Privacy Policy
Online privacy protection
1. Introduction
1.1 Our Commitment to Your Privacy
CreaVe Kitchen & Bathroom Products Co., Ltd. (hereinafter referred to as the “Company,” “we,” “us,” or “our”) is dedicated to safeguarding the privacy of its valued business customers (hereinafter “Business Customer,” “you,” or “your”) and their authorized representatives. This Privacy Policy outlines the Company’s practices concerning the collection, use, disclosure, and protection of Personal Data. The Company prioritizes transparency in its data handling processes, recognizing that such transparency is fundamental to building and maintaining trust, particularly in business-to-business relationships. This commitment extends to ensuring that Business Customers understand how their information, and that of their representatives, is processed when interacting with our Services. This document serves as a comprehensive guide to these practices, reflecting our dedication to responsible data stewardship. The nature of B2B transactions means that while the “Business Customer” is often a legal entity, the Personal Data processed pertains to the individuals acting on behalf of that entity.
1.2 Scope of This Privacy Policy
This Privacy Policy applies to Personal Data collected from representatives of Business Customers through the Company’s B2B e-commerce website located at (the “Website”), and through other B2B interactions, including but not limited to direct communications, account management processes, and customer support services. It specifically pertains to individuals acting in their capacity as employees, directors, owners, independent contractors, agents, or other authorized representatives of a Business Customer engaging with the Company’s Services.
- This Privacy Policy does not extend to:
The Personal Data of the Company’s own employees or job applicants, which is governed by separate internal policies and notices. - Any consumer-facing interactions or services the Company might offer, which would be covered by a distinct consumer privacy policy.
- Data that does not constitute Personal Data, such as anonymous, de-identified, or aggregated data, where individuals are not identifiable.
Precisely defining the scope of this policy is essential to prevent ambiguity and to clearly delineate the Company’s obligations and the rights of data subjects within the B2B context. This focus ensures that the provisions herein are tailored to the specific nature of business-to-business data processing.
1.3 Definitions
For the purposes of this Privacy Policy, the following terms shall have the meanings ascribed to them below:
- Personal Data: Any information relating to an identified or identifiable natural person, particularly a representative, employee, or agent of a Business Customer. This includes, but is not limited to, names, business email addresses, business telephone numbers, job titles, and online identifiers collected in a B2B context. This definition aligns with the principles of major data protection regulations such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
- Business Customer: The legal entity (e.g., company, partnership, sole proprietorship, organization) that purchases sinks or utilizes the B2B Services offered by the Company.
- Services: The B2B e-commerce platform, the range of sinks offered for sale, product information, account management tools, customer support, and any other related services provided by the Company to Business Customers.
- Processing: Any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- Data Controller/Business: For the purposes of applicable data protection laws (e.g., GDPR, CCPA), CreaVe is the entity that determines the purposes and means of the processing of Personal Data covered by this Privacy Policy.
Clear definitions are foundational to any legal document, ensuring that all parties have a common understanding of the terms used throughout this Privacy Policy. This approach is consistent with the best practice of making legal documents accessible and comprehensible.
2. Information We Collect
The Company collects various types of Personal Data from Business Customers and their representatives to provide and improve its Services. This collection occurs through different channels and methods as detailed below. The types of data collected are pertinent to facilitating B2B transactions for sinks and managing the business relationship. B2B data encompasses a spectrum of information, including customer details, transaction figures, and operational statistics, all of which aid in effective decision-making and service delivery.
2.1 Information You Provide Directly to Us
This category includes Personal Data actively and voluntarily provided by representatives of Business Customers when interacting with the Company’s Services.
- Business Registration and Account Information: When a Business Customer registers for an account on the Website or B2B portal, the Company collects information necessary to establish and manage that account. This includes the Business Customer’s legal name, business type (e.g., corporation, partnership), tax identification numbers (where applicable for billing and compliance), primary business address(es), and shipping addresses. For individual representatives, the Company collects names, job titles, business email addresses, business telephone numbers, and credentials for accessing the B2B portal (e.g., username and a securely hashed password). This firmographic and contact data is essential for identifying and verifying Business Customers and their authorized users.
- Order and Transaction Information: When a Business Customer places an order for sinks, the Company collects details specific to that transaction. This includes descriptions and quantities of sinks ordered, negotiated pricing, shipping instructions (including the name and contact details of the person designated to receive the delivery at the specified location), billing information, and a comprehensive purchase history. This transactional data is crucial for order fulfillment, inventory management, and financial accounting.
- Payment Information: To process payments for orders, the Company collects payment details associated with the Business Customer. This may include business credit card numbers, cardholder names, expiration dates, CVV codes, bank account information for Automated Clearing House (ACH) or wire transfers, and the associated billing address. For security, full payment card details may be processed and tokenized by a third-party Payment Card Industry Data Security Standard (PCI-DSS) compliant payment processor, in which case the Company would only store a token or partial information.
- Communications: The Company retains records of communications with representatives of Business Customers. This includes copies of emails exchanged with sales, customer support, or technical teams; summaries or transcripts of phone calls (where recorded, this will be done with prior notification and consent if required by applicable law); and logs from chat sessions conducted via the B2B portal or other communication tools. This also encompasses responses to surveys, feedback forms, or product reviews submitted by Business Customer representatives.
- Marketing Preferences: The Company collects information regarding the preferences of Business Customer representatives for receiving marketing communications. This includes subscriptions to newsletters, product update notifications, or promotional materials, and any choices made to opt-in or opt-out of such communications.
The collection of this directly provided information is transparent and occurs with the active participation of the Business Customer’s representatives. This approach fosters trust and ensures that the data collected is relevant to the B2B relationship.
2.2 Information We Collect Automatically (When You Use Our Services)
When representatives of Business Customers access and use the Company’s Website or B2B portal, certain information is collected automatically through various technologies. This passively collected data helps the Company understand usage patterns, improve service functionality, and ensure security.
- Log Data and Device Information: The Company’s servers automatically record information (“Log Data”) created by the use of the Services. Log Data may include IP addresses, browser type and version, operating system, device identifiers (such as MAC address, if relevant for secure portal access or device-specific settings), the referring URL (the webpage visited before navigating to the Company’s Website), pages viewed on the B2B portal, features utilized, time spent on pages, and the dates and times of access.
- Usage Data: The Company collects information about how representatives of Business Customers interact with the B2B portal and its features. This includes search queries entered (e.g., for specific sink models or features), items added to the virtual shopping cart, clickstream data (the sequence of clicks and navigation paths), and interaction with specific functionalities or content. This intent and behavioral data helps in understanding user preferences and optimizing the portal experience.
- Cookies and Similar Tracking Technologies: The Company uses cookies, web beacons, pixel tags, and other similar technologies to collect information about browsing activities and preferences. These technologies are used for essential website functionality (e.g., maintaining login sessions, shopping cart persistence), performance analytics, and potentially for B2B-focused personalization or marketing efforts. A detailed explanation of the use of cookies and how to manage them is provided in Section 6 of this Privacy Policy.
- Geolocation Data (General): The Company may derive general geolocation information (e.g., city, country) from the IP addresses of devices accessing the Services. This information is used for aggregated analytics, service localization (such as displaying relevant currency or regional information), and for security purposes (e.g., identifying suspicious login attempts from unusual locations). The Company does not collect precise geolocation data (e.g., GPS coordinates) without obtaining explicit consent from the individual representative, and typically, such precise data is not required for the provision of its sink e-commerce services.
The automatic collection of this technical and usage data is crucial for maintaining the operational integrity of the Services, for security monitoring, and for gathering insights that lead to service improvements and a better user experience for Business Customers.
2.3 Information from Third-Party Sources
The Company may also obtain Personal Data relating to Business Customers and their representatives from third-party sources, in compliance with applicable laws.
- Credit Reference Agencies: If a Business Customer applies for credit terms to purchase sinks, the Company may obtain business credit reports and related information from credit reference agencies or financial institutions. This information is used to assess creditworthiness and manage financial risk. Such collection will be disclosed, and consent obtained where required.
- Publicly Available Sources: The Company may collect information from publicly accessible sources such as official company registries, business directories, corporate websites, and professional networking platforms (e.g., LinkedIn). This information, which may include company details and the names and business contact information of relevant professionals, can be used to verify Business Customer information, identify potential B2B leads, or supplement existing Business Customer records.
- Marketing and Sales Partners: The Company may receive business contact information and related data from third-party marketing services, lead generation vendors, or through participation in joint marketing events, trade shows, or industry conferences. Any such data obtained from partners will be processed in accordance with this Privacy Policy, and with appropriate notice and consent mechanisms where required by law.
Transparency regarding the collection of data from third-party sources is important. The Company endeavors to ensure that any third-party data is obtained lawfully and ethically, and is relevant to its B2B operations.
3. How We Use Your Information (Purposes of Processing)
The Company processes the Personal Data collected from Business Customers and their representatives for specific, legitimate business purposes. Each processing activity is linked to the provision, maintenance, and improvement of its B2B Services related to sinks, or to comply with legal and contractual obligations. The utilization of B2B data is aimed at enhancing decision-making, streamlining operations, improving customer experiences, and optimizing marketing efforts.
3.1 To Provide and Manage Our B2B Services
- Order Fulfillment: Processing orders placed by Business Customers for sinks, including verifying order details, coordinating manufacturing or stock allocation, and arranging for shipment and delivery to the specified address.
- Account Management: Creating and maintaining Business Customer accounts on the B2B portal, enabling access to order history, saved preferences, and other account-specific features. This includes administering the account of the Business Customer entity.
- Payment Processing: Facilitating and processing payments for purchased sinks, managing invoices, and handling billing inquiries or disputes.
- Customer Support: Providing customer service and technical assistance to Business Customer representatives, responding to inquiries about products, orders, account issues, or use of the B2B portal. This contributes to streamlining overall operations.
3.2 To Communicate with You
- Transactional Communications: Sending essential communications related to transactions and account activity. This includes order confirmations, shipping notifications, delivery updates, invoices, payment reminders, and service-related announcements (e.g., planned maintenance of the B2B portal).
- Responsive Communications: Responding to inquiries, requests for information (e.g., product specifications, quotes), feedback, or complaints submitted by representatives of Business Customers.
- Administrative Notices: Providing important information about the Services, such as updates to terms and conditions, changes to this Privacy Policy, or security alerts that may affect Business Customer accounts.
3.3 For Marketing and Promotional Purposes (B2B Focus)
- B2B Marketing Communications: Sending information about new sink models, product enhancements, special offers, promotions, industry news, or upcoming events that may be of interest to Business Customers. Such communications will be directed to business contacts and will provide clear options to opt-out or unsubscribe, or will be based on prior consent where required by applicable law (e.g., for new prospects in certain jurisdictions).
- Personalized Marketing: Tailoring marketing messages based on a Business Customer’s past purchase history, expressed interests (e.g., specific types or styles of sinks), or engagement with previous marketing content. This helps to ensure that communications are relevant and valuable.
3.4 For Analytics and Improvement of Our Services
- Usage Analysis: Analyzing how representatives of Business Customers use the B2B portal and interact with the Services. This includes tracking page views, feature usage, navigation patterns, and search queries to understand user needs, identify popular products, and pinpoint areas for improvement in website design, functionality, and user experience.
- Performance Monitoring: Monitoring the technical performance, stability, and security of the B2B portal and underlying systems to ensure they are operating effectively and to identify and resolve any issues.
- Research and Development: Conducting research and analysis based on aggregated and anonymized usage data and Business Customer feedback to inform the development of new sink products, services, or features that meet the evolving needs of B2B clients. This contributes to improved customer insights and operational efficiency.
3.5 For Security, Fraud Prevention, and Legal Compliance
- Identity Verification: Verifying the identity of Business Customer representatives to prevent unauthorized access to accounts and sensitive information.
- Fraud Detection and Prevention: Monitoring transactions and account activities for suspicious patterns to detect, prevent, and investigate potentially fraudulent activities, unauthorized use of the Services, or other illegal conduct.
- Protection of Rights and Safety: Protecting the legal rights, property, and safety of the Company, its Business Customers, its employees, and the public.
- Legal and Regulatory Compliance: Complying with applicable laws, regulations, court orders, subpoenas, or other lawful requests from government authorities. This includes obligations related to financial reporting, tax collection, and other regulatory requirements.
The clear articulation of these purposes for data collection and use is a fundamental requirement of data privacy laws. In the B2B context, these purposes are primarily centered on fulfilling contractual obligations, managing business relationships effectively, and pursuing legitimate business interests such as service improvement and targeted B2B marketing, all while respecting the data protection rights of individuals.
4. Legal Basis for Processing Your Information (Primarily for GDPR Compliance)
For Business Customers located in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, or where the General Data Protection Regulation (GDPR) or similar data protection laws apply, the Company processes Personal Data of their representatives based on specific legal grounds. Understanding these legal bases is crucial for ensuring lawful data processing. The B2B context often relies on “contractual necessity” and “legitimate interests” for many processing activities, while “consent” is paramount for others.
4.1 Contractual Necessity
A significant portion of the Personal Data processing is necessary for the Company to enter into or perform a contract with the Business Customer. This includes, for example:
- Processing orders for sinks, including collecting contact and shipping details of representatives to ensure delivery.
- Managing the Business Customer’s account on the B2B portal, which requires processing login credentials and contact information of authorized users.
- Processing payments and managing billing, which involves handling financial and contact information of the Business
- Customer’s representatives involved in procurement or finance.
4.2 Legitimate Interests:
The Company processes Personal Data of Business Customer representatives for its legitimate business interests, provided that these interests are not overridden by the fundamental rights and freedoms of the individuals whose data is being processed. Examples of processing based on legitimate interests include:
- Direct B2B marketing of similar products or services (e.g., new sink models or related accessories) to existing Business Customers, where permitted by applicable e-privacy regulations. This allows the Company to inform clients of relevant offerings.
- Analyzing usage of the B2B portal to improve its functionality, user experience, and the overall quality of Services offered to Business Customers.
Preventing fraud, ensuring the security of the Company’s IT systems and network, and protecting its assets. - Managing the ongoing relationship with the Business Customer, including communications regarding service updates or business developments.
- Conducting due diligence on prospective Business Customers to assess suitability and risk. When relying on legitimate interests, the Company conducts a balancing test to ensure that the processing is fair and proportionate.
4.3 Legal Obligation:
The Company may be required to process Personal Data of Business Customer representatives to comply with various legal and regulatory obligations to which it is subject. This can include:
- Maintaining financial records and processing transaction data for tax purposes and compliance with accounting standards.
- Responding to lawful requests for information from courts, law enforcement agencies, or other public authorities.
- Complying with industry-specific regulations, if applicable.
4.4 Consent:
In specific situations, the Company will rely on the explicit consent of the individual representative before processing their Personal Data. Consent will be sought when:
- Sending electronic marketing communications to representatives of new prospective Business Customers, where opt-in consent is required by applicable law (e.g., under GDPR ePrivacy rules).
- Deploying non-essential cookies and similar tracking technologies on the B2B portal (as detailed in Section 6.
- Processing sensitive Personal Data, if ever collected in the B2B context (though this is generally not the case for the Company’s standard operations). Consent must be freely given, specific, informed, and an unambiguous indication of the individual’s wishes. The Company aims to make the consent process clear and straightforward, avoiding pre-ticked boxes or bundling consent with other terms. Individuals have the right to withdraw their consent at any time for future processing, without affecting the lawfulness of processing based on consent before its withdrawal. Instructions for withdrawing consent will be clearly provided.
The Company is committed to ensuring that all Personal Data processing is founded on a valid legal basis, and to being transparent with Business Customers and their representatives about these bases.
5. How We Share and Disclose Your Information
The Company does not sell Personal Data of Business Customer representatives in the traditional sense of the word (i.e., for monetary payment). However, it may share or disclose such information with certain third parties under specific circumstances and for legitimate purposes, as outlined below.
Transparency about data sharing practices is a key component of building trust and complying with data protection regulations. All sharing is conducted with a focus on ethical and controlled data handling.
5.1 With Service Providers and Business Partners
The Company engages third-party vendors, suppliers, contractors, and service providers to perform various functions on its behalf and to assist in providing the Services to Business Customers. These service providers may have access to Personal Data of Business Customer representatives only to the extent necessary to perform their contracted services and are typically bound by contractual obligations to maintain the confidentiality and security of such data, and to use it only for the purposes for which it was disclosed by the Company. Examples include:
- Payment Processors: To securely process financial transactions for sink orders and manage payment card information in compliance with PCI-DSS.
- Shipping and Logistics Companies: To arrange for the transportation and delivery of sink orders to Business Customer locations.
- IT and Cloud Hosting Providers: For hosting the B2B Website and portal, storing data (including Personal Data), providing network infrastructure, and ensuring the operational availability of the Services.
- Customer Relationship Management (CRM) and Marketing Automation Platforms: To manage information about Business Customers, streamline communications, and facilitate B2B marketing campaigns.
- Analytics Providers: To assist in analyzing Website and portal usage, understanding user behavior, and generating reports to improve the Services.
- Credit Reference Agencies: If the Business Customer applies for credit terms, information may be shared with these agencies to assess creditworthiness (as mentioned in Section 2.3).
- Professional Advisors: Such as lawyers, auditors, and consultants, when necessary for them to provide their professional services to the Company.
5.2 In the Event of Business Transfers
If the Company is involved in a merger, acquisition, divestiture, financing, reorganization, bankruptcy, receivership, or sale of all or a portion of its business or assets, Personal Data of Business Customers and their representatives may be disclosed, shared, or transferred as part of that transaction or proceeding. Any such transfer would be subject to appropriate confidentiality arrangements and the acquirer would be expected to continue to honor the commitments made in this Privacy Policy or provide notice of any material changes.
5.3 To Comply with Legal Obligations and Protect Our Rights
The Company may disclose Personal Data of Business Customer representatives if it believes in good faith that such disclosure is necessary to:
- Comply with applicable laws, regulations, subpoenas, court orders, or other legal processes or governmental requests.
Enforce its B2B terms of service, contractual agreements with Business Customers, or other policies. - Protect the rights, property, or safety of the Company, its other Business Customers, its employees, or the public from harm or illegal activities.
- Detect, prevent, investigate, or otherwise address fraud, security vulnerabilities, or technical issues.
5.4 With Your Explicit Consent
Beyond the circumstances described above, the Company may share Personal Data of Business Customer representatives with other third parties if it has obtained the explicit and informed consent of the Business Customer or the relevant individual representative to do so.
5.5 Aggregated or De-Identified Information
The Company may share aggregated or de-identified information with third parties for various purposes, including analytics, research, industry reporting, or improving its Services. This type of information does not personally identify any individual representative or Business Customer and is therefore not considered Personal Data.
The Company exercises due diligence in selecting its service providers and aims to ensure that any sharing of Personal Data is done securely and in compliance with applicable data protection laws. The broad definitions of “sell” and “share” under laws like the CCPA require careful consideration, particularly concerning the use of analytics tools or advertising technologies that might involve an exchange of value for data, even if not direct monetary payment. The Company endeavors to be transparent about such practices.
6. Cookies and Other Tracking Technologies
The Company’s B2B Website and portal use cookies and other similar tracking technologies (such as web beacons or pixel tags) to enhance user experience, ensure functionality, analyze performance, and potentially support B2B marketing efforts. This section provides detailed information about these technologies and the choices available to Business Customer representatives regarding their use. Effective cookie management is essential for compliance with regulations like GDPR and ePrivacy directives, as well as CCPA/CPRA.
6.1 What are Cookies?
Cookies are small text files that are placed on a user’s computer or mobile device by a website when they visit it. They are widely used to make websites work, or work more efficiently, as well as to provide information to the owners of the site.
First-party cookies are set by the website the user is visiting directly (i.e., by CreaVe’s Website).
Third-party cookies are set by a domain other than the one the user is visiting, typically by partners who provide services like analytics or advertising. Web beacons (also known as pixel tags or clear GIFs) are tiny graphics with a unique identifier, similar in function to cookies, and are used to track the online movements of web users or to access cookies.
6.2 How We Use Cookies
The Company categorizes the cookies used on its B2B Website and portal by their purpose to provide clarity on their function :
- Strictly Necessary Cookies: These cookies are essential for the operation of the B2B Website and portal and cannot be disabled in our systems. They are usually only set in response to actions made by users which amount to a request for services, such as logging in, filling in forms (e.g., for sink orders), managing shopping cart contents, or maintaining security. While consent is not typically required for these cookies under most regulations, users should be informed of their use. Disabling these cookies through browser settings may cause some parts of the Website to not function properly.
- Performance/Analytics Cookies: These cookies allow the Company to count visits and traffic sources so it can measure and improve the performance of the B2B portal. They help to know which pages are the most and least popular, see how visitors move around the site, and identify any errors. For example, the Company may use services like Google Analytics (configured to anonymize IP addresses where feasible) to gather this information. All information these cookies collect is aggregated and therefore anonymous (or pseudonymized). If users do not allow these cookies, the Company will not know when they have visited the site and will not be able to monitor its performance as effectively.
- Functionality Cookies: These cookies enable the B2B Website and portal to provide enhanced functionality and personalization. They may be set by the Company or by third-party providers whose services have been added to the pages (e.g., a live chat feature). They allow the portal to remember choices made by representatives (such as username, language preference, or region) to provide a more tailored and convenient experience. If users do not allow these cookies, then some or all of these services may not function properly.
- Marketing/Targeting Cookies (B2B Context): These cookies may be set through the Company’s site by its advertising partners (if any). They may be used by those companies to build a profile of a Business Customer representative’s interests (based on browsing activity on the B2B portal and potentially other sites) and show relevant B2B advertisements on other platforms. This is less common for a specialized B2B sink e-commerce site but will be clearly disclosed if applicable. These cookies do not directly store personal information but are based on uniquely identifying the browser and internet device. Consent is typically required for these cookies.
6.3 Your Choices and How to Manage Cookies
The Company provides Business Customer representatives with choices regarding the use of cookies and similar technologies.
- Cookie Consent Banner/Tool: Upon first visiting the B2B Website or portal, users (especially those from jurisdictions requiring explicit consent, like the EEA/UK) will be presented with a cookie consent banner or management tool. This tool will provide clear information about the types of cookies used and allow users to accept all cookies, reject non-essential cookies, or customize their cookie preferences by category. Strictly necessary cookies cannot be opted out of via this tool as they are essential for site functionality.
- Browser Settings: Most web browsers allow some control of most cookies through the browser settings. Users can typically configure their browser to block all cookies, accept only first-party cookies, or delete cookies already set. Information on how to manage cookies can usually be found in the browser’s help section or on the browser developer’s website.
- Opt-Out Links for Third-Party Services: For specific third-party services like Google Analytics, users can often opt-out directly via tools provided by those services (e.g., the Google Analytics Opt-out Browser Add-on). The Company will provide links to such tools where applicable. It is important to note that if users choose to block or delete cookies, particularly strictly necessary or functionality cookies, some parts of the B2B Website and portal may not function correctly or their experience may be impaired. The Company is committed to respecting user choices regarding cookies and ensuring that consent mechanisms are user-friendly and compliant with applicable laws.
7. Data Security
The Company takes the security of Personal Data collected from Business Customer representatives very seriously and implements a range of measures designed to protect it from unauthorized access, use, disclosure, alteration, or destruction. These measures are regularly reviewed and updated to address evolving threats and technological advancements.
7.1 Our Security Measures
The Company employs appropriate administrative, technical, and physical safeguards to protect Personal Data. While no system can be guaranteed to be 100% secure, the Company strives to use commercially reasonable measures. These safeguards include, but are not limited to:
- Encryption: Using encryption technologies, such as Secure Socket Layer (SSL)/Transport Layer Security (TLS), to protect Personal Data during transmission over the internet (e.g., when submitting information through the B2B portal). Data at rest (stored on servers) may also be encrypted where appropriate for its sensitivity.
- Access Controls: Implementing strict access controls to limit access to Personal Data to authorized personnel who have a legitimate business need to access it. This includes role-based access permissions and authentication mechanisms such as strong password policies. The use of multi-factor authentication (MFA) for accessing sensitive systems or the B2B portal is encouraged and may be implemented where feasible.
- Network Security: Utilizing firewalls, intrusion detection and prevention systems, and other network security measures to protect against unauthorized access to the Company’s IT infrastructure.
- Regular Security Assessments: Conducting periodic security assessments, vulnerability scanning, and penetration testing (where appropriate) to identify and address potential security weaknesses.
- Employee Training and Awareness: Providing regular data security and privacy training to employees who handle Personal Data, to ensure they understand their responsibilities and follow established security protocols.
- Secure Data Centers/Cloud Environments: Utilizing reputable data center providers or cloud service providers that maintain high standards of physical and environmental security for their facilities.
- Incident Response Plan: Maintaining an incident response plan to address any potential data breaches or security incidents in a timely and effective manner.
7.2 Your Responsibility
While the Company takes extensive measures to protect Personal Data, Business Customers and their representatives also play a role in maintaining security. It is the responsibility of each authorized representative to safeguard their account login credentials (username and password) for the B2B portal, to choose strong, unique passwords, and to notify the Company immediately of any suspected unauthorized access to their account.
7.3 Disclaimer
Despite the Company’s efforts to protect Personal Data, it is important to acknowledge that no method of transmission over the Internet or method of electronic storage is entirely secure. Therefore, while the Company strives to use commercially acceptable means to protect Personal Data, it cannot guarantee its absolute security.
The Company is committed to maintaining robust security practices to foster trust and confidence among its Business Customers.
8. International Data Transfers
As a business that may operate with global reach or utilize service providers located in various countries, the Company may transfer Personal Data of Business Customer representatives across international borders. This section outlines how such transfers are handled, particularly concerning data originating from regions with specific data protection requirements like the European Economic Area (EEA), the United Kingdom (UK), and Switzerland.
8.1 Cross-Border Transfers
Personal Data collected by the Company may be stored and processed in any country where the Company or its affiliates, subsidiaries, or third-party service providers maintain facilities. This means that Personal Data of Business Customer representatives may be transferred to, and processed in, countries outside of their country of residence, including countries that may not have data protection laws equivalent to those in their own jurisdiction (e.g., transfers from the EEA/UK to the United States).
8.2 Safeguards for International Transfers
When the Company transfers Personal Data originating from the EEA, UK, or Switzerland to a country outside of these regions that has not been deemed by the European Commission (or the relevant UK/Swiss authorities) to provide an adequate level of data protection, it will implement appropriate safeguards to ensure that the Personal Data remains protected in accordance with applicable data protection laws. These safeguards may include:
- Standard Contractual Clauses (SCCs): Utilizing SCCs approved by the European Commission (or their UK/Swiss equivalents) as a legal mechanism for transferring Personal Data to third countries. These clauses impose contractual obligations on the data importer to protect the Personal Data to a standard comparable to that required within the EEA/UK/Switzerland.
- Adequacy Decisions: Relying on adequacy decisions made by the European Commission (or relevant UK/Swiss authorities) which recognize that certain countries provide an adequate level of data protection.
- Binding Corporate Rules (BCRs): For intra-group transfers, BCRs approved by competent data protection authorities may be used, if applicable to the Company’s structure.
- Other Legal Mechanisms: Employing other transfer mechanisms permitted under applicable data protection laws, such as obtaining explicit consent for specific transfers after informing the individual of the risks, or where the transfer is necessary for the performance of a contract with the Business Customer or for important reasons of public interest.
The Company is committed to ensuring that any international transfers of Personal Data are conducted lawfully and with appropriate measures in place to protect the privacy and security of that data. Business Customers or their representatives seeking more information about the specific safeguards applied to their Personal Data can contact the Company using the details provided in Section 15.
9. Data Retention
The Company retains Personal Data of Business Customer representatives only for as long as necessary to fulfill the purposes for which it was collected, as outlined in this Privacy Policy, or as required or permitted by applicable law. The principle of data minimization guides the Company’s retention practices, meaning that Personal Data is not kept longer than it is needed.
9.1 Retention Periods
The specific retention period for different categories of Personal Data will vary depending on the nature of the data and the purposes for its processing. The Company will not retain Personal Data indefinitely. Once Personal Data is no longer necessary for its intended purpose, and there is no legal or regulatory obligation to retain it, it will be securely deleted or anonymized.
9.2 Criteria for Determining Retention
The Company uses the following criteria to determine appropriate retention periods for Personal Data:
- Duration of the B2B Relationship: Personal Data related to a Business Customer’s account and transactions will generally be retained for the duration of the active business relationship with that Customer.
Legal and Regulatory - Obligations: Many laws and regulations require the retention of certain types of data for specific periods. For example, financial records, transaction data, and tax-related information must often be kept for several years to comply with legal obligations (e.g., typically 7-10 years for financial records in many jurisdictions).
- Resolution of Disputes and Enforcement of Agreements: Personal Data may be retained for as long as necessary to resolve potential disputes, enforce the Company’s contractual agreements (e.g., terms of service with Business Customers), or to defend or establish legal claims.
- Nature and Sensitivity of the Personal Data: More sensitive Personal Data may be subject to shorter retention periods or require more stringent anonymization or deletion protocols once its primary purpose is fulfilled.
- Operational Needs: Some data may be retained for a reasonable period for operational purposes, such as for backup and recovery, system audits, or to ensure business continuity.
For example:
- Business Customer account information (e.g., contact details, company information) will typically be retained for the duration of the business relationship and for a defined period thereafter to address any post-termination inquiries or legal requirements.
- Transaction data related to sink purchases (invoices, order details) will be retained in accordance with applicable financial and tax regulations.
- Website/portal usage data collected for analytics purposes (e.g., via cookies) may be retained for a shorter period (e.g., 26 months for Google Analytics data, or as specified in the cookie policy) before being aggregated or anonymized.
- Marketing preferences and consent records will be retained as long as the marketing relationship is active or until consent is withdrawn, and for a period thereafter to demonstrate compliance.
The Company is committed to regularly reviewing its data retention practices to ensure that Personal Data is not held for longer than necessary.
10. Your Data Protection Rights
The Company recognizes and respects the data protection rights of individuals, including the representatives of its Business Customers. Depending on the individual’s location and the applicable data protection laws (such as GDPR or CCPA/CPRA), these representatives may have certain rights concerning their Personal Data held by the Company. This section outlines these general rights. Specific provisions for key jurisdictions are detailed further in Section 11.
10.1 General Rights
Subject to applicable legal limitations and requirements, representatives of Business Customers may have the following rights regarding their Personal Data:
- Right to Access: The right to request confirmation as to whether the Company processes their Personal Data and, if so, to request access to that Personal Data and certain information about how it is processed.
- Right to Rectification: The right to request the correction of any inaccurate or incomplete Personal Data that the Company holds about them.
- Right to Erasure (Right to be Forgotten): The right to request the deletion of their Personal Data under certain conditions, for example, if the data is no longer necessary for the purposes for which it was collected, or if consent is withdrawn and there is no other legal ground for processing.
- Right to Restrict Processing: The right to request that the Company restrict the processing of their Personal Data under certain circumstances, such as if the accuracy of the data is contested or the processing is unlawful.
- Right to Data Portability: The right to receive the Personal Data they have provided to the Company in a structured, commonly used, and machine-readable format, and the right to transmit that data to another data controller without hindrance from the Company, where the processing is based on consent or a contract and is carried out by automated means.
- Right to Object: The right to object to the processing of their Personal Data under certain conditions, particularly where the processing is based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: If the processing of their Personal Data is based on their consent, the right to withdraw that consent at any time. The withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
Rights Related to Automated - Decision-Making: The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, except under certain conditions.
10.2 How to Exercise Your Rights
Representatives of Business Customers who wish to exercise any of these rights should contact the Company using the contact details provided in Section 15 of this Privacy Policy (e.g., via a dedicated email address such as [email protected], a contact form on the B2B portal, or by mail).
To protect Personal Data and ensure that requests are legitimate, the Company may need to verify the identity of the individual making the request before processing it. This may involve asking for specific information to confirm identity, such as details related to their business relationship with the Company.
The Company will respond to verifiable requests within the timeframes required by applicable data protection law. In some cases, the Company may be unable to fulfill a request (or parts of it) due to legal obligations or other permissible exemptions. If a request is denied, the Company will provide an explanation for the decision, where legally permitted.
Empowering users by clearly listing their rights and providing a straightforward process for exercising them is fundamental for compliance and for fostering a transparent and trustworthy relationship with Business Customers. It is important to clarify that these rights apply to the individual representatives of the client company concerning their own Personal Data processed by the Company.
11. Specific Provisions for Key Jurisdictions
While the Company aims to provide a high standard of privacy protection to all Business Customers and their representatives, certain jurisdictions have specific legal requirements that necessitate additional disclosures or confer particular rights.
11.1 Notice to California Residents (CCPA/CPRA)
This section provides additional information for residents of California, as required by the California Consumer Privacy Act of 2018 (CCPA) and as amended by the California Privacy Rights Act (CPRA). This notice applies to Personal Information of B2B contacts who are California residents. The CCPA applies to businesses that meet certain thresholds, such as having annual gross revenues over $25 million, buying, selling, or sharing the personal information of 100,000 or more consumers or households, or deriving 50% or more of their annual revenues from selling or sharing consumers’ personal information. The Company will assess its obligations under these thresholds.
Categories of Personal Information Collected, Disclosed, “Sold,” or “Shared”:
The categories of Personal Information the Company collects from California B2B contacts are generally described in Section 2 (“Information We Collect”). The categories of third parties with whom this information may be disclosed are described in Section 5 (“How We Share and Disclose Your Information”).
Under the CCPA, “sell” is broadly defined and includes exchanging Personal Information for monetary or other valuable consideration. “Share” is defined as disclosing Personal Information to a third party for cross-context behavioral advertising. The Company does not “sell” Personal Information of B2B contacts in the traditional sense of exchanging it for money. However, the use of certain third-party cookies for analytics or B2B-focused advertising (if any) might be considered “sharing” under the CCPA’s definition. The Company will provide necessary opt-out mechanisms if its practices fall under these definitions.
- Your California Privacy Rights:
California residents who are B2B contacts have the following rights regarding their Personal Information, subject to certain exceptions: - Right to Know/Access: The right to request information about the categories and specific pieces of Personal Information the Company has collected about them; the categories of sources from which the Personal Information is collected; the business or commercial purposes for collecting, selling, or sharing Personal Information; the categories of third parties to whom the Company discloses, sells, or shares Personal Information; and the categories of Personal Information that the Company sold or shared.
- Right to Delete: The right to request the deletion of their Personal Information that the Company has collected, subject to certain exceptions (e.g., if the information is necessary to complete a transaction, detect security incidents, or comply with a legal obligation).
- Right to Correct: The right to request the correction of inaccurate Personal Information that the Company maintains about them.
- Right to Opt-Out of Sale/Sharing: If the Company is deemed to “sell” or “share” Personal Information as defined by the CCPA, California B2B contacts have the right to opt-out of such sale or sharing. The Company will provide a clear and conspicuous link titled “Do Not Sell or Share My Personal Information” on its Website if this right is applicable to its practices.
- Right to Limit Use and Disclosure of Sensitive Personal Information (SPI): California B2B contacts have the right to limit the Company’s use and disclosure of their SPI to that which is necessary to perform the services or provide the goods reasonably expected by an average consumer, or for other permitted purposes under the CCPA. For B2B contacts, SPI collected might include account login credentials for the B2B portal. The Company generally does not collect other types of SPI from B2B contacts, such as racial or ethnic origin, religious beliefs, or union membership, in the course of its standard B2B operations.
- Right to Non-Discrimination: The right not to be discriminated against for exercising any of their CCPA privacy rights. This means the Company will not deny goods or services, charge different prices, or provide a different level or quality of goods or services because a B2B contact exercised their rights.
- How to Exercise California Rights:
California B2B contacts can exercise their rights by contacting the Company as described in Section 10.2. For CCPA-specific requests, a toll-free telephone number may also be provided if required by the CCPA thresholds. - Authorized Agents:
California B2B contacts may use an authorized agent to submit requests on their behalf. If an authorized agent is used, the Company may require proof of the agent’s authorization (e.g., a signed permission form or power of attorney) and may also need to verify the B2B contact’s identity directly.
The CCPA’s provisions, particularly its broad definitions of “sell” and “share,” necessitate careful consideration for B2B data handling. The Company is committed to meeting its obligations under this landmark legislation.
11.2 Notice to Residents of the European Economic Area (EEA), United Kingdom (UK), and Switzerland (GDPR)
For representatives of Business Customers located in the EEA, UK, or Switzerland, this section provides additional information relevant to the General Data Protection Regulation (GDPR) and its UK/Swiss equivalents.
- Data Controller: The Data Controller for the processing of Personal Data described in this Privacy Policy is CreaVe, with contact details provided in Section 15. If the Company has appointed a Data Protection Officer (DPO), their contact details will also be available.
- Legal Basis for Processing: As detailed in Section 4, the Company processes Personal Data of representatives from these regions based on lawful grounds such as contractual necessity, legitimate interests, legal obligation, or consent.
- Data Protection Rights: Representatives of Business Customers in the EEA, UK, and Switzerland have the rights outlined in Section 10.1 (e.g., access, rectification, erasure, restriction, portability, objection, withdrawal of consent).
- International Transfers: Information regarding the transfer of Personal Data outside the EEA, UK, or Switzerland and the safeguards implemented is provided in Section 8.
- Right to Lodge a Complaint: Representatives of Business Customers in these regions have the right to lodge a complaint with a supervisory authority (Data Protection Authority) in their Member State of habitual residence, place of work, or place of the alleged infringement if they believe that the Company’s processing of their Personal Data infringes the GDPR or applicable local data protection laws. A list of national Data Protection Authorities in the EEA can be found on the European Data Protection Board’s website.
The GDPR sets a high standard for data protection globally, and the Company is committed to upholding these principles in its interactions with Business Customers from these regions.
12. Children’s Privacy
The Company’s B2B Services are designed and intended for use by businesses and their adult representatives. They are not directed at or intended for children.
12.1 Not Directed to Children
The Company’s B2B Website, portal, and Services are not directed to individuals under the age of 13 (or a higher age threshold if stipulated by local law, such as 16 in some EEA countries for GDPR consent purposes). The Children’s Online Privacy Protection Act (COPPA) in the United States imposes specific requirements on operators of websites or online services directed to children under 13, or those who have actual knowledge of collecting personal information from children under 13. Given the B2B nature of the Company’s sink e-commerce operations, these services are not targeted at children.
12.2 No Knowing Collection
The Company does not knowingly collect Personal Data from children. If the Company becomes aware that it has inadvertently collected Personal Data from a child without verifiable parental consent (where required), it will take commercially reasonable steps to delete such information from its records promptly. If a parent or legal guardian believes that their child has provided Personal Data to the Company without their consent, they should contact the Company using the details provided in Section 15 so that appropriate action can be taken.
While COPPA compliance is a significant consideration for many online services, it is generally not a primary focus for a strictly B2B e-commerce platform selling industrial or commercial goods like sinks. Nevertheless, a clear statement disclaiming any intent to collect children’s data is a standard and prudent practice.
13. Third-Party Links
The Company’s B2B Website or portal may contain links to external websites or services that are not owned, operated, or controlled by the Company.
13.1 External Websites
This Privacy Policy applies only to the Company’s B2B Services and the Personal Data it collects. It does not apply to the practices of third-party websites or services that may be linked from the Company’s Website or portal. The Company is not responsible for the privacy practices, content, or security of these external sites. Business Customer representatives are encouraged to review the privacy policies and terms of service of any third-party websites or services they visit before providing any Personal Data to them. This standard disclaimer helps to manage expectations and limit the Company’s liability concerning the data practices of external entities.
14. Changes to This Privacy Policy
This Privacy Policy is a living document and may be updated periodically to reflect changes in the Company’s data processing practices, the Services offered, or applicable legal and regulatory requirements.
14.1 Policy Updates
The Company reserves the right to modify or amend this Privacy Policy at any time. Any changes will be effective immediately upon posting the revised Privacy Policy on the B2B Website or portal.
14.2 Notification of Changes
The “Effective Date” displayed at the top of this Privacy Policy indicates when it was last revised. For material changes to this Privacy Policy (e.g., changes that significantly alter how Personal Data is used or shared), the Company will provide prominent notice to Business Customers. This may include posting a notification on the B2B portal, sending an email communication to the primary account administrators of Business Customers, or using other appropriate communication channels. Business Customers and their representatives are encouraged to review this Privacy Policy periodically to stay informed about how the Company collects, uses, and protects Personal Data. Continued use of the Services after any such changes take effect will constitute acceptance of the revised Privacy Policy, for new data collected thereafter. Changes will not apply retroactively to previously collected data without consent, where required by law. Clear communication regarding updates to privacy practices is crucial for maintaining transparency and trust.
15. Contact Us
The Company is committed to addressing any questions, concerns, or requests regarding this Privacy Policy or its data practices in a timely and transparent manner. Accessible contact information is essential for individuals to exercise their rights and for the Company to demonstrate accountability.
15.1 How to Reach Us
If a Business Customer or its representatives have any questions about this Privacy Policy, wish to exercise their data protection rights, or have any concerns about the Company’s handling of Personal Data, they may contact the Company through one of the following channels:
Email: [email protected]
Mailing Address: Room 406, Building A, Juntaihao Park, No. 67 Qiguan West Road, East District, Zhongshan City, Guangdong Province, China
Phone Number: +86 760 8822 8560
The Company will endeavor to respond to all legitimate inquiries and requests in accordance with applicable legal requirements and within the prescribed timeframes.