1. Introduction
Kunming Xuming Trading Co., Ltd. (hereafter referred to as the Company, we, us, or our) operates the website located at https://www.xuming.lat (the Site). The Site was developed by XuMing, our lead systems architect and developer. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal data when you visit our Site or use any of our services.
We are committed to protecting your privacy and handling your personal information in a transparent and responsible manner. This policy explains the types of data we may process, the purposes for which we process it, the legal bases for processing, and the rights you have regarding your personal data. By accessing or using our Site, you acknowledge that you have read and understood this Privacy Policy.
If you do not agree with any part of this policy, you should discontinue use of our Site immediately. We reserve the right to update this policy at any time, and we encourage you to review it periodically to stay informed about our data practices.
2. Information We Collect
We collect several categories of information when you interact with our Site. The types of data we gather depend on how you engage with our services and the features you choose to use. Below is a detailed breakdown of the information categories we may collect.
2.1 Personal Identification Information
Personal identification information includes data that can be used to identify you as an individual. This may include your full name, email address, telephone number, company name, job title, and physical mailing address. We collect this information when you voluntarily submit it through our contact forms, when you send us an email, or when you engage in correspondence with our team.
2.2 Technical and Usage Data
When you access our Site, our servers automatically record certain technical information. This includes your Internet Protocol (IP) address, browser type and version, operating system, device type, referring URL, pages visited, time and date of your visit, time spent on each page, and other diagnostic data. This information is collected through server logs and analytics tools and is used to maintain the security and performance of our Site.
2.3 Communication Data
If you contact us via email, through our contact form, or by telephone, we may retain records of that correspondence including the content of your messages, any attachments you send, and the metadata associated with the communication such as timestamps and email headers.
2.4 Business Information
For prospective and current clients, we may collect business-related information such as company registration details, project requirements, technical specifications, and contractual documentation. This information is collected solely for the purpose of providing our services and managing client relationships.
3. How We Collect Information
We employ multiple methods to collect information, each serving a distinct purpose in our operations. We strive to use the least intrusive methods necessary to achieve our legitimate business objectives.
3.1 Direct Collection
Direct collection occurs when you voluntarily provide information to us. This happens when you fill out a contact form on our Site, send us an email message, call our office by telephone, or provide information during a consultation or business meeting. In all cases of direct collection, you are in control of what information you choose to share with us.
3.2 Automated Collection
As you navigate through our Site, we use automated data collection technologies to gather technical information about your equipment, browsing actions, and usage patterns. These technologies include standard server logs, analytics scripts, and cookies. Automated collection helps us understand how visitors use our Site so we can improve the user experience and ensure technical stability.
3.3 Third-Party Sources
In some circumstances, we may receive information about you from third-party sources. This may include publicly available databases, business directories, or professional networking platforms. We only use information from third-party sources when it is reasonably necessary for our legitimate business interests and when we have verified that the source obtained the information lawfully.
4. Use of Personal Information
We use the personal information we collect for a variety of purposes, all of which are grounded in legitimate business needs or legal obligations. We do not use your data for purposes that are incompatible with those described in this policy.
- Service Delivery: To provide, maintain, and improve our computer systems design and consulting services. This includes responding to inquiries, preparing proposals, and executing project work.
- Communication: To communicate with you about your inquiries, projects, or our services. This includes responding to contact form submissions, sending follow-up emails, and providing support.
- Site Operation: To operate, maintain, and optimize the performance of our Site. This includes monitoring server health, diagnosing technical issues, and analyzing traffic patterns.
- Security: To detect, prevent, and address technical issues, fraud, or security breaches. We monitor our systems for unauthorized access and anomalous activity patterns.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests. This includes maintaining records as required by applicable regulations.
- Business Development: To analyze trends, track user engagement, and make informed decisions about our service offerings and business strategy.
We will not use your personal information for any purpose other than those stated in this policy without first obtaining your explicit consent, unless we are required to do so by law.
6. Data Storage and Security
We implement and maintain appropriate technical and organizational measures designed to protect the personal information we process. Our security posture includes multiple layers of protection aligned with industry best practices for data security.
6.1 Security Measures
We employ a combination of administrative, technical, and physical safeguards to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encrypted data transmission via Transport Layer Security (TLS), secure server configurations, access controls with role-based permissions, regular security audits, and ongoing vulnerability assessments.
6.2 Data Storage Location
Your personal information may be stored on servers located in the United States, China, or other jurisdictions where we or our service providers maintain facilities. By providing your information to us, you consent to the transfer and storage of your data in these locations.
6.3 Breach Notification
In the event of a data breach that compromises your personal information, we will notify you and the relevant regulatory authorities in accordance with applicable data protection laws. Our notification will include a description of the breach, the types of data involved, the steps we are taking to address it, and recommendations for protecting yourself against potential harm.
7. Data Retention
We retain your personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable law. The specific retention period depends on the nature of the data and the purpose of processing.
7.1 Retention Criteria
When determining retention periods, we consider the amount, nature, and sensitivity of the personal data; the potential risk of harm from unauthorized use or disclosure; the purposes for which we process the data; whether we can achieve those purposes through other means; and applicable legal, regulatory, tax, accounting, or other requirements.
7.2 Deletion Procedures
When personal information is no longer needed for the purpose for which it was collected, we will delete or anonymize it using secure methods. If deletion is not immediately feasible due to technical constraints, we will isolate the data from further processing until deletion is possible.
8. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights regarding the personal information we hold about you. We respect these rights and provide mechanisms for you to exercise them.
- Right to Access: You may request a copy of the personal data we hold about you and information about how we process it.
- Right to Rectification: You may request that we correct inaccurate or incomplete personal data we hold about you.
- Right to Erasure: You may request that we delete your personal data under certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
- Right to Restrict Processing: You may request that we limit the processing of your personal data in specific situations.
- Right to Data Portability: You may request a copy of your personal data in a structured, machine-readable format and have it transmitted to another controller.
- Right to Object: You may object to the processing of your personal data based on legitimate interests or for direct marketing purposes.
To exercise any of these rights, please contact us using the information provided in the Contact Information section. We will respond to your request within the timeframe required by applicable law.
10. Third-Party Services
Our Site may contain links to third-party websites, plugins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices.
When you leave our Site, we encourage you to read the privacy policy of every website you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
We may also use third-party service providers to support our business operations, such as hosting providers, email delivery services, and analytics platforms. These providers have their own privacy policies and we recommend reviewing them to understand how they handle your data. We select service providers carefully and ensure appropriate contractual protections are in place.
11. Privacy for Children
Our Site is not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16 years of age. If we become aware that a child under 16 has provided us with personal data, we will take steps to delete such information from our systems as quickly as possible.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately using the details provided in the Contact Information section. We will work with you to address the situation promptly and ensure the data is removed.
We encourage parents and guardians to monitor the online activities of children in their care and to educate them about safe internet practices and the importance of protecting personal information online.
12. International Data Transfers
Your information, including personal data, may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those in your jurisdiction. By providing your information to us, you agree to such transfers.
We take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy. When we transfer personal data across borders, we implement appropriate safeguards such as standard contractual clauses or other lawful transfer mechanisms to ensure adequate protection of your data.
If you are located outside of China and choose to provide information to us, please note that we may transfer the data to China and process it there. Your submission of such information represents your agreement to that transfer.
13. California Privacy Rights
If you are a resident of California, you may have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). These rights include the right to know what personal information we collect about you, the right to request deletion of your personal information, the right to opt out of the sale or sharing of your personal information, and the right to non-discrimination for exercising your privacy rights.
We do not sell personal information as that term is defined under California law. We have not sold any personal information in the preceding twelve months and have no plans to do so. We also do not share personal information for cross-context behavioral advertising purposes.
To exercise your California privacy rights, you may submit a verifiable consumer request by contacting us using the information in the Contact Information section. We will verify your identity before processing your request and will respond within the time period required by California law.
14. GDPR Compliance
For individuals located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) provides additional rights and protections. This section outlines our compliance with GDPR requirements.
14.1 Legal Bases for Processing
We process personal data under the following legal bases: consent, which you may withdraw at any time; contractual necessity, when processing is required to fulfill a contract with you; legal obligation, when we must comply with applicable law; and legitimate interests, when processing is necessary for our business purposes and does not override your rights and freedoms.
14.2 Data Subject Rights
Under the GDPR, you have the right to access, rectify, erase, restrict, and port your personal data, as well as the right to object to processing. You also have the right to lodge a complaint with a supervisory authority in your country of residence if you believe our processing of your data violates the GDPR.
14.3 Data Protection Officer
Given the nature and scope of our data processing activities, we have determined that appointment of a formal Data Protection Officer is not currently required under Article 37 of the GDPR. However, we take data protection seriously and designate appropriate personnel to oversee our privacy compliance. You may direct any GDPR-related inquiries to the contact information provided below.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make changes, we will revise the last updated date at the top of this page and post the revised policy on our Site.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. If the changes are material, we will provide a more prominent notice, which may include sending an email notification to users who have provided their email address or displaying a notice on our Site for a reasonable period before the changes take effect.
Your continued use of our Site after any modification to this Privacy Policy will constitute your acknowledgment of the modifications and your consent to abide by and be bound by the modified policy. If you do not agree with the revised policy, you should discontinue use of the Site.
16. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the following details:
Company Name: Kunming Xuming Trading Co., Ltd.
Address: Room 801, 8/F, Julong Building, 33 Renmin Middle Road, Wuhua District, Kunming, 650000, China (CN)
Email: mail@xuming.lat
Phone: +1 609 469 3639
Website: https://www.xuming.lat
We strive to respond to all privacy-related inquiries within thirty days of receipt. If your inquiry is urgent, please indicate this in your message and we will prioritize it accordingly.