1. Processing Personal Data
"Personal data" means any data relating to an identified or identifiable natural person, including, without limitation, name, address, date of birth, telephone number, e-mail address and user IDs of User residing in the EEA.
"Processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
"Controller" means a legal person, etc. which, alone or jointly with others, determines the purposes and means of the processing of personal data. "Processor" means a legal person, etc. which processes personal data on behalf of the Controller.
(2) Types of Personal Data to Be Collected
The Company will collect, including but not limited to, the following types of personal data concerning Users in connection with the Service:
- Name (including family members)
- Name Code
- Organization/Company name
- Title Name
- Employee category
- Gender (including family members)
- Age/Date of birth (including family members)
- Date of employment
- Length of service
- Address (including family members)
- Living together/separated
- Salary (Annual income etc.)
- Account information (Account number etc.)
- Telephone number (including family members)
- E-mail address
- Passport Information
- Country of assignment/Place of assignment
- Date of departure and arrival
- Health information (Medical history, Health check result etc.)
- Information on children's education
(3) Purposes of Use of Personal Data
The Company will process the Users' personal data for the following purposes:
(a) to respond to inquiries and requests from customers
If the Company is to process the Users' personal data for purposes other than the above, the Company will notify Users in advance such new purposes of use and other matters as required by applicable laws.
The Company may require Users to provide their personal data in connection with the provision of the Services. In such case, if certain Users do not provide its personal data, the Company may be unable to provide the Services.
(4) Retention Period
The Company will retain the Users' personal data to the extent the Company requires such data for achieving the purposes of use specified in 1. (3) above.
(5) Third Party Transfer
(a) Certain countries outside the EEA may not be furnished with the same level of data protection laws as the EEA, thus part of the rights granted to Users within the EEA may not be available;
(b) Users' personal data may be provided and processed for the purposes specified in 1. (3) above; and
(c) Users' personal data may be provided to third parties located in a country outside the EEA.
(6) Disclosure, Correction, and Other Procedures Concerning the Personal Data
The Users are entitled with the rights to access to, request for correction, request for deletion, request to limit the processing, object to the processing, and request for data portability, with regards to the personal data retained by the Company pursuant to the provisions of relevant laws and regulations. Such requests shall be attended to the contact point set forth in "4. Contact" as per below.
The Company may refuse the Users' request if the Company deems that there is no basis for such request or if the request is deemed excessive.
The Users may file objections to the data protection authorities having jurisdiction over the location of the Users' domicile with regards to the processing of their personal data by the Company.
2. Safety Management Measures
In order to protect the personal data from unauthorized access and loss etc., taking into account the type of personal data, the degree of sensitivity and the degree of affect to the Users including economic influence and mental harm in case the personal data is unlawfully infringed, the Company has comprehensively evaluated and judged the risks of personal data infringement, and has implemented necessary and appropriate personal, organizational and technical safety management measures in accordance with such the risk of personal data infringement, and further, will review such safety management measures as necessary, set up the process for taking corrective actions, and constantly make effort to improve its security.
If the Company, in its role as a Controller, contracts a Processor, the Company shall select a Processor which is capable of implementing appropriate technical and organizational measures and shall manage such Processor in an appropriate manner.
Pursuant to the GDPR, the Company shall prepare records of the processing of personal data.
Chubu Electric Power Co., Inc.
Post: 1 Higashi-shincho, Higashi-ku, Nagoya, Aichi 461-8680, Japan