Privacy Policy
Last updated: AUGUST 13, 2026
This Privacy Policy describes how ORISEN BIOTECH CORPORATION (“We”, “Us”, “Our”) collects, uses, and discloses information when You visit or interact with Our website, and tells You about Your privacy rights and how the law protects You.
Our website is a business-to-business (“B2B”) website. It is intended for business professionals acting in a professional capacity, and it is not directed to consumers making personal purchases or to children. Even where information relates to You in Your professional capacity (for example, Your work email address or job title), it is still Personal Data under laws such as the GDPR, the CCPA/CPRA, and the Taiwan PDPA, and We treat it accordingly.
By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy. Where the law requires Your consent (for example, for non-essential cookies and similar tracking technologies), We rely on the consent You give through Our cookie banner, not on Your use of the Service.
Notice at Collection (Summary)
This summary is provided for convenience and does not replace the full Policy below.
What We collect: contact details You submit through Our contact form (name, business email address, phone number, company name, and anything You write in the message field); and online activity data collected automatically through cookies and similar tracking technologies (IP address, device and browser information, pages viewed, referring source, campaign identifiers, and advertising identifiers).
Why We collect it: to respond to Your enquiry, to run and secure Our website, to measure and improve Our marketing, and to deliver and measure advertising.
Do We sell or share it: We do not sell Personal Data for money. However, when You allow advertising and analytics cookies, We disclose online identifiers and browsing activity to advertising platforms in a way that may qualify as a “sale” or “share” for cross-context behavioural advertising under the CCPA/CPRA and comparable US state laws. You can opt out at any time — see “Your Choices Regarding Tracking and Advertising” and “Do Not Sell or Share My Personal Information”.
Sensitive Personal Information: We do not collect it and do not ask for it.
How long We keep it: see “Retention of Your Personal Data”.
Contact: inquiry@orisen.com.tw.
Interpretation and Definitions
Interpretation
The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
Business, for the purpose of CCPA/CPRA, refers to the Company as the legal entity that collects Consumers’ personal information and determines the purposes and means of the processing of Consumers’ personal information, or on behalf of which such information is collected and that alone, or jointly with others, determines the purposes and means of the processing of consumers’ personal information, that does business in the State of California.
CCPA and/or CPRA refers to the California Consumer Privacy Act (the “CCPA”) as amended by the California Privacy Rights Act of 2020 (the “CPRA”).
Company (referred to as either “the Company”, “We”, “Us” or “Our” in this Privacy Policy) refers to ORISEN BIOTECH CORPORATION, 3F., No. 192, Zhonggong 2nd Rd., Xitun Dist., Taichung City 407203, Taiwan (R.O.C.). For the purposes of the GDPR, the Company is the Data Controller.
Consumer, for the purpose of the CCPA/CPRA, means a natural person who is a California resident. A resident, as defined in the law, includes (1) every individual who is in the USA for other than a temporary or transitory purpose, and (2) every individual who is domiciled in the USA who is outside the USA for a temporary or transitory purpose. Under the CCPA/CPRA as amended, this includes individuals whose information We collect in a business-to-business context.
Contact Form means any enquiry, demo request, download, or similar form made available on the Service through which You may submit Your details to Us.
Cookies are small files that are placed on Your Device by a website, containing the details of Your browsing history on that website among its many uses. In this Policy, “Cookies” also covers similar technologies such as pixels, tags, web beacons, software development kits, local storage, and device fingerprinting techniques.
Country refers to: Taiwan
Data Controller, for the purposes of the GDPR (General Data Protection Regulation), refers to the Company as the legal person which alone or jointly with others determines the purposes and means of the processing of Personal Data.
Device means any device that can access the Service such as a computer, a cell phone or a digital tablet.
Do Not Track (DNT) is a concept that has been promoted by US regulatory authorities, in particular the U.S. Federal Trade Commission (FTC), for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.
GDPR refers to the EU General Data Protection Regulation, and, where applicable, the UK GDPR as retained and amended in the United Kingdom.
PDPA refers to the Personal Data Protection Act of the Republic of China (Taiwan) (個人資料保護法), as amended, together with its Enforcement Rules.
Personal Data (or “Personal Information”) is any information that relates to an identified or identifiable individual. For the purposes of GDPR, Personal Data means any information relating to You such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity.
For the purposes of the CCPA/CPRA, Personal Data means any information that identifies, relates to, describes or is capable of being associated with, or could reasonably be linked, directly or indirectly, with You.
We use “Personal Data” and “Personal Information” interchangeably unless a law uses a specific term.
Service refers to the website operated by the Company at https://orisen.com.tw, including all pages, forms, and content made available through it.
Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
For the purposes of the GDPR, Service Providers are considered Data Processors.
Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable. Under GDPR, You can be referred to as the Data Subject or as the User as you are the individual using the Service.
Collecting and Using Your Personal Data
Types of Data Collected
Personal Data You Provide to Us
When You complete a Contact Form on the Service, We ask You to provide:
- First name and last name
- Business email address
- Phone number
- Company name
- Any additional information You choose to include in a free-text message or comments field
Fields marked as required are necessary for Us to respond to Your enquiry. If You do not provide them, We may not be able to respond. Please do not submit sensitive personal information (such as health, financial account, government identifier, racial or ethnic origin, religious belief, or trade union membership information) through the Contact Form — We neither request nor need it.
We may also receive Personal Data if You contact Us directly by email, telephone, or through a business social network, or if You provide Us with a business card or exchange details with Us at an event.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device’s Internet Protocol address (e.g. IP address), approximate location derived from that IP address (typically city or region level), browser type, browser version, operating system, the pages of Our Service that You visit, the time and date of Your visit, the time spent on those pages, the website or advertisement that referred You, search terms and campaign parameters, unique device and cookie identifiers, advertising identifiers, and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
Our hosting provider and security infrastructure also generate server logs containing IP addresses, request timestamps, requested URLs, and user-agent strings. These logs are necessary to operate and secure the Service.
Information We Do Not Collect
The Service does not offer user accounts, user registration, or login through social media services. We do not process payments through the Service. We do not collect biometric data, precise geolocation data, or Sensitive Personal Information as defined under the CCPA/CPRA.
Cookies and Tracking Technologies
We use Cookies and similar tracking technologies to operate the Service, to understand how it is used, and to deliver and measure advertising.
Categories of Cookies We use:
- Strictly necessary Cookies. Required for the Service to function — for example, to route requests, balance load, protect against abuse and spam, remember Your cookie consent choices, and preserve the security of form submissions. These are set on the basis of Our legitimate interests and cannot be switched off through Our cookie banner.
- Analytics and performance Cookies. Used to measure how visitors find and use the Service, which pages and content perform well, and where visitors encounter problems, so that We can improve the Service.
- Advertising and targeting Cookies. Used to measure the performance of Our advertising campaigns, to attribute enquiries to the campaigns that generated them, to build audiences of visitors for future advertising, and to show You Our advertising on other websites and platforms.
Third parties that set or receive tracking data through the Service:
- Google Analytics 4 (Google LLC / Google Ireland Limited) — website and campaign analytics, audience and conversion measurement. Privacy information: https://policies.google.com/privacy and https://business.safety.google/privacy/
- Google Tag Manager (Google LLC / Google Ireland Limited) — a tag management container used to deploy and control the tags listed in this section. Google Tag Manager itself does not set analytics or advertising cookies, but it loads the tags that do.
- Google Ads / Google conversion and remarketing tags (Google LLC / Google Ireland Limited) — advertising conversion measurement and remarketing audiences.
- Meta Pixel (Meta Platforms, Inc. / Meta Platforms Ireland Limited) — advertising conversion measurement, audience building, and remarketing on Facebook, Instagram, and Meta’s partner network. Privacy information: https://www.facebook.com/privacy/policy/
We may add, replace, or remove analytics and advertising technologies over time as Our marketing tooling changes. Where We do so, the new technology will fall within the Cookie categories described above and will be subject to the same consent controls. The current, complete, and up-to-date list of the technologies in use, including their names, providers, purposes, and storage durations, is available at any time in Our cookie preference centre at Cookie Settings. Where a new technology would involve a materially different purpose than those described here, We will update this Policy and, where required, obtain Your consent before deploying it.
Consent and control
Where required by law — including in the European Economic Area, the United Kingdom, and other jurisdictions with equivalent rules — We set analytics and advertising Cookies only after You give consent through Our cookie banner. Strictly necessary Cookies are set without consent because the Service cannot function without them.
You can change or withdraw Your consent at any time through Cookie Settings. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal. You can also block or delete Cookies through Your browser settings; note that blocking strictly necessary Cookies may cause parts of the Service to malfunction.
Where We use Google services, We implement Google Consent Mode so that Google tags adjust their behaviour according to the consent choices You make in Our banner.
Joint controllership with Meta and Google
For certain processing carried out through the Meta Pixel — specifically the collection and transmission of event data used for audience building and advertising measurement — We and Meta Platforms Ireland Limited act as joint controllers within the meaning of Article 26 GDPR. The essence of the arrangement between Us and Meta, including the allocation of responsibilities and the fact that Meta is responsible for providing data subjects with information about, and enabling the exercise of, their rights in respect of the data it processes, is set out in Meta’s Controller Addendum: https://www.facebook.com/legal/controller_addendum. Meta processes the data it receives for its own purposes as an independent controller in accordance with its Data Policy, and Our joint responsibility does not extend to that further processing.
A comparable arrangement applies to certain Google advertising and measurement products. Google’s controller terms are available at https://business.safety.google/controllerterms/.
Do Not Track and Global Privacy Control
Our Service does not currently respond to browser “Do Not Track” (DNT) signals, because no common industry standard for interpreting them has been adopted.
We do, however, treat the Global Privacy Control (GPC) signal as a valid request to opt out of the “sale” and “sharing” of Personal Information where applicable law requires it, including under the CCPA/CPRA and comparable US state privacy laws. If Your browser or extension transmits a GPC signal when You visit the Service, We will apply that opt-out to the browser and Device from which the signal is received. Because the signal is tied to a specific browser and Device, You will need to enable it on each browser and Device You use.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
- To respond to Your enquiries. To review, evaluate, and respond to requests, questions, demo requests, quote requests, and other messages You submit through the Contact Form or send Us directly, and to follow up with You about them.
- To take pre-contractual steps and perform a contract. To prepare proposals, negotiate, and conclude and perform an agreement between Us and the organisation You represent.
- To manage Our business relationship with Your organisation. To maintain accurate business contact records and a record of Our communications with You in Our customer relationship management system.
- To operate, maintain, and secure the Service. Including to monitor usage, detect and prevent spam, fraud, abuse and security incidents, troubleshoot faults, and preserve the availability and integrity of the Service.
- For analytics and improvement. To understand how the Service is used, identify usage trends, and evaluate and improve the Service, Our content, and Our products and services.
- For marketing and advertising. To measure the effectiveness of Our advertising and marketing campaigns, to attribute enquiries to the campaigns that generated them, to build audiences for future advertising, and to deliver advertising to You on third-party platforms.
- To send You business communications. To provide You with news, industry information, event invitations, and information about products and services We offer that are relevant to Your professional role, where permitted by law and subject to Your right to opt out at any time.
- To comply with legal obligations. Including record-keeping, responding to lawful requests from public authorities, and establishing, exercising, or defending legal claims.
- For business transfers. We may use Your Personal Data to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about users of the Service is among the assets transferred.
We may share Your Personal Data in the following situations:
- With Service Providers: We may share Your Personal Data with Service Providers who host the Service, host and operate Our customer relationship management and email systems, provide analytics and advertising measurement, provide security and anti-spam services, and otherwise assist Us in operating the Service and Our business. Service Providers are bound by contract to process Personal Data only on Our documented instructions and to apply appropriate security measures.
- With advertising and analytics platforms: As described in “Cookies and Tracking Technologies”, where You have consented (or where consent is not required by applicable law), online identifiers and activity data are disclosed to advertising and analytics platforms which may process that data for their own purposes.
- For business transfers: We may share or transfer Your Personal Data in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.
- With Affiliates: We may share Your Personal Data with Our affiliates, in which case We will require those affiliates to honor this Privacy Policy. Affiliates include Our parent company and any other subsidiaries, joint venture partners or other companies that We control or that are under common control with Us.
- With professional advisers and authorities: With Our lawyers, auditors, insurers, and with courts, regulators, and law enforcement where necessary to comply with a legal obligation or to establish, exercise, or defend legal claims.
- With Your consent: We may disclose Your Personal Data for any other purpose with Your consent.
We do not sell Personal Data for monetary consideration, and We do not disclose Personal Data to unrelated third parties for their own independent marketing purposes. Please see “Sale or Sharing of Personal Information” for how the broader statutory definitions of “sale” and “share” apply to Our use of advertising technologies.
Marketing Communications and Your Right to Opt Out
Where We send You marketing communications, You can opt out at any time by using the unsubscribe link in any marketing email or by contacting Us at inquiry@orisen.com.tw. We will action opt-out requests promptly and in any event within the time limits set by applicable law.
Opting out of marketing does not stop Us from sending You service or transactional messages that are necessary to respond to Your enquiry or to administer a contract with Your organisation.
If You unsubscribe, We retain a minimal record of Your email address on a suppression list. This is necessary so that We can honour Your opt-out and avoid contacting You again; We do not use the suppression list for any other purpose.
Automated Decision-Making and Profiling
We use analytics and advertising technologies that involve profiling for marketing purposes, such as grouping visitors into audiences based on the pages they viewed and estimating the likely relevance of Our advertising to them.
We do not carry out automated decision-making that produces legal effects concerning You or similarly significantly affects You within the meaning of Article 22 GDPR.
Legal Basis for Processing Personal Data under the GDPR
Where the GDPR applies, We rely on the following legal bases:
- Consent (Art. 6(1)(a)). For setting non-essential Cookies and similar tracking technologies, for the analytics and advertising processing that follows from them, and for sending marketing communications where consent is required by applicable law.
- Performance of a contract or pre-contractual steps (Art. 6(1)(b)). To respond to Your enquiry where it concerns entering into or performing an agreement, and to perform an agreement with the organisation You represent.
- Compliance with a legal obligation (Art. 6(1)(c)). For record-keeping, tax and accounting obligations, and responding to lawful requests from public authorities.
- Legitimate interests (Art. 6(1)(f)). To operate, secure, and improve the Service; to maintain business contact records; to promote Our products and services to business contacts in a manner they would reasonably expect; and to establish, exercise, or defend legal claims. Where We rely on legitimate interests, We have assessed that Our interests are not overridden by Your interests or fundamental rights and freedoms. You may obtain further information about that assessment, and object to the processing, by contacting Us.
Where We rely on Your consent, You may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
In any case, the Company will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.
Retention of Your Personal Data
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with Our legal obligations (for example, if We are required to retain Your data to comply with applicable laws), resolve disputes, and enforce Our legal agreements and policies.
Where possible, We apply shorter retention periods and/or reduce identifiability by deleting, aggregating, or anonymizing data. Unless otherwise stated, the retention periods below are maximum periods (“up to”) and We may delete or anonymize data sooner when it is no longer needed for the relevant purpose.
Contact Form and enquiry data
- Enquiries that do not lead to a business relationship: up to 24 months from the date of Your last meaningful interaction with Us, to allow Us to recognise You if You contact Us again and to demonstrate how We handled Your enquiry.
- Business contact records in Our customer relationship management system, where a business relationship exists or is being pursued: for the duration of the relationship plus up to 24 months after Our last meaningful interaction with You or with Your organisation.
- Correspondence and email records: up to 24 months from the date of the last message, or longer where necessary to perform or evidence a contract.
- Records relating to a concluded contract, and associated financial records: for the period required by applicable contract limitation periods and tax and accounting law.
Marketing data
- Marketing consent and opt-out records: for as long as needed to evidence compliance with marketing law.
- Suppression list entries: retained for as long as necessary to continue honouring Your opt-out.
Analytics and advertising data
- Google Analytics 4 user- and event-level data: retained according to the data retention setting configured in Our Google Analytics property, which We set to a maximum of 14 months. Aggregated, non-identifying reports may be retained for longer.
- Advertising platform data (including Meta Pixel data): retained by the relevant platform under its own retention policies and terms, over which We have limited control. Please consult the platform’s privacy policy, linked in “Cookies and Tracking Technologies”.
- Cookie identifiers: retained for the lifetime set for each Cookie, as disclosed in Our cookie preference centre, or until You delete them or withdraw consent.
Operational data
- Server and security logs (IP addresses, access times, request data): up to 12 months for security monitoring and troubleshooting purposes.
We may retain Personal Data beyond the periods stated above for the following reasons:
- Legal obligation: We are required by law to retain specific data (e.g., financial records for tax authorities).
- Legal claims: Data is necessary to establish, exercise, or defend legal claims.
- Your explicit request: You ask Us to retain specific information.
- Technical limitations: Data exists in backup systems that are scheduled for routine deletion.
You may request information about how long We will retain Your Personal Data by contacting Us.
When retention periods expire, We securely delete or anonymize Personal Data according to the following procedures:
- Deletion: Personal Data is removed from Our systems and no longer actively processed.
- Backup retention: Residual copies may remain in encrypted backups for a limited period consistent with Our backup retention schedule and are not restored except where necessary for security, disaster recovery, or legal compliance.
- Anonymization: In some cases, We convert Personal Data into anonymous statistical data that cannot be linked back to You. This anonymized data may be retained indefinitely for research and analytics.
Transfer of Your Personal Data
Your information, including Personal Data, is processed at the Company’s operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ from those from Your jurisdiction. In particular, the analytics and advertising providers named in this Policy process data in the United States and in other countries.
Where required by applicable law, We will ensure that international transfers of Your Personal Data are subject to appropriate safeguards and supplementary measures where appropriate. The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.
International Transfer of Personal Data (GDPR)
We may transfer, store, and process Personal Data in countries other than the country in which You are located, including countries outside the European Economic Area (“EEA”) and the United Kingdom (“UK”), where data protection laws may differ.
Where We transfer Personal Data outside the EEA/UK to a country that has not been recognized as providing an adequate level of protection, We rely on appropriate safeguards, such as:
- An adequacy decision of the European Commission, or UK adequacy regulations, where one applies to the recipient country or framework. This includes, where applicable, transfers to organisations in the United States that are certified under the EU-US Data Privacy Framework and its UK Extension.
- The European Commission’s Standard Contractual Clauses (“SCCs”) and/or the UK International Data Transfer Agreement (“IDTA”) or the UK Addendum to the SCCs (as applicable).
- Supplementary measures where appropriate, such as encryption in transit and at rest, access controls, data minimisation, and vendor security reviews.
We transfer Personal Data internationally only as needed to provide the Service and to work with Our Service Providers and advertising partners (for example, hosting, analytics, advertising measurement, and email delivery). You may contact Us using the details in the “Contact Us” section to request further information about the safeguards We use for international transfers, including copies of relevant contractual protections (redacted where necessary).
Your Rights under the GDPR
The Company undertakes to respect the confidentiality of Your Personal Data and to guarantee You can exercise Your rights.
You have the right under this Privacy Policy, and by law if You are within the EEA or the UK, to:
- Request access to Your Personal Data. The right to obtain confirmation of whether We process Personal Data about You, to access it, and to receive a copy of it.
- Request correction of the Personal Data that We hold about You. You have the right to have any incomplete or inaccurate information We hold about You corrected.
- Request erasure of Your Personal Data. You have the right to ask Us to delete or remove Personal Data when there is no good reason for Us to continue processing it.
- Request restriction of processing. You have the right to ask Us to restrict processing of Your Personal Data in certain circumstances (for example, while We verify accuracy or consider an objection).
- Object to processing of Your Personal Data. This right exists where We are relying on a legitimate interest as the legal basis for Our processing and there is something about Your particular situation which makes You want to object. You also have an unconditional right to object where We process Your Personal Data for direct marketing purposes, including profiling related to direct marketing.
- Request the transfer of Your Personal Data. We will provide to You, or to a third party You have chosen, Your Personal Data in a structured, commonly used, machine-readable format. This right only applies to processing carried out by automated means on the basis of Your consent or the performance of a contract.
- Withdraw Your consent. Where We rely on consent, You have the right to withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Lodge a complaint with a supervisory authority. See below.
Exercising of Your GDPR Data Protection Rights
You may exercise Your rights by contacting Us at inquiry@orisen.com.tw. Please note that We may ask You to verify Your identity before responding to such requests. We generally respond within one month, and may extend by two further months where necessary, in accordance with applicable law. Exercising Your rights is free of charge unless a request is manifestly unfounded or excessive.
You have the right to complain to a Data Protection Authority about Our collection and use of Your Personal Data. If You are in the EEA, please contact Your local data protection authority. If You are in the UK, You may contact the Information Commissioner’s Office (ICO) at https://ico.org.uk/.
EU and UK Representative
The Company is not established in the European Economic Area or in the United Kingdom. In accordance with Article 27 of the EU GDPR and Article 27 of the UK GDPR, We have appointed the following representatives, whom You may contact on all issues related to the processing of Your Personal Data:
- EU representative: TZU-CHIN, WU
- UK representative: TZU-CHIN, WU
Data Protection Officer
We have appointed a Data Protection Officer, who can be contacted at inquiry@orisen.com.tw.
CCPA/CPRA Privacy Notice (California Privacy Rights)
This privacy notice section for California residents supplements the information contained in Our Privacy Policy and it applies solely to all visitors, users, and others who reside in the State of California.
The CCPA/CPRA applies to personal information collected in a business-to-business context. The fact that We collect Your information in Your professional capacity, or that Your information relates to Your employer, does not remove it from the scope of these rights.
Categories of Personal Information Collected
We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or Device. The following is a list of categories of personal information which We may collect or may have been collected from California residents within the last twelve (12) months.
Please note that the categories and examples provided in the list below are those defined in the CCPA/CPRA. This does not mean that all examples of that category of personal information were in fact collected by Us, but reflects Our good faith belief to the best of Our knowledge that some of that information from the applicable category may be and may have been collected.
Category A: Identifiers. Examples: A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, driver’s license number, passport number, or other similar identifiers.
Collected: Yes. We collect name, business email address, phone number, IP address, and cookie and advertising identifiers.
Category B: Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). Examples: A name, signature, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.
Some personal information included in this category may overlap with other categories.
Collected: Yes. Limited to name, telephone number, and employment-related information such as Your employer’s name.
Category C: Protected classification characteristics under California or federal law.
Collected: No.
Category D: Commercial information. Examples: Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
Collected: Yes. Limited to records of the products or services You enquired about or expressed interest in.
Category E: Biometric information.
Collected: No.
Category F: Internet or other similar network activity. Examples: Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement.
Collected: Yes. Collected through the analytics and advertising technologies described in this Policy.
Category G: Geolocation data. Examples: Approximate physical location, physical location or movements.
Collected: Yes, approximate only. Coarse location (typically city or region) inferred from Your IP address by Our analytics and advertising providers. We do not collect precise geolocation data.
Category H: Sensory data.
Collected: No.
Category I: Professional or employment-related information. Examples: Current or past job history or performance evaluations.
Collected: Yes. Limited to Your company name and, if You choose to provide it, Your job title or role.
Category J: Non-public education information (per the Family Educational Rights and Privacy Act).
Collected: No.
Category K: Inferences drawn from other personal information. Examples: Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Collected: Yes. Limited to marketing-related inferences, such as audience segments and estimates of interest in Our products or services, generated by Our advertising and analytics providers.
Category L: Sensitive personal information. Examples: Government-issued identifying numbers, financial account details, genetic data, precise geolocation, race or ethnicity, religious or philosophical beliefs, union membership, mail, email, text messages, biometric data, health data, and sexual orientation or sex life.
Collected: No. We do not collect Sensitive Personal Information and do not use or disclose it for purposes that would trigger the right to limit.
Under CCPA/CPRA, Personal Information does not include:
- Publicly available information from government records
- Deidentified or aggregated consumer information
- Information excluded from the CCPA/CPRA’s scope, such as:
- Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data
- Personal Information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994
Sources of Personal Information
We obtain the categories of personal information listed above from the following categories of sources:
- Directly from You. For example, from the Contact Form You complete on Our Service, or from emails and calls You send Us.
- Indirectly from You. For example, from observing Your activity on Our Service.
- Automatically from You. For example, through Cookies We or Our Service Providers set on Your Device as You navigate through Our Service.
- From Service Providers and advertising platforms. For example, from analytics and advertising providers that report on campaign performance and referral sources.
Use of Personal Information
We may use or disclose personal information We collect for “business purposes” or “commercial purposes” (as defined under the CCPA/CPRA), which may include the following examples:
- To operate Our Service and provide it to You.
- To respond to Your inquiries, including to investigate and address Your concerns and monitor and improve Our Service.
- To fulfill or meet the reason You provided the information. For example, if You share Your contact information to ask a question about Our services, We will use that personal information to respond to Your inquiry.
- For marketing and advertising, including cross-context behavioural advertising, subject to Your right to opt out.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to You when collecting Your personal information or as otherwise set forth in the CCPA/CPRA.
- For internal administrative and auditing purposes.
- To detect security incidents and protect against malicious, deceptive, fraudulent or illegal activity, including, when necessary, to prosecute those responsible for such activities.
- Other purposes consistent with the context in which the information was collected, or as otherwise disclosed to You at the time of collection.
Please note that the examples provided above are illustrative and not intended to be exhaustive. For more details on how We use this information, please refer to the “Use of Your Personal Data” section.
If We decide to collect additional categories of personal information or use the personal information We collected for materially different, unrelated, or incompatible purposes, We will update this Privacy Policy.
Disclosure of Personal Information
We may use or disclose and may have used or disclosed in the last twelve (12) months the following categories of personal information for business or commercial purposes:
- Category A: Identifiers
- Category B: Personal information categories listed in the California Customer Records statute
- Category D: Commercial information
- Category F: Internet or other similar network activity
- Category G: Geolocation data (approximate)
- Category I: Professional or employment-related information
- Category K: Inferences
When We disclose Personal Information for a business purpose, We enter into a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.
Sharing of Personal Information
We may share, and have shared in the last twelve (12) months, Your personal information identified in the above categories with the following categories of third parties:
- Service Providers (including hosting, customer relationship management, email delivery, security, and analytics providers)
- Advertising networks and analytics providers
- Our affiliates
- Professional advisers, courts, regulators, and law enforcement, where legally required
Sale or Sharing of Personal Information
As defined in the CCPA/CPRA, “sell” and “sale” mean selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer’s personal information by the Business to a third party for valuable consideration. “Share” and “sharing” mean disclosing personal information to a third party for cross-context behavioural advertising, whether or not for monetary or other valuable consideration.
We do not sell Personal Information in exchange for money, and We do not disclose Your name, email address, or phone number to third parties for their own independent marketing purposes.
However, when advertising and analytics technologies are active on the Service, online identifiers, Device information, and information about Your interaction with the Service are disclosed to advertising platforms which may use that information for cross-context behavioural advertising and for their own purposes. Under the broad statutory definitions, this may constitute a “sale” and does constitute “sharing”.
We may therefore have “sold” or “shared” the following categories in the last twelve (12) months:
- Category A: Identifiers (online identifiers, IP address, cookie and advertising identifiers)
- Category F: Internet or other similar network activity
- Category G: Geolocation data (approximate)
- Category K: Inferences
You have the right to opt out. See “Do Not Sell or Share My Personal Information” below.
Retention of Personal Information
We retain California residents’ Personal Information for as long as reasonably necessary to achieve the purposes described in this Privacy Policy (including the purposes disclosed in this CCPA/CPRA notice), taking into account: (i) how long We need the information to provide and maintain the Service and respond to Your enquiry; (ii) whether You have requested deletion (subject to applicable exceptions); (iii) Our legal, tax, accounting, and regulatory obligations; (iv) security, fraud prevention, and abuse monitoring needs; and (v) the time periods needed to resolve disputes and enforce Our agreements.
Specific retention periods for major data categories are described in the “Retention of Your Personal Data” section of Our Privacy Policy, and We may retain certain information longer where required or permitted by law.
Personal Information of Minors Under 16 Years of Age
Our Service is directed to business professionals and is not directed to minors. We do not knowingly collect personal information from minors under the age of 16 through Our Service.
We do not sell or share the Personal Information of Consumers We actually know are less than 16 years of age, unless We receive affirmative authorization (the “right to opt-in”) from the Consumer, or from the parent or guardian of a Consumer less than 13 years of age.
If You have reason to believe that a child under the age of 16 has provided Us with personal information, please contact Us with sufficient detail to enable Us to delete that information.
Your Rights under the CCPA/CPRA
The CCPA/CPRA provides California residents with specific rights regarding their personal information. If You are a resident of California, You have the following rights:
- The right to notice. You have the right to be notified which categories of Personal Information are being collected and the purposes for which the Personal Information is being used.
- The right to know/access. You have the right to request that We disclose information to You about Our collection, use, sale, sharing, and disclosure for business purposes of personal information, including the specific pieces of personal information We collected about You.
- The right to say no to the sale or sharing of Personal Information (opt-out). See the “Do Not Sell or Share My Personal Information” section.
- The right to correct Personal Information. You have the right to correct or rectify any inaccurate personal information about You that We collected.
- The right to limit use and disclosure of sensitive Personal Information. We do not collect Sensitive Personal Information, so this right does not currently apply to Our processing.
- The right to delete Personal Information. You have the right to request the deletion of Your Personal Information under certain circumstances, subject to certain exceptions. We may deny Your deletion request if retaining the information is necessary for Us or Our Service Providers to:
- Complete the transaction for which We collected the personal information, provide a good or service that You requested, take actions reasonably anticipated within the context of Our ongoing business relationship with You, or otherwise perform Our contract with You.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et seq.).
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if You previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on Your relationship with Us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which You provided it.
- The right not to be discriminated against. You have the right not to be discriminated against for exercising any of Your rights, including by denying goods or services to You, charging different prices or rates, providing a different level or quality of goods or services, or suggesting that You will receive any of the foregoing.
Exercising Your CCPA/CPRA Data Protection Rights
To exercise any of Your rights under the CCPA/CPRA, You can contact Us:
- By email: inquiry@orisen.com.tw
- By web form: https://orisen.com.tw/contact
Only You, or a person registered with the California Secretary of State that You authorize to act on Your behalf, may make a verifiable request related to Your personal information.
Your request to Us must:
- Provide sufficient information that allows Us to reasonably verify You are the person about whom We collected Personal Information or an authorized representative
- Describe Your request with sufficient detail that allows Us to properly understand, evaluate, and respond to it
We cannot respond to Your request or provide You with the required information if We cannot verify Your identity or authority to make the request and confirm that the personal information relates to You.
We will confirm receipt of Your request within 10 business days and will respond within 45 days of receiving Your verifiable request. The time period may be extended once by an additional 45 days when reasonably necessary and with prior notice. Any disclosures We provide will only cover the 12-month period preceding the verifiable request’s receipt.
For data portability requests, We will select a format to provide Your personal information that is readily usable and should allow You to transmit the information from one entity to another entity without hindrance.
Do Not Sell or Share My Personal Information
You have the right to opt out of the “sale” and “sharing” of Your personal information. You can exercise this right in any of the following ways:
- Set Your cookie preferences at Cookie Settings and reject advertising and targeting Cookies. This is the most effective method, because “sharing” on Our Service takes place through those technologies.
- Enable the Global Privacy Control (GPC) signal in Your browser or via a browser extension. We treat a GPC signal as a valid opt-out request for the browser and Device transmitting it.
- Contact Us at inquiry@orisen.com.tw.
Because opt-outs applied through Cookies and GPC are tied to a specific browser and Device, You will need to repeat them on each browser and Device You use, and if You clear Your Cookies.
“Do Not Track” Policy as Required by the California Online Privacy Protection Act (CalOPPA)
Our Service does not respond to Do Not Track signals, as described in “Do Not Track and Global Privacy Control” above. We do honour the Global Privacy Control signal.
Your California Privacy Rights (California’s Shine the Light law)
Under California Civil Code Section 1798.83 (California’s Shine the Light law), California residents with an established business relationship with Us can request information once a year about Our sharing of their Personal Data with third parties for those third parties’ direct marketing purposes. We do not share Personal Data with third parties for their own direct marketing purposes.
If You would like to make a request under the California Shine the Light law, You can contact Us using the contact information provided below.
California Privacy Rights for Minor Users (California Business and Professions Code Section 22581)
California Business and Professions Code Section 22581 allows California residents under the age of 18 who are registered users of online sites, services or applications to request and obtain removal of content or information they have publicly posted. Our Service does not offer registration or public posting features.
To request removal of such data, and if You are a California resident, You can contact Us using the contact information provided below.
Be aware that Your request does not guarantee complete or comprehensive removal of content or information posted online and that the law may not permit or require removal in certain circumstances.
Other US State Privacy Rights
If You are a resident of a US state with a comprehensive consumer privacy law — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, or Rhode Island — You may have rights to:
- Confirm whether We process Your personal data and access it
- Correct inaccuracies in Your personal data
- Delete personal data You provided or that We obtained about You
- Obtain a portable copy of Your personal data
- Opt out of targeted advertising, the sale of personal data, and certain profiling
- Not be discriminated against for exercising these rights
- Appeal a decision We make on Your request
To exercise these rights, contact Us at inquiry@orisen.com.tw. Where Your state’s law provides a right to appeal, We will inform You how to appeal if We decline Your request, and We will respond to an appeal within the time period set by Your state’s law.
We recognise universal opt-out mechanisms, including the Global Privacy Control, as valid requests to opt out of targeted advertising and the sale of personal data where Your state’s law requires it.
Taiwan Personal Data Protection Act (PDPA)
We are established in Taiwan, and Our collection, processing, and use of Personal Data is governed by the Personal Data Protection Act of the Republic of China (Taiwan). For the purposes of the PDPA, We are a non-government agency. This section provides the information required by Article 8 of the PDPA and supplements the rest of this Privacy Policy.
Identity of the collecting party
ORISEN BIOTECH CORPORATION, 3F., No. 192, Zhonggong 2nd Rd., Xitun Dist., Taichung City 407203, Taiwan (R.O.C.). Email: inquiry@orisen.com.tw.
Specific purposes of collection
We collect, process, and use Personal Data for the following specific purposes, identified using the classification codes published by the Ministry of Justice:
- 040 Marketing (行銷)
- 069 Contract, quasi-contract, or other legal relationship matters (契約、類似契約或其他法律關係事務)
- 090 Consumer, customer management and service (消費者、客戶管理與服務)
- 098 Business and technical information (商業與技術資訊)
- 136 Information, communications, and database management (資(通)訊與資料庫管理)
- 137 Information and communications security and management (資通安全與管理)
- 148 Internet shopping and other electronic commerce services (網路購物及其他電子商務服務)
- 152 Advertising or commercial conduct management (廣告或商業行為管理)
- 157 Investigation, statistics, and research analysis (調查、統計與研究分析)
- 181 Other business activities consistent with Our registered business scope or articles of incorporation (其他經營合於營業登記項目或組織章程所定之業務)
Categories of Personal Data collected
The categories described in “Types of Data Collected” above, namely identification and contact details (name, business email address, phone number, and company name), the content of any message You send Us, and online activity and device data collected through Cookies and similar tracking technologies.
Period, area, recipients, and manner of use
- Period: the retention periods described in “Retention of Your Personal Data”, or for as long as necessary to fulfil the specific purposes listed above, or as otherwise required by law.
- Area: Taiwan, and any country or region in which We, Our affiliates, Our Service Providers, or the analytics and advertising platforms named in this Policy operate, including the United States and the European Union.
- Recipients: the Company, Our affiliates, Our Service Providers, the analytics and advertising platforms named in this Policy, Our professional advisers, and courts, regulators, and other authorities where legally required.
- Manner: by automated machine or other non-automated means, including collection through Our Contact Form, Our email and telephone systems, Our customer relationship management system, and Cookies and similar tracking technologies.
Your rights under Article 3 of the PDPA
In respect of the Personal Data We hold about You, You may:
- Inquire about and request to review Your Personal Data
- Request a copy of Your Personal Data
- Request supplementation or correction of Your Personal Data
- Request that We cease collecting, processing, or using Your Personal Data
- Request deletion of Your Personal Data
These rights may not be waived or restricted by agreement in advance. To exercise them, contact Us at inquiry@orisen.com.tw. We may ask You to verify Your identity, and We may charge the necessary cost of production where You request a copy, as permitted by Article 14 of the PDPA.
In accordance with Article 13 of the PDPA, We will decide on a request to inquire, review, or obtain a copy within 15 days, extendable once by up to a further 15 days with notice to You; and on a request to supplement, correct, cease collecting, processing, or using, or delete within 30 days, extendable once by up to a further 30 days with notice to You.
We may decline a request where the PDPA permits, for example where compliance would impede the performance of a statutory duty, harm a significant public interest, or harm the significant interests of a third party. Where We decline, We will tell You why.
Consequences of not providing Personal Data
Providing Personal Data through the Contact Form is voluntary. If You do not provide the information marked as required, We may be unable to identify You, respond to Your enquiry, or provide the information You have requested. Declining non-essential Cookies does not affect Your ability to browse and use the Service.
Marketing
In accordance with Article 20 of the PDPA, when We first use Your Personal Data to market to You, We provide a means for You to refuse further marketing and We bear the cost of providing it. That means is also included in every subsequent marketing communication. If You tell Us You do not wish to receive marketing, We will immediately stop using Your Personal Data for that purpose.
International transmission
Under Article 21 of the PDPA, the competent authority may restrict the international transmission of Personal Data in certain circumstances. Where any such restriction applies to Us, We will comply with it. Otherwise, We transmit Personal Data internationally as described in “Transfer of Your Personal Data” and “International Transfer of Personal Data (GDPR)”.
Data security and breach notification
We maintain the technical and organisational measures described in “Security of Your Personal Data”, as required by Article 27 of the PDPA. In accordance with Article 12 of the PDPA, if Your Personal Data is stolen, disclosed, altered, or otherwise infringed as a result of a violation of the PDPA, We will investigate and then notify You by an appropriate method.
Complaints
If You believe We have not complied with the PDPA, please contact Us first at inquiry@orisen.com.tw. You may also raise the matter with the Personal Data Protection Commission or other competent authority in Taiwan, or pursue remedies through the courts under Chapter IV of the PDPA.
Your Choices Regarding Tracking and Advertising
In addition to Our cookie preference centre at Cookie Settings, You can control tracking and advertising through the following independent tools:
- Google Analytics opt-out browser add-on: https://tools.google.com/dlpage/gaoptout
- Google ad settings: https://myadcenter.google.com/
- Meta ad preferences: https://www.facebook.com/adpreferences/ad_settings
- Digital Advertising Alliance (US): https://optout.aboutads.info/
- Network Advertising Initiative (US): https://optout.networkadvertising.org/
- Your Online Choices (EU): https://www.youronlinechoices.eu/
- Your browser’s cookie and tracking-protection settings
Opting out of interest-based advertising does not stop You from seeing advertising; it means the advertising You see is less likely to be tailored to You.
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Other legal requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of users of the Service or the public
- Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us. We maintain technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include encryption of data in transit, access controls and authentication for systems that hold Personal Data, restriction of access to personnel who need it for their role, logging and monitoring, and security review of Our Service Providers.
However, remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While We strive to use commercially reasonable means to protect Your Personal Data, We cannot guarantee its absolute security.
If a personal data breach occurs that is likely to result in a risk to Your rights and freedoms, We will notify the competent supervisory authority and, where required by applicable law, affected individuals, within the timeframes set by that law.
Children’s Privacy
Our Service is directed to business professionals and does not address anyone under the age of 16. We do not knowingly collect personally identifiable information from anyone under the age of 16. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 16 without verification of parental consent, We take steps to remove that information from Our servers.
If We need to rely on consent as a legal basis for processing Your information and Your country requires consent from a parent, We may require Your parent’s consent before We collect and use that information.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us, including social media profiles and partner sites. If You click on a third party link, You will be directed to that third party’s site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time, including when We adopt new analytics or advertising technologies, change Our providers, or change the purposes for which We process Personal Data. We will notify You of any changes by posting the new Privacy Policy on this page.
We will let You know via a prominent notice on Our Service, prior to the change becoming effective, and update the “Last updated” date at the top of this Privacy Policy. Where a change requires Your consent under applicable law, We will obtain that consent before the change takes effect for You.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, or wish to exercise any of Your rights, You can contact Us:
- By email: inquiry@orisen.com.tw
- By web form: https://orisen.com.tw/contact
- By post: ORISEN BIOTECH CORPORATION, 3F., No. 192, Zhonggong 2nd Rd., Xitun Dist., Taichung City 407203, Taiwan (R.O.C.)