Privacy Policy

1. Introduction

Hefei Gangan Bai Room Trading Co., Ltd., operating under the brand name GrainRoom Consulting (hereafter referred to as GrainRoom, we, us, or our), is committed to protecting the privacy and security of your personal information. This Privacy Policy describes our practices regarding the collection, use, disclosure, and protection of information when you visit our website at www.grainroom.mom or engage with our computer systems design, integration, and consulting services. We take data protection seriously and have designed our practices to comply with applicable privacy regulations while earning the trust of every client and visitor who interacts with our digital presence.

GrainRoom was developed by the GrainRoom team as a professional computer systems design and integration consultancy, built from the ground up to serve clients who require expert guidance in systems architecture, cloud infrastructure planning, cybersecurity posture assessment, and technology advisory services. The development philosophy behind GrainRoom emphasizes transparency, technical excellence, and respect for the individuals and organizations who entrust us with their data. This Privacy Policy is a reflection of that philosophy and serves as a comprehensive record of how we approach information stewardship across every layer of our operations.

Our organization operates from our office located at Room 1304, Tower A, Zhonghuan International Building, Intersection of Linquan Road and Shengli Road, Yaohai District, Hefei, Anhui 230000, China. We are registered as Hefei Gangan Bai Room Trading Co., Ltd., a professional provider of computer integrated systems design services falling under the Professional, Scientific, and Technical Services sector. From this location, we coordinate engagements with clients across multiple continents, delivering remote and on-site consulting services that span systems architecture design, software integration planning, managed cloud migration, and enterprise cybersecurity consulting. Our global reach is built on a foundation of rigorous data protection practices that we apply uniformly regardless of where our clients are located.

By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described in this policy, please discontinue use of our website and services immediately. We encourage you to read this document carefully and in its entirety to understand our views and practices regarding your personal data, the legal frameworks that govern our processing activities, and the rights available to you under applicable law. This document is designed to be thorough and transparent, providing you with the detail necessary to make informed decisions about sharing your information with us.

2. Information We Collect

We collect several categories of information to provide and improve our services, ensure the security of our systems, and fulfill our contractual and legal obligations to clients. The scope and nature of the information we collect depends on your interaction with our website and the services you request from us. Below we describe each category of information in substantial detail so that you have a complete understanding of what data enters our systems during normal business operations.

Personal Identification Information: When you fill out our contact form, request a consultation, subscribe to communications, or otherwise engage with us through email or telephone, we may collect your full legal name, professional email address, company name, job title or role, telephone number, physical or mailing address, and any supplementary information you voluntarily provide within the body of your message or project description. This category also includes any documents you attach to communications, such as system diagrams, requirements specifications, or architecture proposals that may contain references to individuals or organizational structures. We treat all such information with the highest level of confidentiality and only collect what is necessary to understand your needs, evaluate your inquiry against our service capabilities, and prepare a meaningful response tailored to your circumstances. For prospective consulting engagements, we may also collect details about the scale of your organization, the technical environment you currently operate, and the specific challenges or objectives that motivate your outreach to us. This contextual information allows us to determine whether our expertise aligns with your requirements and to assemble the right team of consultants should we proceed with an engagement.

Technical and Usage Information: When you visit our website, our servers automatically record certain information sent by your browser or device as part of standard Hypertext Transfer Protocol communications. This information may include your Internet Protocol address, which can provide a general indication of your geographic region at the city or country level. We also log the type and version of the browser you are using, the operating system running on your device, the resolution of your screen, the referring Uniform Resource Locator that brought you to our site, the specific pages you visit during your session, the sequence and timing of your navigation between pages, the amount of time you spend reading each section of content, search terms you enter into any on-site search features, and various diagnostic data points such as HTTP status codes and server response times. This technical data is essential for maintaining the operational health of our website, diagnosing performance bottlenecks, detecting and preventing abusive or malicious traffic patterns, and understanding at an aggregate level how visitors consume our content. Importantly, we configure our logging infrastructure to avoid capturing sensitive personal data in URLs or query parameters, and we regularly audit our server logs to ensure that no unintended information is being retained.

Communication Records: We maintain complete and accurate records of all correspondence exchanged between you and GrainRoom. This includes inquiries submitted through our website contact form, email threads exchanged with our team members, summaries or transcripts of telephone conversations when you consent to call recording, notes from in-person or video conference meetings, and records of any support or service requests you make during the course of an engagement. Communication records serve several important purposes within our organization. They allow us to trace the history and evolution of client relationships over time, ensuring that every team member who interacts with you has full context about prior discussions, decisions, and commitments. They provide an auditable trail that we can reference when clarifying scope boundaries on complex consulting projects or when resolving misunderstandings about deliverables or timelines. They also serve as evidence of our compliance with regulatory requirements related to record-keeping in professional services. We treat all communication records as confidential business information and apply the same access controls and retention rules that govern other categories of personal data.

Business Information: In the course of delivering our computer systems design and consulting services, we routinely receive, process, and store information about the business operations, technical infrastructure, and project requirements of our clients. This broad category encompasses system architecture diagrams, network topology maps, software inventory lists, hardware specifications, data flow schematics, security vulnerability assessments, business continuity plans, technology roadmaps, procurement histories, vendor relationship details, and project management documentation. It also includes information about the personnel structures, reporting hierarchies, and operational workflows of client organizations, which we need to understand in order to recommend organizational changes that complement technical system designs. While much of this information pertains to corporate entities rather than identifiable individuals, it may contain references to named persons in roles such as system administrators, engineering leads, or executive sponsors. We protect this business information with the same rigor that we apply to personal data, recognizing that a breach of either category could cause significant harm to our clients and damage the trust that forms the foundation of our consulting relationships.

Cookies and Similar Technologies Data: In addition to the categories described above, we collect certain data through cookies, web beacons, pixels, local storage objects, and similar browser-based tracking technologies. This data includes unique identifiers assigned to your browser session, preferences you have expressed regarding site functionality, and analytical signals that help us understand aggregate user behavior patterns on our website. A comprehensive explanation of our cookie practices is provided in Section 9 of this policy. For the purposes of this section, it is sufficient to note that cookie-derived data constitutes a distinct information category that we manage in accordance with the same principles that govern all other personal information in our custody.

3. How We Collect Information

We collect information through multiple distinct methods, each serving specific operational purposes within our consulting practice. Understanding these collection methods is important because it helps you recognize when and how your information enters our environment, enabling you to make informed choices about the nature and extent of your interaction with our website and services.

Direct Collection: The primary method by which we obtain personal identification information is through direct, voluntary submission by you. This occurs when you complete and submit the contact form on our website, providing your name, email address, phone number, company details, and a description of your inquiry or project needs. Direct collection also takes place when you send an email to any of our published addresses, including service@grainroom.mom, when you call our telephone number at +12723024417 and engage in a conversation with a member of our team, when you schedule and attend a consultation meeting either in person at our Hefei office or via video conferencing platform, when you subscribe to receive newsletters, whitepapers, or technical briefings from us, when you respond to surveys or feedback requests that we distribute to clients and contacts, and when you submit documents, specifications, or proposals as part of a pre-engagement evaluation process. In every case of direct collection, you retain control over the information you choose to share with us. We never use deceptive or coercive methods to obtain information, and we clearly identify ourselves and the purpose of our data collection at every touchpoint.

Automatic Collection: As is standard practice across the internet, our website infrastructure automatically collects certain technical information whenever you access any page on www.grainroom.mom. This automatic collection occurs through server-side logging mechanisms that capture HTTP request headers, through client-side scripts that measure page load performance and user interaction patterns, and through cookies and similar technologies that persist small amounts of data in your browser. Automatic collection is passive and does not require any active participation on your part beyond the normal act of browsing our website. The data collected automatically is essential for maintaining the security, stability, and performance of our online presence. For example, our systems analyze traffic patterns to detect and block distributed denial of service attacks, monitor server resource utilization to ensure adequate capacity during peak usage periods, and identify broken links or page loading errors that degrade the visitor experience. We designed our automatic collection mechanisms to minimize the amount of personal data captured by avoiding the logging of full URLs that might contain query parameters with identifiable information, by truncating IP addresses in analytics databases to preserve geographic region data while removing the precision needed to identify individual households or devices, and by configuring our web analytics platform to respect Do Not Track signals and browser privacy settings to the fullest extent technically feasible.

Third-Party Collection: In limited circumstances, we may receive information about you from third-party sources that are relevant to our consulting practice. For example, a business partner, industry association, or existing client may refer you to us and share your contact information with your prior consent so that we can reach out regarding a potential consulting engagement. We may also receive information from publicly available business directories, professional networking platforms such as LinkedIn, or corporate websites when we conduct due diligence research as part of preparing a proposal or evaluating a potential engagement. Additionally, our analytics service provider, web hosting provider, and email delivery service may collect and process certain technical data about visitors and recipients on our behalf, and we may receive aggregate reports derived from that data. In every case involving third-party sources, we verify that the third party has a lawful basis for sharing the information with us and that the information is relevant to a legitimate business purpose. We never purchase marketing lists or engage in data brokerage activities, and we do not encourage or incentivize third parties to share information with us without the knowledge and consent of the data subjects involved.

Collection During Service Delivery: A distinct collection context arises during the active delivery of our consulting services. When we are engaged to design a computer system, integrate disparate platforms, migrate workloads to cloud environments, or assess cybersecurity postures, we necessarily encounter, review, and process information that resides within the technical environments of our clients. This may include access to log files that contain IP addresses and usernames, configuration databases that list employee contact details for alert escalation, authentication systems that store personal identifiers, and documentation repositories that reference named individuals in system design documents. In these scenarios, we act as a data processor on behalf of the client, who remains the data controller. We process such information strictly in accordance with the terms of our consulting agreement and the documented instructions of the client, and we do not use this service-delivery information for any purpose beyond fulfilling our contractual obligations. We implement additional technical and organizational measures, such as segregated project workspaces, access logging, and data minimization protocols, to ensure that service-delivery information remains isolated from our general business records and is deleted or returned to the client upon conclusion of the engagement in accordance with mutually agreed procedures.

4. How We Use Your Information

The information we collect serves multiple legitimate business purposes, all of which are directed toward delivering high-quality computer systems design and consulting services to our clients while operating our business efficiently and in compliance with applicable law. We do not use your information for any purpose that is incompatible with the purpose for which it was originally collected, and we do not engage in activities that would be unexpected or objectionable to a reasonable person based on the context in which the information was provided.

Service Delivery and Client Communication: The most fundamental use of your personal information is to enable us to respond to your inquiries, evaluate your consulting needs, prepare proposals and statements of work, assemble appropriate project teams, and deliver the services for which you have engaged us. When you submit a contact form describing a systems architecture challenge or a cloud migration requirement, we use your contact details to reach back to you with a thoughtful and personalized response. We analyze the content of your message to understand the technical domain, the scale and complexity of the problem, the urgency of your timeline, and the budget parameters you have indicated. This analysis informs our internal decision about whether we have the right expertise and capacity to serve you effectively. If we progress to a formal engagement, your information continues to be used throughout the project lifecycle for scheduling meetings, sharing progress updates, coordinating deliverables and reviews, managing change requests, processing invoices and payments, and maintaining the collaborative relationship that is essential to successful consulting outcomes. Even after a project concludes, we may use your contact information to follow up on satisfaction, to inform you of relevant service enhancements or new capabilities that address challenges similar to those you faced, and to maintain a professional relationship that could lead to future engagements.

Website Improvement and Analytics: We use technical and usage data to analyze website performance, identify trends in visitor behavior, measure the effectiveness of our content, and continuously improve the online experience we offer. This analysis operates at an aggregate level and focuses on metrics such as which pages attract the most visitors, how long visitors spend reading our service descriptions, what search terms bring people to our site, which geographic regions generate the most inquiries, and whether visitors who arrive from particular referral sources are more likely to complete a contact form submission. These insights guide decisions about content prioritization, site navigation structure, page layout optimization, and the technical performance of our hosting infrastructure. We may also use technical data to personalize certain aspects of the website experience, such as remembering your language preference or presenting content that is relevant to services you have previously viewed. Importantly, any personalization we implement is based on your behavior during your current visit or recent visits to our own website, and we do not build behavioral profiles that track you across third-party websites or combine our data with data from advertising networks to create comprehensive profiles of your online activity.

Business Administration and Operations: Your information supports core business administration functions that are necessary for running our consulting practice. These functions include managing client accounts and maintaining accurate records of engagements, generating invoices and tracking payments, complying with tax reporting and financial auditing requirements, evaluating consultant performance and allocating resources to projects, maintaining adequate professional liability insurance coverage, and fulfilling our obligations under applicable labor and employment laws with respect to our own personnel. Business administration also encompasses internal reporting and analysis that helps our leadership team understand revenue trends, service line profitability, client acquisition costs, and market positioning. Whenever possible, we use aggregated and anonymized data for these analytical purposes to minimize the processing of identifiable personal information.

Security, Fraud Prevention, and Legal Compliance: We process your information as necessary to maintain the security and integrity of our website, systems, and data. This includes monitoring network traffic for signs of malicious activity, investigating suspicious login attempts or unauthorized access patterns, authenticating the identity of users who request access to restricted resources, and enforcing our Terms of Service against abusive or fraudulent conduct. We also process information as required to comply with applicable laws, regulations, and legal processes. This may include responding to lawful requests from government authorities, complying with court orders or subpoenas, maintaining records required by tax or corporate regulations, and cooperating with data protection authorities in the exercise of their supervisory functions. When we process information for legal compliance purposes, we carefully evaluate the validity and scope of each request and disclose only the minimum information necessary to satisfy the legal obligation.

Marketing and Business Development: With your consent where required by applicable law, we may use your contact information to send you communications about our services, industry insights, technical whitepapers, case studies, and invitations to events or webinars that may be of interest to you. Our marketing communications are always relevant to the field of computer systems design and consulting, and we do not send unsolicited promotional messages to individuals with whom we have no prior relationship. Every marketing email we send includes a clear and easy-to-use unsubscribe mechanism that allows you to opt out of future marketing communications with a single click. We honor opt-out requests promptly and do not re-subscribe individuals who have expressed a preference not to receive marketing materials. For clients and contacts in jurisdictions that require explicit opt-in consent for marketing communications, we obtain such consent before sending any promotional messages.

5. Information Sharing and Disclosure

GrainRoom does not sell, trade, rent, exchange, or otherwise transfer your personal information to third parties for their own marketing or commercial purposes. This prohibition is absolute and applies to all categories of personal information we hold, regardless of how the information was collected. We maintain strict controls over data sharing and only disclose information under the limited, specific circumstances described in this section.

Service Providers and Sub-Processors: We engage carefully selected third-party companies and individuals to perform functions on our behalf that are necessary for operating our website, running our business, and delivering services to our clients. These service providers process personal information only under our documented instructions and are contractually bound to maintain the confidentiality and security of your data through agreements that include provisions for data protection at least as stringent as those we apply internally. Categories of service providers we may engage include web hosting and infrastructure providers that operate the servers on which our website runs, cloud storage and collaboration platform operators that host project documentation and facilitate team communication, email delivery services that transmit transactional and marketing messages on our behalf, analytics providers that process website usage data to generate aggregate reports, payment processors that handle financial transactions for client invoicing, and professional advisors such as lawyers, accountants, and auditors who require access to certain records to provide their services to us. We conduct due diligence on every service provider before engagement to verify their security practices, data handling procedures, and compliance with applicable privacy laws. We also maintain an up-to-date list of all active sub-processors and make this list available to clients upon request.

Legal and Regulatory Disclosures: We may disclose your personal information when we have a good faith belief that disclosure is reasonably necessary to comply with a legal obligation, such as a statute, regulation, judicial proceeding, court order, warrant, administrative order, or similar legal process issued by a competent authority. We may also disclose information to law enforcement agencies, regulatory bodies, or other government authorities when we believe in good faith that the disclosure is necessary to investigate, prevent, or take action regarding suspected illegal activities, fraud, threats to the physical safety of any person, violations of our Terms of Service, or as evidence in litigation in which we are involved. Before making any disclosure under this provision, we evaluate the legal basis for the request, the scope of information demanded, and whether the request complies with applicable procedural requirements. Where permitted by law, we make reasonable efforts to notify you of any legal demand for your information before complying, so that you have the opportunity to seek a protective order or other legal remedy.

Business Transfers and Corporate Restructuring: In the event that GrainRoom, or substantially all of its assets, is acquired by or merged with another entity, or in the event of a reorganization, restructuring, dissolution, or bankruptcy proceeding, the personal information we hold may be among the assets transferred to the successor or acquiring entity. In such circumstances, we will require the recipient to agree in writing to continue to honor the terms of this Privacy Policy with respect to your information, or to provide you with notice and an opportunity to consent to any material changes in how your information is handled before those changes take effect. We will also notify you via email and by posting a prominent notice on our website at least thirty days before any such transfer results in your information becoming subject to a materially different privacy policy.

With Your Consent: We may share your personal information with third parties for purposes not described in this Privacy Policy when we have obtained your explicit, informed consent to do so. We will clearly describe the specific information to be shared, the identity of the recipient, and the purpose of the sharing before seeking your consent. You have the right to withhold consent or to withdraw previously given consent at any time, though withdrawal of consent will not affect the lawfulness of any sharing that occurred before the withdrawal took effect.

Aggregated and De-Identified Data: We may share aggregated, anonymized, or de-identified data derived from your information with third parties for purposes such as industry research, market analysis, academic study, or public reporting on technology trends in the consulting sector. Such aggregated data is processed using techniques that prevent the re-identification of any individual person and does not constitute personal information under applicable privacy laws.

6. Data Security Measures

We implement and continuously maintain a comprehensive suite of technical, administrative, and physical security measures designed to protect your personal information from unauthorized access, alteration, disclosure, destruction, or loss. Our security program is modeled on industry-standard frameworks and is subject to regular internal and external review to ensure that it remains effective against evolving threats in the cybersecurity landscape.

Technical Security Controls: Our infrastructure employs multiple layers of technical protection against external and internal threats. All data transmitted between your browser and our servers is protected using Transport Layer Security encryption with strong cipher suites, ensuring that information you submit through our website cannot be intercepted or read by third parties during transmission. At rest, sensitive personal data is encrypted using Advanced Encryption Standard algorithms with 256-bit keys. Our server environments are protected by network firewalls configured according to least-privilege principles, intrusion detection and prevention systems that monitor for anomalous traffic patterns, distributed denial of service mitigation services that absorb volumetric attacks before they reach our infrastructure, and regular automated vulnerability scanning that identifies and flags unpatched software, misconfigurations, or known exploits. Access to production systems requires multi-factor authentication, and all administrative access is logged and reviewed periodically. We apply security patches and updates to our software stack within defined timeframes based on the severity of identified vulnerabilities, with critical patches applied within 24 hours of availability. Our development processes incorporate security review as a mandatory gate before any code is deployed to production, and we conduct periodic external penetration testing to validate the effectiveness of our controls from an adversarial perspective.

Administrative and Organizational Controls: Information security at GrainRoom is governed by a formal security policy that defines roles, responsibilities, and procedures across every function that touches personal data. Access to personal information is restricted to authorized personnel who require it to perform specific job functions, and access rights are reviewed and recertified on a quarterly basis. All employees, contractors, and temporary staff undergo background screening before receiving any access to systems containing client data and are required to sign confidentiality agreements that survive the termination of their relationship with us. A mandatory data protection and security awareness training program is conducted for all personnel at the time of onboarding and at least annually thereafter, covering topics such as phishing recognition, password hygiene, physical security practices, secure remote work protocols, and incident reporting procedures. We maintain a dedicated security incident response plan that defines escalation paths, communication templates, forensic investigation procedures, and remediation timelines. This plan is tested at least annually through tabletop exercises and is reviewed and updated after each real-world security event, whether affecting us directly or serving as a relevant industry case study.

Physical Security Controls: The physical security of our office premises at Room 1304, Tower A, Zhonghuan International Building is an integral component of our overall data protection strategy. Our office is secured with access control systems that require authorized credentials for entry, and visitor access is managed through a check-in procedure that includes escorting visitors while they are on the premises. Server rooms and network equipment are housed in locked enclosures with access limited to authorized information technology personnel. Physical documents containing personal information, if any exist, are stored in locked filing cabinets and are shredded using cross-cut shredders when they reach the end of their retention period. Our building provides 24-hour security personnel and closed-circuit television coverage of common areas, adding an additional layer of physical protection.

Breach Notification Procedures: Despite our best efforts, no security program can provide an absolute guarantee against data breaches. We maintain detailed breach notification procedures that ensure we can respond rapidly and effectively if a security incident occurs involving personal data. In the event of a confirmed breach, we will notify affected individuals without undue delay, providing a description of the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences of the breach, the measures we have taken or propose to take to address the breach and mitigate its effects, and the contact details of the person or team from whom more information can be obtained. We will also notify relevant supervisory authorities where required by applicable data protection law and within the timeframe prescribed by such law. We document all security incidents, including near misses that do not result in confirmed data exposure, to feed into our continuous improvement process.

7. Data Retention Periods

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, after which it is securely deleted, destroyed, or irreversibly anonymized. Our retention periods are determined by reference to multiple factors, including the nature and sensitivity of the information, the purpose for which it was collected, the potential risk of harm from unauthorized use or disclosure, the duration of our business relationship with you, contractual obligations we have entered into with clients, and applicable legal, regulatory, tax, accounting, and professional standards requirements that mandate minimum retention periods.

Contact form submissions and general inquiry records are typically retained for a period of three years following the conclusion of our last substantive communication with you. This three-year window allows us to reference prior discussions, proposals, and evaluations if you return to us for additional consulting work. It also provides a reasonable period for us to demonstrate the trajectory of our client relationships in the event of an audit, dispute, or regulatory inquiry. At the end of the three-year period, we review the records and either delete them, or if there is an ongoing legal or regulatory reason to retain them, we document that reason and schedule a subsequent review.

Technical and website usage data captured through our analytics and logging systems is retained for a maximum of twenty-six months from the date of collection. During this period, the data supports trend analysis that informs our website improvement efforts, helps us understand long-term patterns in visitor engagement, and enables us to compare year-over-year performance metrics. After twenty-six months, the data is either deleted or aggregated to a level where it no longer contains any identifiers that could be linked back to an individual visitor or device. We apply a similar twenty-six month retention period to cookie-derived data and browser identifiers, after which these identifiers are purged from our analytics databases.

Information related to active, completed, or terminated consulting engagements, including project documentation, deliverables, technical assessments, architecture diagrams, meeting minutes, and project correspondence, is retained for a minimum of five years from the date of project closure. This retention period aligns with professional standards applicable to consulting practices, statutes of limitations for contractual claims, and regulatory requirements for retaining business records. It also enables us to provide continuity of service to clients who return for follow-up engagements, as we can reference the technical context and decisions from prior work. For projects that involve particularly complex or long-lived technical systems, we may retain project records for up to seven years if the client requests extended retention or if the nature of the engagement warrants a longer reference period. At the conclusion of the applicable retention period, we securely delete project files or, if the client prefers, return them in their entirety before deleting our copies.

Financial records, tax filings, invoices, payment receipts, and accounting ledgers are retained for the period required by the tax and corporate laws of China, which is generally a minimum of five to ten years depending on the specific type of record. These records are primarily business information rather than personal data, but to the extent they contain personal identifiers such as client names or billing contacts, they are managed in accordance with this policy and are securely destroyed once the mandatory retention period has expired.

Marketing consent records and communication preference logs are retained indefinitely so that we can demonstrate compliance with applicable marketing laws and maintain accurate suppression lists that prevent us from inadvertently contacting individuals who have opted out. This indefinite retention is limited to the record of consent or objection and does not extend to the underlying personal information used for marketing purposes, which is deleted or anonymized according to the standard retention periods described above.

8. Your Rights and Choices

Depending on your jurisdiction of residence, you may have specific legal rights regarding the personal information we hold about you. We are committed to honoring all rights granted to data subjects under applicable data protection laws, and we have established internal procedures to receive, verify, and respond to rights requests in a timely and thorough manner. The summary below describes the rights most commonly available to individuals under modern privacy regulations. The availability of each right depends on your jurisdiction and the specific legal basis on which we process your information.

Right of Access: You have the right to request confirmation of whether we process personal data concerning you and, if so, to obtain a copy of that data along with information about the purposes of processing, the categories of data involved, the recipients or categories of recipients to whom the data has been or will be disclosed, the envisaged retention period or the criteria used to determine that period, the existence of your other rights as a data subject, the source of the data if it was not collected directly from you, and the existence of any automated decision-making including profiling. We provide this information free of charge for the first copy requested in any twelve-month period. For additional copies, we may charge a reasonable fee based on administrative costs.

Right of Rectification: You have the right to request the correction of inaccurate personal data we hold about you. Considering the purposes of the processing, you also have the right to have incomplete personal data completed, including by means of providing a supplementary statement. When we receive a rectification request, we verify the accuracy of the new information you provide and update our records accordingly. If we have disclosed the inaccurate information to any third party, we will notify them of the rectification where practicable and legally required.

Right of Erasure: In certain circumstances, you have the right to request the deletion of your personal data. These circumstances include when the data is no longer necessary for the purpose for which it was collected, when you withdraw consent on which processing is based, when you object to processing and there are no overriding legitimate grounds for continuing, when the data has been unlawfully processed, or when erasure is required to comply with a legal obligation. We will comply with an erasure request unless we are legally required or permitted to retain the data, for example, for compliance with tax record-keeping obligations, for the establishment or defense of legal claims, or for reasons of important public interest.

Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data in certain situations, such as when you contest the accuracy of the data (restriction applies for a period enabling us to verify accuracy), when the processing is unlawful and you oppose erasure and request restriction instead, when we no longer need the data but you require it for legal claims, or when you have objected to processing pending verification of whether our legitimate grounds override yours. When processing is restricted, we may still store your data, but we will not further process it without your consent except for legal claims or for protecting the rights of another person.

Right to Data Portability: Where processing is based on your consent or on a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to have that data transmitted directly to another data controller where technically feasible. This right facilitates your ability to move, copy, or transfer your data between different service providers in a secure and efficient manner.

Right to Object: You have the right to object to the processing of your personal data where we rely on legitimate interests as the legal basis. Upon receiving an objection, we will cease processing the data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defense of legal claims. Even where we do not rely on legitimate interests, you have an absolute right to object to the processing of your data for direct marketing purposes at any time, and we will comply with such an objection without exception and without delay.

Exercising Your Rights: To exercise any of the rights described above, please contact us at service@grainroom.mom or write to our office address provided in Section 16 of this policy. We respond to rights requests within thirty calendar days of receipt, or within the specific timeframe mandated by your jurisdiction if different. We may need to verify your identity before processing your request to protect against fraudulent or unauthorized access to personal data. Identity verification may involve confirming details we already hold about you or requesting additional information or documentation to establish your identity to a reasonable level of certainty. If we decline to comply with your request, we will provide a written explanation of the reasons for our decision and inform you of your right to lodge a complaint with the relevant supervisory authority.

Opting Out of Communications: In addition to formal legal rights, you have practical choices regarding how we communicate with you. You may choose not to provide certain optional information when interacting with us, though this may limit our ability to fully respond to your inquiry or deliver specific services. You may opt out of receiving marketing communications by clicking the unsubscribe link in any marketing email we send, by contacting us with an opt-out request, or by adjusting your communication preferences through any self-service preference center we make available. You may configure your browser to refuse some or all cookies, though this may affect the functionality of certain website features.

9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, understand how our content is consumed, and maintain the security and performance of our online infrastructure. This section provides a thorough explanation of what cookies are, how we use them, the types of cookies deployed on our website, and the choices available to you regarding cookie management.

What Cookies Are: A cookie is a small text file that a website places on your computer or mobile device when you visit that website. Cookies are widely used across the internet to enable websites to function efficiently, to remember user preferences and settings, to provide website owners with information about how their sites are being used, and to support security and authentication functions. The term cookie in this policy also encompasses similar tracking technologies such as web beacons (also known as pixel tags or clear GIFs), which are tiny graphic files embedded in web pages or emails that allow the sender to know whether a page was visited or an email was opened, and local storage objects (sometimes called flash cookies), which can store larger amounts of data than traditional browser cookies. All of these technologies collectively enable a website to recognize a returning device and provide continuity across browsing sessions.

Categories of Cookies We Use: We classify the cookies deployed on www.grainroom.mom into several categories based on their function and purpose. Essential cookies, sometimes called strictly necessary cookies, are required for the website to operate correctly. These cookies enable core functionality such as page navigation, access to secure areas of the website, load balancing across our server infrastructure, and the preservation of session state so that your interactions with the site are consistent during a single visit. Without essential cookies, the website cannot function properly, and we do not require your consent to deploy these cookies. Functionality cookies allow the website to remember choices you make, such as your language preference, the region from which you are accessing the site, or your preferred contact method, and to provide enhanced, more personalized features. These cookies may be set by us or by third-party providers whose services we have integrated into our pages. Analytics and performance cookies collect information about how visitors use our website, such as which pages are visited most frequently, how visitors navigate through the site, and whether visitors encounter error messages on any pages. The data collected by these cookies is aggregated and anonymized before it is reported to us, meaning that individual visitor identities cannot be discerned from the data. We use this information exclusively to improve how our website works and to understand which content resonates with our audience.

Third-Party Cookies: Some cookies placed on your device when you visit our website may be set by third-party services that we use to enhance our site. For example, if we embed a video from a content delivery platform or include social media sharing functionality, the providers of those services may set their own cookies on your device. We do not control the operation of these third-party cookies, and they are governed by the privacy policies of the respective third parties rather than this Privacy Policy. We make reasonable efforts to identify third-party cookies and to ensure that our cookie consent mechanism provides you with information about them and the opportunity to accept or decline them.

Cookie Duration: Cookies can be categorized by their lifespan. Session cookies are temporary and exist only for the duration of your visit to our website. They are automatically deleted when you close your browser and are used primarily to maintain the state of your interaction, such as keeping track of items in a shopping cart or remembering the page you were on before navigating to a new section. Persistent cookies remain on your device for a defined period after you close your browser or until you manually delete them. We set persistent cookies to remember your preferences for future visits, to recognize you as a returning visitor for analytics purposes, and to support security features such as detecting repeated failed login attempts from the same device. The expiration periods of our persistent cookies vary from a few days to a maximum of twenty-six months, after which the cookies are automatically removed by your browser.

Managing Your Cookie Preferences: You have multiple options for controlling which cookies are placed on your device. Most web browsers allow you to manage cookie settings through the preferences or options menu, where you can typically view the cookies currently stored on your device, delete individual cookies or all cookies, block cookies from specific websites, block all third-party cookies, block all cookies entirely, or configure the browser to notify you each time a website attempts to set a cookie so that you can decide on a case-by-case basis whether to accept it. The specific steps for configuring cookie settings vary by browser; consult the help documentation for your particular browser for detailed instructions. In addition to browser-level controls, industry organizations offer opt-out tools that allow you to decline analytics and advertising cookies across multiple websites simultaneously. Finally, you can use private or incognito browsing modes offered by most modern browsers, which automatically delete browsing history, cookies, and site data when you close all private windows. Please be aware that disabling cookies entirely may prevent certain features of our website from functioning as intended.

10. Privacy for Minors

Our website and services are designed for and directed exclusively to adults who are engaged in professional, commercial, or organizational activities. We do not market our consulting services to minors, we do not design our website to appeal to individuals under the age of eighteen, and we do not target any aspect of our outreach or content toward children or adolescents. The subject matter of our services—computer systems design, systems integration, cloud architecture, and cybersecurity consulting—is inherently oriented toward business and professional contexts that are not relevant to or appropriate for minors.

We do not knowingly collect, process, or store personal information from any individual under the age of eighteen. Our data collection mechanisms, including website contact forms and email communications, are not designed to solicit information from minors, and we do not have any business processes that would involve the intentional collection of data about children. If we become aware that we have inadvertently collected personal data from a minor without verified parental consent, we will take immediate steps to identify and remove that information from our servers and any backup systems. The removal process includes locating all instances of the minor data across our databases, file systems, email archives, and backup repositories, deleting those records permanently, and documenting the deletion for our compliance records. We will complete this process within thirty calendar days of becoming aware of the unauthorized collection.

If you are a parent or legal guardian and you have reason to believe that your child has provided us with personal information, we urge you to contact us immediately at service@grainroom.mom so that we can investigate and take corrective action. When you contact us regarding a potential minor data collection, please provide sufficient information for us to identify the relevant records, such as the approximate date of the interaction, the name or online identifier the minor may have used, and any other contextual details that would assist our search. We will acknowledge your communication within five business days and will keep you informed of the progress of our investigation and the actions we take as a result.

We strongly encourage all parents and guardians to take an active role in monitoring and guiding the online activities of the children in their care. This includes educating children about the importance of protecting their personal information, instructing them never to provide personal details on websites without explicit permission, using parental control tools and content filtering software to manage their access to online services, and regularly reviewing their browsing history and the applications installed on their devices. Protecting the privacy and safety of minors in the digital environment is a responsibility shared by website operators, parents, educators, and the broader community, and we fully support efforts to create a safer internet for young people.

Our commitment to protecting minors extends to the data of the employees, contractors, and authorized users of our clients. When we provide consulting services that involve access to client systems containing employee data, we require our clients to represent and warrant that their data collection and processing practices comply with applicable laws regarding the protection of minor information. If during the course of a consulting engagement we identify personal data that appears to belong to a minor and that was collected without appropriate legal basis, we will promptly notify the client and work with them to ensure that the data is handled in accordance with applicable law.

11. Third Party Services and Links

Our website may contain hyperlinks to third-party websites, platforms, applications, resources, or services that are not owned, operated, or controlled by GrainRoom. These third-party destinations operate independently of us and maintain their own privacy policies, terms of service, and data handling practices that differ from the policies described in this document. The presence of a link on our website does not constitute an endorsement, approval, or validation of the content, policies, or practices of the linked destination.

When you click on a link that directs you away from www.grainroom.mom, you leave an environment governed by this Privacy Policy and enter an environment governed by the policies of the third party. We encourage you to read the privacy policy of every website and service you visit before providing any personal information or engaging in transactions. We recommend paying particular attention to the sections of third-party privacy policies that describe data collection, use for advertising or profiling purposes, data sharing with affiliates or partners, data retention periods, and the rights available to you as a data subject in their jurisdiction. Being an informed consumer of online services is one of the most effective ways to protect your privacy.

We may integrate third-party services into our website to provide specific functionality that enhances your experience. For example, we might embed a map to show our office location, include video content hosted on external platforms, display social media sharing buttons, or route our email communications through a specialized delivery service. Each of these integrations may result in the third-party provider receiving technical information such as your IP address, browser identifier, or the specific page you visited at the time the integration loaded. We select integration partners based on their data protection commitments and the safeguards they offer, and we configure integrations to minimize data transmission to the extent technically feasible. However, the processing of data by these third-party providers once it has been transmitted is governed by their own policies and is outside our control.

We may also engage third-party service providers to assist with specific aspects of our website operations or business administration. These providers operate as data processors on our behalf and are subject to binding contractual restrictions that limit their use of your personal information to the performance of the services they provide to us. Examples of such providers include our cloud infrastructure host, our domain name registrar, our email hosting service, our customer relationship management platform provider, and our accounting software vendor. We conduct due diligence on every provider before engagement to verify their security certifications, data handling procedures, incident response capabilities, and compliance with applicable data protection laws. Our contracts with service providers include provisions for data processing agreements that specify the subject matter and duration of processing, the nature and purpose of processing, the types of personal data processed, our respective roles and responsibilities, technical and organizational measures, sub-processing restrictions, data breach notification obligations, and obligations regarding data deletion or return upon contract termination.

12. International Data Transfers

GrainRoom is headquartered in Hefei, Anhui Province, China, and our primary data processing operations are conducted from our office at Room 1304, Tower A, Zhonghuan International Building, Intersection of Linquan Road and Shengli Road, Yaohai District, Hefei, Anhui 230000, China. As a consultancy with a global client base, the personal information we collect may be transferred to, stored in, and processed in China or in other countries where our service providers, business partners, or subsidiary operations maintain facilities.

The data protection laws and regulations of China and of other jurisdictions to which your information may be transferred may differ from the laws applicable in your country of residence. Some jurisdictions may not provide a level of data protection that is considered adequate by the authorities in your home country. When we transfer personal data across international borders, particularly from jurisdictions with stringent data protection standards such as the European Economic Area, the United Kingdom, or Switzerland, we implement appropriate and recognized safeguards to ensure that your information continues to receive a level of protection that is essentially equivalent to the protection it would receive in the jurisdiction of origin. These safeguards may include the use of standard contractual clauses approved by the relevant data protection authorities, binding corporate rules for intra-group transfers, data processing agreements that impose contractual requirements equivalent to the legal protections that apply in the originating jurisdiction, and assessments of the legal environment in the destination country to identify and address any risks to data protection. We document these assessments and make them available to clients and supervisory authorities upon request.

For clients from the European Economic Area or the United Kingdom, we rely on the standard contractual clauses issued by the European Commission and the United Kingdom Information Commissioner Office respectively as the primary transfer mechanism. For each international transfer, we conduct a transfer impact assessment that evaluates whether the laws and practices of the destination country impinge on the effectiveness of the safeguards we have implemented and, where necessary, we implement supplementary measures—such as enhanced encryption, key management practices that prevent the processor from accessing data in the clear, pseudonymization, or contractual commitments regarding government access requests—to bring the level of protection to the required standard.

By providing your personal information to us, you acknowledge and agree that your information may be transferred, stored, and processed in countries other than your country of residence. This acknowledgment does not constitute a waiver of any rights you may have under applicable data protection law, and we remain fully accountable for the protection of your data regardless of where it is processed. If you would like more detailed information about the specific safeguards we apply to international transfers of your personal data, please contact us at service@grainroom.mom.

13. Changes to This Privacy Policy

We reserve the right to update, modify, amend, or replace this Privacy Policy at any time in response to changes in our information practices, operational requirements, business model, service offerings, technology stack, legal obligations, or regulatory environment. This flexibility allows us to maintain a privacy policy that accurately reflects our current practices and remains compliant with applicable law as legal frameworks evolve.

When we make material changes to this Privacy Policy, we will take the following steps to ensure you are informed and have an opportunity to understand the nature of the changes. We will update the Last updated date displayed at the top of this page to reflect the date on which the revised policy becomes effective. We will post a prominent notice on the homepage of www.grainroom.mom alerting visitors that the Privacy Policy has been updated, and we will maintain that notice for a period of at least thirty calendar days following the effective date of the changes. If we have your email address on file as part of an existing client relationship, we will send you a direct notification describing the nature of the changes and providing a link to the revised policy. For changes that materially affect your rights or the way we handle your personal information, we will make reasonable efforts to obtain your affirmative consent before applying the new policy to your data, where such consent is required by applicable law.

We encourage all visitors and clients to review this Privacy Policy periodically, even when no notice of change is posted, to stay informed about how we protect your information. You can always find the most current version of this document at www.grainroom.mom/privacy.html. We maintain an archive of previous versions of this Privacy Policy, which is available upon request for individuals who wish to compare historical versions against the current text. Your continued use of our website or engagement with our services after the effective date of any revised Privacy Policy constitutes your acknowledgment and acceptance of the updated terms, except where applicable law requires us to obtain a new and specific consent before applying revised terms to your data. If you disagree with any material change to this policy, your remedy is to discontinue use of our website and services and, where applicable, to request deletion of your personal data in accordance with the rights described in Section 8 of this policy.

14. Legal Basis for Processing

Data protection laws in many jurisdictions require organizations to identify and document the specific legal basis on which they rely for each category of personal data processing. For individuals located in jurisdictions that mandate such legal bases—including but not limited to the European Economic Area, the United Kingdom, Brazil, and certain other countries with comprehensive privacy legislation—this section identifies the legal grounds on which we process your personal information.

Consent: In specific situations, we process your personal data based on the consent you have freely given. This applies most commonly to the sending of direct marketing communications, the deployment of non-essential cookies and tracking technologies, and the collection of special categories of data where no other legal basis applies. When we rely on consent, we make the request for consent clear, specific, and separate from other terms and conditions. You have the right to withdraw your consent at any time, and we provide simple and accessible mechanisms for doing so. Withdrawal of consent does not affect the lawfulness of processing that occurred before the withdrawal.

Contractual Necessity: We process personal data where it is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract. When you submit a contact form requesting consulting services, we process your data to evaluate your request, prepare a response, and, if appropriate, negotiate and enter into a consulting agreement. During the delivery of services, we process data necessary to fulfill our contractual obligations, communicate with you, manage the project, and deliver the agreed-upon outcomes. If you fail to provide information that is necessary for us to perform a contract, we may be unable to provide the requested services.

Legal Obligations: We process personal data where necessary to comply with a legal obligation to which we are subject. This includes complying with tax laws that require us to retain financial records, responding to lawful requests from government authorities and law enforcement agencies, maintaining records required by corporate and commercial regulations, and cooperating with data protection authorities. When we process data for compliance with a legal obligation, we ensure that we process only the minimum data necessary to satisfy the obligation and that we do not use the data for additional purposes beyond those mandated by law.

Legitimate Interests: In certain circumstances, we process personal data based on our legitimate interests or the legitimate interests of a third party, provided that such interests are not overridden by your rights, interests, and fundamental freedoms. Our legitimate interests include, but are not limited to, responding to inquiries and providing requested information about our services, maintaining and improving the security, stability, and performance of our website and systems, analyzing website usage to understand audience engagement and optimize content, conducting business development and marketing to organizations that may benefit from our services (subject to opt-out rights), protecting our legal rights and interests in the event of a dispute, investigating and preventing fraud, unauthorized access, and other illegal activities, managing our internal operations and administration, and evaluating, pursuing, or completing a merger, acquisition, restructuring, or sale of assets. We conduct a legitimate interests assessment before relying on this legal basis, weighing our interests against the potential impact on your privacy. We document each assessment and review it periodically to ensure that our legitimate interests continue to justify the processing.

Where we process personal data based on legitimate interests, you have the right to object to such processing as described in Section 8 of this policy. We will honor your objection unless we can demonstrate compelling legitimate grounds that override your interests or unless the processing is necessary for the establishment, exercise, or defense of a legal claim.

15. Governing Law and Jurisdiction

This Privacy Policy and any disputes, claims, or controversies arising out of or relating to it, or the breach, termination, enforcement, interpretation, or validity thereof, including the determination of the scope or applicability of this agreement to arbitrate, shall be governed by and construed in accordance with the laws of China. The governing law provision applies to all substantive and procedural matters, including issues of interpretation, construction, validity, performance, and enforcement.

Any legal suit, action, or proceeding arising out of or relating to this Privacy Policy shall be instituted exclusively in the competent courts located in Hefei, Anhui Province, China. By using our website and services, you consent to the personal jurisdiction of and venue in such courts and waive any objection based on inconvenient forum or lack of personal jurisdiction. This exclusive jurisdiction provision is intended to provide clarity and predictability regarding the forum for resolving disputes, and it applies to the fullest extent permitted by applicable law.

We make no representation that our website, services, or the content available through them are appropriate, lawful, or available for use in locations outside of China. Users who access our website from jurisdictions other than China do so entirely on their own initiative and volition, and they are solely responsible for ensuring that their use of our website and engagement with our services complies with all applicable local laws, regulations, and restrictions. The fact that our website is accessible from a particular jurisdiction does not constitute an offer to provide services in that jurisdiction if doing so would violate applicable law or subject us to regulatory obligations that we are not prepared to meet.

If any provision of this Privacy Policy is held by a court of competent jurisdiction to be invalid, illegal, or unenforceable for any reason, such provision shall be modified to the minimum extent necessary to make it valid, legal, and enforceable, or if modification is not possible, the provision shall be severed from this Privacy Policy. The invalidity of any provision shall not affect the validity and enforceability of the remaining provisions, which shall continue in full force and effect.

16. Contact Information

If you have any questions, concerns, comments, or requests regarding this Privacy Policy, our data handling practices, your rights as a data subject, or any other privacy-related matter, please contact us using the information below. We welcome your feedback and are committed to responding to every privacy inquiry in a timely, thorough, and respectful manner.

Hefei Gangan Bai Room Trading Co., Ltd.
Room 1304, Tower A, Zhonghuan International Building
Intersection of Linquan Road and Shengli Road
Yaohai District, Hefei, Anhui 230000
China

Email: service@grainroom.mom
Phone: +12723024417
Website: www.grainroom.mom

We take all privacy-related inquiries seriously and will make every effort to address your concerns promptly and substantively. When you contact us regarding a privacy matter, please provide as much detail as possible about the nature of your inquiry or concern, including any relevant dates, identifiers, or context that will help us investigate and respond efficiently. Our privacy team reviews every incoming inquiry and typically provides an initial response within five business days, with a comprehensive resolution provided within thirty calendar days or sooner, depending on the complexity of the issue.

If you believe that we have not adequately addressed your privacy concerns or have not complied with your rights under applicable data protection law, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction. For individuals in the European Economic Area, the competent supervisory authority is the data protection authority in the member state of your habitual residence, place of work, or place of the alleged infringement. While we encourage you to contact us first so that we have the opportunity to resolve your concern directly, you are not required to do so before filing a complaint with a supervisory authority, and we will not retaliate against or discriminate against any individual who exercises their right to complain.

17. Data Protection by Design

GrainRoom has embedded the principle of data protection by design and by default into the architecture of our consulting practice, our internal processes, and our digital infrastructure. This principle means that we consider privacy and data protection implications at the inception of every new project, service, product feature, or business process, and we design our operations in a manner that minimizes privacy risks from the outset rather than attempting to retrofit protections after systems are deployed.

Practically, data protection by design manifests in several concrete ways throughout our organization. When we develop or modify our website, we conduct privacy impact assessments that identify the personal data that will be collected, the necessity and proportionality of that collection, the security measures that will protect the data, and the retention periods that will apply. We build our contact forms to collect only the minimum information necessary to respond effectively to your inquiry, avoiding optional fields that request data we do not genuinely need. We configure our server logging infrastructure to minimize the capture of identifiers, and we anonymize or pseudonymize analytical data at the earliest technically feasible point in our data pipeline.

Our consultants are trained to apply data minimization principles when working within client environments, keeping their access to personal data limited to what is strictly necessary for the consulting task at hand. We use segregated project workspaces with access controls that prevent the commingling of data from different clients, and we implement role-based access within our organization so that each team member sees only the data relevant to their function on a given project. These design choices are not incidental; they represent a deliberate investment in privacy infrastructure that we believe delivers value to our clients and distinguishes our practice in a marketplace where data stewardship is increasingly recognized as a critical component of professional service quality.

18. Automated Decision Making and Profiling

GrainRoom does not engage in automated individual decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you. None of the decisions we make about the services we offer, the proposals we prepare, the projects we accept, or the manner in which we engage with clients are based solely on automated processing of personal data without meaningful human involvement.

Our consulting practice is fundamentally a human-driven enterprise. When we evaluate whether to accept a potential engagement, the decision is made by experienced consultants who review the inquiry, consider the alignment with our expertise, assess our current capacity, and exercise professional judgment. When we design a system architecture or recommend a technology solution, the analysis and conclusions are the product of human expertise informed by data, not the output of an algorithm operating without human oversight. When we determine how to communicate with clients or contacts, those decisions are made by people who consider the nature of the relationship, the relevance of the communication, and the preferences the individual has expressed.

We do, in limited circumstances, use automated processing to support operational functions. For example, our email system may automatically categorize incoming messages to route them to the appropriate team member, and our analytics platform uses algorithms to aggregate usage data and generate statistical reports. However, these automated processes are purely instrumental and do not result in decisions that have legal or significant effects on individuals. If at any point in the future we deploy automated decision-making systems that could have such effects, we will update this policy to describe the logic involved, the significance and envisaged consequences of such processing for data subjects, and the safeguards we implement to protect your rights, including your right to obtain human intervention, express your point of view, and contest the decision.

19. Supervisory Authority and Complaints

We are committed to resolving privacy concerns collaboratively and transparently. Before escalating a concern to a formal complaint, we encourage you to contact us directly so that we have an opportunity to understand the issue and work with you toward a satisfactory resolution. In our experience, the vast majority of privacy questions and concerns can be addressed through direct communication.

If you are not satisfied with our response, you have the right to lodge a complaint with a competent data protection supervisory authority. For individuals located in the European Economic Area, you may file a complaint with the supervisory authority in the member state where you reside, where you work, or where the alleged infringement of data protection law occurred. A list of EEA supervisory authorities and their contact details is maintained by the European Data Protection Board and is available on its website. For individuals in other jurisdictions that have established data protection authorities, we recommend consulting the official website of the relevant authority for information about complaint procedures.

If you are located in China and have concerns about our data handling practices, you may direct inquiries or complaints to the Cyberspace Administration of China or other relevant regulatory bodies with jurisdiction over personal information protection. We cooperate in good faith with all supervisory authorities and are committed to implementing any remedial measures they recommend to bring our practices into compliance.