Protecting Your Information Through Secure and Transparent Practices
Section 01
Information We Collect
We collect personal information only when it is necessary to provide our services, respond to inquiries, fulfill orders, and comply with legal obligations. The categories of information we may collect include:
Information You Provide Directly
- Full name, job title, and company name
- Business email address and phone number
- Shipping and billing addresses
- RFQ details, product specifications, and order history
- Messages submitted via contact forms or email
- Account credentials (if you register on our portal)
Information Collected Automatically
- IP address and approximate geographic location
- Browser type, version, and operating system
- Pages visited, time on site, and referral source
- Cookie identifiers and session data
- Device identifiers and screen resolution
- Clickstream and interaction event data
Cookies & Tracking Technologies: We use essential cookies required for site functionality, as well as optional analytics cookies to understand how visitors use our website. You may manage cookie preferences through your browser settings or our cookie consent tool. We do not use cookies for targeted advertising.
Section 02
Data Use & Storage
We process personal data only for specific, legitimate purposes and retain it no longer than necessary to fulfil those purposes or meet regulatory requirements.
How We Use Your Information
| Purpose | Legal Basis | Retention Period |
|---|---|---|
| Processing orders & RFQs | Contractual necessity | 7 years (statutory) |
| Customer support & communication | Legitimate interest | 3 years after last contact |
| Website analytics & improvement | Consent | 26 months |
| Product & technical newsletters | Consent | Until unsubscribed |
| Legal & regulatory compliance | Legal obligation | As required by law |
| Fraud prevention & security | Legitimate interest | 12 months post-incident |
Data Storage Locations
Your data is stored on servers located in the European Economic Area (EEA) and, where necessary for order fulfilment, on secure infrastructure in mainland China and the United States. All cross-border data transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms, ensuring an equivalent level of protection regardless of storage location.
Section 03
Information Security Measures
We implement a layered, defense-in-depth security framework to protect personal data against unauthorized access, disclosure, alteration, or destruction. Our security program is reviewed annually and aligns with ISO/IEC 27001 principles.
Encryption in Transit & at Rest
All data transmitted via TLS 1.3. Stored data encrypted using AES-256 at the database and file-system level.
Role-Based Access Control
Access to personal data is restricted to authorized personnel on a strict need-to-know basis. Multi-factor authentication (MFA) is mandatory for all staff accounts.
Regular Audits & Penetration Testing
Annual third-party penetration tests and quarterly internal vulnerability scans. All findings are remediated within defined SLA windows.
Automated Backups
Daily encrypted backups stored in geographically separate data centers. Recovery point objective (RPO) of 24 hours; recovery time objective (RTO) of 4 hours.
Breach Notification Protocol
In the event of a data breach, we will notify affected individuals and relevant supervisory authorities within 72 hours of becoming aware, as required by applicable law.
Staff Training & Awareness
All employees handling personal data complete mandatory annual data protection training and sign confidentiality agreements upon onboarding.
Important Notice: While we employ industry-leading security practices, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to use strong, unique passwords and to contact us immediately if you suspect unauthorized access to your account.
Section 04
Third-Party Information Sharing
We do not sell, rent, or trade your personal information. We share data only in the limited circumstances described below, and only with parties who are contractually bound to protect it.
Service Providers & Sub-processors
We engage trusted third-party service providers to operate our business, including cloud hosting providers, payment processors, logistics and freight partners, CRM software vendors, and email delivery services. These parties act as data processors under our instruction and are prohibited from using your data for any purpose beyond the contracted service.
Customs, Freight & Regulatory Authorities
For international shipments of ceramic heating elements and related industrial goods, we may be required to disclose shipment details -- including consignee name and address -- to customs authorities, freight forwarders, and export compliance bodies in accordance with applicable trade regulations.
Legal & Regulatory Compliance
We may disclose personal data to law enforcement agencies, courts, or government authorities when required by law, court order, or to protect the legal rights, safety, and property of CeraTherm, our customers, or the public.
Business Transfers
In the event of a merger, acquisition, joint venture, or sale of company assets, personal data may be transferred to the successor entity. We will provide notice before your data becomes subject to a materially different privacy policy.
We Never Share Your Data For:
Section 05
Your Rights & Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data. We honor these rights without discrimination and will respond to verified requests within 30 calendar days (extendable by a further 60 days for complex requests, with notice).
Right of Access
Request a copy of the personal data we hold about you, including information about how it is used and with whom it has been shared.
Right to Rectification
Request correction of inaccurate or incomplete personal data we hold about you. We will update records promptly upon verification.
Right to Erasure
Request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to our legal retention obligations.
Right to Restrict Processing
Request that we limit how we use your data while a dispute is being resolved or while you exercise other rights.
Right to Data Portability
Receive your personal data in a structured, machine-readable format and transfer it to another controller, where technically feasible.
Right to Object & Withdraw Consent
Object to processing based on legitimate interests, or withdraw consent at any time for processing based solely on your consent, without affecting prior lawful processing.
How to Exercise Your Rights
Submit your request in writing to our Data Protection Officer. We may ask you to verify your identity before processing your request to protect against unauthorized disclosures.
Section 06
Policy Updates & Version History
We review and update this Privacy Policy periodically to reflect changes in our business practices, applicable laws, and evolving data protection standards. We are committed to transparent communication whenever material changes are made.
How We Notify You of Changes
Email Notification
For material changes, we will email registered users at least 30 days before the new policy takes effect.
Website Banner
A prominent notice will appear on our homepage and this page for 30 days following any significant update.
Version Log
A full version history is maintained below. Previous versions are available upon request from our DPO.
Version History
Updated data retention schedule; added sub-processor list; clarified cross-border transfer mechanisms; expanded user rights section to address Chinese PIPL requirements.
Major revision to align with GDPR, CCPA, and China PIPL. Introduced structured data table format; added breach notification protocol; expanded security measures.
Added cookie consent framework; updated third-party service provider list; minor clarifications to data collection section.
Initial publication of Privacy Policy upon company website launch.
Your continued use of our website or services after the effective date of a revised policy constitutes your acceptance of the updated terms. If you do not agree with the revised policy, please discontinue use of our services and contact us to discuss your options.