Effective Date: August 1, 2026
Shanxi Zhanghai Trading Co., Ltd. (hereinafter referred to as --the Company,-- --we,-- --us,-- or --our--) is committed to protecting the privacy and personal data of all individuals who interact with our website, services, and business operations. This Privacy Policy explains in clear terms how we collect, use, store, disclose, and safeguard information when you visit our website at www.zhanghai.mom or engage with our computer integrated systems design services.
The Company was founded and is led by Zhang Hai, a systems architect with deep expertise in computer systems design and engineering. We operate from our registered office in Taiyuan, Shanxi, China, and serve clients across domestic and international markets. As a professional services firm operating in the technology sector, we understand the critical importance of data confidentiality and have designed our privacy practices to meet or exceed applicable data protection standards.
By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, you should discontinue use of our website and refrain from providing any personal information to us. This policy applies solely to information collected through our website and in the course of our business communications and does not extend to any third-party websites that may be linked from our pages.
We collect several categories of information to operate our business effectively and to provide you with relevant information about our computer integrated systems design services. The types of information we collect depend on the nature of your interaction with us and the specific services you inquire about or engage us to perform.
Personal identification information includes your full name, email address, telephone number, company name, job title, and physical mailing address. This information is typically collected when you fill out our contact form, request a consultation, subscribe to communications, or enter into a service agreement with us. We also collect professional information such as details about your organization, the nature of your technical requirements, and the scope of systems integration projects you discuss with our team.
Technical and usage data is automatically collected when you browse our website. This includes your Internet Protocol (IP) address, browser type and version, device type, operating system, referring URLs, pages visited, time spent on pages, and the date and time of each visit. This data is collected through server logs and standard web analytics technologies to help us understand how visitors use our website and to improve its performance and content.
Communication data encompasses any information you voluntarily provide when you correspond with us via email, telephone, contact forms, or any other communication channel. This includes the content of messages, attachments, inquiry details, project specifications, and any other information you choose to share during the course of our business relationship. We treat all communication data as confidential and use it only for the purposes for which it was provided.
We employ several methods to collect information, each designed to be transparent and proportionate to the purpose of collection. The primary method is direct collection, where you voluntarily provide information through our website contact forms, email correspondence, telephone calls, or in-person meetings with our representatives. When you submit a contact form, the fields you complete are transmitted securely and processed by our internal systems.
Automated collection occurs through the use of cookies, web beacons, and server log files that record technical data about each visit to our website. These technologies operate in the background without requiring any active input from you. We use a minimal set of cookies necessary for website functionality and basic analytics. You may configure your browser settings to refuse cookies or alert you when cookies are being sent; however, some features of the website may not function as intended if cookies are disabled.
Third-party sources may occasionally provide us with information, such as when a business partner refers you to our services or when we use publicly available business directories to verify company information. In all such cases, we ensure that the third party has a lawful basis to share that information with us and that the data is relevant to our legitimate business purposes. We do not purchase personal data lists from data brokers or engage in any form of surreptitious data collection.
The information we collect serves specific and clearly defined business purposes related to the delivery and improvement of our computer integrated systems design services. We do not use your personal data for purposes that are incompatible with those disclosed in this policy, and we do not engage in automated decision-making or profiling that produces legal or similarly significant effects concerning you.
Primarily, we use your information to respond to inquiries and provide the services you request. When you contact us about a potential systems integration project, we use the details you provide to understand your requirements, prepare proposals, conduct technical assessments, and communicate with you throughout the engagement lifecycle. This includes scheduling consultations, delivering project documentation, and providing ongoing support and maintenance updates for deployed systems.
We also use information to improve our website and service offerings. Aggregated and anonymized usage data helps us identify which pages and content are most valuable to visitors, allowing us to refine our information architecture and user experience. Individual personal data is never used for these analytical purposes unless it has been fully anonymized and can no longer be linked back to you. Additionally, we may use your contact information to send occasional service-related announcements, industry insights, or updates about our capabilities, but only where you have expressly opted in to receive such communications.
Operational and legal purposes form another category of use. We process data as necessary to fulfill contractual obligations, comply with applicable laws and regulations, enforce our terms of service, protect our legal rights, and prevent fraud or misuse of our systems. In the event of a corporate transaction such as a merger or acquisition, your data may be transferred as a business asset, subject to the same privacy protections described in this policy.
Under applicable data protection laws, including the Personal Information Protection Law of the Peoples Republic of China and the General Data Protection Regulation (GDPR) where applicable to our international clients, we must have a valid legal basis for processing your personal data. The specific basis depends on the nature of the data and the purpose for which it is processed.
Consent serves as the legal basis when you voluntarily provide information through our website forms or opt in to receive marketing communications. You have the right to withdraw your consent at any time by contacting us at the email address provided in the Contact Information section below. Withdrawal of consent does not affect the lawfulness of processing that occurred before the withdrawal.
Contractual necessity applies when processing is required to perform a contract with you or to take steps at your request before entering into a contract. This includes processing necessary to prepare service proposals, execute engagement agreements, deliver our systems design services, and manage billing and payment arrangements. Without this processing, we would be unable to fulfill our contractual obligations to you.
Legitimate interests provide the legal basis for processing that is reasonably necessary for our business operations, provided that your rights and interests do not override those legitimate interests. This includes processing for website analytics, service improvement, fraud prevention, and direct marketing to existing clients about similar services. We conduct a balancing test before relying on legitimate interests to ensure that your privacy expectations are respected.
Legal obligation requires us to process personal data when necessary to comply with applicable laws, regulations, court orders, or lawful requests from government authorities. This may include retaining transaction records for tax purposes, responding to lawful information requests from regulatory bodies, or disclosing information as required by judicial proceedings.
We retain personal data only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable laws and regulations. Our retention periods are determined based on the type of data, the purpose of collection, and any legal or contractual requirements that mandate specific retention durations. Once the retention period expires, we securely delete or anonymize the data so that it can no longer be associated with you.
Contact form submissions and inquiry data are retained for a period of twenty-four months from the date of your last interaction with us, unless a formal business relationship is established. For clients with whom we enter into service agreements, project-related data including communications, technical specifications, and deliverables are retained for the duration of the engagement plus an additional seven years to comply with tax, accounting, and legal record-keeping requirements under Chinese law.
Website usage data and server logs are retained in an aggregated and anonymized form indefinitely for analytical purposes. Raw log data containing IP addresses is retained for a maximum of ninety days before being purged or irreversibly anonymized. We store all personal data on secure servers located within the Peoples Republic of China, with access restricted to authorized personnel who have a legitimate business need to access such data.
We do not sell, rent, trade, or otherwise disclose your personal data to third parties for their own marketing or commercial purposes. Any sharing of personal data with external parties is strictly limited to circumstances where it is necessary to provide our services, comply with legal obligations, or protect our legitimate business interests, and always subject to appropriate confidentiality and security safeguards.
Service providers and subcontractors who assist us in operating our business may receive access to personal data as needed to perform their functions. These include website hosting providers, email communication platforms, cloud storage services, and professional advisors such as legal counsel and accountants. We enter into written data processing agreements with all service providers that require them to process data only on our documented instructions, implement appropriate security measures, and delete or return data upon completion of services.
Legal and regulatory disclosures may occur when we are required to disclose personal data in response to a valid court order, subpoena, government investigation, or as otherwise required by applicable law. We will notify you of such disclosures unless prohibited by law or where notification would compromise an ongoing investigation. In the event of a merger, acquisition, or sale of all or a portion of our business assets, personal data may be transferred to the successor entity, subject to the same privacy commitments outlined in this policy.
As a company headquartered in China that serves international clients, there may be circumstances where your personal data is transferred across national borders. We take the protection of your data seriously regardless of where it is processed, and we implement safeguards to ensure that any cross-border data transfers comply with applicable data protection laws.
When we transfer personal data from the European Economic Area, the United Kingdom, or other jurisdictions with data transfer restrictions, we ensure that appropriate safeguards are in place. These safeguards may include standard contractual clauses approved by relevant data protection authorities, adequacy decisions recognizing that a destination country provides an adequate level of protection, or binding corporate rules where applicable. You may request details of the specific safeguards applicable to your data by contacting us using the information provided in the Contact Information section.
For clients and website visitors within China, your personal data is primarily stored and processed on servers located within mainland China. Any transfer of data outside China is conducted in compliance with the cross-border data transfer requirements of the Personal Information Protection Law, including conducting necessary security assessments and obtaining your separate consent where required by law. We do not transfer personal data to jurisdictions that do not provide adequate protection for data subjects without first implementing supplementary measures to bring the level of protection to an adequate standard.
Depending on your jurisdiction, you may have certain rights regarding the personal data we hold about you. We are committed to facilitating the exercise of these rights and will respond to all valid requests within the timeframes prescribed by applicable law. To exercise any of the rights described below, please contact us using the email address in the Contact Information section of this policy.
The right of access entitles you to request confirmation of whether we process your personal data and, if so, to obtain a copy of that data along with information about how and why it is processed. The right to rectification allows you to request correction of inaccurate or incomplete personal data we hold about you. We will promptly update our records upon verification of the corrected information.
The right to erasure, also known as the right to be forgotten, permits you to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected or when you withdraw consent and no other legal basis for processing exists. This right is not absolute and may be limited by our need to retain data for legal compliance or the establishment, exercise, or defense of legal claims.
The right to restrict processing allows you to limit how we use your data in specific situations, such as when you contest the accuracy of the data or object to processing based on legitimate interests. The right to data portability entitles you to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller where technically feasible. The right to object permits you to object to processing based on legitimate interests or for direct marketing purposes, in which case we will cease such processing unless we demonstrate compelling legitimate grounds that override your interests.
Our website and services are intended for business professionals and organizations and are not directed toward children under the age of sixteen. We do not knowingly collect, solicit, or maintain personal data from anyone under the age of sixteen, and we do not design any part of our website or service offerings to attract or engage minors. Our content, language, and service descriptions are oriented toward enterprise-level technology decision-makers and business stakeholders.
If we become aware that we have inadvertently collected personal data from a child under the age of sixteen without verified parental consent, we will take immediate steps to delete that information from our systems. If you are a parent or guardian and believe that your child has provided personal data to us, please contact us promptly using the details in the Contact Information section so that we can investigate and take appropriate corrective action, including removal of the data from our records.
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and understand where our visitors originate. A cookie is a small text file that is placed on your device when you visit a website, allowing the website to recognize your browser on subsequent visits and remember certain preferences or actions over time.
We classify the cookies we use into two categories. Essential cookies are strictly necessary for the operation of the website, enabling core functionality such as page navigation, secure form submissions, and session management. These cookies do not require your consent and cannot be disabled through our systems, though you may block them through your browser settings at the cost of reduced website functionality.
Analytics cookies help us understand how visitors interact with our website by collecting and reporting information anonymously. We use these cookies to measure page views, visit duration, traffic sources, and user navigation patterns. The data collected through analytics cookies is aggregated and does not identify individual visitors. You may opt out of analytics cookies through your browser settings without affecting the core functionality of the website. We do not use advertising cookies, social media tracking pixels, or any form of behavioral profiling technology.
We implement and maintain technical, administrative, and physical security measures designed to protect your personal data from unauthorized access, alteration, disclosure, or destruction. Our security framework is built on industry-standard practices appropriate to the sensitivity of the data we process and the nature of our computer systems design business.
Technical measures include Transport Layer Security (TLS) encryption for all data transmitted between your browser and our servers, ensuring that information you submit through our website forms is protected in transit. Our servers are protected by firewalls, intrusion detection systems, and regular security patch management. Access to personal data within our organization is controlled through role-based access controls, multi-factor authentication, and audit logging of all data access events.
Administrative measures include regular privacy and security training for all personnel who handle personal data, confidentiality agreements with employees and contractors, and documented data handling procedures that govern how personal data is collected, stored, accessed, and disposed of. We conduct periodic reviews of our security practices and update them as necessary to address evolving threats and technological developments. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities without undue delay and in accordance with applicable legal requirements.
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our data practices, legal obligations, or business operations. When we make material changes, we will revise the effective date at the top of this page and, where appropriate, provide additional notice through our website or via direct communication to clients who have an active relationship with us.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website or services after any changes to this policy constitutes your acknowledgment and acceptance of the revised terms. If a change would permit us to use previously collected personal data in a materially different way, we will obtain your consent before applying the new usage to your existing data where required by applicable law.
Historical versions of this Privacy Policy are archived and available upon request. If you have questions about any changes or wish to understand how a previous version of this policy applied to your data, please contact us using the information below.
If you have questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us using the following details. We are committed to addressing all privacy-related inquiries promptly and thoroughly.
Data Controller: Shanxi Zhanghai Trading Co., Ltd.
Registered Address: 1-2-301, Guangjian Home Community, 50 meters east of the intersection of Bingzhou Road and Dicun North Street, Xiaodian District, Taiyuan -- 030000, China (CN)
Email: service@zhanghai.mom
Phone: +1 (507) 572-6805
Website: www.zhanghai.mom
You also have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction if you believe that our processing of your personal data violates applicable data protection laws. We would, however, appreciate the opportunity to address your concerns directly before you approach any regulatory body, and we encourage you to contact us first so that we can seek to resolve the matter.