MAX - Data Protection Notice

Effective date: July 01, 2020

The protection of your personal data is of great importance to MAX CO.,LTD ("us", "we", "our", or “MAX”). This privacy policy (the “Data Protection Notice”) therefore intends to inform you about how we collect and process your personal data that yousubmit or disclose to us. We also act as data processor when we process your personal data received or obtained through third-parties. We process this personal data in accordance with the Privacy Act 1988of Australia(Cth) ("Australian Privacy Act") and the Privacy Act 1993of New Zealand (the "New Zealand Privacy Act").

We encourage you to read this Data Protection Notice carefully. This Data Protection Notice describes how we collect, process and use your personal data when you visit and/or interact with our services, website, and the choices we offer. Unless otherwise stated, MAX is the data controller for personal data we collect through theservices, websites and apps subject to this Data Protection Notice.

Our office address is MAX CO., LTD, 6-6, hakozaki-cho, nihonbashi, chuo-ku, Tokyo, Japan.

The privacy authorities in each jurisdiction can be reached using the following details:

Australia
Office of the Australian Information Commissioner
GPO Box 5218Sydney NSW 2001
+61 2 9284 9749
New Zealand
Office of the New Zealand Privacy Commissioner
investigations@privacy.org.nzOnline complaint form
+64 0800 803 909

You have the right to lodge a complaint also with the relevant privacy authority (Australia or New ZealandEU), which you can find as mentioned above.

If you have any queries or comments relating to this Data Protection Notice, please contact us at privacypolicy_oceania@max-ltd.co.jp.

1. Terms

Terms used in this Data Protection Notice shall have the following meaning:

Terms like “we”, “us”, “our”, etc. in this Data Protection Notice refer to MAX.

Terms like “you”, “your”, “yours”, etc. refer to you as a natural person.

The term “personal data” as used in this Data Protection Notice means for the purposes of the Australian jurisdiction and in accordance with the Australian Privacy Act, "personal data" means information or an opinion about you, whether true or not, which identifies you or from which your identity is reasonably identifiable. For the purposes of the New Zealand jurisdiction and in accordance with the "New Zealand Privacy Act "personal data" is the equivalent of "personal information" and means information about an identifiable individual.

2. Responsibility for the Handling of Your Personal Data

The party responsible for the collection, processing and use of personal data is MAX as the provider of the services and websites.

3. Applicability

This notice applies to all MAX services and websites that link to this document. This Data Protection Notice does not apply to services offered by other companies or individuals, including products or sites that may be displayed to you in search results, sites that may include MAX services, or other sites linked from our services.

Our Data Protection Notice does not cover the information practices of other companies and organizations who advertise our services, and who may use cookies, pixel tags and other technologies to serve and offer relevant ads.

3. Types of Personal Data We Collect, Process and Use

Personal data that we collect, process and use in connection with the services, websites and apps includes not only information that we actively collect while you interact with us but also information that you provide to us over the customer service, at any physical locations, and to our sales team. Where you do not wish to provide us with your personal data, we may not be able to provide you with our services.

Data Subject Log Information Device Information Location Information and Unique Identifiers
Website User
  • user preferences (e.g., preferred language settings)
  • automatically log files for troubleshooting and security purposes (e.g. to fend off hacker attacks)
  • log for crash report, and in exceptional cases, such as when malfunctions, errors or security incidents have occurred, a manual analysis of the logs may be performed by us or by our authorized service providers
  • date and time of the request
  • name, URL and amount of data transferred for the requested file
  • report indicating that the retrieval was successful or the reason for its failure
  • type and version of the operating system of the requesting computer (if transmitted)
  • screen resolution and color depth (if transmitted)
  • type and version of the browser used (if transmitted)
  • language setting and plugins installed on the browser used (if transmitted)
  • cookies that uniquely identify your browser
  • IP address, operating system, browser type, browser version, browser configuration
  • name of internet service provider, and other types of computer and connection related information relevant to identifying your type of device connecting to the web-site, enabling data exchange with you and your device, and ensuring a convenient use of the services, websites and apps
  • URL and IP address of the website from which you accessed, or were directed to our website, including date and time
  • subpages visited while on our website, links followed on the website, including date and time
  • subpages visited including date, time and time spent on page – on the apps
  • the full Uniform Resource Locator (URL) click stream to, through and from the website, including date and time
  • device event information such as crashes, system activity, hardware settings, browser type, browser language, the date and time of your request and referral URL
Company Information
  • name, address, department, contact information and other information in relation to a company that you represent and your function within this company
  • customer number
  • GST number
  • delivery address
  • business email address,
  • order number
  • business telephone number
  • business mobile phone number
  • company
  • contact language
  • customer advisor / point of contact
  • importance of customer
  • organizational unit
  • participation in campaigns or events
  • postal code
  • product history
  • region
  • returns
  • order number
In Person Surveys or Customer Service
  • name
  • address
  • email address

In certain cases, we may also collect personal data from publicly available sources and third parties, such as suppliers, contractors, our clients and business partners. If we collect personal data about you from a third party we will, where appropriate, request that the third party inform you that we are holding such personal data, how we will use and disclose it, and that you may contact us to gain access to and correct and update the information.

We will seek your consent before collecting, processing and using your personal data for the above-mentioned purposes, where legally required.

Likewise, if we wish to use your personal data for a new or different purpose, we will notify you thereof and will only make such other use if it is required or permitted by applicable law or if you have consented to it.

Any access to your personal data at MAX is restricted to those individuals that have a need to know in order to fulfill their job responsibilities. For the purposes mentioned above, only a limited number of individuals within MAX (e.g. individuals in sales, support, legal, finance, IT and accounting departments, as well as certain managers with assigned responsibility) will receive access to your personal data.

When you contact MAX, we keep a record of your communication to help solve any issues you might be facing. We may use your provided email address or phone number to inform you about our services, such as letting you know about upcoming changes or improvements.

5. Disclosure and Sharing of Personal Data

We do not sell, trade or rent out your personal data.

For the purposes mentioned in this Data Protection Notice we disclose, transfer or otherwise share your personal data, with other entities of the MAX group of companies to the extent described in the following or as agreed by you in a specific context (e.g., where you consenting to other types of data transfers in connection with enrolling for a specific service). When sharing personal data, we do strictly comply with applicable laws.

We do not share your personal data with companies, organizations and individuals outside of the MAX group of companies, unless one of the following circumstances applies:

External Processing:

We provide personal data to our third-party service providers under appropriate instructions as necessary for the respective processing purposes, to perform specific tasks on our behalf and under our instructions. Any third-party provider will have access only to such personal data needed to perform its specific tasks, and only to perform such tasks.

We will ensure that any third-party service provider is aware of and abides to these duties. We will also ensure that any third-party service provider treats your personal data no less protectively as required by applicable data protection laws and that they adopt adequate technical and organizational security measures based on our instructions and in compliance with our Data Protection Notice and any other appropriate confidentiality and security measures.

Third party service providers provides services such as hosting, maintenance, support services, email services, marketing, auditing, fulfilling your orders, processing payments, data analytics, providing customer service, conducting customer research and satisfaction surveys.

Distributors and repairers:

We may provide personal data to our third-party distributors and authorized repair dealers under appropriate instructions as necessary to perform specific distribution and repair functions and to distribute promotional materials, discount coupons and gifts to customers and potential customers in respect of MAX's, products and services or their related services. You can opt out of receiving promotional materials, discount coupons and gifts by contacting MAX using the details in paragraph 8.

We ask our third-party distributors and repairers to be aware of and abide by their obligations under the Australian Privacy Act and the New Zealand Privacy Act.

Legal Requirements:

We may share your personal data in cases where it is required by law or binding order of courts, law enforcement authorities or regulators. Should we decide to disclose personal data in such circumstances we will also consider ways of reducing the scope of the disclosure, for instance by redacting the information provided.

Consent:

Except in the circumstances above, we will only share personal data with companies, organizations or individuals outside of the MAX group of companies when we have your consent to do so. We require opt-in consent for the sharing of any personal data in these circumstances.

6. Transfer of Data

We take steps to ensure that the data we collect under this Data Protection Notice is processed according to the provisions of this Notice and the requirements of applicable law wherever the data is located. Such transfers may take place for the purposes of providing you customer services, processing your data by our service provider, or providing you with services at your location. For each of these transfers, we make sure that we provide an adequate level of protection to the data transferred, in particular, taking reasonable steps to ensure that the recipient deals with your personal data in compliance with the Australian Privacy Act and the New Zealand Privacy Act.

We disclose your personal data to overseas recipients including by storing your personal data on servers and backups located in Japan, in compliance with this Data Protection Notice.

7. Purposes of Processing Personal Data and Retention Period

To the extent it is technically possible, MAX is striving in all of its MAX services and websites to retain personal data no longer than necessary for the described purposes in this notice and/or as required or permitted under applicable law.

The following table gives an overview of the processing activities of MAX services, websites with their purpose of the data collection, their type, the legal basis and the applicable data retention periods.

Processing Purpose(s) Type of Personal Data Retention Period
To provide, maintain, and improve our services and website
  • User profile information (i.e., first name, name, email address, phone number, address)
  • User preferences (e.g., preferred language settings)
  • IP address, operating system, browser type, browser version, browser configuration, name of internet service provider, and other types of computer and connection related information relevant to identifying your type of device, connecting to the services, websites, enabling data exchange with you and your device, and ensuring a convenient use of the services, websites
  • If you use the mobile version of the services, websites: information on the operating system of your mobile device, used services, websites and apps version, name of internet service provider, and other types of device and connection related information relevant to improve the mobile services, websites, connecting to our servers, enabling and facilitating synchronization services
  • URL and IP address of the website from which you accessed, or were directed to our services, websites and apps, including date and time
  • Subpages visited and functions used when using services, websites, links followed from the services, websites, including date and time
  • The full Uniform Resource Locator (URL) click stream to, through and from the services, websites, including date and time
  • Search terms entered
  • Consents and authorizations granted
MAX retains the collected data for an undefined period to fulfill the purposes outlined in this Privacy Policy and will then be anonymized or deleted. If requested, personal data retained will be updated, and, if necessary, archived or deleted.
To provide customer support, respond to your inquiries, comments, and suggestions, or contact you when necessary
  • Name, address, phone number, and email address
  • Information on the device used (browser type, IP-address)
  • Date and time of the contact submission
  • Content of any communication sent through the content form
for advertising and market research purposes and to enable us to tailor website content to individual preferences
  • User profile information (i.e., first name, name, email address, phone number, address)
  • User preferences (e.g., preferred language settings)
  • IP address, operating system, browser type, browser version, browser configuration, name of internet service provider, and other types of computer and connection related information relevant to identifying your type of device, connecting to the services, websites, enabling data exchange with you and your device, and ensuring a convenient use of the services, websites
  • If you use the mobile version of the services, websites: information on the operating system of your mobile device, used services, websites and apps version, name of internet service provider, and other types of device and connection related information relevant to improve the mobile services, websites, connecting to our servers, enabling and facilitating synchronization services
  • URL and IP address of the website from which you accessed, or were directed to our services, websites and apps, including date and time
  • Subpages visited and functions used when using services, websites, links followed from the services, websites, including date and time
  • The full Uniform Resource Locator (URL) click stream to, through and from the services, websites, including date and time
  • Search terms entered
  • Consents and authorizations granted
To prevent abusive or illegal use of our services and websites

Compliance with legal obligations, resolving disputes, and enforcement of our agreements
Any necessary data to fulfill the relevant purposes
Evaluation of your eligibility for certain types of offers, products or services
  • Name, title and address
  • Personal contact information (phone, email, fax, etc.)
  • Name, address, department, contact information and other information in relation to a company that you represent (if any) and your function within this company
  • VAT/GST number
  • User profile information
  • Confirmation of being either a private or a professional user
  • Newsletter subscriptions, enrollment for promotions, use of special offers, etc
  • Consents, authorizations, etc. granted
To communicate with you on other matters (e.g., to send you reminders, technical notices, updates, security alerts, support and administrative messages or service bulletins)
  • Email address
  • Country
  • Language
  • Date of last contact
  • Mobile phone number
To provide you with information about products and services that may be of interest to you through email, telephone and mail.
  • Name
  • Email address
  • Country
  • Language
  • Consent state with date
  • Date of last contact
  • Phone number

8. Your Privacy and Marketing Choices

We aim to maintain our services and website in a manner that protects information from accidental or malicious destruction. Because of this, after you delete information from our services and website, we may not immediately delete residual copies from our active servers and may remove information from our backup systems only after certain timeframes in accordance with applicable laws (see pt. 6).

You can set your marketing preferences at any time through our customer service. By signing up for marketing information offered by MAX, you agree that the data you provided when signing up (e.g. your email address) can be collected, processed and used by MAX for the regular dispatching of written electronic communication containing company, product and service-related information such as news about new MAX products or MAX’s services or about MAX’s marketing campaigns (e.g. competitions, discounts, promotions), about changes within the company or to invite you to customer surveys (e.g. on customer satisfaction or customer requirements).

For the purposes of the Australian and New Zealand jurisdictions, we are committed to compliance with the Spam Act 2003 (Australia) and the Unsolicited Electronic Messages Act 2007 (New Zealand). You can unsubscribe from our written electronic communications at any time by clicking the "Unsubscribe" link embedded in these electronic communications.

Alternatively, and in all other jurisdictions, you can modify and adjust your consent to use your email address or mobile phone number by contacting us at privacypolicy_oceania@max-ltd.co.jp.

Once you have unsubscribed from or modified your subscription to our written electronic communications, you will be removed from our marketing list as soon as reasonably practicable.

9. Your Rights Under the Applicable Privacy Laws

You can at any time contact us at privacypolicy_oceania@max-ltd.co.jp to exercise the following rights under the GDPR:

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability

Please use the EU website to learn more about these rights.

In the case you withdraw your consent to a processing activity, MAX reserves the right to further process and use your personal data to the extent this is required or permitted by law (e.g. to administrate your unsubscribe or set an over layer cookie to respect your cookie settings).

  1. We may charge you our reasonable costs for providing you with access to any personal data. In some cases the laws allow us to decline to provide you access to your personal data. If we do decline access, we will give you reasons in writing.
  2. We may decline to correct any of your personal data if we do not agree that it requires correction. If so, we will give you reasons in writing and tell you what other options are available, including, if it is reasonable in the circumstances, to attach or associate a statement of any correction sought but not made to your personal data.

In New Zealand, we may also charge you our reasonable costs for correcting your personal data or attaching a statement of any correction sought but not made to your personal data.

10. Other Protections for Your Personal Data

MAX understands the importance of information and data security and we want your browsing and purchasing experience with us to be as safe as possible. To protect your personal data, we have implemented reasonable and state of the art safeguards and precautions, including technical and organizational measures against unauthorized access, improper use, alteration, unlawful or accidental destruction and accidental loss, both in an online and offline context.

For example:

  • when you use our website, communication with your browser is encrypted using SSL (Secure Socket Layer) technology. This means that when you use our website the personal data you submit during the registration and login processes are encrypted before being sent over the Internet.
  • we review the integrity our information collection process, storage and processing practices, including physical security measures, to guard against unauthorized access to systems.
  • we restrict access to personal data for MAX employees, contractors and agents based on a need to know approach in order to process it for us. Involved parties are subject to strict contractual confidentiality obligations and may be disciplined or terminated if they fail to meet these obligations.

The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

11. Cookies

We use cookies and similar technologies in connection with our services and website. For more information, please see our cookie policy.

12. Links to Other Websites

Our services and websites may contain links to other services, websites and apps of interest, once you have used these links you leave our services area. When you visit such other services, websites and apps you should exercise caution and look at the privacy statement applicable to the app or website in question. MAX cannot, and does not, assume any responsibility or liability for such other websites, the content of such services, websites and apps and their privacy practices, nor do we endorse them.

13. Compliance and Cooperation with Regulatory Authorities

14. Changes to the Data Protection Notice

We may update our Data Protection Notice from time to time. We will notify you of any changes by posting the new Data Protection Notice on this page. Please check this Data Protection Notice from time to time to ensure that you are comfortable with any changes we had to make. We will not reduce your rights under this Data Protection Notice without your explicit consent.

We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the "effective date" at the top of this Data Protection Notice.

15. Contact us

If you have any questions about this Data Protection Notice, please contact us:

By email: privacypolicy_oceania@max-ltd.co.jp

Postal address: MAX CO., LTD, 6-6, hakozaki-cho, nihonbashi, chuo-ku, Tokyo, Japan