once leaked, illegally provided, or misused, may endanger personal safety and property, or could easily result to harm a natural person's reputation, mental or physical health, or leading discrimination. Such data includes personal financial Data such as bank accounts and loan records, personal biometric data such as fingerprints, iris scans, and facial recognition features, personal health and physiological data such as past medical history and fertility information, and personal identification data such as ID cards and passports, as well as other data such as religious beliefs and location histories. Please carefully consider whether to provide such data to us during the usage process.
Scope of Application
This privacy policy applies to (1) your personal data collected online when you use our website; and (2) your personal data we obtain through your purchase and use of our products and services. This privacy policy does not apply to products and services that have separate privacy policies.
Our official website may contain links to third-party websites. The products or services related to such third-party websites are not governed by this Privacy Policy. We recommend that you review their personal data protection policies of those third-party websites to understand their personal data protection measures.
Collection of Personal Data
You purchase products and use services of HEA, we will collect your personal data, including but not limited to your name, age, gender, date of birth, ID number/passport number, residential address, email address, telephone number (including mobile phone), social media accounts such as WeChat, bank account information and other data. When we collect your personal data, we will state the purpose and use of data collection, and inform you how to request access to or correction of the personal data you provided.
Use of Cookie and Web Beacon
Cookie refers to small text files sent by our official website to your browser when you visit our official site, which helps the browser record information related to the visit, such as default language, browser type and settings, operating system, and other settings. Cookies provide a more convenient browsing experience when you visit our website next time. Web Beacon technology can be used in conjunction with cookies and can record number of times you log in to specific pages, IP address, geographic location, browsing time, and web pages visited, and other visitor-related data.
We use Cookie for multiple purposes, including making it more convenient for you to use our official website, counting the number of visitors to our webpages, remembering your language preferences, providing customized advertisements, optimizing website design and others. Our official website may use Cookie or similar technologies such as web beacons (Clear GIF), but we will not, and do not intend to, use Cookie and web beacons to collect data for identifying your personal identity. You may also change the settings of your web browser to reject Cookies or configure your browser to alert you when cookies are being accepted. By rejecting Cookies, you can also reject web beacons. For details, please refer to your browser's instructions. If you refuse to accept cookies, you may not be able to use services on the official website that require cookies. We appreciate your understanding.
Purposes of Using Personal Data
HEA will only use your personal data collected through the above channels, within the necessary scope, for the purposes stated below. We will obtain your prior consent when using your personal data for the purposes outlined in sections (d) and (g), as well as for any other purposes not previously specified.
a)To perform contracts between business partners and HEA;
b)To contact customers or suppliers for business negotiations or meetings;
c)To provide our services, including after-sales service for products;
d)To deliver meeting guidelines or new product information;
e)To respond to various inquiries;
f)To conduct customer surveys and analyze them to improve products or our services;
g)To provide relevant personal data to affiliates of Hitachi Group when HEA and such affiliates jointly carry out business activities;
h)To comply with legal and regulatory requirements, execute court orders or perform other legal procedures, or respond to requests from competent government authorities.
Provision of Personal Data to Third Parties
HEA will not provide your personal Data to third parties without your explicit consent, except in the following circumstances:
a)with your prior explicit consent;
b)when there is a clear requirement in accordance with applicable laws and regulations;
c)when it is necessary to use your personal data for urgent purposes such as protecting lives, preventing bodily harm, or safeguarding property, but it is difficult to obtain your consent at the same time;
d)when it is strongly necessary to use the data for the purpose of improving public health conditions or promoting children's healthy development, but it is difficult to obtain your consent at the same time;
e)when in accordance with disclosure requirements of higher supervisory authorities, including but not limited to provision to government agencies, judicial authorities, and their subordinate units, and obtaining your consent may hinder the progress of such work.
Retention of Personal data
Unless otherwise specified by laws and regulations and law enforcement authorities, we will retain your personal data within the shortest period stipulated by law and for the period necessary to achieve the purposes described in this Privacy Policy.
Your Rights and Choices Regarding Personal Data
We will endeavor to ensure your right to access, update, correct, or delete your personal data. If applicable laws and regulations prevent us from fulfilling your request, we will provide you with a reasonable explanation.
a)Right to access: You have the right to complete the designated form to request that we inform you whether we hold any of your personal data. You may also request that we provide you with a copy of that data if we hold it. Generally, we will respond within 40 days after properly receiving the designated form for a data access request, in accordance with Section 19 of the Personal Data (Privacy) Ordinance.
The designated form for data access requests is as follows:Chinese / English
The completed form shall be send to Human Resources and Administration Department, Suite 1507, 15/F, Wharf T&T Centre, Harbour City, 7 Canton Road, Tsim Sha Tsui, Kowloon Hong Kong,
We may recover directly related costs based on the time required for our staff to locate, retrieve and copy the data in accordance with your request and the actual expenses incurred. In most cases, the cost of complying with a data access request is a nominal amount. However, if the request is large-scale (including but not limited to involving a large volume of documents and covering a long period of time) the cost may be substantial.
b)Right to correct: When you find that your personal data held by us is inaccurate or incomplete, you have the right to request the correction of your personal data. Generally, we will make the necessary corrections within 40 days after properly receiving such request, in accordance with the Personal Data (Privacy) Ordinance, Article23, Privacy;
c)Right to delet: When you no longer use our services, you have the right to request the deletion of your personal data, unless deletion is prohibited by applicable laws or is not aligned with the public interests;
d)Right to Withdraw: Each service requires certain basic personal data in order to be completed. For personal data that is not necessary to collect, you may give or withdraw your authorization and consent at any time.
Except for the above paragraphs (a) and (b), when you request to exercise the above rights or file other complaints, we will conduct a brief verification of your identity and the authenticity of your request. As a general rule, we will respond with our handling opinion or result within 15 days.
Except for the above paragraph (a), we do not charge fees for your reasonable requests as a general rule. However, for repeated requests that exceed reasonable scope, we may charge a certain at our discretion. For requests requiring excessive technical measures or deemed impractical, we may reject them where permitted by applicable laws.
Cross-Border Transfer of Personal Data
We operate our business in cooperation with global group companies and business partners. In order to operate efficiently and provide you with a better service experience, in specific data processing activities, we may transfer the collected personal data mentioned above to group companies or business partners located overseas. We will endeavor to ensure that the transfer of personal data complies with applicable privacy laws and implement appropriate technical, organizational, and administrative measures to safeguard the security of personal data.
Personal Data Protection Measures
We are continuously improving the organizational and technical measures related to personal data protection. Through a comprehensive internal management system for personal data, We strictly restrict access to and use of personal data. At the same time, we adopt necessary security technical measures to protect your personal data from unauthorized access, destruction, modification, or disclosure.
The internet environment is not100% secure and we will endeavor to ensure the security of any data you send to us. In the event of a cybersecurity incident, we will promptly address the security risks, take corresponding remedial actions, and report to the relevant authorities in accordance with applicable laws and regulations. At the same time, we will inform you in a timely manner, in accordance with applicable laws and regulations, about the basic situation and potential impact of such incident, the measures we have taken or will take to address it, and the remedies available to you. We will promptly notify you of the details of the incident through the contact methods you have provided, such as text messages, emails, or phone calls. If it is not feasible to notify each affected individual individually, we will use reasonable and effective means to issue public announcements, such as posting notices on our official website.
Protection of Minors
Unless otherwise required by applicable laws, regulations, or law enforcement authorities, we will not actively or independently collect personal data of minors, unless we have obtained the consent of a responsible parent or guardian. If you believe that we have collected data of a minor, please contact us promptly, and we will verify the matter and delete their personal data in a timely manner.
Contact Us
If you have any questions, comments or suggestions regarding this Personal Data Protection Policy, please click here contact us.