JPEN

Supplementary Provisions for Customers Residing in the EEA and the United Kingdom

These By-Laws are made by and between GRANIF Corporation (hereinafter referred to as “the Company”) and the European Economic Area (hereinafter referred to as the “EEA”).
European Economic Area (“EEA”) The By-Laws shall set forth the data protection policy for the European Economic Area (hereinafter referred to as “EEA”) and the United Kingdom.


We will properly manage your personal information in accordance with our privacy policy (hereinafter referred to as the “Rules”). The Company appropriately manages customers' personal information in accordance with the Company's privacy policy (hereinafter referred to as the “Rules”). In addition to the Rules, the Company shall also manage the personal information of customers in the target countries (hereinafter referred to as “Target Countries”) and target regions (hereinafter referred to as “Target Regions”). In addition to the Rules, the Company will manage the personal information of customers residing in the countries covered by the Rules (“Covered Countries”) and the Covered Territories (“Covered Territories”). In addition to the Rules, we will manage the personal information (referred to as “Personal Data” in accordance with the description of the Rules below) of our customers residing in the EU and the European Economic Area (hereinafter referred to as “EU”). The General Data Protection Regulation on Data Protection in the European Union and the European Economic Area (the “EEA”) The personal data of our customers in the European Union and the European Economic Area (hereinafter referred to as “EEA”) will be managed and processed in accordance with the General Data Protection Regulation No. 2016/679 and the Data Protection Act in the United Kingdom (hereinafter collectively referred to as the “GDPR”). The data protection law in the United Kingdom (hereinafter collectively referred to as the “GDPR”).


If you do not want us to process your Personal Data as described in these Rules and the Supplementary Terms, please do not provide us with your Personal Data.
Please note that if you do so, we may not be able to provide you with our services, you may not be able to access the website and/or app and use its features, and your experience of using the website and/or app may be affected.

Legal Basis for Handling Your Personal Data and Types of Personal Data

Personal data is information that can or may identify an individual directly or indirectly by reference to one or more unique factors such as name, address, identification number, location data, online identifier, or physical, physiological, genetic, mental, economic, cultural, or social identity. information. We collect the following personal data about you When we acquire your personal data, we handle it in accordance with the GDPR and other applicable laws and regulations, including informing you of the purposes for which we will use your personal data. We will use your Personal Data for the following purposes. If we need to handle your personal data for any other purpose, we will notify you separately.

  1. (1) When processing is necessary for the purpose of a contract
    We process the following personal data about you for the purposes listed in the table below in order to enter into a contract with you or to perform procedures requested by you prior to entering into a contract
    Purpose of Processing Type of Personal Data
    To provide our products and services and for customer management Name, age, e-mail address, mailing address, shipping address, phone number, product purchase history
    To identify suspicious transactions and to ensure the safety of customers when settling their orders. Name, age, email address, mailing address, shipping address, phone number, payment, transaction information, product purchase history, IP address, device information, usage information

  2. (2) When processing is necessary for the pursuit of legitimate interests
    We obtain and process the following personal data about you for the following purposes because it is necessary for the pursuit of our legitimate interests.
    Purpose of Processing Type of Personal Data
    To administer and protect our e-commerce site (troubleshooting, data analysis, testing, system maintenance, support, data reporting and hosting, etc.) Name, date of birth, e-mail address, address, telephone number, payment, transaction information, product purchase history, IP address, device information, usage information
    To use data analytics to improve the customer experience on our website, products, services, marketing, and customer support Google Analytics data, cookies, name, age, email address, mailing address, shipping address, phone number, payment, transaction information, product purchase history, survey information, IP address, device information, usage information
    To make suggestions or recommendations regarding products and services that may be of interest to you Google Analytics data, cookies, name, age, email address, mailing address, shipping address, phone number, payment, transaction information, product purchase history, survey information, IP address, device information, usage information
    To respond to customer inquiries, opinions, and requests Name, age, e-mail address, mailing address, shipping address, telephone number, transaction information, product purchase history, device information, usage information
    To enable customers to participate in a drawing or complete a survey Cookies, name, age, email address, mailing address, shipping address, phone number, payment, transaction information, product purchase history, survey information, IP address, device information, usage information
    To improve safety and security by monitoring for fraudulent activity, investigating suspicious or potentially illegal activity, or violations of our policies or terms and conditions. Google Analytics, cookies, name, age, email address, address, phone number, payment, transaction information, product purchase history, survey information, IP address, device information, usage information

  3. (3) When we have your prior explicit consent
    With your prior explicit consent, we will also collect and process your personal data for the following purposes
    Purpose of Processing Type of Personal Data
    To conduct marketing activities, including the provision of information on products and services offered by the Company, such as the distribution of e-mails Name, age, e-mail address, mailing address, shipping address, telephone number, transaction information, product purchase history, survey information, device information, usage information
    To share your personal data with third parties who may provide you with information about their products and services Google Analytics data, cookies, name, age, email address, mailing address, shipping address, phone number, payment, transaction information, product purchase history, survey information, browser setting information, IP address, device information, usage information

    If the processing of your personal data by us is based on your consent, you may withdraw your consent at any time. Withdrawal of such consent does not affect the lawfulness of our processing of your personal data based on the consent you gave before the withdrawal. You may withdraw your consent through the services you use or by contacting us.

    The personal data we collect does not include information provided via third parties such as business partners, subcontractors, business associates or social media providers.

Sharing of Your Personal Data

We will not disclose or provide your personal data to third parties except in the following cases

  1. (i) When the customer has been notified in advance
  2. (ii) When we have obtained consent from the customer
  3. (iii) When disclosed or provided in accordance with GDPR or other applicable laws and regulations.

The third parties to whom we provide your personal data are as follows

  1. (1) Subcontractors
    In the course of providing products or services to our customers, we may outsource part or all of our operations and provide personal data to outsourced parties to the extent necessary to achieve the purpose of use. In the event that we outsource the handling of our customers' personal data to such third parties, we will take necessary and appropriate measures in accordance with the GDPR and other applicable laws and regulations.
  2. (2) Business partners and business partners
    In the course of providing products or services to customers, we may provide customers' personal data to service providers, software developers, credit card companies, customer support operators, and other business partners involved in the development, provision, sale, and settlement of products or services, to the extent necessary to achieve the purpose of use. We may provide your personal data to service providers, software developers, credit card companies, customer support operators, and other business partners involved in the development, provision, sale, and settlement of products or services.
    We may also share your personal data with the above business partners to the extent necessary to respond to your inquiries or other requests.
  3. (3) Disclosure of Personal Data to Regulatory Authorities and Professionals
    We may disclose personal data to government agencies, regulatory authorities, law enforcement authorities, and professionals (including, but not limited to, attorneys and certified public accountants in the applicable countries and territories and in Japan) when necessary for the purposes we have informed you of, when compelled by law, or when legally required to protect our legitimate interests in compliance with applicable laws. (including, but not limited to, attorneys and certified public accountants in the applicable countries and territories and in Japan). We may share or provide your personal data to

Transfer of Personal Data to Covered Territories or Outside of Covered Countries

Your personal data that we have acquired may be transferred to, managed or processed in the Territories or outside of the Territories. In such cases, your personal data must be secured and protected with the same level of security as in the Territory or within the Territory. In order to ensure that your data is securely stored and handled in accordance with the provisions of this Policy, the Supplementary Provisions, the GDPR, and other applicable laws and regulations, we will transfer personal data to countries that have been certified by the European Commission as adequate under the GDPR or to countries other than those that have been certified as adequate. We will take all steps reasonably necessary (including entering into standard contractual clauses approved by the European Commission under the GDPR) when transferring personal data to countries that have been certified as sufficient by the European Commission under the GDPR or to countries other than those that have been certified as sufficient. We will take all reasonably necessary steps (including entering into standard contractual clauses approved by the European Commission under the GDPR) to

Period of Retention of Personal Data

We will retain your personal data for as long as is necessary to fulfill the purposes for which it is used or to fulfill our obligations under applicable laws and regulations. The specific retention period will be determined by taking into consideration the purpose for which the personal data was acquired, the purpose and nature of its use, and the legal or business necessity for retaining the personal data.

Customer's Choice

In principle, provision of personal data by customers to us is done of their own volition, and customers are under no obligation to provide personal data.

However, if you do not provide us with your personal data, you may not be able to use the various services we provide, or some of the functions of the system may not work properly, or you may experience other disadvantages.

Handling of Children's Personal Data

We do not knowingly collect and process information about children under the age of 16 without their parents' permission and consent. If we discover that we have directly collected and processed personal data of children under the age of 16 or under the minimum age for the purposes of the GDPR, which varies according to EU Member State law, we will take steps to delete the information as soon as possible.

Organizational and Technical Measures to Protect Customers' Personal Data

We will establish a management system for personal data protection and take appropriate organizational, physical, and technical safety control measures to prevent unauthorized access to personal data, loss, destruction, falsification, leakage, etc. of personal data, and to otherwise safely manage personal data. In addition, we recognize the importance of personal data protection, and will take appropriate personnel security control measures, such as training efforts to protect personal data for directors, officers, employees, and others who handle personal data.

In the unlikely event of a leakage of personal data, we will investigate the facts and causes, implement measures to prevent secondary damage and recurrence, and take appropriate action.

Automated Decision-Making

We do not make decisions based on automated processes, including profiling, that have legal effect or similarly significant impact on our clients.

Data Processing Records

Whether acting as a data controller or data processor, we will handle records of the processing of personal data in accordance with our obligations under the GDPR and other applicable laws and regulations. We will reflect in these records all information necessary to comply with the GDPR and other applicable laws and regulations and to cooperate with supervisory authorities in accordance with the GDPR and other applicable laws and regulations.

Notification of Data Breaches to Competent Supervisory Authorities

In the event of a security breach resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access of personal data subject to transfer, storage or other processing, we have mechanisms and guidelines in place to promptly detect and evaluate the breach.
Depending on the results of our assessment, we will make the necessary notifications to the supervisory authorities and contact affected data subjects, including our clients.

Your Rights

You have the following rights with respect to the personal data we use

If we receive any of the following requests from a customer, we will respond to the request sincerely and appropriately in accordance with the GDPR and other applicable laws and regulations, after confirming that the person making the request is the person in question or a person authorized by the person in question.

  1. (1) Right of Access to Personal Data
    You have the right to obtain confirmation from us as to whether or not personal data concerning you is being processed, and if so, you have the right to access your personal data and certain related information.
  2. (2) Right to Correction of Personal Data
    You have the right to request that we correct your personal data if it is inaccurate.
  3. (3) Right to erasure of personal data
    If certain conditions are met, you may have the right to request that we erase your personal data held by us.
  4. (4) Right to Restrict Processing of Personal Data
    If certain conditional requirements are met, you may have the right to restrict the processing of your personal data held by us.
  5. (5) Objections to the Processing of Personal Data
    Under certain conditions, you may have the right to object to our processing of your personal data.
  6. (6) Right to Data Portability of Personal Data
    If certain conditions are met, you have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to transfer it to another controller without hindrance to us.

Contact Information

If you have any requests, questions or demands regarding the handling of personal data, please contact us by e-mail at the contact information below.
Please note that we may not be able to respond to unrelated inquiries. In addition, responses sent to you by us are sent to individual customers for the purpose of responding to your inquiry. Please refrain from reprinting or making secondary use of our responses, in whole or in part, on social networking sites or for any other purpose.

For inquiries, please contact
graniph Online Store below or as described in this rule
https://www.graniph.com/en/inquiry/inquiry

Appeal to a Supervisory Authority

You have the right to appeal against our processing of your personal data to the supervisory authority of the Member State in which you reside, work or where the breach of the GDPR or other applicable laws or regulations for data protection occurred.

EEA and UK Agent

We have appointed DataRep as our data protection agent for the purposes of the General Data Protection Regulation No. 2016/679 on data protection in the EU/EEA and the Data Protection Act in the UK. If you have any questions for us or wish to exercise your rights regarding your personal data, you may contact DataRep from your country by

Email DataRep, Inc.
datarequest@datarep.com
Please make sure to include in the Subject line.
Inquire by form
Please fill in the form at https://www.datarep.com/data-request .
Inquire by mail

Please mail to the address listed at the end of this Privacy Policy.
If you contact us by mail, please be sure to include 'DataRep' in the address.

Administrator of these Rules and Supplementary Provisions

graniph Inc.
Sumitomo Fudosan Harajuku Building 6F, 2-34-17 Jingumae, Shibuya-ku, Tokyo 150-0001, Japan
Kimio Arakawa, Director and CFO

Revision

MUTOH HOLDINGS reserves the right to change, modify, add, or delete the contents of the Rules or Supplementary Provisions from time to time in response to changes in laws and regulations, business needs, or other factors.

Contact DataRep by mail at

Country Address
Austria DataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria
Belgium DataRep, Rue des Colonies 11, Brussels, 1000
Bulgaria DataRep, 132 Mimi Balkanska Str., Sofia, 1540, Bulgaria
Croatia DataRep, Ground & 9th Floor, Hoto Tower, Savska cesta 32, Zagreb, 10000, Croatia
Cyprus DataRep, Victory House, 205 Archbishop Makarios Avenue, Limassol, 3030, Cyprus
Czech Republic DataRep, Platan Office, 28. Října 205/45, Floor 3&4, Ostrava, 70200, Czech Republic
Denmark DataRep, Lautruphøj 1-3, Ballerup, 2750, Denmark
Estonia DataRep, 2nd Floor, Tornimae 5, Tallinn, 10145, Estonia
Finland DataRep, Luna House, 5.krs, Mannerheimintie 12 B, Helsinki, 00100, Finland
France DataRep, 72 rue de Lessard, Rouen, 76100, France
Germany DataRep, 3rd and 4th floor, Altmarkt 10 B/D, Dresden, 01067, Germany
Greece DataRep, Ippodamias Sq. 8, 4th floor, Piraeus, Attica, Greece
Hungary DataRep, President Centre, Kálmán Imre utca 1, Budapest, 1054, Hungary
Iceland DataRep, Kalkofnsvegur 2, 3rd Floor, 101 Reykjavík, Iceland
Ireland DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland
Italy DataRep, Viale Giorgio Ribotta 11, Piano 1, Rome, Lazio, 00144, Italy
Latvia DataRep, 4th & 5th floors, 14 Terbatas Street, Riga, LV-1011, Latvia
Liechtenstein DataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria
Lithuania DataRep, 44A Gedimino Avenue, 01110 Vilnius, Lithuania
Luxembourg DataRep, BPM 335368, Banzelt 4 A, 6921, Roodt-sur-Syre, Luxembourg
Malta DataRep, Tower Business Centre, 2nd floor, Tower Street, Swatar, BKR4013, Malta
Netherlands DataRep, Cuserstraat 93, Floor 2 and 3, Amsterdam, 1081 CN, Netherlands
Norway DataRep, C.J. Hambros Plass 2c, Oslo, 0164, Norway
Poland DataRep, Budynek Fronton ul Kamienna 21, Krakow, 31-403, Poland
Portugal DataRep, Torre de Monsanto, Rua Afonso Praça 30, 7th floor, Algès, Lisbon, 1495-061, Portugal
Romania DataRep, 15 Piaţa Charles de Gaulle, nr. 1-T, Bucureşti, Sectorul 1, 011857, Romania
Slovakia DataRep, Apollo Business Centre II, Block E / 9th floor, 4D Prievozska, Bratislava, 821 09, Slovakia
Slovenia DataRep, Trg. Republike 3, Floor 3, Ljubljana, 1000, Slovenia
Spain DataRep, Calle de Manzanares 4, Madrid, 28005, Spain
Sweden DataRep, S:t Johannesgatan 2, 4th floor, Malmo, SE - 211 46, Sweden
Switzerland DataRep, Leutschenbachstrasse 95, ZURICH, 8050, Switzerland
United Kingdom DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom