1. Information We Collect

We collect several categories of information depending on how you interact with our website and services. The types of data we may gather include personal identification information such as your full name, email address, telephone number, company name, job title, and physical mailing address when you voluntarily submit this information through our contact forms, service inquiry forms, or email communications. We also collect professional and business-related information including the name of your organization, your role within that organization, and details about the projects or services you are interested in exploring with us.

Technical data is automatically collected when you browse our website. This includes your Internet Protocol (IP) address, browser type and version, operating system, device type, referring and exit URLs, pages visited on our site, the date and time of your visit, time spent on each page, clickstream data, and other diagnostic and usage information. This technical data helps us understand how visitors interact with our website and allows us to improve site performance, navigation, and content relevance.

We may also collect communication data including the content of messages you send through our contact forms, email correspondence, and any attachments you choose to share with us. If you participate in surveys, feedback requests, or beta testing programs, we collect the responses and input you provide. Additionally, we may collect information from publicly available sources, business directories, and professional networking platforms to supplement the information you provide directly, enabling us to better understand your business needs and tailor our services accordingly.

2. How We Collect Information

We collect information through several different methods, all designed to be transparent and respectful of your privacy. Direct collection occurs when you voluntarily provide information by filling out a contact form on our website, sending us an email, calling our office, registering for a webinar or event, subscribing to our newsletter, downloading a whitepaper or resource, requesting a consultation, or otherwise engaging with our services through channels where you actively submit your data.

Automated collection happens through cookies, web beacons, server logs, and similar tracking technologies as you navigate our website. These technologies automatically record technical and usage data that help us understand site traffic patterns, detect potential security threats, and optimize the user experience. We also use analytics services provided by third parties that collect and process data on our behalf, subject to the privacy practices described by those providers.

In some cases, we may receive information about you from third-party sources. This includes business partners who refer you to our services, data enrichment services that help us verify and update contact information, and publicly available databases that provide company and professional information relevant to our business development activities. When we receive data from such sources, we ensure that the data was lawfully obtained and that we have a legitimate business purpose for processing it.

3. How We Use Your Information

Your information is used for a defined set of business purposes, each carefully evaluated to ensure it serves both your interests and our legitimate operational needs. The primary use of your personal data is to respond to your inquiries, provide the services you have requested, and fulfill our contractual obligations to you. This includes processing service requests, delivering technical consultations, managing project workflows, and communicating with you about the status and details of your engagement with us.

We use your information to improve and personalize your experience on our website and with our services. This involves analyzing usage patterns to optimize page layouts, content placement, and navigation flows. We may use your data to recommend services, case studies, or resources that are relevant to your industry, role, or expressed interests. Additionally, we process information to maintain the security and integrity of our systems, including detecting and preventing fraudulent activity, unauthorized access attempts, and violations of our terms of service.

For marketing and communications purposes, we may use your contact information to send you newsletters, service updates, event invitations, promotional materials, and thought leadership content that we believe may be of interest to you. You may opt out of marketing communications at any time by using the unsubscribe link included in every email we send or by contacting us directly. We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you.

4. Legal Bases for Processing

Our processing of your personal information is grounded in one or more lawful bases as defined by applicable data protection regulations, including the General Data Protection Regulation (GDPR) where it applies. The legal bases we rely upon include your explicit consent, which you give when you voluntarily submit your information through our forms and agree to our privacy practices. Where we process data based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

We process data as necessary for the performance of a contract with you or to take steps at your request before entering into a contract. This covers situations where you engage us for services, request a proposal, or enter into a business relationship with us. Legitimate interests form another basis for processing, where we have a valid business reason that does not override your fundamental rights and freedoms. Such legitimate interests include improving our services, conducting analytics, ensuring network and information security, preventing fraud, and marketing our services to existing and prospective clients.

In certain circumstances, we may need to process your data to comply with a legal obligation, such as responding to lawful requests from public authorities, maintaining records required by applicable laws, or meeting tax and accounting requirements. We carefully document the legal basis for each category of processing we undertake and review these determinations regularly to ensure ongoing compliance with evolving legal standards.

5. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and understand where our visitors come from. Cookies are small text files placed on your device by your web browser when you visit a website. They serve various functions including remembering your preferences, enabling certain site features, and providing analytics data to site operators. The cookies we use fall into several categories including essential cookies that are necessary for the basic functioning of the website, performance cookies that help us understand how visitors interact with our pages, and functionality cookies that remember choices you make to improve your experience.

We may also use third-party analytics cookies from service providers that help us measure and analyze site traffic and user behavior. These providers may collect information about your visits to our website and other sites over time. The data collected through analytics cookies is aggregated and anonymized where possible, and we do not use such data to identify individual users. You can control cookie settings through your browser preferences, including the option to block all cookies, delete existing cookies, or receive notifications when cookies are being set. Please note that disabling certain cookies may affect the functionality and performance of our website. For more detailed information about the specific cookies we use and their purposes, you may contact us using the information provided in this policy.

6. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes. We may share your data with trusted service providers and business partners who assist us in operating our website, conducting our business, and delivering services to you. These third parties include cloud hosting providers, email and communication platforms, analytics services, customer relationship management systems, and professional advisors such as legal counsel and accounting firms. All service providers are contractually obligated to protect your data, use it only for the specific purposes we have authorized, and comply with applicable data protection laws.

We may disclose your information when required by law, regulation, legal process, or governmental request. This includes responding to subpoenas, court orders, or other lawful requests from public authorities. We may also disclose information when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, to investigate fraud, or to respond to a government request. In the event of a merger, acquisition, reorganization, or sale of all or a portion of our assets, your information may be transferred as part of that transaction, subject to the same privacy protections described in this policy.

We may share aggregated or de-identified information that cannot reasonably be used to identify you with third parties for research, marketing, analytics, and other lawful purposes. Such data does not constitute personal information and is not subject to the restrictions described in this section. We implement appropriate technical and contractual measures to ensure that any de-identification processes are robust and irreversible.

7. Data Retention and Deletion

We retain your personal information only for as long as is necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. The specific retention period depends on the nature of the data and the purposes of processing. Contact information and correspondence related to business engagements are typically retained for the duration of the business relationship plus a period of seven years following the conclusion of that relationship, in accordance with applicable statutes of limitations and record-keeping obligations.

Technical and usage data collected through automated means is retained for a shorter period, generally twenty-four months, after which it is either deleted or irreversibly anonymized. Marketing data is retained until you opt out or unsubscribe from our communications, after which your contact details are suppressed from marketing lists. We periodically review our data holdings and delete or anonymize information that is no longer needed for the purposes for which it was collected. If you would like to request deletion of your personal information before the expiry of the standard retention period, you may do so by contacting us using the details provided in this policy. We will evaluate your request and respond in accordance with applicable legal requirements.

8. Data Security Measures

We implement a comprehensive set of technical and organizational measures designed to protect your personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Our security framework includes multiple layers of protection that address both digital and physical security concerns. These measures are reviewed and updated regularly to address evolving threats and to incorporate advances in security technology and best practices.

Technical measures include transport layer encryption (TLS/SSL) for all data transmitted between your browser and our servers, encryption of data at rest using industry-standard algorithms, firewalls and intrusion detection systems that monitor and protect our network perimeter, access controls that limit data access to authorized personnel on a strict need-to-know basis, multi-factor authentication for administrative systems, regular vulnerability scanning and penetration testing, and secure development practices that include security reviews as part of our software development lifecycle.

Organizational measures include mandatory data protection and security training for all employees and contractors, documented security policies and procedures, incident response plans that are tested and updated regularly, vendor risk assessment processes that evaluate the security practices of third-party service providers, confidentiality agreements with all personnel who have access to personal data, and periodic audits of our data processing activities and security controls. While we strive to protect your information, no method of electronic storage or transmission is one hundred percent secure, and we cannot guarantee absolute security against all possible threats.

9. Your Rights and Choices

Depending on your jurisdiction, you may have a number of rights regarding your personal information. These rights typically include the right to access your data and obtain a copy of the personal information we hold about you, the right to rectify or correct inaccurate or incomplete data, the right to request deletion of your personal data under certain circumstances, the right to restrict or object to the processing of your data, and the right to data portability, which allows you to receive your data in a structured, commonly used, and machine-readable format and to transmit it to another controller.

You may also have the right to withdraw consent at any time where processing is based on your consent, without affecting the lawfulness of processing that occurred before the withdrawal. Additionally, you may have the right not to be subject to automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you. To exercise any of these rights, please contact us using the contact details provided in Section 14 of this policy. We will respond to your request within the timeframes required by applicable law and may need to verify your identity before processing your request.

If you believe that our processing of your personal information violates applicable law, you have the right to lodge a complaint with the relevant supervisory authority or data protection regulator in your jurisdiction. We encourage you to contact us first so that we may address your concerns directly and resolve any issues promptly.

10. International Data Transfers

SourceSolid is headquartered in Kunming, China, and our operations may involve the transfer of personal data across international borders. If you are located outside of China and choose to provide information to us, your data may be transferred to, processed, and stored on servers located in China or other countries where we or our service providers maintain facilities. The data protection laws in these countries may differ from those in your jurisdiction and may not provide the same level of protection as the laws where you reside.

When we transfer personal data internationally, we implement appropriate safeguards to ensure that your information receives an adequate level of protection in accordance with this Privacy Policy and applicable law. These safeguards may include standard contractual clauses approved by relevant regulatory authorities, binding corporate rules for intra-group transfers, certification to recognized data protection frameworks, and contractual provisions that impose equivalent data protection obligations on the recipients of your information. By using our website and services and providing your information to us, you acknowledge and consent to the transfer, processing, and storage of your data in China and other countries as described in this policy.

11. Privacy for Children

Our website and services are not directed to or intended for individuals under the age of eighteen (18). We do not knowingly collect, use, or disclose personal information from children under eighteen. If we become aware that we have inadvertently collected personal data from a child under the age of eighteen without verifiable parental consent, we will take prompt steps to delete that information from our records and systems. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately using the contact details provided in this policy and we will work to address the situation without delay.

We encourage parents and guardians to monitor their childrens online activities and to instruct their children never to provide personal information through websites or online services without parental permission. We are committed to complying with the applicable provisions of childrens privacy laws, including the Childrens Online Privacy Protection Act (COPPA) in the United States and equivalent legislation in other jurisdictions, to the extent such laws apply to our operations.

12. Third-Party Services and Links

Our website may contain links to third-party websites, plugins, applications, and services that are not owned or controlled by SourceSolid. This Privacy Policy applies solely to information collected by our website and services. When you click on a link to a third-party site or engage with a third-party service, you will be subject to that third partys own terms, conditions, and privacy practices. We encourage you to review the privacy policies of every website and service you visit before providing any personal information to them.

We may integrate third-party services into our website to provide functionality such as analytics, embedded content, social media features, and payment processing. These third parties may collect information about your interactions with their services through cookies and other tracking technologies. We do not control these third-party tracking technologies or how they may be used. If you have questions about how a specific third-party service collects and uses your data, please consult the privacy policy of that third party directly. We assume no responsibility or liability for the content, privacy practices, or actions of any third-party sites or services linked to or from our website.

13. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, technologies, legal obligations, or operational requirements. When we make material changes to this policy, we will post the updated version on this page with a revised Last Updated date and, where appropriate, provide notice on our website homepage or through other communication channels such as email. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal information.

The updated Privacy Policy becomes effective as of the Last Updated date indicated at the top of this page. Your continued use of our website and services after any changes to this Privacy Policy constitutes your acceptance of the revised terms. If you do not agree with the updated policy, you should discontinue use of our website and services and contact us to request deletion of your personal information where applicable law allows.

14. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information below. We welcome your inquiries and are committed to addressing your privacy-related concerns promptly and transparently.

15. Additional Disclosures for Specific Jurisdictions

Depending on your country or state of residence, you may have additional privacy rights under local laws. Residents of the European Economic Area (EEA), the United Kingdom, and Switzerland have rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with a supervisory authority in your country. California residents may have rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to request deletion, and the right to opt out of the sale or sharing of personal information. We do not sell personal information as defined under the CCPA.

Residents of other jurisdictions, including Brazil under the Lei Geral de Protecao de Dados (LGPD), Canada under the Personal Information Protection and Electronic Documents Act (PIPEDA), Australia under the Privacy Act, and other countries with comprehensive data protection legislation, may have additional rights not described in this general policy. If you are a resident of one of these jurisdictions and would like to understand your full range of rights, please contact us and we will provide you with supplementary information tailored to your location. We are committed to respecting all applicable privacy laws and will work with you to honor your rights under the legal framework that governs your data.

16. Do Not Track Signals

Some web browsers offer a Do Not Track (DNT) setting that sends a signal to websites requesting that they not track your online activities. At this time, our website does not respond to DNT signals or similar mechanisms transmitted by web browsers. This is because there is no universally accepted standard for how websites should interpret and respond to such signals, and the mechanisms continue to evolve. We support industry efforts to develop a clear and enforceable framework for responding to DNT signals and will update our practices as those standards mature and become widely adopted.

In the meantime, you can exercise control over tracking through the cookie settings in your browser, as described in Section 5 of this policy. You may also use opt-out mechanisms provided by certain analytics and advertising industry groups, such as the Network Advertising Initiative and the Digital Advertising Alliance, to manage tracking preferences across multiple websites and services.

17. Data Breach Notification Procedures

We have established procedures for detecting, investigating, and responding to data security incidents. In the event of a data breach that affects your personal information, we will take immediate steps to contain the incident, assess the scope and impact of the breach, and implement measures to prevent further unauthorized access or disclosure. We maintain a detailed incident response plan that defines roles and responsibilities, communication protocols, and remediation steps.

If we determine that a breach poses a risk to your rights and freedoms, we will notify you and any relevant regulatory authorities in accordance with applicable legal requirements. Our notification will describe the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences of the breach, the measures we have taken or propose to take to address the breach, and the steps you can take to protect yourself. We will provide this notification without undue delay, as required by law, through the contact information we have on file and through other appropriate communication channels.