Privacy & Website Security Policy

Last updated: 13 June 2026 (version v2026.06)

Company
JIE HENG INFORMATION CO., LTD.
Business No.
54063163
Address
10F-6, No. 206, Xinsheng N. Rd., Fengyuan Dist., Taichung 420, Taiwan
Phone
+886-2-7756-3921
Email
service@jie-heng.com.tw
Website
https://www.jie-heng.com.tw

Scope: the Company's websites (including this site aihr.jie-heng.com.tw and all subdomains), apps and all digital services.

1. Introduction & Scope

This policy is established under Taiwan's Personal Data Protection Act, its related regulations, and the ISO/IEC 27001:2022 information security management system. It applies to:

  • The official website and all subdomains
  • Applications and platforms developed and maintained for clients
  • Interactions via phone, email, LINE official account or in person
  • Personal-data matters under service contracts with clients and partners

2. Categories of Personal Data Collected

We may collect the following categories of personal data:

  • Identification: name, gender, date of birth, ID document numbers.
  • Contact details: phone, email, mailing and residential addresses, LINE ID and social media accounts.
  • Business records: company name, business number, job title, procurement needs, contracts, quotes, invoices and payment records, project communications.
  • Browsing data (collected automatically): IP address, browser type and version, pages and paths visited, time on page, click behavior, Cookies and similar technologies, device identifiers.
  • Support data: error logs, system diagnostics, login times and IP records, issue descriptions and attachments you submit.

This site (aihr.jie-heng.com.tw) is a marketing page with no online form; contact links lead to email or our official channels. It collects anonymized browsing data via Google Analytics only after your consent (see Section 7).

3. Purposes, Legal Basis & Retention

PurposeLegal basisRetention
Custom website, app and system developmentContractual7 years after contract ends
Customer service, technical support and after-salesContractual5 years after service ends
Sales inquiries, quotes and contract managementPre-contract3 years
Accounting, invoicing and financial recordsLegal obligationPer tax law (at least 7 years)
Security audit, system logs and intrusion detectionLegitimate interest1 year
Marketing and newsletters (separate consent required)ConsentUntil consent is withdrawn
Compliance with law and government requirementsLegal obligationAs required by law

4. Processing & Use of Personal Data

We use collected data only within the specific purposes disclosed at collection, where required by law, to protect the public interest without undue harm to the individual, or with the individual's separate written consent.

(1) Disclosure to third parties

We do not sell or rent personal data. It may be disclosed only to: government or judicial authorities as required by law; technology providers we work with under data-processing agreements; third parties you explicitly authorize; or in a merger, acquisition or asset transfer.

(2) International transfers

Where cross-border transfer is needed, we confirm the destination country offers adequate data protection under Article 21 of the PDPA, or apply appropriate safeguards (e.g., standard contractual clauses).

5. Your Rights

RightDescriptionResponse time
Right to accessRequest to review the personal data we hold15 business days
Right to a copyRequest a copy of your personal data15 business days
Right to rectificationRequest to complete or correct inaccurate data10 business days
Right to restrictRequest to stop collection, processing or use20 business days
Right to erasureRequest deletion (except where retention is legally required)30 business days

To exercise your rights, email service@jie-heng.com.tw or call +886-2-7756-3921 with information sufficient to verify your identity. A reasonable administrative fee may apply.

6. Information Security (ISO/IEC 27001:2022)

We are ISO/IEC 27001:2022 certified and apply the following measures:

(1) Technical

  • Encryption in transit: TLS 1.2 / 1.3 (HTTPS); data at rest encrypted with AES-256.
  • Access control: least privilege, role-based access control (RBAC), and multi-factor authentication (MFA) for sensitive functions.
  • Firewall and intrusion detection (WAF, IDS/IPS); regular vulnerability scans and penetration tests.
  • Centralized security logs (kept at least 1 year); daily automatic backups with periodic restore tests.

(2) Organizational

  • A complete information security policy framework reviewed annually; regular staff security training.
  • NDAs and data-processing agreements (DPAs) with third-party vendors.
  • Annual security risk assessments; an incident response plan (IRP).

(3) Physical

  • Server-room access control, 24-hour monitoring, and immediate revocation of access when an employee leaves.

(4) Breach notification

In the event of a breach, we assess severity within 72 hours of becoming aware, notify the competent authority (National Development Council) as required by law, notify affected individuals in writing, and take necessary remedial action.

7. Cookies & Tracking Technologies

This website uses Cookies and similar technologies (e.g., Local Storage, Session Storage).

Cookie typePurposeRequiredRetention
Essential CookiesCore website functionsYesEnd of session
Functional CookiesRemember preferencesNoUp to 1 year
Analytics CookiesTraffic and behavior analysisNoUp to 2 years
Marketing CookiesRelevant ads and remarketingNoUp to 90 days

This site's consent mechanism (Google Consent Mode v2)

This site uses Google Consent Mode v2: before you choose, analytics and advertising Cookies are denied by default, keeping only what's essential for the site to work. On your first visit you can choose "Accept all" or "Reject non-essential" in the consent banner; your choice is stored in your browser and can be changed anytime via "Cookie Settings" in the footer. You can also block or delete Cookies in your browser, which may affect some features.

8. Protection of Minors

  • Our services are aimed primarily at business clients and adults.
  • We do not knowingly collect personal data from minors under 18; if collected unknowingly, it will be deleted immediately.
  • Legal guardians may contact service@jie-heng.com.tw.

9. Third-Party Links & Services

This website may contain links to third-party sites or services; we are not responsible for their privacy policies. Main third-party services currently in use:

  • Google Analytics: website traffic analysis (with Consent Mode v2; full measurement only after your consent).
  • LINE Official Account: customer service communication.
  • Google Cloud Platform (GCP): cloud hosting and infrastructure (under a data-processing agreement).

10. Data Protection Contact

  • Data protection officer: Information Security Management Department
  • Email: service@jie-heng.com.tw
  • Phone: +886-2-7756-3921
  • Address: 10F-6, No. 206, Xinsheng N. Rd., Fengyuan Dist., Taichung 420, Taiwan
  • LINE Official Account:https://lin.ee/5XyPKHh
  • Hours: Mon–Fri 09:00–18:00 (excluding public holidays)

Supervisory authority: the competent personal-data authority (National Development Council) Tel: (02) 2316-5300 Web: https://www.ndc.gov.tw

11. Changes to This Policy

We may revise this policy due to business needs, legal changes or technical updates. Revisions are published on the official website with the latest version date; for material changes we give 30 days' advance notice by email or website notice. Continued use after a revision constitutes acceptance.

Appendix: ISO/IEC 27001:2022 Information Security Statement

JIE HENG INFORMATION CO., LTD. is ISO/IEC 27001:2022 certified, covering the design, development, maintenance and client-data management of all our information systems. Following ISO 27001, we establish, implement, maintain and continually improve an information security management system (ISMS) to ensure:

  • Confidentiality: information is accessible only to authorized personnel
  • Integrity: the accuracy and completeness of information and processing
  • Availability: authorized users can access information and related assets when needed

The ISO 27001 certificate can be downloaded from our website or requested from us.