HansaWorld Personal Information Protection Policy (China)
HansaWorld logo — integrated business software

HansaWorld Personal Information Protection Policy (China)


1. This Policy only applies to the product(s) and service(s) of HansaWorld, including Standard ERP and Standard Accounts product lines.

Latest update: 07/2022 (Month/Year)
Please contact us using the details below if you have any doubt, comment or suggestion:
E-mail: ppi_china@hansaworld.com
Tel.: +353 615 48 021
Fax: +353 615 48 021

2. This Policy will help you better understand the following:



2.1 Rules for the collection and use of PI for legitimate business cooperation between HansaWorld, its affiliates and HansaWorld potential customers (to promote possible cooperation with a potential customer, to examine and propose possibilities of using our products and services to a potential customer, to make a quotation to a potential customer, to inform a potential customer about our products and services);

2.2 Rules for the collection and use of PI for legitimate business cooperation between HansaWorld, its affiliates and HansaWorld existing customers (to maintain the cooperation with an existing customer, to manage access to our products and services used by an existing customer, to inform an existing customer about our products and services and ensure the access of an existing customer to upgrades and updates of our products and services);

2.3 Rules for the collection and use of PI for legitimate business cooperation between HansaWorld, its affiliates and HansaWorld potential partners (to promote possible cooperation with a potential partner, to examine and propose to a potential partner the possibilities of cooperation in distribution of our products and services, to inform a potential partner about our products and services and possibilities of different models of possible cooperation in distribution of our products and services);

2.4 Rules for the collection and use of PI for legitimate business cooperation between HansaWorld, its affiliates and HansaWorld existing partners (to maintain and promote the cooperation with an existing partner, to inform an existing partner about the development of our products and services and possibilities of different models of cooperation in distribution of our products and services);

2.5 How we protect your PI;

2.6 Your rights;

Your rights:
2.6.1 How we process children’s PI;
2.6.2 How your PI is transferred worldwide;
2.6.3 How this Policy will be updated;
2.6.4 How to contact us.

2.7 HansaWorld understands the importance of PI to you and will do our best to ensure the security and reliability of your PI. We are committed to maintaining your trust in us and sticking to the following principles to protect your PI: principle of consistency between rights and responsibilities, principle of clear purpose, principle of optional consent, principle of minimum necessary, principle of security assurance, principle of subject participation, and principle of openness and transparency. In the meantime, HansaWorld hereby promises that we will take security measures to protect your PI according to mature standards of the industry.

Please read carefully and understand this PI Protection Policy before using our product/service.

3. Rules for the collection and use of PI for legitimate business cooperation between HansaWorld, its affiliates and HansaWorld potential customers



3.1. What kind of PI we collect about you:

The business functions we and our services provide require some information to run. If you choose to use this business function, you will need to provide us with or allow us to collect the essential information including: (i) name and surname of the contact person; (ii) office address of the contact person; (iii) phone number of the contact person; (iv) email address of the contact person; (v) login name and password in MyStandard system; (vi) name of the company the contact person is representing;

A total of 6 types of PI.

3.2 You may choose, at your discretion, whether to provide us with or allow us to collect the following information: (i) date of birth of the contact person; (ii) gender of the contact person; (iii) ID number of the contact person; (iv) Skype name; (v) social media link; (vi) LinkedIn profile name.

A total of 6 types of PI. Such information is not essential for the delivery of the business function, but it is important to improve the quality of service, develop new products or services, etc. We will not force you to provide this information, and your refusal will not adversely affect the use of the business functions.

3.3 When you use this business function, our System (APP) will request the following permissions to access PI in the system: (i) access to the name and surname of the contact person; (ii) access to the office address of the contact person; (iii) access to the phone number of the contact person; (iv) access to the email address of the contact person; (v) access to the login name and password in MyStandard system; (vi) access to the name of the company the contact person is representing; (vii) access to the Skype name; (viii) access to the social media link; (ix) LinkedIn profile name.

A total of 9 permissions. If you do not authorize, we will be unable to provide this business function. Except the permissions above, you can choose whether to grant additional system permissions to our System (APP).

4. Rules for the collection and use of PI for legitimate business cooperation between HansaWorld, its affiliates and HansaWorld existing customers



4.1. What kind of PI we collect about you:

The business functions we and our services provide require some information to run. If you choose to use this business function, you will need to provide us with or allow us to collect the essential information including: (i) name and surname of the end-user; (ii) office address of the end-user; (iii) phone number of the end-user person; (iv) email address of the end-user person; (v) login name and password of the end-user in MyStandard system; (vi) name of the company the end user is representing;

A total of 6 types of PI.

4.2 You may choose, at your discretion, whether to provide us with or allow us to collect the following information: (i) date of birth of the contact person; (ii) gender of the contact person; (iii) ID number of the contact person; (iv) position of the end user in the company the end user is working for; (v) Skype name; (vi) social media link; (vii) LinkedIn profile name.

A total of 7 types of PI. Such information is not essential for the delivery of the business function, but it is important to improve the quality of service, develop new products or services, etc. We will not force you to provide this information, and your refusal will not adversely affect the use of the business functions.

4.3 When you use this business function, our System (APP) will request the following permissions to access PI in the system: (i) access to the name and surname of the end-user; (ii) access to the office address of the end-user person; (iii) access to the phone number of the end-user; (iv) access to the email address of the end-user; (v) access to the login name and password of the end-user in MyStandard system; (vi) access to the position of the end user in the company the end user is working for; (vii) access to the Skype name; (viii) access to the social media link; (ix) LinkedIn profile name.

A total of 9 permissions. If you do not authorize, we will be unable to provide this business function. Except the permissions above, you can choose whether to grant additional system permissions to our System (APP).

5. Rules for the collection and use of PI for legitimate business cooperation between HansaWorld, its affiliates and HansaWorld potential partner



5.1. What kind of PI we collect about you:

The business functions we and our services provide require some information to run. If you choose to use this business function, you will need to provide us with or allow us to collect the essential information including: (i) name and surname of the contact person; (ii) office address of the contact person; (iii) phone number of the contact person; (iv) email address of the contact person; (v) login name and password in MyStandard system; (vi) name of the company the contact person is representing;

A total of 6 types of PI.

5.2 You may choose, at your discretion, whether to provide us with or allow us to collect the following information: (i) date of birth of the contact person; (ii) gender of the contact person; (iii) ID number of the contact person; (iv) Skype name; (v) social media link; (vi) LinkedIn profile name

A total of 6 types of PI. Such information is not essential for the delivery of the business function, but it is important to improve the quality of service, develop new products or services, etc. We will not force you to provide this information, and your refusal will not adversely affect the use of the business functions.

5.3 When you use this business function, our System (APP) will request the following permissions to access PI in the system: (i) access to the name and surname of the contact person; (ii) access to the office address of the contact person; (iii) access to the phone number of the contact person; (iv) access to the email address of the contact person; (v) access to the login name and password in MyStandard system; (vi) access to the name of the company the contact person is representing;(vii) access to the Skype name; (viii) access to the social media link; (ix) LinkedIn profile name.

A total of 9 permissions. If you do not authorize, we will be unable to provide this business function. Except the permissions above, you can choose whether to grant additional system permissions to our System (APP).

6. Rules for the collection and use of PI for legitimate business cooperation between HansaWorld, its affiliates and HansaWorld existing partner



6.1. What kind of PI we collect about you:

The business functions we and our services provide require some information to run. If you choose to use this business function, you will need to provide us with or allow us to collect the essential information including: (i) name and surname of the contact person; (ii) office address of the contact person; (iii) phone number of the contact person; (iv) email address of the contact person; (v) login name and password in MyStandard system; (vi) name of the company the contact person is representing;

A total of 6 types of PI.

6.2 You may choose, at your discretion, whether to provide us with or allow us to collect the following information: (i) date of birth of the contact person; (ii) gender of the contact person; (iii) ID number of the contact person; (iv) position of the contact person in the company the contact person is working for; (v) Skype name; (vi) social media link; (vii) LinkedIn profile name

A total of 7 types of PI. Such information is not essential for the delivery of the business function, but it is important to improve the quality of service, develop new products or services, etc. We will not force you to provide this information, and your refusal will not adversely affect the use of the business functions.

6.3 When you use this business function, our System (APP) will request the following permissions to access PI in the system: (i) access to the name and surname of the contact person; (ii) access to the office address of the contact person; (iii) access to the phone number of the contact person; (iv) access to the email address of the contact person; (v) access to the login name and password in MyStandard system; (vi) access to the name of the company the contact person is representing; (vii) access to the position of the contact person in the company the contact person is working for; (viii) access to the Skype name; (ix) access to the social media link; (x) LinkedIn profile name.

A total of 10 permissions. If you do not authorize, we will be unable to provide this business function. Except the permissions above, you can choose whether to grant additional system permissions to our System (APP).

7. How we use your PI



For essential and non-essential PI, we will use it to provide the business functions including promoting cooperation with potential customers and partners and maintaining cooperation with existing customers and partners. We also use such information to maintain and improve this business function and develop new business functions, etc.

8. How we entrust the processing, sharing, transfer and publicly disclosure of your PI



8.1 Entrustment of processing
Certain specific modules or sub-functions of this business function may be provided by external vendors. For example, we engage external service providers to assist us in providing customer support.

We will sign strict confidential agreements or will add strict confidentiality clauses into our agreements with the companies, organizations and individuals to whom we entrust the processing of PI, which will bind them to processing the PI in accordance with our requirements, this PI Protection Policy and other relevant confidentiality and security measures.

8.2 Sharing
We will not share your PI with any company, organization or individual other than HansaWorld Group of companies, unless with your explicit consent.

At present, we will seek your consent to the sharing of your PI in the following scenarios:

a) Our Company is a member of the HansaWorld Group of companies with offices in different countries and our employees are located in different offices therefore to ensure the business functions we are sharing your PI with other companies within HansaWorld Group.
To learn about the companies, organizations, and individuals currently involved in this scenario, click here https://www.hansaworld.com/en/about-us

b) Our Company has a network of local business partners around the world with offices in different locations who may also render customer support services therefore to ensure the business functions we may be sharing your PI with other companies within HansaWorld Group Business Partners Network.
To learn about the companies, organizations, and individuals currently involved in this scenario, click here https://www.hansaworld.com/en/partners2/overview

We might share your information as stipulated by laws, regulations or the mandatory requirements of government agencies.

8.3 Transfer
We will not transfer your PI to any company, organization, or individual except under the following circumstances:
a) Transfer with explicit consent: after acquiring your explicit consent, we will transfer your PI to other parties;
b) When the transfer of PI is involved in a(n) merger, acquisition or bankruptcy liquidation, we will require the new company or organization to which your PI is transferred to continue to be bound by this PI Protection Policy, otherwise we will require the new company or organization to seek your consent again.

8.4. Public Disclosure
We will only publicly disclose your PI under the following circumstances:
a) After we obtain your explicit consent;
b) Statutory disclosure: we might publicly disclose your PI as stipulated by laws, regulations or the mandatory requirements of government agencies.

9. How we protect your PI



9.1 We have employed security protection measures according to industry standards to protect your PI, prevent unauthorized access to, disclosure, use, modification, damage or loss of data. We will take every practical measure to protect your PI. For instance, we will ensure your PI is accessed only by those our employees who need access to such information to ensure the business functions (need-to-know basis); our systems have strong access control measures and data security protocols.

9.2 We have acquired the following certificates: ISO 270001

9.3 Our data security capability includes:

9.4 We will take all reasonable and practical measures to ensure that
unnecessary PI are not collected. We will only retain your PI for the period necessary to deliver the purposes stated in this Policy, unless the extended retention is required or allowed by laws.

9.5 We will regularly update and publicize reports on security risks, PI impact assessment, etc. You can access these by looking at update notes in our software and consulting our website www.hansaworld.com.

9.6 The network environment is not 100% secure. We will do our utmost to ensure or guarantee the security of any information you send to us. If your legal rights and benefits are adversely affected due to the unauthorized access to, disclosure, tampering or damage of your PI resulting from the damage of our physical, technical or management protection facilities, we will assume legal liabilities accordingly.

9.7 In the case of an unfortunate PI security incident, we will, in a timely manner and in accordance with laws and regulations, inform you of the basic conditions and possible impacts of the security incident, response measures that are already taken or to be taken by us, suggestions for you regarding self-prevention and risk mitigation, our remedial measures for you, etc. We will inform you of such information by email, fax, telephone, push notification, etc., and when it is difficult to notify each PI Subject individually, we will properly and effectively issue a public notice.
At the same time, we will also take the initiative to report the handling of PI security incidents in accordance with regulatory requirements.

10. Your rights



According to relevant laws, regulations and standards in China, as well as common practices in other countries and regions, we will ensure your following rights to your PI:

10.1 Access your PI

You have the right to access your PI, unless laws and regulations specify otherwise. If you wish to access your data, you can do so by: accessing your MyStandard Portal,
first login at https://mystandard.hansaworld.com
Select the "My Account" button on the upper right menu.
Here you'll be able to view the email address of your StandardID, edit your name, default language, recovery email, recovery phone and enable/disable the option to use the two factor to reset the password.

If you cannot access the PI via the links above, you can use our Web form or send an email to ppi_china@hansaworld.com at any time. We will respond to your access request in 30 days.
As for other PI generated during your use of our products or services, we will provide you with access to such information as long as no excessive input is required. If you wish to access such data, please send an email to ppi_china@hansaworld.com.

10.2 Rectify your PI
When you find a mistake in your information that we are processing, you have the right to ask us to rectify it. You can submit a rectification request through the channels listed in “10.1 Access your PI”.
If you cannot rectify the PI via the links above, you can use our Web form or send an email to ppi_china@hansaworld.com at any time. We will respond to your rectification request within 30 days.

10.3 Delete your PI
You can submit a request to delete your PI to us under the following circumstances:
10.3.1 If our processing of PI violates laws or regulations;
10.3.2 If we collected and used your PI without your consent;
10.3.3 If our processing of PI breaches our agreement with you;
10.3.4 If you no longer use our products or services or you have cancelled your account;
10.3.5 If we no longer provide you with products or services.

When we decide to respond to your deletion request, we will also inform the entity that acquires your PI from us and ask it to delete your PI without delay, unless otherwise specified in laws and regulations, or the entity has acquired specific authorization from you.
When you delete the information from our services, we might not immediately delete the corresponding information from our backup system, but will delete it when the backup system is updated.

10.4 Change the scope of your consent

Each business function needs some basic PI to be completed. As to the collection and use of additional PI, you can give or withdraw your consent at any time.

You can do so by: writing to us at ppi_china@hansaworld.com or calling our hotline.

When you withdraw your consent, we will stop processing the corresponding PI. However, your withdrawal of consent will not affect the processing of PI carried out based on your prior consent.
If you do not wish to receive our business promotion ads, you can unsubscribe at any time by: writing to us by email to ppi_china@hansaworld.com.

10.5 De-register
You can de-register at any time by closing your profile at our system or writing to us by email to ppi_china@hansaworld.com.
After de-registration, we will stop providing you with any product and service and delete your PI according to you request, unless laws and regulations specify otherwise.

10.6 Acquisition of a copy of PI by PI Subjects
You have the right to obtain a copy of your PI by: writing to us by email to ppi_china@hansaworld.com.
When it is technologically feasible, e.g. with matched data interface, we can directly transmit the copy of your PI to the third party designated by you according to your request.

10.7 Restrict automated decision-making by information system
For some business functions, decisions are made solely based on an automated decision-making mechanism such as information system and algorithm. If these decisions significantly affect your legal rights and interests, you have the right to ask for our explanation and we will make proper remedies.

10.8 Respond to your above-mentioned requests
For security, you might be required to submit written requests or prove your identity by other means. We might ask you to verify your identity before handling your request.
We will respond in 30 days. If you are not satisfied, you can file a complaint by email to ppi_china@hansaworld.com.

We will not charge you for your reasonable requests in principle. However, a fee to reflect the cost will be imposed as appropriate on repeated requests beyond reasonable scope. As for repeated requests that are groundless and need excessive technological means (e.g. developing a new system or fundamentally changing the current practices) to fulfill, bring about risks to others’ legitimate rights and interests or are downright impractical (e.g. involving information stored on a backup disk), we might reject.

We will not be able to respond to your request under the following circumstances:
    1. Related to our compliance with the obligations under the laws and regulations;
    2. Directly related to national security or defense security;
    3. Directly related to public security, public health or major public interests;
    4.Directly related to criminal investigations, prosecutions, trials and enforcement of court decisions, etc.;
    5. We have sufficient proof that you have subjective malice or abuse of rights;
    6. For the purpose of safeguarding your life, property and other important legal rights and interests or those of other individuals but it is difficult to obtain consent;
    7. Responding to your request will cause serious harm to your legitimate rights and interests, or those of other individuals or organizations.
    8. Involving trade secrets.

11. How we process children’s PI



Our products, websites and services are business to business and are adult oriented. A child must not create his/her own account or use our services.

If we find that a child’s PI has been collected without his/her parents’ prior consent, we will delete relevant data as soon as possible.

12. How your PI is transmitted worldwide



In principle, the PI we collect and generate in the territory of the People’s Republic of China will be stored within the People’s Republic of China and within HansaWorld Group as described hereof.

We provide products or services based on our resources and servers worldwide, that is to say, with your consent, your PI might be transmitted to or accessed from a jurisdiction outside of the country/region where your products or services are located.

Such jurisdiction might have a different data protection law, or even no relevant laws. Under such circumstances, we will ensure that your PI will enjoy the same level of protection as it does in the People’s Republic of China. For instance, we will ask you for your consent to the cross-border transmission of your PI, or employ data de-identification and other security measures before the cross-border transmission of data.

13. How to contact us



If you have any doubt, comment or suggestion regarding this Policy, please contact us via:

Address: HansaWorld China PPI Section, Roselawn House, University business complex, National Technology Park, Limerick, Republic of Ireland

Phone/Fax: +353 615 48 021

Email: ppi_china@hansaworld.com

We have set up a dedicated department for PI protection (or a PI protection officer) that you can contact via:

Address: HansaWorld China PPI Section, Roselawn House, University business complex, National Technology Park, Limerick, Republic of Ireland

Phone/Fax: +353 615 48 021

Email: ppi_china@hansaworld.com

Generally, we will reply to you in 30 days.

If you are not satisfied with our reply, especially if our processing of PI hurts your legal rights and interests, you can seek solutions through the following external channels:
(i) by contacting your local government agency responsible for protection of PI such as but not limited to State Administration for Market Supervision of the People’s Republic of China (https://www.samr.gov.cn/jg/lxfs/) or (ii) by contacting Data Protection Commission of the Republic of Ireland (https://www.dataprotection.ie/en/contact/how-contact-us) or
(iii) seek judicial protection of your rights in the courts having jurisdiction.