Controller and contact
Controller: Hangzhou Maodunfang New Materials Technology Co., Ltd. Address: Building 5, 10F, Yindong Tech Park, Future Sci-Tech City, Yuhang, Hangzhou, China Email: zzl@yiihee.com Phone: +86 186 6814 6900 Send privacy requests to the email above. We may request proportionate information to verify identity and authority.
Data we handle
Public visits may generate IP address, request time, pages and referrer, browser, device and operating-system information, language, error and security-event logs. If you contact us by email, phone or social media, we handle the name, organisation, role, contact details, message and files you choose to provide. Authorised CMS users also provide an email username and generate display name, role, account status, session, login and content-operation records. The CMS does not store plaintext passwords; password verification is handled by our authentication provider. Do not send identity, payment, health or other sensitive data unless specifically requested through an appropriate channel.
Purposes and lawful grounds
We use necessary data to deliver and secure the site, diagnose faults, prevent misuse, respond to enquiries, discuss requested projects, authenticate administrators, control permissions, preserve content history, comply with law and establish or defend legal claims. Depending on context, our grounds include steps requested before a contract, contract performance, legal obligations, consent, and legitimate interests in operating a secure corporate website. We do not sell personal data, conduct behavioural advertising or make solely automated decisions producing legal or similarly significant effects.
Cookies and tracking
Public pages currently use no advertising or cross-site marketing cookies. The CMS uses strictly necessary HttpOnly security cookies: contex_admin_access for short-lived authentication and contex_admin_refresh for session renewal for up to 30 days. Logging out, account suspension or token expiry ends access. Server logs are not cookies. If analytics, advertising, forms, subscriptions or commerce are introduced, this Policy and any consent controls will be updated before activation.
Processors and international transfers
The site uses Cloudflare's global network, compute, D1 database and R2 object storage for delivery, storage and security. CMS email authentication uses Supabase, with the current authentication project located in Singapore. These providers may handle access logs, CMS content and uploads, administrator email, password verification material, sessions and authentication-security events. Data may therefore be processed outside your country, including China, Singapore and locations used by Cloudflare's network and support operations. Where required, we use applicable contractual safeguards, transfer assessments and supplementary measures. Social platforms process data independently after you follow a link or message an account.
Sharing and retention
We disclose data only to service providers acting for us, professional advisers where necessary, competent authorities under a valid legal requirement, or a lawful successor in a corporate transaction. We retain data only as long as required for its purpose, security, disputes and legal duties. Enquiries are normally reviewed for deletion 12 months after closure; administrator access is disabled promptly when authority ends; necessary version and security records may be retained longer for audit. Provider-controlled logs and backups follow configured service periods and applicable law.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability where relevant, withdrawal of consent and closure of an administrator account. Withdrawal does not affect earlier lawful processing. UK and EEA individuals may complain to their local supervisory authority. For a complaint governed by UK law, write “Data protection complaint” in the subject line; we will acknowledge it within 30 days, investigate without undue delay and explain the outcome. California and other regional rights apply where their statutory thresholds and scope are met. We will not discriminate for exercising a valid right.
Security, children and updates
We use HTTPS, individual accounts, password hashing by the authentication provider, role-based access, HttpOnly secure cookies, operation logs and restricted uploads. No online system is absolutely secure; we investigate incidents and notify regulators or affected people where required. The site is not directed to children under 16 and we do not knowingly collect their data. Material changes to this Policy will be highlighted and the effective date updated.
This is a general website policy, not legal advice for a particular transaction. Local counsel should confirm targeting, transfers and retention before new data-collection features are launched.