Privacy Policy (Hong Kong)
Japan Bio Products Co., Ltd. (hereinafter referred to as the "Company") establishes this Privacy Policy (hereinafter referred to as the "Policy") regarding the handling of personal data of users of the Company's services (hereinafter referred to as "Users"). The Company shall build a personal data protection system, ensure that all employees recognize the importance of personal data protection, and thoroughly promote the protection of personal data.
Article 1 (Personal Data)
"Personal Data" refers to "personal data" as defined under the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (and/or applicable Japanese laws such as the APPI where relevant), which relates to a living individual and can be used to identify a specific individual through a name, date of birth, or other descriptions contained in such data, or which contains a personal identifier.
Article 2 (Purpose of Use of Personal Data)
The Company will collect and use Users' personal data to the extent necessary for the following purposes. If the Company intends to use personal data beyond the scope of the following purposes, the Company shall obtain the prior consent of the User through appropriate methods: (1) To provide the services of the Company (hereinafter referred to as the "Services"); (2) To improve and modify the contents of the Services or to develop new services; (3) To provide information on new features, update information, campaigns, etc., of the Services, as well as other services provided by the Company (including sending e-mails, flyers, or other direct mail); (4) To contact Users as necessary for maintenance, important notices, etc.; (5) To respond to inquiries, opinions, etc., from Users regarding the Services (including conducting identity verification); (6) To report the usage status of the Services to Users; (7) To request cooperation in surveys, interviews, etc., or participation in various events regarding the Services, or to report the results thereof; (8) To investigate and analyze the usage history of the Services, and to use the results for improving/developing the Services or delivering advertisements; (9) To provide personal data to event-participating companies, etc., sponsored by the Company, based on the User's consent or application; (10) To identify Users who violate the Terms of Service or those who attempt to use the Services for fraudulent or unjustified purposes, and to refuse their use.
Article 3 (Management and Protection of Personal Data)
The Company shall manage personal data strictly and shall not disclose or provide data to third parties without the User's consent, except in the following cases. In addition, the Company shall take preventive and corrective measures against risks such as unauthorized access to personal data, loss, destruction, falsification, and leakage of personal data in consideration of security: (1) When it is necessary for the protection of human life, body, or property and it is difficult to obtain the User's consent; (2) When it is particularly necessary for improving public health or promoting the sound growth of children and it is difficult to obtain the User's consent; (3) When it is necessary to cooperate with a national government agency, a local government, or a person entrusted by them in executing affairs prescribed by laws and regulations, and obtaining the User's consent is likely to impede the execution of such affairs; (4) When otherwise permitted by laws and regulations.
Article 4 (Entrustment of Personal Data Handling)
The Company may entrust all or part of the handling of personal data within the scope necessary to achieve the purpose of use. In this case, the Company shall thoroughly examine the eligibility of the subcontractor, stipulate matters concerning confidentiality obligations in the contract, and exercise necessary and appropriate supervision over the subcontractor.
Article 5 (Disclosure of Personal Data)
When the Company is requested by a User (limited to the individual concerned; the same shall apply in this Article) to disclose their personal data held by the Company, the Company shall disclose it to the User without delay. However, if the disclosure falls under any of the following cases, the Company may decide not to disclose all or part of it, and if the Company decides not to disclose, it shall notify the User to that effect without delay: (1) When there is a risk of harming the life, body, property, or other rights and interests of the User or a third party; (2) When there is a risk of causing significant hindrance to the proper execution of the Company's business; (3) When it would violate other laws and regulations.
Article 6 (Correction, etc., of Retained Personal Data)
If the personal data held by the Company is incorrect, the User may request the Company to correct, add, or delete (hereinafter referred to as "Correction, etc.") the personal data. Upon receiving the request in the preceding paragraph, the Company shall conduct necessary investigations without delay, and if it determines that the request is justified, it shall carry out the Correction, etc., of the personal data without delay. When the Company has made a decision on whether or not to implement the Correction, etc., based on the preceding paragraph, it shall notify the User concerned without delay.
Article 7 (Suspension of Use, etc., of Personal Data)
The User may request the Company to suspend the use, erase, or stop providing to third parties (hereinafter referred to as "Suspension of Use, etc.") the personal data held by the Company. Upon receiving the request in the preceding paragraph, the Company shall conduct necessary investigations without delay, and if it determines that the request is justified, it shall carry out the Suspension of Use, etc., of the personal data. However, if the Suspension of Use, etc., requires a large amount of costs or if it is otherwise difficult to carry out the Suspension of Use, etc., and alternative measures necessary to protect the rights and interests of the User can be taken, such alternative measures shall be taken. When the Company has made a decision on whether or not to implement the Suspension of Use, etc., based on the preceding paragraph, it shall notify the User concerned without delay.
Article 8 (Procedures for Changing the Privacy Policy)
The Company shall review the contents of this Policy from time to time and strive to improve it. The contents of this Policy may be changed, except as otherwise provided by laws and regulations or this Policy. The revised Privacy Policy shall take effect when notified to Users by a method prescribed by the Company or posted on the Company's website.
Article 9 (Compliance with Laws and Norms)
The Company shall comply with applicable laws, regulations, and other norms regarding the personal data it holds.
Article 10 (Response to Complaints and Consultations)
The Company shall accept and respond appropriately and promptly to complaints and consultations from Users regarding the handling of personal data. The Company will also respond promptly and appropriately to requests from Users for disclosure, correction, addition, deletion, refusal of use or provision of such personal data.
Article 11 (Security Control Measures)
Personal data entrusted to the Company by Users shall be protected by implementing organizational, physical, human, and technical measures, such as implementing access restrictions to personal data files, recording access logs, and implementing security measures to prevent unauthorized access from outside, thereby preventing unauthorized intrusion, loss, destruction, falsification, and leakage of personal data. In the unlikely event of an accident such as a leakage of Users' personal data, the Company shall promptly report to the regulatory authorities in accordance with the Personal Data (Protection) Law and related guidelines, and take necessary responses such as preventive measures against similar cases and recurrence prevention measures in accordance with the instructions of the regulatory authorities. For details, please check the attached "Security Control Measures for Personal Data".
Article 12 (Use of Cookies)
The Company's website (https://jbp.placenta.co.jp/) uses cookies in some parts. Through the use of cookies, we can grasp the browsing history of customers on the Company's website and make the use of the Company's website more beneficial. Note that cookies may identify the browser used by the customer, but they do not identify the customer's personal data and are used only to grasp the browsing status of the Company's website.
Article 13 (Company Address, Representative Name, and Personal Data Protection Manager)
The address, representative, and personal data protection manager of the Company are as follows:
-
Address: 1-44-4 Tomigaya, Shibuya-ku, Tokyo 151-0063, Japan
-
Representative: Honsok Lim, Representative Director and President
Article 14 (Inquiry Desk / Cross-Border Data Transfer & Direct Marketing Notice)
If you have any questions, comments, or requests regarding the handling of the Company's personal data, or if you wish to opt-out of direct marketing or exercise your data protection rights, please contact the desk below.
-
Note on Cross-Border Data Transfer: Personal data collected in Hong Kong may be transferred to, stored, and processed in Japan where our servers and main operations are located. We ensure that appropriate safeguards are implemented in accordance with applicable laws.
-
Note on Direct Marketing: If you do not wish to receive direct marketing communications from us, you may opt-out at any time free of charge by contacting us below.
Japan Bio Products Co., Ltd. Inquiry Desk
1-44-4 Tomigaya, Shibuya-ku, Tokyo 151-0063, Japan
Inquiry URL: https://jbp.placenta.co.jp/inquiry/
Established on July 24, 2024