• Home
  • Products
    • Products
    • Industrial Edge Gateway
    • Tower Light Sensor
    • Screen Data Extractor

    • Services
    • GoodLinker Cloud Field View
  • Case Studies
  • About Us
  • Blog
  • Login
  • Book a Demo
  • 中 / EN
    • 繁體中文
    • English
  1. Home
  2. About Us
  3. Privacy Policy

Privacy Policy

GoodLinker Co., Ltd. (谷林運算股份有限公司) (the "Company", "we" or "us") respects and protects your personal data. This Privacy Policy (this "Policy") explains how we collect, process, use and protect your personal data, and the rights available to you.

The personal data we process depends on the context of your interactions with us, the products, services and features you use, and applicable law. Terms not defined in this Policy have the meanings given in our Terms of Use.

1. Scope

  • 1.1 This Policy applies to all GoodLinker products and services provided by the Company (the "Service"), including our websites, the GenAIoT cloud platform, LESI software, the BCS-MX industrial edge gateway, our mobile applications, and any other product or service offered under the GoodLinker name.
  • 1.2 This Policy does not apply to third-party websites or services not operated by the Company, nor to the personal data of our employees and job applicants, which is handled under our internal human resources policies.

2. Identity of the Data Controller

  • Name: GoodLinker Co., Ltd. (谷林運算股份有限公司)
  • Unified Business Number: 50849424
  • Registered address: 4F., No. 19, Wuquan 2nd Rd., Wugu Dist., New Taipei City 248, Taiwan (R.O.C.)
  • Telephone: +886-2-2599-7987
  • Privacy contact: info@goodlinker.io

3. Categories of Personal Data Collected

  • 3.1 Data you provide: the company name, name, email address, telephone number, product or service of interest and remarks that you submit through the "Contact Us" form on our website or through other channels; and the account credentials, department and job title, postal address and support correspondence you provide when registering an account or making an enquiry.
  • 3.2 Data collected automatically: IP address, device type and unique device identifiers, operating system, browser type and language, visit times and page views, login and activity logs, and identifiers generated by cookies and similar technologies.
  • 3.3 Under the Ministry of Justice classification issued pursuant to the Personal Data Protection Act ("PDPA"), the above falls within categories C001 (identifiers), C011 (personal descriptions), C031 (residence and facilities) and C061 (current employment).
  • 3.4 We do not collect personal data that is not necessary for the provision of the Service.

4. Purposes and Legal Bases

  • 4.1 We collect, process and use your personal data for the following purposes:
    • Creating and maintaining accounts and authenticating users
    • Providing and maintaining the Service, and handling subscriptions, orders, delivery and billing
    • Customer service, technical support and troubleshooting
    • Improvement of products and services, statistical analysis and research
    • Information security, and the prevention of misuse and unlawful activity
    • Sending product information, event notices and marketing messages, unless you have opted out
    • Complying with legal, tax, accounting and regulatory obligations
  • 4.2 Under the Ministry of Justice classification, these purposes correspond to codes 040 (marketing), 063 (collection, processing and use by a non-government agency under a legal obligation), 069 (contractual, quasi-contractual or other legal relationships), 090 (consumer and customer management and service), 135 (information and communications services), 136 (information, communications and database management), 137 (information and communications security and management), 148 (online shopping and other electronic commerce services), 157 (surveys, statistics and research analysis) and 181 (other business operations consistent with the company's registered scope or articles).
  • 4.3 Our collection, processing and use of your personal data is based on Article 19(1), subparagraphs 1 (express provision of law), 2 (a contractual or quasi-contractual relationship with the data subject) and 5 (consent of the data subject) of the PDPA.
  • 4.4 We do not use your personal data beyond the scope necessary for the above purposes, and we do not sell, rent or otherwise provide your personal data to third parties for commercial gain.

5. Customer Content, Personal Data, and Our Role as Processor

  • 5.1 The industrial operating data and equipment data uploaded, transmitted or generated by Users through the Service ("Customer Content" as defined in the Terms of Use) is not, as a rule, personal data. We do not use Customer Content for advertising purposes, and we do not use, disclose or provide Customer Content for third-party advertising purposes.
  • 5.2 Where a User processes data by which an individual may be identified through the Service (for example, workforce reporting records, access control records or video data), the User is the controller and the Company is the processor in respect of that personal data.
  • 5.3 In that case, we process such personal data solely on the User's instructions and only to the extent necessary to provide the Service, and not for our own purposes. The parties' rights and obligations are governed by Article 4 of the PDPA, Article 8 of its Enforcement Rules, and any separate data processing terms agreed between the parties. The User is responsible for the lawfulness of the collection, processing and use of such personal data, including the giving of notices and the obtaining of consents.
  • 5.4 A data subject wishing to exercise rights in respect of such personal data should contact the relevant User. On being notified by the User, we will provide the assistance agreed in the applicable contract.
  • 5.5 Retention and deletion of such personal data are governed by the provisions of the User's subscription agreement and the Terms of Use relating to Customer Content.

6. Artificial Intelligence Features

  • 6.1 Certain features of the Service use artificial intelligence (including AI analytical models and AI agents). What these features process is, as a rule, the industrial operating data and equipment data within Customer Content.
  • 6.2 We do not use your personal data or Customer Content to train general-purpose AI models.
  • 6.3 As provided in the Terms of Use, we may collect statistics and metrics concerning the use, operation, support and maintenance of the Service ("Systems Information") and use them for operations and product improvement. Systems Information derived from Customer Content is aggregated to a level at which neither the underlying Customer Content nor any individual is identifiable.
  • 6.4 Output generated by AI features may be incomplete or inaccurate. You should verify its accuracy and completeness before relying on it for operational decisions, and it must not be relied upon as the sole basis for personal safety protection or emergency response.

7. Cookies and Similar Technologies

  • 7.1 Our websites and the Service use cookies and similar technologies (including web beacons, tags, scripts and browser local storage) to maintain login state, ensure information security and proper system operation, and compile statistics on visits and usage in order to improve the Service.
  • 7.2 Our website uses Google Analytics and Google Tag Manager to compile statistics on traffic and usage behaviour. These tools may obtain your IP address, device and browser information, and page view records.
  • 7.3 We do not use cookies to collect data unrelated to the purposes above, and we do not provide activity records from the logged-in service platform to third-party advertising companies.
  • 7.4 You may configure your browser to refuse all cookies or to notify you when a cookie is set. If cookies necessary for maintaining login state or system operation are refused, parts of the Service may not function correctly. You may also opt out of Google Analytics collection using the opt-out tool provided by Google.
  • 7.5 Third-party resources. Certain code libraries and fonts used on our website are loaded from third-party content delivery networks (including cdnjs, jsDelivr and Google Fonts). When your browser loads those resources it sends a request directly to those third parties, which may therefore obtain your IP address, browser and device information (User-Agent) and the referring page (Referer). Their own processing of that data is governed by their respective privacy policies.

8. Period, Territory, Recipients and Manner of Use

  • 8.1 Period: as set out in Section 9.
  • 8.2 Territory: the Republic of China (Taiwan), and the countries or regions in which the data centres or cloud services used by us or our service providers are located (see Section 10).
  • 8.3 Recipients: the Company, its affiliates, the service providers listed in Section 11, and the third-party content delivery network and font providers described in Section 7.5; and, in the circumstances set out in Section 12, competent authorities, judicial authorities and other bodies authorized by law.
  • 8.4 Manner: by automated or non-automated means, for collection, processing, international transfer and use within the scope permitted by the PDPA and this Policy.

9. Retention

  • 9.1 We retain your personal data for as long as the specified purposes subsist. Once those purposes cease, we delete the data or stop processing and using it, except where:
    • a statutory retention period applies (for example, the retention of vouchers and books required under the Business Entity Accounting Act and tax legislation);
    • retention is necessary to establish, exercise or defend legal claims, in which case data is retained until the relevant limitation period expires; or
    • you have separately consented to continued retention.
  • 9.2 Account-related data is deleted within five (5) years after deletion of the account or termination of the subscription. Logs and security records are retained for no more than two (2) years.
  • 9.3 Personal data contained within Customer Content is retained and deleted in accordance with the Terms of Use provisions on Customer Content.

10. International Transfers

  • 10.1 We may use data centres, cloud infrastructure providers and subcontractors located in various countries or regions to provide the Service, and your personal data may therefore be stored or processed outside the country or region in which you are located. Details of the cloud service providers and principal storage regions currently used by us are available on request. By using the Service, you are deemed to have agreed that the Company may transfer and process data cross-border within the necessary scope specified above.
  • 10.2 Where personal data is transferred internationally, we apply lawful and appropriate safeguards, including entering into data transfer contract terms providing an adequate level of protection, requiring the recipient to maintain equivalent security measures, and limiting the transfer to what is necessary to provide the Service.
  • 10.3 Where the competent authority imposes restrictions on international transfers under Article 21 of the PDPA, we will comply with those restrictions.

11. Service Providers

  • 11.1 We may engage third parties to assist in providing the Service, in the following categories: cloud hosting and infrastructure; databases and backup; email and notification delivery; customer relationship management and support; payment processing and invoicing; website analytics (Google Analytics, Google Tag Manager); and information security monitoring.
  • 11.2 Such service providers may process your personal data only on our instructions and only to the extent necessary to provide the Service, and are bound by confidentiality obligations. We supervise them as required under the Enforcement Rules of the PDPA.
  • 11.3 A current list of our service providers is available on request.

12. Disclosure of Personal Data

  • 12.1 Except as described in this Policy, we do not disclose your personal data to third parties, other than:
    • with your consent;
    • as required by law, or at the request of a competent authority, judicial authority or other body authorized by law;
    • where necessary to protect the rights, property or personal safety of the Company, you or a third party;
    • where necessary to investigate, prevent or address suspected unlawful conduct or breaches of the Terms of Use; or
    • in connection with a merger, acquisition, demerger or transfer of assets involving the operation of the Service, in which case we will give appropriate notice before the transfer.

13. Data Security

  • 13.1 We apply the following safeguards: encryption of data in transit; access control on a least-privilege basis; authentication; retention of activity logs; regular backups; vulnerability management and patching; confidentiality obligations and training for personnel; and security management of our service providers.
  • 13.2 Although we protect your personal data by commercially reasonable means, no method of transmission over the internet or of electronic storage can be guaranteed to be absolutely secure, and we cannot warrant that your personal data will never be compromised.

14. Personal Data Incidents: Notification and Reporting

  • 14.1 If we become aware that personal data held by us has been stolen, altered, damaged, destroyed or disclosed, we will take remedial action, investigate the incident, and notify affected data subjects within a reasonable timeframe after determining the circumstances and scope of the incident, by email, telephone, SMS, website announcement or other appropriate means.
  • 14.2 The notification will describe the facts of the incident, the measures taken in response, and our contact point for enquiries.
  • 14.3 Where the incident falls within the reportable scope prescribed by law, we will report it to the competent authority in accordance with the PDPA and its subordinate regulations, and will retain the related records.

15. Your Rights and How to Exercise Them

  • 15.1 Under Article 3 of the PDPA, in respect of your personal data held by us, you may:
    • enquire about and request to review it;
    • request a copy of it;
    • request that it be supplemented or corrected;
    • request that its collection, processing or use cease; and
    • request its deletion.
  • 15.2 These rights may not be waived in advance or restricted by agreement.
  • 15.3 How to exercise: email info@goodlinker.io stating your name, contact details and request. To protect your interests, we will first verify your identity.
  • 15.4 Response times: for enquiries, review requests or requests for a copy, we will decide within fifteen (15) days of receipt, extendable once by no more than fifteen (15) days. For requests to supplement, correct, cease collection, processing or use, or delete, we will decide within thirty (30) days, extendable once by no more than thirty (30) days. Where an extension applies, we will notify you in writing of the reason.
  • 15.5 Under Article 14 of the PDPA, we may charge the necessary costs for enquiries, reviews or the provision of copies.
  • 15.6 We may refuse a request, giving written reasons, where the law so provides, or where compliance would prejudice a major national interest, the performance of statutory duties by a government agency, a major interest of the collecting body, or a major interest of a third party.
  • 15.7 Consequences of not providing personal data: you are free to decide whether to provide personal data. If you do not provide the data necessary for the Service, we may be unable to create an account for you, provide the Service, or process your request.

16. Marketing and Opt-Out

  • 16.1 When we first use your personal data for marketing, we will provide you with a means of refusing further marketing free of charge.
  • 16.2 You may opt out at any time through the unsubscribe link in any marketing email, or by writing to info@goodlinker.io, and we will cease using your personal data for marketing immediately.

17. Minors

  • 17.1 The Service is designed for business and professional users. A person under eighteen (18) years of age may use the Service and provide personal data only with the consent of a parent or other statutory agent.
  • 17.2 We do not knowingly collect personal data from persons under eighteen (18). If we become aware that such data has been collected without the consent of a statutory agent, we will delete it.

18. Special-Category Personal Data

We do not, as a rule, collect the special categories of personal data specified in Article 6 of the PDPA (medical records, healthcare, genetic data, sex life, health examinations and criminal records). Where a User processes biometric or other sensitive data through the Service, the User is responsible for establishing its legal basis and obtaining the necessary consents, and we act solely as a processor in respect of such data.

19. Region-Specific Supplements

  • 19.1 This Policy is based on the Personal Data Protection Act of the Republic of China (Taiwan). Where the law of your location grants you additional rights in respect of your personal data, we will comply with that law to the extent it applies.
  • 19.2 We do not currently offer or market the Service in the European Economic Area, the United Kingdom or Switzerland. Should we offer the Service in those regions in future, we will publish a separate supplement applicable to them.
  • 19.3 California: We do not sell your personal information and do not share it for cross-context behavioural advertising purposes, and have not done so in the preceding twelve (12) months. Under the CCPA/CPRA you may request to know the categories and sources of personal information we collect, request deletion, and request correction, and you will not be treated differently for exercising these rights. Requests may be made as set out in Section 15.

20. Links to Third-Party Sites

The Service may contain links to websites or services not operated by us. We have no control over, and accept no responsibility for, the content, privacy policies or practices of such third parties. We recommend that you review their privacy policies before use.

21. Changes to this Policy

  • 21.1 We may revise this Policy to reflect changes in law, in our business or in technology.
  • 21.2 For material changes affecting your rights, we will notify you at least thirty (30) days before the change takes effect, by email or by a prominent notice within the Service. Other changes take effect when posted on this page.
  • 21.3 When a revised Policy is published, we will update the "last updated" date below. We recommend that you review this page periodically.

22. Contact Us

If you have any question about this Policy or about our handling of personal data, or wish to exercise any right under Section 15, please contact us:

  • GoodLinker Co., Ltd. (谷林運算股份有限公司)
  • Unified Business Number: 50849424
  • Address: 4F., No. 19, Wuquan 2nd Rd., Wugu Dist., New Taipei City 248, Taiwan (R.O.C.)
  • Telephone: +886-2-2599-7987
  • Email: info@goodlinker.io
Last updated: 1 August 2026

This English version is provided for reference only. In the event of any inconsistency between the English and Traditional Chinese versions, the Traditional Chinese version shall prevail.

GoodLinker

Industrial Data Infrastructure for AI-Ready Operations

Core Products

  • Industrial Edge Gateway
  • GoodLinker Cloud Field View
  • LESI Monitoring Kit

About Company

  • About GoodLinker
  • Customer Case Studies
  • News & Media Coverage
  • Contact Us
© 2019–2026 GoodLinker. All rights reserved. Taipei, Taiwan
TW EN
Privacy Policy Terms of Use Cookie settings