Privacy & Data Protection

Protecting Your Information Through Secure and Transparent Practices

Effective Date: January 1, 2026 Last Updated: June 1, 2026 Version 1.0

Section 01

Information We Collect

We collect personal information only when it is necessary to provide our services, respond to inquiries, fulfill orders, and comply with legal obligations. The categories of information we may collect include:

Information You Provide Directly

  • Full name, job title, and company name
  • Business email address and phone number
  • Shipping and billing addresses
  • RFQ details, product specifications, and order history
  • Messages submitted via contact forms or email
  • Account credentials (if you register on our portal)

Information Collected Automatically

  • IP address and approximate geographic location
  • Browser type, version, and operating system
  • Pages visited, time on site, and referral source
  • Cookie identifiers and session data
  • Device identifiers and screen resolution
  • Clickstream and interaction event data

Cookies & Tracking Technologies: We use essential cookies required for site functionality, as well as optional analytics cookies to understand how visitors use our website. You may manage cookie preferences through your browser settings or our cookie consent tool. We do not use cookies for targeted advertising.

Section 02

Data Use & Storage

We process personal data only for specific, legitimate purposes and retain it no longer than necessary to fulfil those purposes or meet regulatory requirements.

How We Use Your Information

Purpose Legal Basis Retention Period
Processing orders & RFQs Contractual necessity 7 years (statutory)
Customer support & communication Legitimate interest 3 years after last contact
Website analytics & improvement Consent 26 months
Product & technical newsletters Consent Until unsubscribed
Legal & regulatory compliance Legal obligation As required by law
Fraud prevention & security Legitimate interest 12 months post-incident

Data Storage Locations

Your data is stored on servers located in the European Economic Area (EEA) and, where necessary for order fulfilment, on secure infrastructure in mainland China and the United States. All cross-border data transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms, ensuring an equivalent level of protection regardless of storage location.

Section 03

Information Security Measures

We implement a layered, defense-in-depth security framework to protect personal data against unauthorized access, disclosure, alteration, or destruction. Our security program is reviewed annually and aligns with ISO/IEC 27001 principles.

Encryption in Transit & at Rest

All data transmitted via TLS 1.3. Stored data encrypted using AES-256 at the database and file-system level.

Role-Based Access Control

Access to personal data is restricted to authorized personnel on a strict need-to-know basis. Multi-factor authentication (MFA) is mandatory for all staff accounts.

Regular Audits & Penetration Testing

Annual third-party penetration tests and quarterly internal vulnerability scans. All findings are remediated within defined SLA windows.

Automated Backups

Daily encrypted backups stored in geographically separate data centers. Recovery point objective (RPO) of 24 hours; recovery time objective (RTO) of 4 hours.

Breach Notification Protocol

In the event of a data breach, we will notify affected individuals and relevant supervisory authorities within 72 hours of becoming aware, as required by applicable law.

Staff Training & Awareness

All employees handling personal data complete mandatory annual data protection training and sign confidentiality agreements upon onboarding.

Important Notice: While we employ industry-leading security practices, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to use strong, unique passwords and to contact us immediately if you suspect unauthorized access to your account.

Section 04

Third-Party Information Sharing

We do not sell, rent, or trade your personal information. We share data only in the limited circumstances described below, and only with parties who are contractually bound to protect it.

A

Service Providers & Sub-processors

We engage trusted third-party service providers to operate our business, including cloud hosting providers, payment processors, logistics and freight partners, CRM software vendors, and email delivery services. These parties act as data processors under our instruction and are prohibited from using your data for any purpose beyond the contracted service.

B

Customs, Freight & Regulatory Authorities

For international shipments of ceramic heating elements and related industrial goods, we may be required to disclose shipment details -- including consignee name and address -- to customs authorities, freight forwarders, and export compliance bodies in accordance with applicable trade regulations.

C

Legal & Regulatory Compliance

We may disclose personal data to law enforcement agencies, courts, or government authorities when required by law, court order, or to protect the legal rights, safety, and property of CeraTherm, our customers, or the public.

D

Business Transfers

In the event of a merger, acquisition, joint venture, or sale of company assets, personal data may be transferred to the successor entity. We will provide notice before your data becomes subject to a materially different privacy policy.

We Never Share Your Data For:

Third-party advertising or marketing networks Data brokers or list aggregators Social media profiling or behavioral targeting Sale or commercial exchange to any third party

Section 05

Your Rights & Choices

Depending on your jurisdiction, you may have the following rights regarding your personal data. We honor these rights without discrimination and will respond to verified requests within 30 calendar days (extendable by a further 60 days for complex requests, with notice).

01

Right of Access

Request a copy of the personal data we hold about you, including information about how it is used and with whom it has been shared.

02

Right to Rectification

Request correction of inaccurate or incomplete personal data we hold about you. We will update records promptly upon verification.

03

Right to Erasure

Request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to our legal retention obligations.

04

Right to Restrict Processing

Request that we limit how we use your data while a dispute is being resolved or while you exercise other rights.

05

Right to Data Portability

Receive your personal data in a structured, machine-readable format and transfer it to another controller, where technically feasible.

06

Right to Object & Withdraw Consent

Object to processing based on legitimate interests, or withdraw consent at any time for processing based solely on your consent, without affecting prior lawful processing.

How to Exercise Your Rights

Submit your request in writing to our Data Protection Officer. We may ask you to verify your identity before processing your request to protect against unauthorized disclosures.

miafang@xmssheating.com
+86 13606932580
xiamen senshuo technology Co., Ltd.

Section 06

Policy Updates & Version History

We review and update this Privacy Policy periodically to reflect changes in our business practices, applicable laws, and evolving data protection standards. We are committed to transparent communication whenever material changes are made.

How We Notify You of Changes

Email Notification

For material changes, we will email registered users at least 30 days before the new policy takes effect.

Website Banner

A prominent notice will appear on our homepage and this page for 30 days following any significant update.

Version Log

A full version history is maintained below. Previous versions are available upon request from our DPO.

Version History

Version 1.0 Current June 1, 2026

Updated data retention schedule; added sub-processor list; clarified cross-border transfer mechanisms; expanded user rights section to address Chinese PIPL requirements.

Version 1.0 January 1, 2026

Major revision to align with GDPR, CCPA, and China PIPL. Introduced structured data table format; added breach notification protocol; expanded security measures.

Version 1.0 March 15, 2026

Added cookie consent framework; updated third-party service provider list; minor clarifications to data collection section.

Version 1.0 September 1, 2026

Initial publication of Privacy Policy upon company website launch.

Your continued use of our website or services after the effective date of a revised policy constitutes your acceptance of the updated terms. If you do not agree with the revised policy, please discontinue use of our services and contact us to discuss your options.