Privacy & Personal Data Protection Policy
SynPower Co., Ltd. (the “Company”) values the protection of personal data and privacy. This Policy explains how personal data is collected and used, the security measures applied, the rights of data subjects, and the Company's incident response mechanisms in order to protect the rights and interests of website users and other relevant individuals.
01 Collection and Use of Personal Data
Purposes include, but are not limited to, customer management, marketing and promotional activities, contract performance, after-sales service, recruitment, and other business activities that are consistent with the Company's registered scope of operations.
- Identification Data: such as name, job title, telephone number, email address, and address.
- Personal Characteristics: such as age, gender, and date of birth, where required for specific business purposes.
Unless otherwise required by applicable laws or regulations, personal data may be used during the Company's operating period and within the geographic areas in which the Company conducts business.
02 Personal Data Security Measures
The Company protects personal data through technical, organizational, and personnel-management measures. In 2025, SynPower maintained a record of zero material cybersecurity or personal data incidents.
Technical Safeguards
Security measures include firewalls, Managed Detection and Response (MDR) systems, SSL-encrypted data transmission, and other appropriate protection mechanisms.
Organizational Controls
Access control mechanisms are established so that only authorized personnel may access personal data, while information security risk assessments are conducted periodically.
Employee Awareness
In 2025, the Company conducted six cybersecurity awareness activities and three social engineering simulation exercises to continuously strengthen information security awareness.
03 Exercise of Data Subject Rights
In accordance with Taiwan's Personal Data Protection Act, data subjects may exercise the following rights in relation to personal data held by the Company.
04 Personal Data Breach Response
In the event of a personal data breach, the Company will initiate investigation, containment, notification, remediation, and rights-protection procedures according to the nature and impact of the incident.
Investigation and Containment
Determine the scope and impact of the incident and take necessary isolation and containment measures to prevent further harm.
Notification and Reporting
Where required, notifications or reports will be made in accordance with applicable laws, regulations, and competent-authority requirements, including information on the affected scope and response measures.
Vulnerability Remediation and Prevention
Conduct root-cause analysis and vulnerability reviews, remediate identified security gaps, and improve relevant management procedures.
Protection and Remedial Support
Provide necessary information and assistance based on the impact of the incident in order to reduce potential harm to affected individuals.
05 Use of Cookies
To provide website services and improve the user experience, this website may use Cookies in your browser. Users may restrict or disable Cookies through their browser settings; however, certain website functions may be affected as a result.
Personal Data Protection Team