1. Introduction and Scope

This Privacy Policy applies to all personal information that we process in the course of our business. The business of the Company is computer systems design and related services, including computer integrated systems design, platform engineering, data services, integration, security and technical support. We deliver these services to business clients and to individuals who visit our website or use the software that we build and operate.

We treat privacy as a design consideration rather than a compliance chore. Every system we build starts with a clear picture of which data is needed, why it is needed, how long it must be kept and who may access it. This policy reflects that approach and explains the practical details of how personal information flows through our operations.

When this policy uses the term personal information, it means any information relating to an identified or identifiable natural person. Information that has been aggregated or de-identified in such a way that it can no longer be linked to a natural person is not treated as personal information under this policy, and we may use such aggregated data freely for analysis, reporting and product improvement.

This policy covers the website available at https://www.zhuocuo.lat, the contact and support channels we operate, and the software platforms that we develop and maintain for our clients. Where a client operates its own privacy policy on top of the systems we build, that policy governs the client relationship, while this policy governs our own direct interactions with you.

2. Information You Provide Directly

When you interact with our website, we collect information that you choose to give us. The most common example is the contact form on our Contact page, where you may submit your name, your email address, a subject line and a message. We use that information solely to respond to your enquiry, to follow up on the topic you raised and to provide the assistance you requested.

If you contact us by email at reply@zhuocuo.lat or by telephone at +13253862315, we may receive your email address, your phone number and the content of your communication. We keep records of these communications so that we can provide continuity of service and so that we can document the history of a support request or a commercial discussion.

In the course of a client engagement, you or your organization may share additional information with us, including business contact details, technical specifications, system access credentials and operational data needed to design, build and maintain the relevant systems. We process this information on the instructions of the client organization and subject to the terms of the applicable services agreement.

We do not ask you to provide sensitive categories of personal information such as health records, biometric data or political opinions, and we ask that you avoid sending such information through our contact channels unless it is strictly necessary for the service you are requesting.

3. Information Collected Automatically

When you visit our website, certain information is collected automatically by the technology that serves the site. This includes your internet protocol address, the type of browser you use, the type of device you use, your operating system, the pages you view, the time and date of your visit, the referring website that brought you to us and approximate geographic location derived from your internet protocol address.

We collect this information for the legitimate purposes of operating the website, diagnosing technical faults, defending against malicious traffic and understanding how visitors use the site. Log data is held for a limited period and is not combined with the personal information we hold about you for any purpose unrelated to the operation and security of the website.

Like most websites, we use standard server logs and minimal cookies to support the reliable delivery of content. We do not run advertising networks on this site, and we do not sell browsing data to third parties. Any analytics that we apply are configured to respect your privacy and to avoid the unnecessary collection of identifying details.

If your browser sends a do not track signal, we treat it with respect by limiting the non-essential tracking that occurs on the site. Because our data practices are deliberately minimal, the effect of such a signal on your experience is limited, but we nonetheless honor the intent behind it.

4. Information from Other Sources

In addition to information you provide directly and information collected automatically, we may receive information about you from other sources. The most important source is your organization. When an employer or business partner engages us to build or maintain a system, that organization may provide us with contact details of the individuals who will interact with the system, such as administrators, operators and authorized users.

We may also receive professional information from public business registries, professional networking platforms and publicly available corporate filings, where such information is necessary to establish a business relationship or to verify the identity of a commercial counterparty. We use this information only for the purpose for which it was obtained.

If you participate in a technical review, a support call or a training session, we may keep notes and records of that interaction. These records help us deliver consistent support and help us avoid asking the same questions repeatedly across different members of our team.

When we receive information about you from a third party, we process it in accordance with this policy and we treat the source of the information as an additional safeguard on the accuracy and lawfulness of what we receive.

5. How We Use Your Information

We use the personal information we collect for a defined set of purposes that are directly related to our business. First, we use it to respond to enquiries, to answer support questions and to deliver the professional services that clients have requested. Without the ability to contact you, we would be unable to provide the services that are the purpose of our business.

Second, we use personal information to operate and maintain the systems and platforms we build, including authentication, access control, audit logging and incident response. These activities protect both our clients and the individuals whose data flows through the systems we operate.

Third, we use aggregated and de-identified information to improve our services, to measure performance, to produce reports and to plan capacity. This analysis never seeks to single out an individual and is designed around the operational questions of the business rather than the profiling of visitors.

Fourth, we use contact information to send service notices, security advisories and important updates that are necessary for the proper use of our services. We may also send occasional business communications where we have a legitimate interest in doing so, and you may always ask us to stop sending those communications.

We do not use your personal information for purposes that are materially different from those described in this policy without first notifying you and, where required by law, obtaining your consent.

6. Legal Basis for Processing

Our processing of personal information is supported by clear legal grounds under applicable data protection law. Where the law requires a lawful basis, we rely on the following. First, we process information where it is necessary to perform a contract with you or to take steps at your request before entering into a contract, such as when we deliver services under an agreement with your organization.

Second, we process information where it is necessary to comply with a legal obligation that applies to us, such as accounting, tax and regulatory record-keeping requirements that apply to our business.

Third, we process information where we have a legitimate interest that is not overridden by your rights and interests. Our legitimate interests include operating our business, responding to enquiries, securing our systems, preventing fraud and abuse, and improving the quality of our services. We balance these interests carefully against your expectations of privacy.

Fourth, where we rely on consent, we obtain your consent before the relevant processing begins, and you may withdraw that consent at any time by contacting us using the details at the end of this policy. Withdrawal of consent does not affect the lawfulness of processing that took place before the withdrawal.

7. How We Share Your Information

We do not sell, rent or trade your personal information to any third party. Sharing of personal information occurs only in the limited circumstances described in this policy, and every sharing arrangement is governed by contractual obligations that protect your information.

We may share personal information with the developer ZhuoCuo and with our affiliated entities where necessary to provide the services you have requested. This internal sharing is limited to the personnel who need the information to perform their duties, and all such personnel are bound by confidentiality obligations.

We may share personal information with regulators, law enforcement authorities and other government bodies where we are required to do so by law, by a court order or by an official request that we have determined to be lawful. Where possible and lawful, we will inform you of such a request before responding.

In the event of a merger, acquisition, reorganization or sale of assets, personal information may be transferred to the successor entity as part of that transaction. We will require any successor to honor the commitments made in this policy or to notify you of the change before the transfer.

8. Service Providers and Processors

We rely on a small number of service providers to operate our business. These include cloud hosting providers that run our servers, email services that deliver our messages, analytics providers that help us understand website performance, and professional advisers such as accountants and lawyers. Each provider processes personal information on our behalf and only for the purposes we direct.

Before engaging a service provider, we evaluate its security posture, its data protection commitments and its track record. Our contracts with providers require them to maintain confidentiality, to implement appropriate technical and organizational measures, to process data only on our documented instructions and to support us in responding to data subject requests.

We select providers that are located in jurisdictions with adequate data protection frameworks, and where a provider operates across borders we rely on transfer mechanisms that meet the applicable legal requirements, including standard contractual clauses where required.

We review our provider list periodically and we remove or replace any provider that no longer meets our standards. We never authorize a provider to use your personal information for its own independent purposes.

9. Data Security Measures

The protection of personal information is a core responsibility of our engineering teams. We apply a layered set of technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure and destruction, as well as against accidental loss and other forms of unlawful processing.

On the technical side, we use encryption for data in transit and for sensitive data at rest, strict access controls based on the principle of least privilege, multi-factor authentication for administrative access, network segmentation, firewalls, intrusion detection and continuous monitoring of our systems for signs of compromise.

On the organizational side, we maintain internal security policies, conduct regular training for staff, manage access through formal provisioning and de-provisioning processes, and perform periodic reviews of our controls. Access to personal information is limited to the personnel who need it for their specific role.

No method of transmission over the internet and no method of electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee its absolute security. If we become aware of a data breach that affects your personal information, we will investigate promptly, mitigate the impact, and notify you and the relevant authorities as required by applicable law.

10. Data Retention Periods

We retain personal information only for as long as necessary to fulfill the purposes described in this policy, and we have defined retention periods for each category of data that we process. Enquiry correspondence is retained for a limited period after the matter is closed, and business records are retained for the periods required by accounting and tax regulations.

Server logs are retained for a short operational window, typically measured in days or weeks, and are then automatically deleted or de-identified. This limited retention reflects the fact that the logs exist for operational and security purposes rather than for long-term profiling.

Client engagement records are retained for the duration of the engagement and for a reasonable period afterwards to support warranties, dispute resolution and the continuity of maintained systems. After the applicable period, the records are securely deleted or anonymized.

When retention is no longer justified, we delete or de-identify the information in a secure manner. You may ask us to delete your personal information earlier, and we will honor that request subject to legal obligations that require continued retention.

11. Your Privacy Rights

Depending on where you live, you may have a number of rights over the personal information we hold about you. These rights include the right to access a copy of your information, the right to request correction of inaccurate information, the right to request deletion of your information and the right to object to or restrict certain processing.

You may also have the right to data portability, which allows you to receive the information you provided to us in a structured, commonly used and machine-readable format, and to transmit that information to another controller where the technical conditions permit.

To exercise any of these rights, you may contact us using the details at the end of this policy. We will respond to verified requests within the time period required by applicable law, and we will not charge a fee for exercising your rights except where the law permits us to do so for manifestly unfounded or excessive requests.

Before acting on a request, we will verify your identity to protect your information from unauthorized access. We may ask for additional confirmation where the request concerns sensitive information. If you are not satisfied with our response, you may lodge a complaint with the supervisory authority in your jurisdiction, and we will cooperate with any such authority in resolving the matter.

12. Privacy for Children

Our website and services are directed at business users and at individuals who are at least eighteen years old. We do not knowingly collect personal information from children, and we design our services with the expectation that they will be used by adults in a professional or commercial context.

If you are a parent or guardian and you believe that a child has provided personal information to us without your consent, you may contact us using the details at the end of this policy. We will investigate the matter promptly and will delete any personal information collected from a child as soon as we become aware of it, unless we are required by law to retain it.

We encourage parents and guardians to supervise the online activity of children and to guide them away from providing personal information to websites without permission. We also encourage the organizations we serve to implement appropriate age-gating and parental controls where their own services are accessible to children.

Our commitment under this section reflects our view that the protection of children deserves special care, and we apply that care in the design of every system we build.

13. International Data Transfers

The Company operates globally, and the systems we build and maintain may process personal information in more than one country. Our headquarters are located in Hefei, China, and our service providers may store and process data in cloud regions across multiple jurisdictions.

Where personal information is transferred across national borders, we apply appropriate safeguards to ensure that the information continues to receive a level of protection consistent with this policy and with applicable law. These safeguards include standard contractual clauses, adequacy decisions where available, and contractual commitments from all parties in the processing chain.

We choose hosting regions with care, balancing data residency requirements, latency and security. Where a client has specific data residency requirements, we configure the relevant systems to honor those requirements and we document the configuration for audit purposes.

By using our services, you acknowledge that your personal information may be transferred to and processed in jurisdictions outside your country of residence. You may contact us to obtain details of the safeguards we apply to such transfers.

14. Cookies and Tracking Technologies

This website uses a minimal set of cookies and similar technologies to function correctly and to measure its performance. We do not use advertising cookies, and we do not permit third party advertising networks to set cookies on this site.

Strictly necessary cookies are essential for the operation of the site, such as cookies that maintain session state or remember preferences. These cookies do not collect information for marketing purposes and cannot be switched off through the site settings, although you may block them through your browser settings.

Analytics technologies help us understand how visitors use the site so that we can improve its structure and content. Where we use such technologies, we configure them to minimize the collection of identifying information and to respect privacy by design.

You can control cookies through your browser settings, which allow you to refuse all cookies, to delete cookies or to receive a warning before a cookie is set. Disabling cookies may affect the functionality of the site, but it will not stop you from viewing the publicly available content.

15. Third Party Links and Content

Our website and the materials we distribute may contain links to websites and services operated by third parties. This Privacy Policy does not apply to those third party websites, and we are not responsible for the privacy practices or the content of any site that we do not control.

When you follow a link to a third party website, you leave the scope of this policy and the practices of the third party begin to apply. We encourage you to review the privacy policy of any website you visit before providing personal information to it.

The presence of a link on our site does not imply endorsement of the linked site or its content. Links are provided as a convenience, and we have no ongoing control over the availability, accuracy or privacy practices of third party destinations.

If you believe that a third party link on our site is misleading or unsafe, please notify us so that we can review and, where appropriate, remove it.

16. Automated Decision Making

We do not make decisions that produce legal effects concerning you or that significantly affect you solely on the basis of automated processing. Our systems may perform automated calculations for operational purposes, such as capacity planning and monitoring thresholds, but these calculations do not profile individuals or determine eligibility for rights and services.

Where we operate monitoring and alerting systems on behalf of clients, those systems flag technical conditions rather than making decisions about people. Any decision that affects an individual is taken by a human with the benefit of the relevant context.

If we ever introduce automated decision making that has legal or similarly significant effects on individuals, we will update this policy and, where required by law, provide you with the right to request human review of the decision and the right to contest it.

Our position is that important decisions deserve human judgment, and we intend to keep it that way.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, changes in the law or changes in the design of our services. The date at the top of this page indicates when the policy was last revised, and the revised policy applies to the information we hold from that date forward.

If we make changes that are material, we will take reasonable steps to notify you, including by updating the date on this page and, where we have your contact details and the change affects you directly, by sending you a notice. We encourage you to review this page periodically so that you are aware of the current version of the policy.

Your continued use of our website or services after the revised policy takes effect constitutes your acceptance of the revised terms. If you do not agree with the revised policy, you should stop using the website and the services and you may request the deletion of your personal information.

Material changes include, without limitation, new categories of personal information, new purposes for processing, new sharing arrangements and any change that reduces the protections described in this policy.

18. How to Contact Us

If you have any questions about this Privacy Policy, about the personal information we hold about you, or about any of the rights described in this document, you are welcome to contact us. Our contact channels are open to all individuals whose information we process.

You may write to us by email at reply@zhuocuo.lat, by telephone at +13253862315, or by mail at Rm 304, Building 8, Shukeyuan, Qiongyang Road, Wulidun Street, Shushan District, Hefei - 230000, China (CN). The contact person for privacy matters is Feng Li.

We aim to acknowledge privacy enquiries within two business days and to provide a substantive response within thirty days. If a request is complex or requires additional verification, we will inform you of the expected timeline and keep you updated on progress.

We take every privacy concern seriously and we commit to resolving any issue you raise. If you remain dissatisfied after we respond, you may escalate the matter to the competent supervisory authority in your jurisdiction, and we will cooperate fully with any such authority.