Add localized legal documents and update consent versions

This commit is contained in:
Warren Chen 2026-07-17 18:16:25 +09:00
parent 96a1584bbe
commit b41e5a17a0
8 changed files with 726 additions and 12 deletions

View File

@ -2,6 +2,6 @@ namespace MemberCenter.Application.Constants;
public static class ConsentVersions
{
public const string TermsVersion = "2026-07-13";
public const string PrivacyVersion = "2026-07-13";
public const string TermsVersion = "2026-07-17";
public const string PrivacyVersion = "2026-07-17";
}

View File

@ -0,0 +1,142 @@
<section>
<h2>1. Scope</h2>
<p>This Privacy Policy explains how Innovedus Inc. (Chinese legal name: 智匯創育股份有限公司; "we," "us," or "our") collects, processes, uses, stores, and protects personal data when you use the Member Center (https://member.innovedus.com), shared sign-in, OAuth/OpenID Connect authorization, profile management, newsletter subscription and unsubscribe features, delegated file access authorization, and related websites or APIs (collectively, the "Service").</p>
<p>The Service is currently designed primarily for users and operations in Taiwan. If the Service later expands to other jurisdictions with specific legal requirements, we will supplement or update this Policy as required by applicable law.</p>
<p>The Service may be integrated with multiple websites, tenants, or partner services. When you are redirected from a third-party website to the Service to sign in, register, manage your profile, or subscribe to newsletters, this Policy applies to personal data processed by us through the Service. Data collected, processed, or used independently by third-party websites or partner services is governed by their own privacy policies.</p>
</section>
<section>
<h2>2. Our Role as Controller or Processor</h2>
<p>Depending on the service context, we may process your personal data as a data controller or a data processor.</p>
<p>When you register directly with the Service, sign in, manage member information, or subscribe to newsletters, we generally act as the data controller. When a tenant website, partner, or business customer engages the Service to provide authentication, member management, newsletter management, authorization management, or other technical services, we may process the relevant data as a data processor acting on its instructions. In that situation, the data controller is primarily responsible for the purposes, legal basis, and subsequent use of personal data.</p>
</section>
<section>
<h2>3. Notice under Article 8 of the Taiwan Personal Data Protection Act</h2>
<p>When we collect personal data from you, Article 8 of the Taiwan Personal Data Protection Act requires notice of the collector's identity, purposes of collection, categories of personal data, period, region, recipients, and methods of use, your statutory rights, and the effect of choosing not to provide data. The sections of this Policy provide those details.</p>
<p>You may exercise the rights to inquire, access, request a copy, supplement, correct, stop collection, stop processing, stop use, and request deletion as provided by law. If you decline to provide data necessary for the Service, we may be unable to create your account, verify your identity, complete authorization, manage subscriptions, or provide certain features. You may choose whether to provide data that is not necessary.</p>
</section>
<section>
<h2>4. Personal Data We Collect</h2>
<p>Depending on how you use the Service, we may collect the following categories of personal data:</p>
<ol>
<li><strong>Account and sign-in data:</strong> email address, password hash, account identifier, account creation time, last sign-in or activity time, email verification status, account disabled or blocked status, and security tokens or records related to sign-in, sign-out, password reset, and email verification.</li>
<li><strong>Profile data:</strong> name, nickname, mobile and landline phone numbers, date of birth, gender, company name, department, job title, company phone number, tax ID, invoice title, remarks, and other data you voluntarily provide.</li>
<li><strong>Address book data:</strong> address label, recipient name and phone number, country or region, postal code, state or region, city, district, address lines, company name, default address setting, and other address metadata.</li>
<li><strong>Newsletter subscription data:</strong> email address, subscription list, tenant or website, subscription status and preferences, confirmation and unsubscribe records, one-click unsubscribe tokens, subscription-to-account linking records, and suppression or blacklist records generated due to bounces, complaints, account restrictions, or suppression rules.</li>
<li><strong>OAuth/OpenID Connect and API authorization data:</strong> authorized clients, scopes, tenant identifiers, resource audiences, records related to access or refresh tokens, authorization requests, and redirect URI validation data. We do not store your password in plaintext.</li>
<li><strong>File access authorization data:</strong> tenant identifier, user identifier, file identifier or object key, HTTP method, scope, issuing client, expiration time, revocation time, and validation time.</li>
<li><strong>Consent and audit records:</strong> the Terms of Service and Privacy Policy versions you accepted, registration method, IP address, User-Agent, acceptance time, and audit records generated by administrators or system operations.</li>
<li><strong>Device, browser, and technical records:</strong> IP address, User-Agent, request time, referrer URL, cookie or session identifiers, language settings, error and security event records, rate-limit records, and abnormal access detection records.</li>
<li><strong>Third-party sign-in data:</strong> if Google or another external sign-in provider is enabled, we may receive basic account data provided within the scope you authorize, such as email, name, or an external account identifier. The provider's own privacy policy governs its processing of your data.</li>
</ol>
</section>
<section>
<h2>5. Purposes of Processing</h2>
<ol>
<li>To create, verify, maintain, and manage member accounts.</li>
<li>To provide shared sign-in, OAuth/OpenID Connect authorization, token issuance, sign-out, and account security features.</li>
<li>To provide profile, address book, subscription preference, and member data management features.</li>
<li>To provide newsletter subscription, double opt-in confirmation, unsubscribe, one-click unsubscribe, subscription status synchronization, and blacklist management.</li>
<li>To communicate with you about account verification, password resets, security notices, service changes, subscription confirmation, and unsubscribe confirmation.</li>
<li>To provide authorization, synchronization, and webhook notifications required by tenant websites, partner services, Send Engine, or other integrations.</li>
<li>To prevent fraud, abuse, unauthorized access, security incidents, and service disruption.</li>
<li>To conduct internal audits, permission control, debugging, maintenance, recordkeeping, and legal compliance.</li>
<li>To handle user requests, customer support, disputes, complaints, or requests from competent authorities.</li>
<li>To perform other clearly disclosed purposes with your consent or as permitted by law.</li>
</ol>
</section>
<section>
<h2>6. Legal Bases for Processing</h2>
<p>Where required by applicable law, we process personal data based on one or more of the following legal bases:</p>
<ul>
<li>performance of a contract;</li>
<li>compliance with legal obligations;</li>
<li>legitimate interests pursued by us or our customers;</li>
<li>your consent; and</li>
<li>protection of vital interests where applicable.</li>
</ul>
</section>
<section>
<h2>7. Cookies and Similar Technologies</h2>
<p>The Service uses cookies, sessions, browser local storage, or similar technologies to maintain sign-in status, complete OAuth flows, remember language or interface preferences, prevent cross-site request forgery, perform security checks, apply rate limits, and improve service stability.</p>
<p>You may configure your browser to reject or delete cookies. However, some features may not function properly, including sign-in status, authorization flows, language switching, or security verification.</p>
</section>
<section>
<h2>8. Data Sharing and Outsourced Processing</h2>
<p>We do not sell your personal data. Except in the circumstances below, we will not provide your personal data to third parties:</p>
<ol>
<li>When you consent or actively request sharing.</li>
<li>When necessary to provide the Service, including sharing data with a tenant website, partner service, OAuth client, Send Engine, file access service, or other integrated system that you use or authorize.</li>
<li>When we engage cloud hosting, database, email delivery, monitoring, security, customer support, or other providers to process data on our instructions and within the necessary scope.</li>
<li>When required to comply with law, court orders, competent authority requests, tax requirements, or audit requirements.</li>
<li>When necessary to detect, prevent, or handle fraud, abuse, security incidents, service stability issues, rights violations, or other unlawful conduct.</li>
<li>In connection with restructuring, merger, spin-off, assignment, asset transfer, or a similar transaction, within the necessary scope and subject to protections no less protective than this Policy.</li>
</ol>
<p>If a third-party website or tenant service obtains data within an authorized scope through the Service, that third party is responsible for its subsequent use under its agreement with you and its own privacy policy.</p>
</section>
<section>
<h2>9. Regions of Use and Cross-Border Transfers</h2>
<p>The Service primarily uses cloud infrastructure in the Amazon Web Services (AWS) Asia Pacific (Tokyo) Region (ap-northeast-1) to store and process data. The Service may also use email, monitoring, security, or other outsourced services located in Taiwan or other regions. Accordingly, your personal data may be transferred to, stored in, or processed outside your country or region. We will protect cross-border transfers and outsourced processing with reasonable safeguards and in accordance with applicable law.</p>
</section>
<section>
<h2>10. Methods of Use and Data Retention</h2>
<p>We process and use personal data by automated or non-automated means within the scope necessary to fulfill the purposes of collection, and retain it only for the necessary period. In general:</p>
<ol>
<li><strong>Account data</strong> is retained until account deletion, for a reasonable period after account disabling, or until the period required for legal, audit, security, or dispute-resolution purposes expires.</li>
<li><strong>Newsletter subscription data</strong> is retained for a reasonable period after you unsubscribe to maintain unsubscribe, blacklist, complaint, or bounce suppression records and avoid sending unnecessary messages again.</li>
<li><strong>Security tokens</strong> are retained until expiration, revocation, or completion of their purpose, plus a reasonable period where necessary. Newsletter confirmation and unsubscribe tokens are valid for seven days by default; file download tokens are short-lived by design.</li>
<li><strong>Audit and security records</strong> are retained for the period necessary for security, audit, debugging, legal compliance, and dispute-resolution purposes.</li>
<li><strong>Data subject to legal or contractual requirements</strong> is retained in accordance with applicable law, competent authority requirements, accounting, tax, or contractual obligations.</li>
</ol>
<p>When data is no longer necessary, we will delete it, anonymize it, or otherwise stop identifying a specific individual by reasonable means.</p>
</section>
<section>
<h2>11. Your Rights</h2>
<p>Subject to applicable law, you may exercise the following rights regarding your personal data:</p>
<ol>
<li>Request inquiry or access.</li>
<li>Request a copy.</li>
<li>Request supplementation or correction.</li>
<li>Request that we stop collecting, processing, or using your data.</li>
<li>Request deletion.</li>
<li>Withdraw consent previously given, without affecting the lawfulness of processing before withdrawal.</li>
<li>Manage newsletter subscription preferences or unsubscribe.</li>
</ol>
<p>You may submit requests through Member Center account settings, subscription management, unsubscribe links, or the contact information listed in this Policy. To protect your data, we may ask for information necessary to verify your identity. Where continued retention or processing is required by law, contract, security, audit, dispute resolution, or service provision, we may be unable to immediately delete or stop using all data, but we will restrict processing to the necessary scope.</p>
</section>
<section>
<h2>12. Information Security and Personal Data Incidents</h2>
<p>We apply reasonable technical and organizational security measures to protect your data, including password hashing, token lifetime controls, OAuth scope and audience validation, tenant isolation, administrator permission controls, rate limits, protections for sign-in and reset flows, database access controls, audit logs, certificate management, webhook signatures, and replay protection.</p>
<p>No network transmission or information system can be guaranteed to be absolutely secure. If a personal data incident, unauthorized access, data breach, or other security event may affect users' rights or interests, we will take necessary investigative, remedial, notification, and reporting measures in accordance with applicable law and the nature of the incident.</p>
</section>
<section>
<h2>13. Children and Minors</h2>
<p>The Service is generally intended for natural persons with full legal capacity, businesses, organizations, or users with lawful authorization. If you are a minor or a person under guardianship or assistance, you should use the Service with the consent of your legal representative, guardian, or assistant. If we discover that relevant data was provided without appropriate consent, we will take deletion, suspension of processing, or other necessary measures in accordance with applicable law.</p>
</section>
<section>
<h2>14. Updates to This Policy</h2>
<p>We may update this Policy due to changes in service features, law, security measures, or business operations. The updated Policy will be posted on the Service or provided through another appropriate notice. If a change materially affects your rights or interests, we will take reasonable steps to notify you. Where consent is required by law, we will obtain it separately.</p>
</section>
<section>
<h2>15. Contact Us</h2>
<p>If you have questions about this Policy, our handling of personal data, or the exercise of your rights, please contact us:</p>
<address>
<span>Operator: Innovedus Inc. (智匯創育股份有限公司)</span>
<span>Unified Business Number: 93698713</span>
<span>Email: <a href="mailto:cs@innovedus.com">cs@innovedus.com</a></span>
<span>Address: 4F., No. 19-11, Sanchong Rd., Nangang Dist., Taipei City, Taiwan</span>
</address>
</section>

View File

@ -0,0 +1,131 @@
<section>
<h2>一、政策範圍</h2>
<p>本隱私權政策說明智匯創育股份有限公司Innovedus Inc以下稱「我們」在您使用 Member Center 會員中心https://member.innovedus.com、共用登入、OAuthOpenID Connect 授權、個人資料管理、電子報訂閱與退訂、檔案存取授權及相關網站或 API 服務(以下合稱「本服務」)時,如何蒐集、處理、利用、保存及保護您的個人資料。</p>
<p>本服務目前主要以台灣使用者及台灣營運需求為基礎提供。若未來服務範圍擴及其他有特別法令要求的司法管轄區,我們將依適用法令補充或調整本政策。</p>
<p>本服務可能與多個網站、租戶或合作服務整合。當您透過第三方網站導向本服務登入、註冊、管理個人資料或訂閱電子報時,本政策適用於我們透過本服務所處理的個人資料;第三方網站或合作服務自行蒐集、處理或利用的資料,則適用其各自的隱私權政策。</p>
</section>
<section>
<h2>二、資料控制者與資料處理者身分</h2>
<p>依不同服務情境我們可能以資料控制者Controller或資料處理者Processor身分處理您的個人資料。</p>
<p>當您直接向本服務註冊、登入、管理會員資料或訂閱電子報時,我們通常作為資料控制者處理您的資料。當本服務受租戶網站、合作夥伴或企業客戶委託提供身分驗證、會員管理、電子報管理、授權管理或其他技術服務時,我們可能依其指示作為資料處理者處理相關資料;在此情況下,該資料控制者對個人資料的蒐集目的、法律依據及後續利用負主要責任。</p>
</section>
<section>
<h2>三、個人資料保護法第八條告知事項</h2>
<p>依據中華民國個人資料保護法第八條規定,我們向您蒐集個人資料時,將告知蒐集者名稱、蒐集目的、個人資料類別、利用期間、地區、對象及方式,以及您依法得行使的權利。本政策各節即為前述事項的具體說明。</p>
<p>您得依法行使查詢、閱覽、請求製給複製本、補充、更正、停止蒐集、停止處理、停止利用及刪除等權利。若您拒絕提供本服務所必要的資料,我們可能無法完成帳號建立、身分驗證、授權、訂閱管理或提供部分功能;非必要資料則由您自行決定是否提供。</p>
</section>
<section>
<h2>四、我們蒐集的個人資料</h2>
<p>依您使用本服務的方式不同,我們可能蒐集下列資料:</p>
<ol>
<li><strong>帳號與登入資料:</strong>電子郵件地址、密碼雜湊、帳號識別碼、帳號建立時間、最後登入或活動時間、電子郵件驗證狀態、帳號停用或封鎖狀態,以及登入、登出、密碼重設與電子郵件驗證相關的安全權杖或紀錄。</li>
<li><strong>個人基本資料:</strong>姓名、暱稱、手機、室內電話、生日、性別、公司名稱、部門、職稱、公司電話、統一編號、發票抬頭、備註及您主動提供的其他資料。</li>
<li><strong>地址簿資料:</strong>地址標籤、收件人姓名與電話、國家或地區、郵遞區號、縣市、行政區、地址、公司名稱、是否為預設地址及其他地址補充資料。</li>
<li><strong>電子報訂閱資料:</strong>電子郵件地址、訂閱清單、所屬租戶或網站、訂閱狀態與偏好、訂閱確認及退訂紀錄、one-click 退訂權杖、訂閱與會員帳號綁定紀錄,以及因退信、投訴、停權或抑制規則產生的黑名單紀錄。</li>
<li><strong>OAuthOpenID Connect 與 API 授權資料:</strong>授權用戶端、授權範圍scopes、租戶識別碼、資源 audience、存取權杖或更新權杖相關紀錄、授權請求及 redirect URI 驗證資料。我們不會以明文保存您的密碼。</li>
<li><strong>檔案存取授權資料:</strong>租戶識別碼、使用者識別碼、檔案識別碼或 object key、HTTP method、scope、簽發用戶端、到期時間、撤銷時間及驗證時間。</li>
<li><strong>同意與稽核紀錄:</strong>您同意的服務條款及隱私權政策版本、註冊方式、IP 位址、User-Agent、同意時間以及管理者或系統操作產生的稽核紀錄。</li>
<li><strong>裝置、瀏覽器與技術紀錄:</strong>IP 位址、User-Agent、請求時間、參照網址、Cookie 或 session 識別資訊、語言設定、錯誤及安全事件紀錄、速率限制與異常存取偵測紀錄。</li>
<li><strong>第三方登入資料:</strong>如本服務啟用 Google 或其他外部登入,我們可能接收該第三方依您授權範圍提供的電子郵件地址、姓名或外部帳號識別碼等基本資料。第三方登入服務對資料的處理仍依其自身政策辦理。</li>
</ol>
</section>
<section>
<h2>五、蒐集、處理及利用目的</h2>
<ol>
<li>建立、驗證、維護及管理會員帳號。</li>
<li>提供共用登入、OAuthOpenID Connect 授權、權杖簽發、登出及帳號安全功能。</li>
<li>提供個人資料、地址簿、訂閱偏好及會員資料管理功能。</li>
<li>提供電子報訂閱、double opt-in 確認、退訂、one-click 退訂、訂閱狀態同步及黑名單管理。</li>
<li>與您聯絡,包括帳號驗證、密碼重設、安全通知、服務異動、訂閱確認及退訂確認。</li>
<li>提供租戶網站、合作服務、Send Engine 或其他整合服務所需的授權、同步及 webhook 通知。</li>
<li>防止詐欺、濫用、未授權存取、資訊安全事件及服務中斷。</li>
<li>進行內部稽核、權限控管、除錯、維運、紀錄保存及法令遵循。</li>
<li>處理使用者請求、客服、爭議、申訴或主管機關要求。</li>
<li>在取得您同意或依法允許的範圍內,進行其他已明確告知的目的。</li>
</ol>
<p>在適用法令要求的範圍內,我們會依履行契約或提供服務、遵守法定義務、我們或客戶的合法利益、您的同意,或保護重大利益等適當依據處理個人資料。</p>
</section>
<section>
<h2>六、Cookie 與類似技術</h2>
<p>本服務使用 Cookie、session、瀏覽器本機儲存或類似技術以維持登入狀態、完成 OAuth 流程、記住語言或介面偏好、防止跨站請求偽造、執行安全檢查、套用速率限制及改善服務穩定性。</p>
<p>您可透過瀏覽器設定拒絕或刪除 Cookie但登入狀態、授權流程、語言切換或安全驗證等部分功能可能因此無法正常運作。</p>
</section>
<section>
<h2>七、資料分享與委外處理</h2>
<p>我們不會出售您的個人資料。除下列情形外,我們不會將您的個人資料提供給第三人:</p>
<ol>
<li>您同意或主動要求分享。</li>
<li>為提供本服務所必要將資料提供給您正在使用或已授權的租戶網站、合作服務、OAuth 用戶端、Send Engine、檔案存取服務或其他整合系統。</li>
<li>委託雲端主機、資料庫、郵件寄送、監控、資訊安全、客服或其他供應商,在我們指示及必要範圍內處理資料。</li>
<li>為遵守法律、法院命令、主管機關、稅務或稽核要求。</li>
<li>為偵測、防止或處理詐欺、濫用、資訊安全事件、服務穩定性、權利侵害或其他違法行為。</li>
<li>因組織重整、合併、分割、讓與、資產移轉或類似交易,在必要範圍內移轉資料,並要求承受方以不低於本政策的標準保護資料。</li>
</ol>
<p>第三方網站或租戶服務透過本服務取得授權範圍內的資料後,應依其與您的約定及其隱私權政策對後續使用負責。</p>
</section>
<section>
<h2>八、利用地區與跨境傳輸</h2>
<p>本服務主要使用 Amazon Web ServicesAWSAsia Pacific (Tokyo) Regionap-northeast-1亞太地區東京區域的雲端基礎設施保存及處理資料並可能搭配位於台灣或其他地區的郵件、監控、資訊安全或其他委外服務。因此您的個人資料可能被傳輸、儲存或處理於您所在國家或地區以外的地點。我們會依適用法令及合理安全措施保護跨境傳輸與委外處理的資料。</p>
</section>
<section>
<h2>九、資料利用方式與保存期間</h2>
<p>我們會以自動化或非自動化方式,在達成蒐集目的所必要範圍內處理及利用您的資料,並僅於必要期間保存。一般而言:</p>
<ol>
<li><strong>帳號資料:</strong>保存至帳號刪除、停用後合理期間,或法律、稽核、安全及爭議處理所需期間屆滿為止。</li>
<li><strong>電子報訂閱資料:</strong>保存至取消訂閱後合理期間,以維持退訂、黑名單、投訴或退信抑制紀錄,避免再次寄送不必要訊息。</li>
<li><strong>安全權杖:</strong>依系統設定保存至到期、撤銷或完成用途後合理期間。電子報確認及退訂權杖預設有效期間為七日;檔案下載權杖原則上為短效權杖。</li>
<li><strong>稽核與安全紀錄:</strong>依資訊安全、稽核、除錯、法令遵循及爭議處理所需期間保存。</li>
<li><strong>法定或契約要求資料:</strong>依相關法令、主管機關、會計、稅務或契約義務所要求的期間保存。</li>
</ol>
<p>資料已無保存必要時,我們將刪除、匿名化或以其他合理方式停止識別特定個人。</p>
</section>
<section>
<h2>十、您的權利</h2>
<p>依適用法令,您可就您的個人資料向我們行使下列權利:</p>
<ol>
<li>查詢或請求閱覽。</li>
<li>請求製給複製本。</li>
<li>請求補充或更正。</li>
<li>請求停止蒐集、處理或利用。</li>
<li>請求刪除。</li>
<li>撤回先前給予的同意,但不影響撤回前處理行為的合法性。</li>
<li>管理電子報訂閱偏好或取消訂閱。</li>
</ol>
<p>您可透過會員中心的帳號設定、訂閱管理、退訂連結或本政策所列聯絡方式提出請求。為保護資料安全,我們可能要求您提供必要資訊以確認身分。若依法令、契約、資訊安全、稽核、爭議處理或服務提供仍有保存或處理必要,我們可能無法立即完全刪除或停止使用,但會將處理限制於必要範圍。</p>
</section>
<section>
<h2>十一、資訊安全與個人資料事故處理</h2>
<p>我們採取合理的技術與組織安全措施保護您的資料包括密碼雜湊、權杖時效控管、OAuth scope 與 audience 驗證、租戶隔離、管理者權限控管、速率限制、登入及重設流程保護、資料庫存取控管、稽核紀錄、憑證管理、webhook 簽章與重放防護等。</p>
<p>網路傳輸與資訊系統無法保證絕對安全。如發生可能影響使用者權益的個人資料事故、未授權存取、資料外洩或其他資訊安全事件,我們將依適用法令及事件性質採取必要的調查、補救、通知及通報措施。</p>
</section>
<section>
<h2>十二、兒童與未成年人</h2>
<p>本服務原則上提供具備完全行為能力的自然人、企業、組織或經合法授權的使用者使用。若您為未成年人、受監護宣告或受輔助宣告之人,應在法定代理人、監護人或輔助人同意下使用本服務。若我們發現相關資料未經適當同意而提供,將依適用法令採取刪除、停止處理或其他必要措施。</p>
</section>
<section>
<h2>十三、政策更新</h2>
<p>我們可能因服務功能、法令、資訊安全措施或營運模式變更而更新本政策。更新後的政策將公布於本服務或以其他適當方式通知您。若變更重大影響您的權益,我們會以合理方式提醒您;依法需要取得同意時,我們將另行取得您的同意。</p>
</section>
<section>
<h2>十四、聯絡我們</h2>
<p>如您對本政策、個人資料處理或權利行使有疑問,請透過下列方式聯絡我們:</p>
<address>
<span>營運主體智匯創育股份有限公司Innovedus Inc</span>
<span>統一編號93698713</span>
<span>聯絡信箱:<a href="mailto:cs@innovedus.com">cs@innovedus.com</a></span>
<span>聯絡地址臺北市南港區三重路19之11號4樓</span>
</address>
</section>

View File

@ -0,0 +1,170 @@
<section>
<h2>1. Applicability and Acceptance</h2>
<p>Welcome to the Member Center (https://member.innovedus.com), shared sign-in, OAuth/OpenID Connect authorization, newsletter subscription management, member profile management, delegated file access authorization, and related websites or APIs (collectively, the "Service") provided by Innovedus Inc. (Chinese legal name: 智匯創育股份有限公司; "we," "us," or "our").</p>
<p>By registering for, signing in to, using, or accessing the Service, being redirected from a partner website to the Service, subscribing to newsletters, managing personal data, or using OAuth authorization, you acknowledge that you have read, understood, and agree to be bound by these Terms of Service and the <a asp-area="" asp-controller="Home" asp-action="Privacy">Privacy Policy</a>. If you do not agree to these Terms, please stop using the Service.</p>
<p>If you use the Service on behalf of a company, organization, tenant website, or other legal entity, you represent that you have authority to accept these Terms on behalf of that entity. In that case, "you" also refers to that entity.</p>
</section>
<section>
<h2>2. Service Description</h2>
<p>The Service currently provides the following main features:</p>
<ol>
<li>Shared member accounts and a sign-in center for multiple websites.</li>
<li>OAuth 2.0/OpenID Connect authorization, including Authorization Code + PKCE, client credentials, token issuance, and token validation.</li>
<li>Member registration, sign-in, sign-out, email verification, forgot password, password reset, and password change.</li>
<li>Member profile, address book, and subscription data management.</li>
<li>Newsletter subscription, double opt-in confirmation, subscription preference management, unsubscribe, and one-click unsubscribe.</li>
<li>Administration features for tenants, OAuth clients, newsletter lists, subscriptions, blacklists, audit logs, and security settings.</li>
<li>Necessary webhook, token, scope, audience, and tenant data synchronization with Send Engine, file access services, or other partner services.</li>
</ol>
<p>We may add, adjust, suspend, or terminate certain features based on operational needs. If a material change affects your important rights or interests, we will provide reasonable notice.</p>
<p>The Service currently does not include paid memberships, payment processing, or guaranteed service levels (SLA). If we later provide paid plans, enterprise agreements, SLA commitments, or other commercial services, the relevant fees, service levels, support scope, and special conditions will be governed by the applicable plan description or written agreement between the parties.</p>
</section>
<section>
<h2>3. Beta, Preview, and Experimental Features</h2>
<p>We may periodically provide beta, preview, experimental, or other features that have not been generally released. These features may still be under development, testing, or validation and may be changed, interrupted, contain errors, cause data loss or reduced performance, or operate differently from generally available features.</p>
<p>Except as otherwise required by law, we do not guarantee the availability, stability, continued provision, or fitness for a particular purpose of these features, and we may modify, limit, or discontinue them at any time without prior notice.</p>
</section>
<section>
<h2>4. Eligibility and Use by Minors</h2>
<p>The Service is generally intended for natural persons with full legal capacity, businesses, organizations, or users with lawful authorization.</p>
<p>If you are a minor or a person under guardianship or assistance, you must use the Service with the consent of your legal representative, guardian, or assistant. By using the Service, you represent that you have obtained the necessary consent or authorization.</p>
<p>If we reasonably believe that you have not obtained the necessary consent or authorization, we may restrict, suspend, or terminate your account or certain Service features.</p>
</section>
<section>
<h2>5. Account Registration and Security</h2>
<p>You must provide accurate, complete, and up-to-date registration and account information, and update it promptly when it changes. You may not use another person's email address, impersonate another person, create false accounts, or register for or use the Service through automated, malicious, or otherwise prohibited means.</p>
<p>You are responsible for safeguarding your account, password, sign-in session, authorization tokens, API client secrets, and other credentials. Except where attributable to us, activities conducted through your account, credentials, or an authorized client are your responsibility.</p>
<p>If you discover unauthorized use, leakage, or a suspected security incident involving your account, password, tokens, or client secrets, you must notify us immediately and take necessary replacement, revocation, or disabling measures.</p>
</section>
<section>
<h2>6. External Sign-In and Third-Party Websites</h2>
<p>The Service may support Google or other third-party sign-in providers, and third-party websites, tenant websites, or partner services may redirect you to the Service for sign-in, authorization, subscription, or unsubscribe flows.</p>
<p>Third-party websites, sign-in providers, partner services, and tenant websites are operated by their respective operators. We do not control their content, data processing, service quality, security measures, or terms and policies. When you use third-party services, you should read and comply with their terms of service and privacy policies.</p>
</section>
<section>
<h2>7. Newsletter Subscription and Unsubscribe</h2>
<p>You may subscribe to newsletters through flows provided by tenant websites or the Service. Some subscriptions use double opt-in and require confirmation through an email. You may unsubscribe through unsubscribe links, one-click unsubscribe, the Member Center subscription management page, or other methods we provide.</p>
<p>You may not subscribe using another person's email address without authorization, conduct malicious mass subscriptions, interfere with unsubscribe mechanisms, forge subscription confirmations, or abuse newsletter features. Due to bounces, spam complaints, legal requirements, platform security, or email deliverability considerations, we or tenant websites may stop sending, unsubscribe an email address, or add it to a suppression list or blacklist.</p>
</section>
<section>
<h2>8. API, OAuth Client, and Integration Rules</h2>
<p>If you use APIs, OAuth clients, webhooks, or delegated file access authorization as a tenant, developer, administrator, or partner service, you must comply with the following rules:</p>
<ol>
<li>Use APIs and data only for lawful, authorized, and necessary purposes.</li>
<li>Properly protect client secrets, private keys, webhook secrets, tokens, and other credentials, and do not disclose, transfer, or provide them to unauthorized persons.</li>
<li>Request only scopes, audiences, and tenant data that correspond to the service purpose, and do not bypass or compromise tenant isolation.</li>
<li>Do not attempt to forge tokens or bypass PKCE, redirect URI, scope, audience, tenant, or webhook signature validation.</li>
<li>Do not use crawlers, stress testing, scanning, brute-force attacks, replay attacks, or other methods to interfere with the Service.</li>
<li>Process data obtained from the Service in accordance with applicable personal data, security, electronic communications, anti-spam, and other laws.</li>
<li>If a data breach, credential leak, or security incident occurs, notify us immediately and cooperate with investigation, revocation, rotation, and remediation.</li>
</ol>
<p>For security, compliance, maintenance, or abuse-prevention reasons, we may limit, suspend, revoke, or adjust API access, tokens, clients, webhooks, or integration features.</p>
</section>
<section>
<h2>9. Security Vulnerability Reporting</h2>
<p>If you discover a vulnerability, misconfiguration, authorization bypass, credential exposure, or other security issue that may affect the Service, you should notify us within a reasonable period using the contact information in these Terms and avoid publicly disclosing technical details that may increase security risk.</p>
<p>Without our prior written consent, you may not publicly disclose or exploit a vulnerability, expand the scope of testing, or test or validate the issue in any other manner that may interrupt the Service or expose data.</p>
</section>
<section>
<h2>10. User Conduct</h2>
<p>When using the Service, you must not:</p>
<ol>
<li>Violate law, competent authority orders, third-party rights, or these Terms.</li>
<li>Impersonate another person, provide false information, or mislead us, tenant websites, or other users.</li>
<li>Intrude into, interfere with, damage, reverse engineer, scan, or test vulnerabilities of the Service unless you have obtained our prior written consent.</li>
<li>Upload, transmit, or distribute malware, spam, phishing content, fraudulent content, or infringing content.</li>
<li>Collect, query, export, copy, or use another person's personal data without authorization.</li>
<li>Circumvent rate limits, access controls, permission validation, tenant isolation, or other security measures.</li>
<li>Cause excessive load or service interruption to the Service or related infrastructure.</li>
<li>Use the Service for unlawful marketing, unsolicited email, or other communications against recipients' wishes.</li>
</ol>
</section>
<section>
<h2>11. Responsibilities of Administrators and Tenants</h2>
<p>If you are an administrator, tenant website, OAuth client owner, or partner service, you must ensure that you have the legal basis, consent, or authorization required to process user personal data, send newsletters, call APIs, receive webhooks, synchronize data, or entrust the Service to process data.</p>
<p>You must maintain the security of your own systems and integrations, including redirect URIs, return URLs, client secrets, webhook endpoints, email delivery flows, unsubscribe links, data exports, and personnel permissions. You are responsible for damages caused by inadequate protection, misconfiguration, or unlawful use by you or your systems.</p>
</section>
<section>
<h2>12. Intellectual Property</h2>
<p>The programs, interfaces, designs, documents, trademarks, logos, database structures, API specifications, technical content, and other materials included in the Service are owned by us or lawful rights holders, unless otherwise indicated or owned by third parties.</p>
<p>Except as authorized by these Terms or by our separate written authorization, you may not reproduce, modify, distribute, publicly transmit, lease, sell, reverse engineer, decompile, or otherwise exploit Service content. You retain rights to data you provide or upload, but you authorize us to use, process, store, transmit, and display that data within the scope necessary to provide, maintain, protect, and improve the Service.</p>
</section>
<section>
<h2>13. Personal Data and Privacy</h2>
<p>We process your personal data in accordance with the <a asp-area="" asp-controller="Home" asp-action="Privacy">Privacy Policy</a>, which forms part of these Terms. Please read the Privacy Policy to understand what data we collect, the purposes of use, sharing recipients, retention periods, security measures, and your rights.</p>
</section>
<section>
<h2>14. Service Availability and Changes</h2>
<p>We will use reasonable efforts to maintain the stability and security of the Service, but we do not guarantee that the Service will be uninterrupted, error-free, vulnerability-free, or always compatible with all browsers, devices, third-party services, or integration methods.</p>
<p>We may suspend, limit, or adjust the Service due to maintenance, updates, security, system failure, third-party service interruption, force majeure, legal requirements, or other reasonable causes. Where feasible, we will provide reasonable notice of material maintenance or changes.</p>
</section>
<section>
<h2>15. Suspension, Restriction, and Termination</h2>
<p>If you violate these Terms or the law, infringe others' rights, create security risks, abuse the Service, access data without authorization, or if we reasonably believe action is necessary to protect users, tenants, third parties, or the Service, we may:</p>
<ol>
<li>Request correction, supplementation of information, or cessation of specific conduct.</li>
<li>Limit, suspend, or terminate accounts, administrator permissions, API clients, tokens, webhooks, or integration features.</li>
<li>Delete, restrict access to, or isolate violating data.</li>
<li>Notify affected users, tenants, partner services, competent authorities, or law enforcement agencies.</li>
<li>Take other necessary measures permitted by law.</li>
</ol>
<p>You may stop using the Service, delete your account, or request data handling through methods provided by the Service. However, we may continue to retain data within the necessary scope where required by law, contract, audit, security, dispute resolution, or abuse prevention.</p>
</section>
<section>
<h2>16. Disclaimer</h2>
<p>To the maximum extent permitted by law, the Service is provided on an "as is" and "as available" basis. We do not warrant that the Service will fully meet all of your needs, be uninterrupted, completely secure, error-free, virus-free, free from data loss, or compatible with all third-party services, tenant websites, email services, cloud platforms, browsers, or devices.</p>
<p>Except where we are responsible under law or contract, third-party websites, tenant websites, external sign-in providers, Send Engine, file storage services, email services, or other third-party services are responsible for problems, damages, or data processing arising from their own services.</p>
</section>
<section>
<h2>17. Limitation of Liability</h2>
<p>Except for willful misconduct, gross negligence, liabilities that may not be limited by law, or mandatory provisions such as consumer protection laws, we are not liable for indirect, incidental, special, consequential, punitive, goodwill, business, data loss, lost profit, or third-party claim damages arising from use of or inability to use the Service.</p>
<p>If we are legally required to bear liability, our liability is limited to the fees you actually paid to us for the service giving rise to the liability during the twelve months before the event. If the service is provided free of charge, our liability is limited to NTD 10,000. This limitation does not apply where prohibited by law.</p>
</section>
<section>
<h2>18. Indemnification</h2>
<p>If your violation of these Terms, unlawful use of the Service, infringement of third-party rights, failure to safeguard accounts or credentials, misconfiguration of integrations, or failure to obtain necessary consent or authorization causes us, our affiliates, employees, partners, tenants, or other users to suffer damages, expenses, fines, settlements, attorneys' fees, or third-party claims, you shall indemnify and hold them harmless to the extent permitted by law.</p>
</section>
<section>
<h2>19. Updates to These Terms</h2>
<p>We may update these Terms due to changes in service features, law, security, or business operations. Updated Terms will be posted on the Service or provided through another appropriate notice. If you continue using the Service after the updated Terms take effect, you agree to the updated Terms. If you do not agree, please stop using the Service.</p>
<p>If an update materially affects your rights or interests, we will take reasonable steps to notify you. Where law requires renewed consent, we will handle it in accordance with law.</p>
</section>
<section>
<h2>20. Governing Law and Jurisdiction</h2>
<p>These Terms are governed by the laws of the Republic of China (Taiwan). Any dispute arising from these Terms or the Service shall first be resolved through good-faith negotiation. If negotiation fails, the Taiwan Taipei District Court shall be the court of first instance, unless mandatory law provides otherwise.</p>
</section>
<section>
<h2>21. Miscellaneous</h2>
<p>If any part of these Terms is held invalid or unenforceable by a court or competent authority, the remaining parts remain effective. Our failure to immediately exercise a right under these Terms does not constitute a waiver of that right. You may not assign your rights or obligations under these Terms without our prior written consent. We may assign these Terms in connection with restructuring, merger, spin-off, asset transfer, or service transfer.</p>
</section>
<section>
<h2>22. Contact</h2>
<p>If you have questions about these Terms or the Service, please contact us:</p>
<address>
<span>Operator: Innovedus Inc. (智匯創育股份有限公司)</span>
<span>Unified Business Number: 93698713</span>
<span>Email: <a href="mailto:cs@innovedus.com">cs@innovedus.com</a></span>
<span>Address: 4F., No. 19-11, Sanchong Rd., Nangang Dist., Taipei City, Taiwan</span>
</address>
</section>

View File

@ -0,0 +1,170 @@
<section>
<h2>一、條款適用與接受</h2>
<p>歡迎使用智匯創育股份有限公司Innovedus Inc以下稱「我們」提供的 Member Center 會員中心https://member.innovedus.com、共用登入、OAuthOpenID Connect 授權、電子報訂閱管理、會員資料管理、檔案存取授權及相關網站或 API 服務(以下合稱「本服務」)。</p>
<p>當您註冊、登入、使用或存取本服務、透過合作網站導向本服務、訂閱電子報、管理個人資料或使用 OAuth 授權時,即表示您已閱讀、了解並同意受本服務條款及<a asp-area="" asp-controller="Home" asp-action="Privacy">隱私權政策</a>拘束。若您不同意本條款,請停止使用本服務。</p>
<p>如您代表公司、組織、租戶網站或其他法人使用本服務,您聲明您有權代表該法人接受本條款;在此情形下,「您」亦指該法人。</p>
</section>
<section>
<h2>二、服務內容</h2>
<p>本服務目前主要提供下列功能:</p>
<ol>
<li>多網站共用會員帳號與登入中心。</li>
<li>OAuth 2.0OpenID Connect 授權,包括 Authorization Code + PKCE、client credentials、權杖簽發與驗證。</li>
<li>會員註冊、登入、登出、電子郵件驗證、忘記密碼、重設密碼及修改密碼。</li>
<li>會員個人資料、地址簿及訂閱資料管理。</li>
<li>電子報訂閱、double opt-in 確認、訂閱偏好管理、取消訂閱及 one-click 退訂。</li>
<li>租戶、OAuth 用戶端、電子報清單、訂閱、黑名單、稽核紀錄及安全設定等管理功能。</li>
<li>與 Send Engine、檔案存取服務或其他合作服務進行必要的 webhook、權杖、scope、audience 及租戶資料同步。</li>
</ol>
<p>我們得依實際營運需要新增、調整、暫停或終止部分功能。重大變更影響您的重要權益時,我們會以合理方式通知。</p>
<p>本服務目前未包含付費會員、付款處理或保證服務水準SLA。如未來提供付費方案、企業合約、SLA 或其他商業服務,相關費用、服務水準、支援範圍及特殊條件將另依方案說明或雙方書面約定辦理。</p>
</section>
<section>
<h2>三、Beta、Preview 及實驗性功能</h2>
<p>我們可能不定期提供測試版Beta、預覽版Preview、實驗性功能Experimental Features或其他尚未正式發布的功能。該等功能可能仍處於開發、測試或驗證階段因此可能發生功能變更、中斷、錯誤、資料遺失、效能下降或與正式版本不同的情形。</p>
<p>除法律另有規定外,我們不保證該等功能的可用性、穩定性、持續提供或特定用途適用性,並得隨時修改、限制或終止該等功能,而無須事前通知。</p>
</section>
<section>
<h2>四、使用資格與未成年人使用</h2>
<p>本服務原則上提供具備完全行為能力的自然人、企業、組織或經合法授權的使用者使用。</p>
<p>如您為未成年人、受監護宣告或受輔助宣告之人,應在法定代理人、監護人或輔助人同意下使用本服務;您使用本服務時,即表示您已取得必要的同意或授權。</p>
<p>若我們合理認為您未取得必要同意或授權,我們得限制、暫停或終止您的帳號或部分服務功能。</p>
</section>
<section>
<h2>五、帳號註冊與安全</h2>
<p>您應提供正確、完整且最新的註冊與帳號資料,並在資料變更時及時更新。您不得使用他人電子郵件地址、冒用他人身分、建立不實帳號,或以自動化、惡意或違反本條款的方式註冊或使用本服務。</p>
<p>您應妥善保管帳號、密碼、登入狀態、授權權杖、API client secret 及其他憑證。除可歸責於我們者外,凡以您的帳號、憑證或經您授權的用戶端所進行的活動,應由您自行負責。</p>
<p>若您發現帳號、密碼、權杖或 client secret 遭未授權使用、外洩或涉及疑似安全事件,應立即通知我們,並採取必要的更換、撤銷或停用措施。</p>
</section>
<section>
<h2>六、外部登入與第三方網站</h2>
<p>本服務可能支援 Google 或其他第三方登入,也可能由第三方網站、租戶網站或合作服務導向本服務進行登入、授權、訂閱或退訂。</p>
<p>第三方網站、第三方登入服務、合作服務或租戶網站由其各自營運者負責。我們不控制其內容、資料處理、服務品質、安全措施或條款政策。您使用第三方服務時,應自行閱讀並遵守其服務條款及隱私權政策。</p>
</section>
<section>
<h2>七、電子報訂閱與退訂</h2>
<p>您可依各租戶網站或本服務提供的流程訂閱電子報。部分訂閱採 double opt-in您需透過確認信完成訂閱。您可透過退訂連結、one-click 退訂、會員中心訂閱管理頁或其他我們提供的方式取消訂閱。</p>
<p>您不得以他人電子郵件地址進行未經授權的訂閱、惡意大量訂閱、干擾退訂機制、偽造訂閱確認或濫用電子報功能。因退信、垃圾郵件投訴、法令要求、平台安全或寄送品質考量,我們或租戶網站得停止寄送、取消訂閱,或將電子郵件地址加入抑制名單或黑名單。</p>
</section>
<section>
<h2>八、API、OAuth 用戶端與整合服務使用規則</h2>
<p>若您以租戶、開發者、管理者或合作服務身分使用 API、OAuth 用戶端、webhook 或檔案存取授權功能,您應遵守下列規則:</p>
<ol>
<li>僅在合法、授權且必要的目的範圍內使用 API 及資料。</li>
<li>妥善保存 client secret、private key、webhook secret、權杖及其他憑證不得公開、轉讓或提供給未授權者。</li>
<li>僅請求與服務目的相符的 scopes、audience 及租戶資料,不得繞過或破壞租戶隔離。</li>
<li>不得嘗試偽造權杖,或繞過 PKCE、redirect URI、scope、audience、tenant 或 webhook 簽章驗證。</li>
<li>不得以爬蟲、壓力測試、掃描、暴力破解、重放攻擊或其他方式干擾本服務。</li>
<li>應依適用的個人資料、資訊安全、電子通訊、反垃圾郵件及其他法令處理從本服務取得的資料。</li>
<li>如發生資料外洩、憑證外洩或安全事件,應立即通知我們,並配合調查、撤銷、輪替及補救。</li>
</ol>
<p>我們得基於安全、法令遵循、維運或濫用防治需要,限制、暫停、撤銷或調整 API 存取、權杖、用戶端、webhook 或整合功能。</p>
</section>
<section>
<h2>九、安全漏洞通報</h2>
<p>如您發現可能影響本服務安全的漏洞、錯誤設定、權限繞過、憑證外洩或其他安全問題,應在合理期間內透過本條款所列聯絡方式通知我們,並避免公開揭露可能擴大安全風險的技術細節。</p>
<p>未經我們事前書面同意,您不得以公開揭露、利用漏洞、擴大測試範圍或其他可能造成服務中斷或資料外洩的方式進行測試或驗證。</p>
</section>
<section>
<h2>十、使用者行為規範</h2>
<p>您使用本服務時,不得從事下列行為:</p>
<ol>
<li>違反法律、主管機關命令、第三方權利或本條款。</li>
<li>冒用他人、提供不實資料,或誤導我們、租戶網站或其他使用者。</li>
<li>入侵、干擾、破壞、逆向工程、掃描或測試本服務弱點,但事前取得我們書面同意者不在此限。</li>
<li>上傳、傳送或散布惡意程式、垃圾訊息、釣魚內容、詐欺內容或侵權內容。</li>
<li>未經授權蒐集、查詢、匯出、複製或使用他人個人資料。</li>
<li>規避速率限制、存取控制、權限驗證、租戶隔離或其他安全措施。</li>
<li>對本服務或相關基礎設施造成過度負載或服務中斷。</li>
<li>將本服務用於非法行銷、未經同意的電子郵件寄送或其他違反收件者意願的通訊。</li>
</ol>
</section>
<section>
<h2>十一、管理者與租戶責任</h2>
<p>若您為管理者、租戶網站、OAuth 用戶端擁有者或合作服務,您應確保已取得處理使用者個人資料、發送電子報、呼叫 API、接收 webhook、同步資料或委託本服務處理資料所需的合法依據、同意或授權。</p>
<p>您應維護自身系統及整合流程的安全,包含 redirect URI、return URL、client secret、webhook endpoint、發信流程、退訂連結、資料匯出及人員權限管理。因您或您的系統未妥善保護、錯誤設定或違法使用所生的損害由您自行負責。</p>
</section>
<section>
<h2>十二、智慧財產權</h2>
<p>本服務所包含的程式、介面、設計、文件、商標、標誌、資料庫結構、API 規格、技術內容及其他素材,除另有標示或屬第三方權利外,均由我們或合法權利人保有智慧財產權。</p>
<p>除本條款或我們另行書面授權外,您不得重製、改作、散布、公開傳輸、出租、出售、反向工程、反編譯或以其他方式利用本服務內容。您就自行提供或上傳的資料仍保留原有權利,但授權我們在提供、維護、保護及改善本服務所必要範圍內使用、處理、儲存、傳輸及顯示該資料。</p>
</section>
<section>
<h2>十三、個人資料與隱私</h2>
<p>我們將依<a asp-area="" asp-controller="Home" asp-action="Privacy">隱私權政策</a>處理您的個人資料,該政策為本條款的一部分。請您詳閱隱私權政策,以了解我們蒐集的資料、使用目的、分享對象、保存期間、安全措施及您的權利。</p>
</section>
<section>
<h2>十四、服務可用性與變更</h2>
<p>我們會盡合理努力維持本服務穩定與安全,但不保證服務不中斷、無錯誤、無漏洞、永遠相容於所有瀏覽器、裝置、第三方服務或整合方式。</p>
<p>我們可能因維護、更新、資訊安全、系統故障、第三方服務中斷、不可抗力、法令要求或其他合理原因,暫停、限制或調整本服務。若可行,我們會以合理方式通知重大維護或變更。</p>
</section>
<section>
<h2>十五、暫停、限制與終止</h2>
<p>若您違反本條款、違法、侵害他人權利、造成資訊安全風險、濫用服務、未經授權存取資料,或我們合理認為有必要保護使用者、租戶、第三方或本服務,我們得採取下列措施:</p>
<ol>
<li>要求更正、補充資料或停止特定行為。</li>
<li>限制、暫停或終止帳號、管理權限、API 用戶端、權杖、webhook 或整合功能。</li>
<li>刪除、限制存取或隔離違規資料。</li>
<li>通知受影響使用者、租戶、合作服務、主管機關或執法機關。</li>
<li>採取法律允許的其他必要措施。</li>
</ol>
<p>您可依本服務提供的方式停止使用、刪除帳號或請求資料處理。但依法令、契約、稽核、資訊安全、爭議處理或防止濫用所必要的資料,我們仍得在必要範圍內保存。</p>
</section>
<section>
<h2>十六、免責聲明</h2>
<p>在法律允許的最大範圍內,本服務依「現況」及「可提供狀態」提供。我們不保證本服務完全符合您的所有需求、永不中斷、完全安全、無錯誤、無病毒、無資料遺失,或能與所有第三方服務、租戶網站、郵件服務、雲端平台、瀏覽器及裝置相容。</p>
<p>第三方網站、租戶網站、外部登入服務、Send Engine、檔案儲存服務、郵件服務或其他第三方服務所造成的問題、損害或資料處理除依法或契約應由我們負責者外由該第三方或您自行負責。</p>
</section>
<section>
<h2>十七、責任限制</h2>
<p>除因故意、重大過失、法律不得限制的責任,或消費者保護法等強制規定不得排除者外,我們對因使用或無法使用本服務所生的間接、附隨、特殊、衍生、懲罰性損害、商譽損失、營業損失、資料遺失、預期利益損失或第三方請求,不負賠償責任。</p>
<p>如依法我們仍須負賠償責任,責任範圍以您就引發責任的服務於事件發生前十二個月內實際支付給我們的費用為上限;若該服務為免費提供,則以新臺幣 10,000 元為上限。但法律不得限制者,不在此限。</p>
</section>
<section>
<h2>十八、賠償</h2>
<p>若因您違反本條款、違法使用本服務、侵害第三方權利、未妥善保護帳號或憑證、錯誤設定整合服務,或未取得必要同意或授權,導致我們、關係企業、員工、合作夥伴、租戶或其他使用者受有損害、支出、罰鍰、和解金、律師費或第三方請求,您應在法律允許範圍內負責賠償並使其免受損害。</p>
</section>
<section>
<h2>十九、條款更新</h2>
<p>我們可能因服務功能、法令、資訊安全或營運模式變更而更新本條款。更新後的條款將公布於本服務或以其他適當方式通知您。若您於更新生效後繼續使用本服務,即表示您同意更新後條款;若您不同意,請停止使用本服務。</p>
<p>若更新重大影響您的權益,我們會以合理方式提醒您;在法律要求重新取得同意的情形下,我們將依法辦理。</p>
</section>
<section>
<h2>二十、準據法與管轄</h2>
<p>本條款的解釋、適用及爭議處理,以中華民國法律為準據法。因本條款或本服務所生的爭議,雙方應先以誠信方式協商解決;協商不成時,除法律另有強制規定外,以臺灣臺北地方法院為第一審管轄法院。</p>
</section>
<section>
<h2>二十一、其他</h2>
<p>本條款任一部分經法院或主管機關認定無效或不可執行,不影響其他部分的效力。我們未立即行使本條款下的權利,不代表拋棄該權利。未經我們事前書面同意,您不得轉讓本條款下的權利義務;我們得在組織重整、合併、分割、資產移轉或服務移轉時轉讓本條款。</p>
</section>
<section>
<h2>二十二、聯絡方式</h2>
<p>如您對本條款或本服務有疑問,請透過下列方式聯絡我們:</p>
<address>
<span>營運主體智匯創育股份有限公司Innovedus Inc</span>
<span>統一編號93698713</span>
<span>聯絡信箱:<a href="mailto:cs@innovedus.com">cs@innovedus.com</a></span>
<span>聯絡地址臺北市南港區三重路19之11號4樓</span>
</address>
</section>

View File

@ -1,10 +1,30 @@
@{
@using System.Globalization
@{
Layout = "_AuthLayout";
ViewData["Title"] = L["Privacy Policy"];
ViewData["ShowAuthVisual"] = false;
var isTraditionalChinese = CultureInfo.CurrentUICulture.Name == "zh-TW";
}
<div class="auth-document">
<h1>@L["Privacy Policy"]</h1>
<p></p>
</div>
<article class="auth-document legal-document" aria-labelledby="privacy-policy-title">
<header class="legal-document-header">
<h1 id="privacy-policy-title">@L["Privacy Policy"]</h1>
<p class="legal-document-meta">
@(isTraditionalChinese ? "版本日期2026/7/17" : "Version date: 2026/7/17")
</p>
<p class="legal-document-scope">
@(isTraditionalChinese
? "適用服務Member Center 會員中心、共用登入服務及電子報訂閱管理服務"
: "Applicable services: Member Center, shared sign-in services, and newsletter subscription management services")
</p>
</header>
@if (isTraditionalChinese)
{
<partial name="Legal/_PrivacyZhTw" />
}
else
{
<partial name="Legal/_PrivacyEnUs" />
}
</article>

View File

@ -1,10 +1,30 @@
@using System.Globalization
@{
Layout = "_AuthLayout";
ViewData["Title"] = L["Terms of Service"];
ViewData["ShowAuthVisual"] = false;
var isTraditionalChinese = CultureInfo.CurrentUICulture.Name == "zh-TW";
}
<div class="auth-document">
<h1>@L["Terms of Service"]</h1>
<p></p>
</div>
<article class="auth-document legal-document" aria-labelledby="terms-of-service-title">
<header class="legal-document-header">
<h1 id="terms-of-service-title">@L["Terms of Service"]</h1>
<p class="legal-document-meta">
@(isTraditionalChinese ? "版本日期2026/7/17" : "Version date: 2026/7/17")
</p>
<p class="legal-document-scope">
@(isTraditionalChinese
? "適用服務Member Center 會員中心、共用登入服務及電子報訂閱管理服務"
: "Applicable services: Member Center, shared sign-in services, and newsletter subscription management services")
</p>
</header>
@if (isTraditionalChinese)
{
<partial name="Legal/_TermsZhTw" />
}
else
{
<partial name="Legal/_TermsEnUs" />
}
</article>

View File

@ -465,13 +465,74 @@ span.field-validation-error {
}
.auth-document {
width: min(100%, 42rem);
width: min(100%, 52rem);
}
.auth-document h1 {
margin-bottom: 1.25rem;
}
.legal-document {
color: #30343b;
font-size: 0.94rem;
line-height: 1.75;
}
.legal-document-header {
margin-bottom: 2.25rem;
padding-bottom: 1.4rem;
border-bottom: 1px solid #c9c7c1;
}
.legal-document-header h1 {
margin-bottom: 0.8rem;
}
.legal-document-meta,
.legal-document-scope {
color: #626872;
font-size: 0.82rem;
}
.legal-document-scope {
margin-top: 0.15rem;
}
.legal-document section + section {
margin-top: 2rem;
}
.legal-document h2 {
margin: 0 0 0.75rem;
color: #111827;
font-size: 1.12rem;
font-weight: 700;
line-height: 1.45;
}
.legal-document p {
margin: 0.65rem 0 0;
}
.legal-document ol,
.legal-document ul {
margin: 0.75rem 0 0;
padding-left: 1.45rem;
}
.legal-document li + li {
margin-top: 0.45rem;
}
.legal-document address {
margin: 0.75rem 0 0;
font-style: normal;
}
.legal-document address span {
display: block;
}
.auth-modal {
position: fixed;
inset: 0;