Customer Privacy Notice
Last updated: April 3, 2023
We, TA-TO Contacts Co. LTD., prioritize our customer’s privacy as defined under the applicable laws on personal data protection. Therefore, we would like to inform our customers of this Customer Privacy Notice (the “Notice”), which defines the process and conditions that we will be collecting, processing, and transferring your personal data if needed.
Scope. This Notice is applicable only to the personal data processing undertaken directly by us in the provision of contact lenses delivery services (the “Services”) by us to you, not the personal data processing undertaken by other third parties that may or may not relate to our Services (i.e., other third party logistics service providers). Please study the relevant privacy notices of those third parties separately from this Notice.
Acceptance. Once you visit our website, contacts and/or use our Service, it shall be deemed that you have acknowledged and accepted this Notice and understand that the process of the personal data under this Notice is critical for the performance of our Services to you. We may amend this Notice from time to time, and we will notify you of such an amendment and if you continue to use our Service after the amendment, we will deem that you accept the Notice as amended.
Your Personal Data to be Processed
We may collect or receive your personal data either directly (i) from your visit to our website or your contact to our communication channels (i.e., website, social media, or call center); (ii) your registration for the user account on our website; or (iii) from other circumstances that you may submit your personal data to us directly for the event or campaign participation or complaint handling process; and indirectly from our partner who may refer you or your order to us to process in performing the Services.
In the delivery of our Services to you, we would need to collect, use, or disclose the following personal data of you:
- Your contact information, including your full name and contact information (i.e., telephone number, social media account) and any other personal data information that you may give to us to process during the first contact; in the participation in any campaign hosted by us and you may interest to join; or in case of any complaint made;
- Technical Identifier, including IP address, operating system setting and browser connection that you use to connect to our website and cookies;
- User Registration Information, including e-mail, date of birth, gender, interest and preference that you may fill in the form for the user registration; and your username and password for log-in;
- Delivery Data, the delivery address or the google map location (longitude / latitude) that you would give for the delivery purposes;
- Payment Information, including credit card information that will be processed by the third-party payment gateway or bank transfer payment slip; and in case you request for a tax invoice, we would need to collect your identification documents to be included in such tax invoice;
- Transaction Data, including your order information (i.e., product details, purchase price and total costs), your website usage or search history, the use of discount and promotional code where our system will collect that information automatically when you use your user account to transact on our website;
Other personal identifiable information that you provide us or we may collect from you, including without limitation in case you visit our store, our CCTV installed for the company safety may collect your facial image.
Purpose for Personal Data Use & Processing
We would need to process your personal data for the following purposes:
- To perform our Service to you from the first contact to product delivery and feedback handling; and in case of online delivery via website, to verify your qualification and to transact your order made on the website; provided that we would need to retain your personal data for the period of time as required for the delivery of the Services; and in case that you have the user account, for so long as you still have the user account on our website;
- For our accounting and tax purposes, we would need to collect and retain your personal data in accordance with the timeframe specified under the relevant laws.
- To build and improve our Services and your user experiences, we would process your personal data for product and Services development and improvement; complaint management; customer segmentation for marketing and public relations planning (including Facebook Lookalike); and for other advertisement purposes (except for the direct marketing purposes); provided that we will retain your personal data as necessary to fulfill those business purposes without causing excessive impact on your right as the data subject; and
- In case Consent is given, we will process your personal data for the specific purpose permitted by the Customer until such consent is withdrawn, including without limitation for the use of cookies (other than strictly necessary cookies) to customize your experiences on our website; and for direct marketing purposes.
Cookies
For the performance of the website, to ensure the basic functionality of the website, and to enhance your online experience, we need to use four types of Cookies for specific purposes as defined below:
- Strictly Necessary Cookies, which are cookies required for the website to function and for you to receive Services in the most secure and feasible manner;
- Functionality Cookies, which are cookies that keep track of the preferences you make when using website (including your account information, preferred language, font, or display layout);
- Performance Cookies, which are third-party cookies used to assess how well each function of the website performs; and
- Advertising Cookies, which are third-party cookies that track your visit behavior with the purpose of presenting you with offers for goods and services.
For any cookies, other than the Strictly Necessary Cookies, with your consent, we will only use those Cookies for a limited purpose as defined.
Disclosure of your Personal Data
Generally, we will not disclose or transfer your personal data to any third party, except the disclosure to these following persons where we would need to do so in order to ensure the performance of our Services to you: (1) To the relevant external service provider, being engaged to provide support service to us in the performance of our Services to You (i.e., outsourced IT service provider, outsourced deliverymen, payment gateway); or being engaged to support our business operation (i.e. legal, accounting or marketing consultant); provided that we will only disclose your personal data on the need-to-know basis under the defined scope of the data processing agreement to be entered into between us and such external service providers; (2) To government authorities, that we may be obliged under the relevant laws or the government judgment or orders to disclose your personal data to; and to other persons that you give explicit consent to us to disclose such personal data to.
Protection for your Personal Data
We will implement appropriate information security measures in accordance with applicable laws to prevent unauthorized access, use, amendment, or disclosure of your personal data and we will review those information security measures to ensure compliance with the applicable laws.
Your Rights
We respect your statutory rights as the data subject with regard to your own personal data under our control. You can request to exercise your data subject rights under the applicable laws as follows: (1) the right to withdraw consent; (2) the right to request access to or a copy of their personal data; (3) the right to revise their personal data; (4) the right to request data portability; (5) the right to object to any processing of their personal data; (6) the right to request deletion or de-identification of their personal data once no longer required; and (7) the right to request the suspension of processing of their personal data.
Data Deletion Policy
At TA-TO Contacts Co., LTD., we respect your privacy and are committed to protecting your personal data. If you wish to delete your data from our systems, please follow the process outlined below.
How to Request Data Deletion
If you want to request the deletion of your personal data, please send an email to our customer service team at customerservice@ta-to.com with the subject line "Data Deletion Request." In your email, please include the following information:
- Your full name
- The email address associated with your account
- A detailed description of the data you wish to delete
Processing Your Request
Upon receiving your request, we will:
- Verify your identity to ensure the security of your data.
- Review your request and confirm receipt within 7 business days.
- Process your data deletion request within 30 days of confirmation, and inform you once the deletion is complete.
Please note that some data may need to be retained for legal or regulatory reasons, but we will inform you if this is the case.
For any questions or further assistance, please contact us at customerservice@ta-to.com.