Privacy & Personal Data Protection Policy
SynPower Co., Ltd. (hereinafter referred to as "the Company") highly values your privacy. To ensure your peace of mind while using our website and related services, we have established this Privacy Protection Policy to safeguard your rights. This policy applies to the collection, processing, and protection of personal data involved in your use of the Company's website.
I. Collection & Use of Personal Data
- Purpose of Collection: Including but not limited to customer management, marketing, contract fulfillment, after-sales service, recruitment, and other business needs aligned with our registered business scope.
- Categories of Collection:
- Identification: Name, job title, contact number, email address, mailing address, etc.
- Characteristics: Age, gender, date of birth, etc. (limited to specific business requirements).
- Period & Region: Unless otherwise stipulated by law, your data will be utilized during the Company's operational period within the regions where the Company operates.
II. Data Security Measures
The Company implements rigorous technical and organizational security measures to protect your personal data. In 2025, we maintained a record of zero major cybersecurity or data breach incidents:
- Technical Aspects: Deployment of high-end firewalls, Managed Detection and Response (MDR) systems, SSL encrypted transmission, and strict access control mechanisms.
- Management Aspects: Conducted 6 security awareness sessions and 3 social engineering drills in 2025. Access to data is restricted to authorized personnel only, with regular security risk assessments.
III. Rights of the Data Subject
Under the Personal Data Protection Act, you may exercise the following rights regarding the personal data held by the Company:
- Right to inquire, review, or request a duplicate copy.
- Right to request supplements or corrections.
- Right to request cessation of collection, processing, or utilization.
- Right to request deletion (within the scope permitted by law).
IV. Personal Data Breach Response Mechanism
In the event of theft, leakage, tampering, or other infringements of personal data, the Company will initiate the "Cybersecurity Incident Response Procedures":
The security team will immediately isolate affected systems and block threat sources to prevent further damage.
Notification to competent authorities within 72 hours of discovery, with public disclosure of the incident scope and remedial measures.
Conducting root cause analysis and vulnerability scanning to harden defenses and update management protocols.
Proactively assisting affected individuals with preventive steps and providing legal consultation to protect their rights.
V. Use of Cookies
To provide the best service, this website places cookies on your browser. If you do not wish to accept cookies, you may disable them in your browser settings; however, this may result in some functions of the website not operating correctly.
Privacy Protection Inquiry Desk
If you have any questions regarding this policy or wish to exercise your data rights, please contact our dedicated team:
📞 Phone: +886-3-369-0966 (Data Protection Group)
This policy will be modified at any time in response to requirements and posted on the website.
Last Updated: December 31, 2025
