1. Introduction
This Privacy Policy explains how SUIZHOU DENGYANG ECOMMERCE CO., LTD. collects, uses, stores, shares and otherwise handles information when you visit our website, contact our workshop or engage our services. The policy is written to be read plainly, and we have avoided decorative language so that the meaning of each paragraph is clear on a first reading.
SUIZHOU DENGYANG ECOMMERCE CO., LTD. is a computer integrated systems design practice working in the field of computer systems design and related services. We build and integrate commerce systems, order pipelines, inventory telemetry and marketplace connections for merchants, and in the course of that work we sometimes handle information on behalf of our clients as well as information about visitors to this website. This policy describes both situations and explains the different roles we take in each one.
We believe that a person should be able to understand what happens to their information without needing legal training. If any part of this policy raises a question, you are welcome to write to us at service@dengyangecom.lol and we will explain it in plain terms.
2. Who We Are
The data controller for the purposes of this website and for our direct business relationships is:
SUIZHOU DENGYANG ECOMMERCE CO., LTD.
No 201 Unit 1 Building 3 Shangcheng International, Dongcheng, Zengdu District, Suizhou, 441300, China (CN)
Email: service@dengyangecom.lol
Phone: +17089384717
When we process personal information as part of a systems integration project for a client, the client is normally the controller of that information and we act as a processor on the client instructions. In that role we handle information only for the purposes the client has defined and only in accordance with the written agreement between us and the client.
Our website address is https://www.dengyangecom.lol. Questions about this policy, about our role in any particular processing activity, or about the rights described later in this document may be directed to the contact details above.
3. Scope Of This Policy
This policy applies to personal information that we handle when you browse this website, when you send us a message through the contact form or by email, when you telephone the workshop, and when you engage our services or correspond with us about a potential engagement.
This policy does not apply to the independent privacy practices of third parties, including marketplaces, payment providers, delivery companies or other services that you may reach through a link on this website or through a commerce system we have built for a client. Those parties publish their own privacy notices, and we encourage you to read them.
Where we process personal information on behalf of a client as a processor, the client privacy notice governs the relationship with the individuals concerned, and this policy applies only to the extent that it describes our internal handling standards and security measures.
4. Information We Collect
The categories of information we may collect depend on how you interact with us. The main categories are described below.
Information you give us directly
When you complete a contact form, send an email or speak with us by telephone, we may receive your name, your email address, your telephone number, your organisation name, your role and the content of your message. If you engage our services, we may also receive billing details, project information and the operational information needed to design and build a system.
Information collected automatically
When you visit this website, our hosting infrastructure may record technical information such as the internet protocol address associated with your connection, the browser and device type you used, the pages you requested, the time of each request and the address of the page that referred you. This information is used to serve the site reliably and to understand aggregate usage.
Information from business partners
If you are introduced to us by a partner, a marketplace or a shared client, we may receive limited contact information about you from that source. We use it only to respond to the introduction and to conduct the conversation you would expect from it.
5. How We Collect Information
We collect information through several straightforward routes. You provide information directly when you fill in a form, send an email or call the workshop. Our infrastructure collects technical information automatically as part of serving pages and protecting the site. We receive information from business partners when an introduction is made with your knowledge.
We do not purchase personal information from data brokers, and we do not build advertising profiles from information gathered across unrelated websites. If we ever introduce a feature that changes these practices, we will describe it in this policy and, where required, ask for your consent before it takes effect.
Where we collect information as a processor for a client, the collection is carried out inside the systems the client operates, under the client instructions and according to the agreement we hold with that client.
6. Why We Use Information
We use personal information for the following purposes, and we keep the purposes narrow and connected to the reason the information was provided.
- To respond to enquiries, questions and requests for a proposal.
- To provide, operate and maintain the services a client has engaged.
- To design, build, test and support commerce systems and integrations.
- To communicate about projects, timelines, invoices and support matters.
- To protect the website and our systems against abuse, fraud and attack.
- To meet accounting, tax and other legal obligations that apply to us.
- To improve the clarity and reliability of our own website and documentation.
We do not sell personal information, and we do not use the information you send us for unrelated purposes. When information is used for a purpose that is not described here and not required by law or by a client instruction, we will ask for your consent beforehand or explain the legal basis that permits the use.
7. Legal Bases For Processing
Where data protection law requires a legal basis for processing, we rely on one or more of the following foundations, chosen to match the activity.
Contract. We process information when it is necessary to take steps before entering a contract or to perform a contract we hold with you or with your organisation. Providing a proposal, delivering an engagement and issuing an invoice all fall within this basis.
Legitimate interests. We process limited information where we have a legitimate interest that is not overridden by your rights. Operating and securing the website, responding to business correspondence and improving our services are examples of this basis. We consider the impact on individuals before relying on it and we keep the processing proportionate.
Consent. Where we ask for consent, for example before sending a newsletter or adding a non-essential cookie, we rely on that consent and you may withdraw it at any time. Withdrawing consent does not affect processing that took place before the withdrawal.
Legal obligation. We process information where the law requires it, including accounting and tax record keeping and responses to lawful requests from competent authorities.
10. Service Providers And Processors
We use a small number of carefully chosen service providers to run the workshop. Each provider is selected for reliability and security, and we place written terms in every relationship that require confidentiality, appropriate security and limits on the use of information.
Our hosting and email providers process technical and correspondence information on our instruction. Our accounting and professional advisers process billing and corporate information where necessary. When we engage a subcontractor on a client project, the subcontractor works under our agreement with the client and receives only the access needed for the assigned task.
We review our providers periodically to confirm that their security posture and their commitments remain appropriate. If a provider can no longer meet our standards, we replace it and, where necessary, migrate the data in a controlled manner.
11. International Data Transfers
SUIZHOU DENGYANG ECOMMERCE CO., LTD. is based in China (CN), and we work with clients and providers in other countries. Information may therefore be transferred to and processed in a country other than the one in which it was collected.
When we transfer information internationally, we take steps to ensure that the information continues to receive an appropriate level of protection. These steps may include contractual commitments, such as standard contractual clauses, the use of providers with recognised safeguards, and the application of our internal security standards to every location where information is handled.
Where a client engagement involves a transfer, the transfer is described in the agreement with that client and handled according to the client instructions. You may contact us to ask about the safeguards that apply to a particular transfer.
12. Data Retention
We keep personal information only for as long as it is needed for the purpose it was collected, for as long as the law requires, or for as long as a client instruction directs. Retention periods are set by type of information rather than by a single blanket rule.
Enquiries and correspondence are generally kept for the period needed to resolve the matter and to maintain a reasonable business record, after which they are deleted or reduced to an anonymised summary. Project and billing records are kept for the period required by accounting and tax law. Information processed on behalf of a client is kept for the period defined in the client agreement and is returned or deleted at the end of the engagement.
When information is no longer needed, we delete it or render it anonymous so that it can no longer be associated with an individual. Where deletion is not immediately possible because information is held in a backup, we isolate it and allow the backup cycle to complete before the copy is removed.
13. How We Protect Information
We take the security of personal information seriously and apply technical and organisational measures that are appropriate to the sensitivity of the information and the risk of the processing.
Our measures include access controls that limit information to people who need it for their work, encryption of information in transit where supported, authentication requirements for systems that hold personal data, logging of access to sensitive systems, and a practice of keeping software dependencies current. We also review our providers to confirm that they maintain comparable safeguards.
No method of storage or transmission is perfect, and we cannot promise absolute security. We can promise that we design for security from the start, that we look for the simplest design that reduces exposure, and that we respond quickly and openly if a problem occurs.
14. Your Privacy Rights
Depending on where you live, you may have some or all of the rights described below. These rights are not absolute, and in every case they are balanced against other obligations such as legal retention requirements and the rights of other people.
- The right to be informed about how personal information is handled.
- The right to request access to the personal information we hold about you.
- The right to ask us to correct information that is inaccurate or incomplete.
- The right to ask us to delete information where there is no good reason to keep it.
- The right to ask us to restrict or object to certain processing activities.
- The right to receive information you provided in a portable format.
- The right to withdraw consent where processing is based on consent.
- The right to lodge a complaint with a supervisory authority.
To exercise a right, write to service@dengyangecom.lol with enough detail for us to identify you and understand the request. We may ask for additional information to verify your identity before acting, which protects the information from being released to the wrong person. We respond within the period required by the applicable law, and we explain our reasoning if we cannot fully meet a request.
15. Privacy For Children
This website and our services are intended for businesses and professional users. We do not knowingly collect personal information from children, and we do not design our services to appeal to them.
If you believe that a child has provided personal information to us, please contact us at service@dengyangecom.lol. We will investigate the matter and delete the information promptly if it was collected without the appropriate involvement of a parent or guardian.
16. Marketing Communications
We send marketing communications only where we have a lawful basis to do so, which in most cases means that you have asked to receive them or that you are an existing business contact and the message is relevant to your role. Every marketing message we send includes a way to stop receiving further messages.
If you ask to stop receiving marketing communications, we will honour the request promptly and will keep only the minimum record needed to ensure that we continue to respect it. We do not share contact details with advertising networks, and we do not sell mailing lists.
17. Third Party Links And Services
This website may contain links to third party websites, and the commerce systems we build may connect to third party marketplaces, payment providers and delivery services. Those third parties operate independently and are responsible for their own privacy practices.
We encourage you to review the privacy notice of any third party service before providing information to it. We are not responsible for the content or the practices of a third party, and a link from this website does not imply that we endorse the way that party handles personal information. When we build an integration that shares information with a third party, we document the sharing in the blueprint so that the client can see exactly where information flows.
18. Automated Decisions And Profiling
We do not make decisions about individuals that produce legal or similarly significant effects through automated processing alone. The systems we design for clients may include automated routing, scoring or validation steps, and where those systems are under our design influence we ensure that a meaningful human review path exists for the outcomes that matter.
Where an automated process is used, we document its purpose, its inputs and its limits as part of the build. If a client system makes an automated decision that affects an individual, the client is responsible for providing the information and the review options that the applicable law requires, and we support that obligation in the design of the system.
19. Data Incidents And Notification
We maintain a simple and practical incident process. If we become aware of a personal data breach, we assess the nature of the incident, the categories of information involved, the likely consequences for the individuals concerned and the measures needed to contain and remedy the situation.
Where the law requires notification, we inform the relevant supervisory authority without undue delay and, where the risk to individuals is high, we inform the affected individuals directly. When we act as a processor for a client, we notify the client without undue delay so that the client can meet its own notification obligations.
After an incident we review what happened, update our controls where needed and record the lessons so that the same failure is less likely to recur. We treat transparency after an incident as part of the duty of care we owe to the people whose information we handle.
20. Changes To This Policy
We review this policy periodically and update it when our practices, our services or the applicable law change. When we make a material change, we will update the date at the top of the page and, where the change is significant, we will provide a clearer notice on the website or by direct message.
We encourage you to return to this page from time to time so that you remain aware of how we handle personal information. Continued use of the website after an update indicates that you have had the opportunity to read the revised policy.
21. How To Contact Us
For any question about this policy, about the information we hold or about the rights described above, please contact us using the details below. We aim to respond promptly and to explain our position clearly.
SUIZHOU DENGYANG ECOMMERCE CO., LTD.
No 201 Unit 1 Building 3 Shangcheng International, Dongcheng, Zengdu District, Suizhou, 441300, China (CN)
Email: service@dengyangecom.lol
Phone: +17089384717
If you are not satisfied with our response, you may contact the supervisory authority responsible for data protection in your jurisdiction. We would welcome the chance to resolve the matter with you first.
Thank you for taking the time to read this Privacy Policy. Every thread of information we hold is accounted for, and this document is our plain record of how that is done.