Privacy Policy
Applicable services: Member Center, shared sign-in services, and newsletter subscription management services
1. Scope
This Privacy Policy explains how Innovedus Inc. (Chinese legal name: 智匯創育股份有限公司; "we," "us," or "our") collects, processes, uses, stores, and protects personal data when you use the Member Center (https://member.innovedus.com), shared sign-in, OAuth/OpenID Connect authorization, profile management, newsletter subscription and unsubscribe features, delegated file access authorization, and related websites or APIs (collectively, the "Service").
The Service is currently designed primarily for users and operations in Taiwan. If the Service later expands to other jurisdictions with specific legal requirements, we will supplement or update this Policy as required by applicable law.
The Service may be integrated with multiple websites, tenants, or partner services. When you are redirected from a third-party website to the Service to sign in, register, manage your profile, or subscribe to newsletters, this Policy applies to personal data processed by us through the Service. Data collected, processed, or used independently by third-party websites or partner services is governed by their own privacy policies.
2. Our Role as Controller or Processor
Depending on the service context, we may process your personal data as a data controller or a data processor.
When you register directly with the Service, sign in, manage member information, or subscribe to newsletters, we generally act as the data controller. When a tenant website, partner, or business customer engages the Service to provide authentication, member management, newsletter management, authorization management, or other technical services, we may process the relevant data as a data processor acting on its instructions. In that situation, the data controller is primarily responsible for the purposes, legal basis, and subsequent use of personal data.
3. Notice under Article 8 of the Taiwan Personal Data Protection Act
When we collect personal data from you, Article 8 of the Taiwan Personal Data Protection Act requires notice of the collector's identity, purposes of collection, categories of personal data, period, region, recipients, and methods of use, your statutory rights, and the effect of choosing not to provide data. The sections of this Policy provide those details.
You may exercise the rights to inquire, access, request a copy, supplement, correct, stop collection, stop processing, stop use, and request deletion as provided by law. If you decline to provide data necessary for the Service, we may be unable to create your account, verify your identity, complete authorization, manage subscriptions, or provide certain features. You may choose whether to provide data that is not necessary.
4. Personal Data We Collect
Depending on how you use the Service, we may collect the following categories of personal data:
- Account and sign-in data: email address, password hash, account identifier, account creation time, last sign-in or activity time, email verification status, account disabled or blocked status, and security tokens or records related to sign-in, sign-out, password reset, and email verification.
- Profile data: name, nickname, mobile and landline phone numbers, date of birth, gender, company name, department, job title, company phone number, tax ID, invoice title, remarks, and other data you voluntarily provide.
- Address book data: address label, recipient name and phone number, country or region, postal code, state or region, city, district, address lines, company name, default address setting, and other address metadata.
- Newsletter subscription data: email address, subscription list, tenant or website, subscription status and preferences, confirmation and unsubscribe records, one-click unsubscribe tokens, subscription-to-account linking records, and suppression or blacklist records generated due to bounces, complaints, account restrictions, or suppression rules.
- OAuth/OpenID Connect and API authorization data: authorized clients, scopes, tenant identifiers, resource audiences, records related to access or refresh tokens, authorization requests, and redirect URI validation data. We do not store your password in plaintext.
- File access authorization data: tenant identifier, user identifier, file identifier or object key, HTTP method, scope, issuing client, expiration time, revocation time, and validation time.
- Consent and audit records: the Terms of Service and Privacy Policy versions you accepted, registration method, IP address, User-Agent, acceptance time, and audit records generated by administrators or system operations.
- Device, browser, and technical records: IP address, User-Agent, request time, referrer URL, cookie or session identifiers, language settings, error and security event records, rate-limit records, and abnormal access detection records.
- Third-party sign-in data: if Google or another external sign-in provider is enabled, we may receive basic account data provided within the scope you authorize, such as email, name, or an external account identifier. The provider's own privacy policy governs its processing of your data.
5. Purposes of Processing
- To create, verify, maintain, and manage member accounts.
- To provide shared sign-in, OAuth/OpenID Connect authorization, token issuance, sign-out, and account security features.
- To provide profile, address book, subscription preference, and member data management features.
- To provide newsletter subscription, double opt-in confirmation, unsubscribe, one-click unsubscribe, subscription status synchronization, and blacklist management.
- To communicate with you about account verification, password resets, security notices, service changes, subscription confirmation, and unsubscribe confirmation.
- To provide authorization, synchronization, and webhook notifications required by tenant websites, partner services, Send Engine, or other integrations.
- To prevent fraud, abuse, unauthorized access, security incidents, and service disruption.
- To conduct internal audits, permission control, debugging, maintenance, recordkeeping, and legal compliance.
- To handle user requests, customer support, disputes, complaints, or requests from competent authorities.
- To perform other clearly disclosed purposes with your consent or as permitted by law.
6. Legal Bases for Processing
Where required by applicable law, we process personal data based on one or more of the following legal bases:
- performance of a contract;
- compliance with legal obligations;
- legitimate interests pursued by us or our customers;
- your consent; and
- protection of vital interests where applicable.
7. Cookies and Similar Technologies
The Service uses cookies, sessions, browser local storage, or similar technologies to maintain sign-in status, complete OAuth flows, remember language or interface preferences, prevent cross-site request forgery, perform security checks, apply rate limits, and improve service stability.
You may configure your browser to reject or delete cookies. However, some features may not function properly, including sign-in status, authorization flows, language switching, or security verification.
8. Data Sharing and Outsourced Processing
We do not sell your personal data. Except in the circumstances below, we will not provide your personal data to third parties:
- When you consent or actively request sharing.
- When necessary to provide the Service, including sharing data with a tenant website, partner service, OAuth client, Send Engine, file access service, or other integrated system that you use or authorize.
- When we engage cloud hosting, database, email delivery, monitoring, security, customer support, or other providers to process data on our instructions and within the necessary scope.
- When required to comply with law, court orders, competent authority requests, tax requirements, or audit requirements.
- When necessary to detect, prevent, or handle fraud, abuse, security incidents, service stability issues, rights violations, or other unlawful conduct.
- In connection with restructuring, merger, spin-off, assignment, asset transfer, or a similar transaction, within the necessary scope and subject to protections no less protective than this Policy.
If a third-party website or tenant service obtains data within an authorized scope through the Service, that third party is responsible for its subsequent use under its agreement with you and its own privacy policy.
9. Regions of Use and Cross-Border Transfers
The Service primarily uses cloud infrastructure in the Amazon Web Services (AWS) Asia Pacific (Tokyo) Region (ap-northeast-1) to store and process data. The Service may also use email, monitoring, security, or other outsourced services located in Taiwan or other regions. Accordingly, your personal data may be transferred to, stored in, or processed outside your country or region. We will protect cross-border transfers and outsourced processing with reasonable safeguards and in accordance with applicable law.
10. Methods of Use and Data Retention
We process and use personal data by automated or non-automated means within the scope necessary to fulfill the purposes of collection, and retain it only for the necessary period. In general:
- Account data is retained until account deletion, for a reasonable period after account disabling, or until the period required for legal, audit, security, or dispute-resolution purposes expires.
- Newsletter subscription data is retained for a reasonable period after you unsubscribe to maintain unsubscribe, blacklist, complaint, or bounce suppression records and avoid sending unnecessary messages again.
- Security tokens are retained until expiration, revocation, or completion of their purpose, plus a reasonable period where necessary. Newsletter confirmation and unsubscribe tokens are valid for seven days by default; file download tokens are short-lived by design.
- Audit and security records are retained for the period necessary for security, audit, debugging, legal compliance, and dispute-resolution purposes.
- Data subject to legal or contractual requirements is retained in accordance with applicable law, competent authority requirements, accounting, tax, or contractual obligations.
When data is no longer necessary, we will delete it, anonymize it, or otherwise stop identifying a specific individual by reasonable means.
11. Your Rights
Subject to applicable law, you may exercise the following rights regarding your personal data:
- Request inquiry or access.
- Request a copy.
- Request supplementation or correction.
- Request that we stop collecting, processing, or using your data.
- Request deletion.
- Withdraw consent previously given, without affecting the lawfulness of processing before withdrawal.
- Manage newsletter subscription preferences or unsubscribe.
You may submit requests through Member Center account settings, subscription management, unsubscribe links, or the contact information listed in this Policy. To protect your data, we may ask for information necessary to verify your identity. Where continued retention or processing is required by law, contract, security, audit, dispute resolution, or service provision, we may be unable to immediately delete or stop using all data, but we will restrict processing to the necessary scope.
12. Information Security and Personal Data Incidents
We apply reasonable technical and organizational security measures to protect your data, including password hashing, token lifetime controls, OAuth scope and audience validation, tenant isolation, administrator permission controls, rate limits, protections for sign-in and reset flows, database access controls, audit logs, certificate management, webhook signatures, and replay protection.
No network transmission or information system can be guaranteed to be absolutely secure. If a personal data incident, unauthorized access, data breach, or other security event may affect users' rights or interests, we will take necessary investigative, remedial, notification, and reporting measures in accordance with applicable law and the nature of the incident.
13. Children and Minors
The Service is generally intended for natural persons with full legal capacity, businesses, organizations, or users with lawful authorization. If you are a minor or a person under guardianship or assistance, you should use the Service with the consent of your legal representative, guardian, or assistant. If we discover that relevant data was provided without appropriate consent, we will take deletion, suspension of processing, or other necessary measures in accordance with applicable law.
14. Updates to This Policy
We may update this Policy due to changes in service features, law, security measures, or business operations. The updated Policy will be posted on the Service or provided through another appropriate notice. If a change materially affects your rights or interests, we will take reasonable steps to notify you. Where consent is required by law, we will obtain it separately.
15. Contact Us
If you have questions about this Policy, our handling of personal data, or the exercise of your rights, please contact us:
Operator: Innovedus Inc. (智匯創育股份有限公司) Unified Business Number: 93698713 Email: cs@innovedus.com Address: 4F., No. 19-11, Sanchong Rd., Nangang Dist., Taipei City, Taiwan