Privacy Policy for GMAC Japan

1. Introduction

At GMAC Japan (“we”, “our”, or “us”), accessible via gmacjapan.com, we are fully committed to safeguarding the privacy and personal data of our users. We are dedicated to adhering to the highest standards of data protection and accountability as required under applicable global data privacy laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). This Privacy Policy outlines how we collect, use, disclose, and protect your information when you visit or interact with our website.

2. Scope and Data Controller Role

This Privacy Policy applies to all visitors, users, and others who access gmacjapan.com (the “Website”) and any related online services. GMAC Japan acts as the Data Controller in relation to the collection and processing of personal data through this Website. If you have questions related to this Policy or your data, please contact us at [email protected].

3. Categories of Personal Data We Process

We may collect and process the following categories of personal data, in accordance with applicable laws:

Usage Data

We collect data about your interactions with the Website, which may include your IP address, browser type, operating system, referral URLs, access times, and session information.

Account Data

When you create an account or communicate with us as a customer, we may collect your full name, postal address, email address, and telephone number.

Profile Data

Information relating to your preferences, purchase history, browsing behavior, and demographic interests may be collected to personalize your experience.

Communication Data

Any data provided during inquiries, support tickets, or customer communications (e.g., emails, feedback forms) will be stored, including a history of your interactions.

Technical Data

We collect data from your devices, including hardware model, operating system version, unique device identifiers, network information, browser settings, and other system configurations.

Transaction Data

If you make purchases or conduct transactions through our Website, we may collect billing addresses, payment confirmation details, and delivery instructions.

Preference Data

We may collect your preferences for receiving marketing, newsletters, product updates, and personalized content, as well as your opt-in or opt-out statuses.

4. Legal Bases for Processing Personal Data

We rely on the following lawful bases under GDPR and CCPA to process your personal data:

– Consent: Where you have actively consented to data collection for specific purposes, such as marketing or account registration.
– Contract: Where data processing is necessary for the performance of a contract to which you are a party.
– Legal Obligation: Where we are required by applicable law to collect and retain data.
– Legitimate Interests: Where processing is necessary for the legitimate interests pursued by GMAC Japan, such as ensuring the security and performance of our Website, provided such interests are not overridden by your individual rights.

5. Your Rights

Subject to the GDPR and CCPA, you may exercise the following rights in relation to your personal data:

– Right of Access – You have the right to request and receive a copy of the personal data we hold about you.
– Right to Rectification – You may request correction of any inaccurate or incomplete data.
– Right to Erasure – You have the right to request deletion of your personal data under certain conditions.
– Right to Restrict Processing – You may request that we limit the processing of your personal data in specific circumstances.
– Right to Data Portability – You can request a copy of your personal data in a structured, commonly used, and machine-readable format.
– Right to Object – You may object to our processing of your data where we rely on legitimate interests or direct marketing as a lawful basis.
– Non-Discrimination – Under the CCPA, we will never discriminate against you for exercising any of your privacy rights.

To exercise any of these rights, please contact us at [email protected].

6. Security Measures

GMAC Japan implements industry-standard security controls to protect your personal data from unauthorized access, alteration, disclosure, or loss. These measures include:

– Encryption of sensitive data both in transit and at rest
– Role-based access control and least privilege principles
– Regular data backups and secure storage
– Firewalls and intrusion prevention systems
– Personnel training in data privacy and security

While no system is entirely immune, we strive to apply the most effective measures available to maintain data protection.

7. International Data Transfers

Your personal data may be transferred to, stored, and processed in countries outside of your country of residence, including jurisdictions that may have different data protection standards. When we transfer your data internationally, we use standard contractual clauses approved by the European Commission or other legally approved mechanisms to ensure appropriate safeguards are in place.

8. Data Retention

We retain personal data for only as long as necessary to fulfill the purposes for which it was collected, including:

– Usage Data: up to 12 months for analytics and performance measurement
– Account Data: retained as long as the account remains active, and up to 5 years following account closure
– Profile and Preference Data: retained up to 24 months from last user interaction
– Transaction Data: retained for 7 years in compliance with legal obligations
– Communication Data: retained for 3 years for customer service history
– Technical Data: retained for up to 12 months for operational diagnostics

Upon expiration of the retention period, data is securely deleted or anonymized.

9. Cookie Policy

We use cookies and similar technologies to enhance your experience on gmacjapan.com. These include:

– Essential Cookies: Required for navigation and core website functionality.
– Functional Cookies: Enable personalized features such as remembering preferences.
– Performance and Analytics Cookies: Help analyze user behavior and website performance.
– Targeting Cookies: Used for delivering relevant marketing based on your interests.

10. Cookie Management and Compliance

When you first visit gmacjapan.com, you will be presented with a cookie consent banner to manage your cookie preferences in accordance with GDPR and CCPA. Essential cookies are deployed by default, while other categories will only be used with your explicit consent. You can update or withdraw your consent at any time via our Cookie Settings interface or by adjusting your browser settings.

11. Children’s Privacy

gmacjapan.com and its services are not intended for use by children under the age of 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data without parental consent, please contact us at [email protected], and we will promptly take appropriate action.

12. Policy Updates

We reserve the right to modify or update this Privacy Policy in response to changing legal, regulatory, or operational requirements. Any changes will be clearly communicated on this page. Your continued use of gmacjapan.com following such updates constitutes acceptance of the revised Policy.

13. Contact Information

If you have any questions, privacy-related concerns, or wish to exercise your data protection rights, you may contact us at:

Email: [email protected]

We are committed to maintaining compliance with applicable privacy laws and protecting your rights. For further guidance or complaints, you may also contact your local data protection authority.