Privacy Policy
Effective Date: 1 January 2025 | Last Updated: 15 March 2025
Silk Path — operated by Zhijiang Sugai Trading Co., Ltd. — respects your privacy and is committed to protecting the personal data you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.
Our registered office is located at No. 13, Group 1, Zhangjiawan Village, Xiannu Town, Zhijiang City, Yichang City, 443000, China. We operate in the field of Computer Systems Design and Related Services. Please read this policy carefully to understand our views and practices regarding your personal data.
1. Scope & Applicability
This Privacy Policy applies to all users of the Silk Path website, its subdomains, and any related services offered by Zhijiang Sugai Trading Co., Ltd. It covers personal data collected through online forms, email communications, support requests, and automated technologies such as cookies and analytics.
If you are a resident of the European Economic Area (EEA), the United Kingdom, or California, additional rights and protections may apply to you under the GDPR or CCPA respectively. We have outlined these rights in Section 10.
2. Data We Collect
We may collect, store, and process the following categories of personal data:
- Identity Data: full name, job title, company name, username or similar identifier.
- Contact Data: email address, phone number, billing address, and physical address.
- Technical Data: IP address, browser type and version, time zone setting, operating system and platform, device identifiers, and other diagnostic data.
- Usage Data: information about how you interact with our website, including pages visited, clickstream data, referral URLs, and session duration.
- Communication Data: any correspondence you send to us via email, contact forms, or support channels, including recordings if applicable.
- Marketing Data: your preferences in receiving marketing from us and your communication preferences.
We do not collect sensitive categories of personal data (such as race, religion, health data, or biometric information) unless you voluntarily provide it and explicitly consent.
3. How We Collect Your Data
We collect personal data through the following methods:
- Direct interactions: when you fill out a contact form, subscribe to a newsletter, create an account, request a quote, or communicate with us via email or phone.
- Automated technologies: as you navigate our website, we automatically collect Technical Data and Usage Data using cookies, server logs, and similar tracking technologies. See Section 7 for details.
- Third-party sources: we may receive data from analytics providers (such as Google Analytics), advertising networks, and public databases, but only where those parties have a lawful basis to share that information.
4. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we rely on the following lawful bases for processing your personal data:
- Consent: where you have given clear consent for us to process your data for a specific purpose (e.g., marketing emails). You have the right to withdraw consent at any time.
- Contractual necessity: processing is necessary to perform a contract with you or to take steps at your request before entering into a contract (e.g., providing a service you requested).
- Legal obligation: processing is necessary to comply with a legal or regulatory obligation (e.g., tax reporting, fraud prevention).
- Legitimate interests: processing is necessary for our legitimate business interests or those of a third party, provided your rights and freedoms do not override those interests. Our legitimate interests include improving our website, analyzing usage patterns, and ensuring network security.
5. How We Use Your Data
We use the data we collect for the following purposes:
- To provide, operate, and maintain our website and services.
- To respond to your inquiries, support requests, and feedback.
- To process orders, invoices, and payments where applicable.
- To send administrative information, including changes to our terms or policies.
- To send marketing and promotional communications only where you have opted in, with the option to unsubscribe at any time.
- To analyze usage trends and improve user experience.
- To detect, prevent, and address technical issues, fraud, or security incidents.
- To comply with applicable legal obligations and regulatory requirements.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS/SSL protocols.
- Secure server infrastructure with firewalls and intrusion detection systems.
- Access controls and authentication mechanisms for our staff.
- Regular security audits and penetration testing.
- Staff training on data protection and privacy best practices.
While we strive to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to take precautions to protect your personal data when online.
9. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements. Specific retention periods are as follows:
- Contact and communication data: retained for the duration of our relationship plus 2 years after the last interaction, unless a longer period is required by law.
- Technical and usage data: retained for a period of 26 months from the date of collection, after which it is anonymized or deleted.
- Marketing data: retained until you withdraw consent or unsubscribe, plus a grace period of 30 days to process the request.
- Data subject to legal obligations: retained for the period required by applicable tax, accounting, or regulatory frameworks (typically 5 to 7 years).
When data is no longer needed, we securely destroy or anonymize it to prevent unauthorized access.
10. Your Rights — GDPR & CCPA
If you are in the EEA or UK (GDPR)
You have the following rights under the General Data Protection Regulation:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your data where there is no compelling reason for continued processing.
- Right to restrict processing: request that we limit how we use your data in certain circumstances.
- Right to data portability: request a structured, machine-readable copy of your data to transfer to another controller.
- Right to object: object to processing based on legitimate interests, including direct marketing.
- Rights related to automated decision-making: request human intervention or contest decisions made solely by automated means.
To exercise any of these rights, please contact us using the details in Section 14. We will respond within one month (or sooner) and may require proof of identity.
If you are in California (CCPA)
Under the California Consumer Privacy Act (CCPA), California residents have the right to:
- Know: request disclosure of the categories and specific pieces of personal data we have collected about you.
- Delete: request deletion of personal data we have collected, subject to certain exceptions.
- Opt-out: direct us not to sell your personal data. We do not sell personal data as defined by the CCPA.
- Non-discrimination: exercise your rights without fear of discriminatory treatment.
To make a CCPA request, please email us at thorpe@silkpath.hair or call +8618021061990. We will verify your identity before processing the request.
11. International Transfers
Your personal data may be transferred to, stored, and processed in countries outside your country of residence, including China, where our servers and service providers are located. These countries may have data protection laws that differ from those in your jurisdiction.
When we transfer data from the EEA or UK to countries that have not been deemed adequate by the European Commission, we rely on appropriate safeguards, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Binding Corporate Rules (where applicable).
- Other valid transfer mechanisms recognized under applicable law.
By using our website and services, you acknowledge and consent to the transfer of your data as described above. If you have questions about the safeguards we use, please contact us.
12. Children's Privacy
Our services are not intended for individuals under the age of 16 (or the relevant age of digital consent in your country). We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data without verifiable parental consent, we will delete that information promptly.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at thorpe@silkpath.hair.
13. Changes to This Policy
We reserve the right to update or modify this Privacy Policy at any time. When we make changes, we will revise the Last Updated date at the top of this page. In the case of material changes, we will notify you via email (if we have your contact information) or by posting a prominent notice on our website.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data. Your continued use of our website after any changes constitutes your acceptance of the revised policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Point of Contact:
Zhijiang Sugai Trading Co., Ltd.
No. 13, Group 1, Zhangjiawan Village, Xiannu Town, Zhijiang City
Yichang City, 443000, China
Email: thorpe@silkpath.hair
Phone: +86 180 2106 1990
Business hours: Monday to Friday, 09:00 – 18:00 (China Standard Time)
You also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated. We encourage you to contact us first so we can resolve any issue directly.