Privacy Policy
Effective Date: August 2026 · Version 2.1
At Day 1 Coworking (“Day 1”, “we”, “our”, “us”), we respect your privacy and are committed to protecting your personal information.
This Privacy Policy is issued as the statutory notice required by Article 8 of the Personal Data Protection Act of the Republic of China (Taiwan) (個人資料保護法, the “PDPA”). It explains who collects your data, why, what we collect, how long we keep it, who we share it with, and the rights you have.
1. Statutory Notice under Article 8 of the PDPA
The following table sets out the matters we are required to notify you of before collecting your personal information.
| Collecting entity | 第一天共創公司, trading as Day 1 Coworking. Full company details appear at the end of this policy. |
| Purposes of collection | We collect personal information for the following statutory specific purposes (特定目的) as classified by the Ministry of Justice: 040 Marketing 069 Contractual, quasi-contractual or other legal relationship matters 090 Consumer, customer management and service 091 Consumer protection 148 Internet shopping and other electronic commerce services 157 Survey, statistics and research analysis 182 Provision of member services and management 136 Information (communications) and database management |
| Categories of data | We collect the following categories of personal information (個人資料類別): C001 Identifiers of the individual (name, email address, telephone number, address, member platform account, IP address) C002 Financial identifiers (payment card reference, bank account details where used) C003 Identifiers in government data (identification or passport number, only where required for building access or invoicing) C011 Personal description (photograph, where you provide one for your member profile) C038 Occupation (company or organisation, job title — optional) C093 Financial transactions (payment records, invoices, refunds) Membership and usage data (plan, membership history, access and check-in records, room bookings, event registrations) Device, connection and log data (browser and device type, whether the installed app or a web browser is used, and the approximate city and country derived from your IP address) |
| Period of use | For the duration of your membership or relationship with us, and thereafter: Accounting and tax records: five (5) years, as required by the Business Entity Accounting Act and tax law; Contract and membership records: five (5) years after the relationship ends; Access and check-in logs: twelve (12) months; Marketing contact details: until you unsubscribe or withdraw consent; Website and member platform technical logs (IP address, device and browser data): twelve (12) months; or such longer period as required by law or necessary to establish, exercise or defend legal claims. |
| Area of use | The Republic of China (Taiwan), and any country where our service providers process data on our behalf. Certain providers (for example payment, email and cloud hosting services) may process data outside Taiwan, including in the United States, the European Union, Japan and Singapore. Where data is transferred outside Taiwan, we require the recipient to apply protection at least equivalent to that required by the PDPA. |
| Recipients | Day 1 staff who need access to perform their role; Payment processors and acquiring banks; Accounting, bookkeeping and tax service providers; IT, cloud hosting, email and member-platform providers; Building management and access control providers (for entry credentials); Professional advisers (legal, insurance); Government authorities, courts and regulators where required by law. |
| Method of use | Collection, processing, international transmission, storage, retrieval, analysis and deletion, by electronic and paper-based means, in each case only to the extent necessary for the purposes listed above. |
2. Your Rights under Article 3 of the PDPA
| Article 3 of the PDPA grants you the following rights in respect of your personal information. These rights cannot be waived in advance or restricted by contract. To inquire about and request to review your personal information; To request a copy of your personal information; To request supplementation or correction of your personal information; To request that we cease collecting, processing or using your personal information; To request deletion of your personal information. To exercise any of these rights, contact us using the details at the end of this policy. We will respond within fifteen (15) days, which may be extended by a further fifteen (15) days where necessary, in which case we will tell you the reason. We may charge a fee that does not exceed our necessary cost where you request a copy of your data. |
We may decline a request where we are required or permitted by law to retain the information — for example, accounting records we must keep for tax purposes, or information needed to establish, exercise or defend a legal claim. If we decline, we will explain why.
3. Consequences of Not Providing Your Information
Providing your personal information is voluntary. However, certain information is necessary for us to perform our contract with you:
- Name, email address and telephone number are required to create a membership. Without these we cannot provide membership services.
- Payment information is required to process payments. Without it we cannot complete a purchase.
- Access credential information is required to grant entry to the space.
- Emergency contact details are optional but recommended for your safety.
- Company, job title and profile photograph are optional and used only for community features.
Declining to provide optional information will not affect your membership or the standard of service you receive.
4. How We Collect Your Information
- Directly from you when you enquire, register, purchase or attend an event;
- Automatically when you access the space using your credentials or book a room;
- Through our website, including cookies and analytics tools;
- Automatically from your device when you visit our website, use the member platform or register for an event — including your IP address, the approximate city and country it indicates, and your browser and device type;
- From third parties where you have authorised them to share information with us (for example a payment provider confirming a transaction).
5. Payment Information
Payments are processed by third-party payment providers. Day 1 does not store your complete payment card number. Our payment providers are responsible for the security of card data in accordance with applicable card scheme standards.
6. Marketing Communications
With your consent, we may send you updates about community events, new membership offerings, workshops, space announcements and member benefits.
You may withdraw consent and unsubscribe from marketing communications at any time, at no cost, using the link in any marketing email or by contacting us. We will action your request promptly.
Operational communications — such as billing notices, access information, safety notices and changes to these policies — will continue while you are a member, as they are necessary to perform our contract with you.
7. Sharing Your Information
We do not sell your personal information.
We share information only with the categories of recipient listed in Section 1 above, and only to the extent necessary. We require our service providers to process personal information only on our instructions and to apply appropriate security measures.
We may disclose information where required by law, court order, or a lawful request by a government authority, and where necessary to protect the safety of members, staff or the public.
8. Data Security
We maintain administrative, technical and physical measures designed to protect personal information against unauthorised access, disclosure, alteration or destruction, including:
- Access controls limiting staff access to data on a need-to-know basis;
- Encryption of data in transit;
- Secured member platform accounts;
- Confidentiality obligations for staff and service providers;
- Periodic review of our security practices and lifecycle management of personal data.
No method of electronic storage or internet transmission is completely secure, and we cannot guarantee absolute security.
9. Data Breach Notification
| In accordance with the PDPA and the requirements introduced by the 2025 amendments (in force from January 2026): If personal information is stolen, disclosed, altered or otherwise infringed, we will investigate immediately and take remedial action; We will notify the Personal Data Protection Commission (個人資料保護委員會) where the incident is likely to harm the rights and interests of data subjects, within the period required by law; We will notify affected individuals of the facts of the incident and the measures we have taken, by email, telephone or other appropriate means, as soon as reasonably practicable after we have verified the incident. |
10. Confidentiality of Member Work
Day 1 respects the confidentiality of our members' work. We do not access, monitor, or claim ownership over any work, ideas, documents or intellectual property created or discussed within our space.
11. Cookies and Website Analytics
Our website uses cookies and similar technologies to improve website performance, understand visitor behaviour and remember your preferences.
Strictly necessary cookies are required for the website to function. Analytics and marketing cookies are used only where you have given consent through our cookie banner, and you may change or withdraw that consent at any time.
You may also disable cookies through your browser settings, although some website functionality may be affected.
12. Device, Log and Location Data
When you use our website or member platform, our servers record technical information about the connection. This is standard practice for any website; we keep what we record deliberately minimal.
- Your IP address, recorded when your member account is created, each time you sign in, and when you register for an event;
- The approximate city and country indicated by that IP address. This is derived from the IP address by our hosting provider — we do not collect GPS or precise device location;
- Your browser and device type, and whether you are using our installed app or a web browser, taken from the technical information your browser sends with each request.
We use this information to keep accounts secure — for example to spot sign-ins that do not look like you, and duplicate or automated event registrations — to help you if something goes wrong, and to understand in aggregate how members and event guests reach us. We do not use it to build advertising profiles, we do not sell it, and we do not track your activity across other websites.
This information is visible only to Day 1 staff with administrative access to the member platform, and is retained for twelve (12) months, after which it is deleted or aggregated into statistics that no longer identify you.
Registering for an event creates a member platform account for you, using the name and email address you provide, so that you can access your ticket and manage your registration. We email you a one-time link to confirm your email address and, if you wish, complete a member profile. That link signs you in without a password, is valid for seven (7) days and can be used once, so please do not forward it. If you would rather not keep the account, you may ask us to delete it at any time using the contact details below.
13. Third-Party Services
Our website may contain links to third-party websites or services. Day 1 is not responsible for the privacy practices of external websites, and we encourage you to review their respective privacy policies.
14. Children and Minors
Our services are intended for individuals aged eighteen (18) or over. We do not knowingly collect personal information from persons under eighteen without the consent of a parent or legal guardian. If you believe we have collected such information, please contact us and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version is always available on our website. Where a change materially affects how we use your personal information, we will notify you by email at least thirty (30) days before the change takes effect and, where required by law, seek your consent.
16. Contact and Complaints
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us using the details set out below.
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission (個人資料保護委員會) or with the competent authority for our industry, and you may seek remedies through the courts under the PDPA.
Language
This Privacy Policy is published in English and in Traditional Chinese. The English version is the governing version. In the event of any inconsistency or conflict between the two versions, the English version prevails, save where a mandatory provision of Taiwan law requires otherwise.
Company Information
The following details are required to be displayed under Taiwan law and by our payment providers.
| Legal entity | 第一天共創公司 (Day 1 Coworking) |
| Unified Business No. | — |
| Registered address | — |
| Business address | — |
| Telephone | — |
| — | |
| Website | www.day1taipei.com |
Questions about this document? Get in touch.