PLEASE READ THIS PRIVACY POLICY CAREFULLY

1. OUR PRIVACY STATEMENT

Scope and Controller
This privacy policy applies to the site https://www.jfc.eu as well as activities related to our business as described below.

This site is operated and maintained by the data controller, JFC International (Europe) GmbH
Theodorstrasse 293
40472 Düsseldorf
Germany

JFC International (Europe) GmbH (“We”, “us”) is part of the Kikkoman Group, headquartered with the Kikkoman Corporation situated in 2-1-1 Nishi-Shinbashi, Minato-ku, Tokyo 105-8428, Japan. 

The protection of your personal data is of great importance to Kikkoman Corporation (“Company”) and its affiliates in the European Economic Area (the “EEA”) (together, the “Company Group”). This privacy policy (the “Privacy Policy”) therefore intends to inform you about JFC International (Europe) GmbH, acting as data controller, collects and processes your personal data that you submit or disclose to us. We also act as data controller when we process your personal data received or obtained through third parties. We process this personal data in accordance with the applicable EU and Member State regulations on data protection in particular, the General Data Protection Regulation No 2016/679 (the “GDPR”). We encourage you to read this Privacy Policy carefully. If you do not wish for your personal data to be used by us as set out in this Privacy Policy, please do not provide us with your personal data. Please note that in such a case, we may not be able to provide you with our services, you may not have access to and/or be able to use some features of the Website, and your customer experience may be impacted.

2. HOW DO WE USE YOUR PERSONAL DATA?

We will always process your personal data based on one of the legal bases provided for in the GDPR (Articles 6 and 7). In addition, we will always process your sensitive personal data, for example, concerning your trade union membership, religious views, or health condition, in accordance with the special rules provided for in the GDPR (Articles 9 and 10).

We may collect and process your personal data for the purposes detailed below, which are required so that we can pursue our legitimate interests and provide you with adequate services and products:

Contractual basis (Article 6 (1) b))

  • to offer you products and services;
  • to manage our contractual relationship with you;
  • to manage your customer account;
  • to inform you about our policies and terms;
  • to notify you about changes to our service(s);

Legitimate Interest (Article 6 (1) f))

  • to promote safety and security, such as by monitoring fraud and investigating suspicious or potentially illegal activity or violations of our terms or policies;
  • to provide, improve, and develop our products, services, and advertising;
  • to use personal information for purposes such as data analysis, research, and audits;
  • to ensure business continuity;
  • to ensure that content from our site is presented in the most effective manner for you;

In certain cases we may ask for your consent for other purposes. The purpose will be described within the consent form. In such cases, please be aware that you are entitled to withdraw your consent at any time, and this without affecting the lawfulness of processing based on your consent before withdrawal thereof.

We will process your data for these specified, explicit, and legitimate purposes, and will not further process the data in a way that is incompatible with these purposes. If we intend to process personal data originally collected for one purpose in order to attain other objectives or purposes, we will ensure that you are informed of this.

3. HOW LONG DO WE KEEP YOUR PERSONAL DATA?

Unless noted differently, we will keep your personal data for as long as it is necessary for us to comply with our legal obligations, to ensure that we provide an adequate service, and to support its business activities (Article 5 and 25(2) GDPR).
We will keep personal data that we received as part of you contacting us for as long as required to answer your request. If the request is part of a contractual relationship, or in preparation of entering into such, we will further retain the personal data as long as required for such purpose.
If you have a contractual relationship with us, we will keep your personal data at least for as long as the contract requires us to do so.

4. WHAT TYPES OF PERSONAL DATA DO WE USE?

For the purposes specified under this Privacy Policy, we process the personal data obtained from you directly (when you decide to communicate such data to us, i.e., your contact data when you contact us, or when you fill in forms displayed on the Website) or indirectly (data provided to us by a third-party).
We also process some information about your browser and internet connection when you connect to this website such as your IP-Address, your timezone or the date and time of your connection. We keep these logs for detecting fraud and attacks on our infrastructure for 7 days.
We ensure that the personal data processed be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.

5. HOW DO WE SHARE YOUR PERSONAL DATA?

We may share your personal data with Company Group entities and with third parties in accordance with the GDPR and only for legitimate purposes, such as fulfilling your request or handling logistics. Where we share your data with an external party, we will put the appropriate legal framework in place in order to cover such transfer and processing (Articles 26, 28 and 29). Furthermore, where we share your data with any entity outside the EEA, we will put appropriate legal frameworks in place as required, notably Standard Contract Clauses approved by the European Commission, in order to cover such transfers (Articles 44 ff. GDPR).

Service Providers

We share your personal data with companies which provide services on our behalf, such as hosting, maintenance, support services, email services, marketing, auditing, fulfilling your orders, processing payments, data analytics, providing customer service, and conducting customer research and satisfaction surveys.

Cloudflare Turnstile

To prevent malicious actors from abusing our contact form, we have implemented Cloudflare Turnstile, provided by the US company Cloudflare Inc. based in 101 Townsend St., San Francisco, CA 94104, USA (“Cloudflare”). We have concluded a data processing agreement with Cloudflare. Cloudflare is certified under the EU-US Data Privacy Framework.
When opening our contact page, the challenge widget provided by Cloudflare is loaded, and Cloudflare will become aware of your IP address as well as additional browser and operating system information and which webpage you have opened. The widget itself processes behavioural indicators from you, such as operating system, JavaScript support, cursor movement. These indicators are processed locally by the widget and only the result is sent to Cloudflare servers, authenticating you as a valid user.
We have implemented this technology due to the high risk of spam being send through our contact form, to prevent DDoS attacks and malicious behaviour on our website, as is our legitimate interest according to Art. 6 (1) f) of the GDPR.

Hosting

We are hosting our website with Mittwald CM Service GmbH & Co. KG, based in Königsberger Straße 4-6, 32339 Espelkamp, Germany (“Mittwald”). We have concluded a data processing agreement with them. Mittwald will know your IP address, information on your browser and operating system as well as which webpages you visit.
It is our legitimate interest to serve a modern website with minimal technical disruption, our use of a dedicated hosting provider is based on Art. 6 (1) f) of the GDPR.

Corporate Affiliates and Corporate Business Transactions

We may share your personal data with all Company’s affiliates. In the event of a merger, reorganization, acquisition, joint venture, assignment, spin-off, transfer, or sale or disposition of all or any portion of our business, including in connection with any bankruptcy or similar proceedings, we may transfer any and all personal data to the relevant third party.

Legal Compliance and Security

It may be necessary for us – by law, legal process, litigation, and/or valid requests from public and governmental authorities within or outside your country of residence – to disclose your personal data. We will always carefully consider such disclosures to determine the validity of the request and the necessity of disclosure. We may also disclose your personal data if we determine that, due to purposes of national security, law enforcement, or other issues of public importance, the disclosure is necessary or appropriate.
We may also disclose your personal data if we determine in good faith that disclosure is reasonably necessary to protect our rights and pursue available remedies, enforce our terms and conditions, investigate fraud, or protect our operations or users.

Data Transfers to Japan

Disclosures may involve transferring your personal data out of the European Union to Japan, where some companies of the Kikkoman Group are located. Such transfer may take place for employee or business management purposes by the Company. For each of these transfers, we make sure that we provide an adequate level of protection to the data transferred as required, in particular by ensuring compliance with the adequacy agreement between the EU and Japan or by entering into standard contract clauses.
We will not use your personal data for online marketing purposes unless you have expressly consented to such use of your personal data. You can change your marketing preferences at any time by contacting us.

6. SECURITY MEASURES

We process your personal data in a manner that ensures their appropriate security, including protection against unauthorised or unlawful processing, accidental loss, destruction, or damage. We use appropriate technical or organisational measures to achieve this level of protection. We will retain your personal information for as long as it is necessary to fulfil the purposes outlined in this Privacy Policy unless a longer retention period is required or permitted by law.

7. YOUR RIGHTS

You have the following rights regarding personal data collected and processed by us.

  • Information regarding your data processing: You have the right to obtain from us all the requisite information regarding our data processing activities that concern you (Articles 13 and 14 GDPR).

  • Access to personal data: You have the right to obtain from us confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data and certain related information (Article 15 GDPR).

  • Rectification or erasure of personal data: You have the right to obtain from us the rectification of inaccurate personal data concerning you without undue delay, and to complete any incomplete personal data (Article 16 GDPR). You may also have the right to obtain from us the erasure of personal data concerning you without undue delay, when certain legal conditions apply (Article 17 GDPR).

  • Restriction on processing of personal data: You may have the right to obtain from us the restriction of processing of personal data, when certain legal conditions apply (Article 18 GDPR).

  • Object to processing of personal data: You may have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you, when certain legal conditions apply (Article 21 GDPR).

  • Data portability of personal data: You may have the right to receive your personal data in a structured, commonly used and machine-readable format, and have the right to transmit those data to another controller without our hindrance, when certain conditions apply (Article 20 GDPR).

  • Not to be subject to automated decision-making: You may have the right not to be subject to automated decision-making (including profiling) based on the processing of your personal data, insofar as this produces legal or similar effects on you, when certain conditions apply (Article 22 GDPR).

  • Revocation of consent: You may at any time revoke consent that you have given us for the processing of data. The revocation does not affect the lawfulness of processing based on your consent before withdrawal thereof.

If you intend to exercise such rights, you can contact our data protection officer as described below or contact us directly. If you are not satisfied with the way in which we have proceeded with any request, or if you have any complaint regarding the way in which we process your personal data, you may lodge a complaint with a Data Protection Supervisory Authority.

8. CHILDREN

Our products and services are intended for adult customers. Thus, we do not knowingly collect and process information on children under sixteen (16). If we discover that we have collected and processed the personal data of a child under sixteen (16), or the equivalent minimum age depending on the concerned jurisdiction, we will take steps to delete the information as soon as possible. If you become aware that a child under sixteen (16) has provided us with personal data, please contact us immediately as detailed below.

9. CONTACT DETAILS OF DATA PROTECTION OFFICER

You can contract our data protection officer at:

Enobyte GmbH
Augustenstr. 49
80333, Munich
Germany

E-Mail: dpo@enobyte.com
Website: https://enobyte.com

10. LINKS TO OTHER SITES

We may propose hypertext links from the Website to third-party websites or Internet sources. We do not control and cannot be held liable for third parties’ privacy practices and content. Please carefully read their privacy policies to find out how they collect and process your personal data.

11. UPDATES TO PRIVACY POLICY

We may revise or update this Privacy Policy from time to time. Any changes to this Privacy Policy will become effective upon posting of the revised Privacy Policy via the Services. If we make changes which we believe are significant, we will inform you through the Website to the extent possible and seek your consent where applicable.

CONTACT

For any questions or requests relating to this Privacy Policy, you can contact us by e-mail at privacy@jfc.eu