Information Security and Trade Secret Protection
Goertek complies with national laws, regulations and relevant standards, and strictly protects clients’ business information during the operation process of its information security management system to ensure that its activities meet the requirements for information security.
In order to ensure that the information security management requirements and objectives can be decomposed into various departments in different levels, Goertek has built a three-level information security organization of decision-making, management and executive layers to guarantee lay-by-layer communication and decomposition of information security management requirements and objectives, promote the performance of information security strategies, and ensure the achievement of information security objectives.
Goertek takes the following key measures to ensure the compliance of information security:
● It has established management systems related to information security, such as network security and trade secret protection, and required all its employees to strictly comply with trade secrets. It also respects others’ trade secrets, conform to relevant laws and regulations, and prohibit improper acquisition, disclosure, use, and disposal of others’ trade secrets.
● It regularly carries out training and publicity activities of information security and trade secret protection to all its employees, and continues to deepen the information security compliance awareness of all its employees.
● Through risk assessment, inspection, audit and other means, it supervises the implementation of various requirements for information security and trade secret protection to ensure effective execution of related policies, procedures and systems.
Goertek attaches great importance to data compliance and personal information protection. It strictly complies with all applicable data‑protection laws, regulations and regulatory requirements, and has established sound internal management systems covering the full lifecycle of personal information to implement end‑to‑end compliance management for personal data of employees, customers and visitors.
Except as otherwise provided by law, Goertek shall fulfill its legal obligation of notification and obtain explicit consent from the data subjects. Goertek adheres to the principles of lawfulness, fairness, necessity and data minimisation. Personal information processing is strictly limited to the scope and means necessary for business operations. Retention periods and disposal measures are set in accordance with statutory requirements and the shortest timeframe needed to achieve processing purposes.
Goertek respects and safeguards data subjects’ statutory rights, including access, copy, correct and delete their personal information, withdrawal of consent, and request their personal information transfer to other service providers where applicable. Data subjects may exercise their rights via the designated data‑protection lead or other official channels specified by Goertek, and the Company will respond within statutory time limits.