Introduction

ModulesLink ("we", "us", "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and protect information about you in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679, the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

Effective Date:
Last Updated:

Data Controller: ModulesLink, Inc., 100 Innovation Way, Shenzhen, Guangdong 518000, China. Data Protection Officer (DPO): dpo@moduleslink.com

1. Information We Collect

We collect the following categories of personal information:

  • Identity Data: Name, job title, company name (when you contact us, request a quote, or register for an account)
  • Contact Data: Email address, phone number, mailing address
  • Technical Data: IP address, browser type and version, time zone settings, operating system (collected automatically via cookies and server logs)
  • Usage Data: Pages visited, time spent on pages, referring website, page interaction data
  • Marketing Data: Preferences in receiving marketing communications

2. Legal Basis for Processing (GDPR Art. 6)

We process your personal data under the following legal bases:

  • Consent (Art. 6(1)(a)): When you opt-in to receive marketing emails or accept non-essential cookies
  • Contractual Necessity (Art. 6(1)(b)): To fulfill quote requests, process orders, and deliver products
  • Legal Obligation (Art. 6(1)(c)): To comply with tax, accounting, and regulatory record-keeping requirements
  • Legitimate Interest (Art. 6(1)(f)): For website security, fraud prevention, and business analytics (with balancing test)

3. How We Use Your Information

We use your personal information to:

  • Respond to inquiries and provide quotes
  • Process and fulfill orders, including shipping and invoicing
  • Provide customer support and technical assistance
  • Improve our website, products, and services through analytics
  • Send marketing communications (only with your consent)
  • Maintain website security and prevent fraud
  • Comply with legal and regulatory obligations

4. Third-Party Data Sharing

We share your personal data with the following categories of recipients:

  • Logistics providers: DHL, FedEx (for product delivery)
  • Payment processors: Stripe, PayPal (for payment processing)
  • Analytics providers: Google Analytics 4 (with IP anonymization)
  • Hosting providers: Cloudflare, AWS (for website hosting)
  • Legal authorities: When required by law, court order, or regulatory request

We do NOT sell your personal data to any third party. Sub-processors are bound by data processing agreements (DPAs) compliant with GDPR Art. 28.

5. International Data Transfers

Your personal data may be transferred to, and processed in, countries outside the European Economic Area (EEA) or your country of residence (e.g., for hosting in the USA or manufacturing in China). We ensure such transfers are protected by:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements with all sub-processors
  • Binding Corporate Rules (where applicable)
  • Transfers to countries with an adequacy decision (e.g., UK, Japan, South Korea)

6. Data Retention

We retain your personal data only as long as necessary for the purposes set out in this policy:

  • Customer accounts and order data: 7 years (tax/legal record-keeping requirement)
  • Marketing data: Until you withdraw consent or unsubscribe
  • Inquiry records: 3 years from last interaction
  • Server logs: 90 days for security purposes

7. Your Data Protection Rights (GDPR Art. 15-22)

Under GDPR, CCPA, and other laws, you have the following rights:

  • Right of Access (Art. 15): Request a copy of your personal data
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete data
  • Right to Erasure (Art. 17): Request deletion of your personal data
  • Right to Restriction (Art. 18): Limit processing in certain circumstances
  • Right to Data Portability (Art. 20): Receive your data in a machine-readable format
  • Right to Object (Art. 21): Object to processing based on legitimate interest
  • Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time

To exercise these rights, email privacy@moduleslink.com with a copy of your ID. We respond within 30 days. You may also lodge a complaint with your local Data Protection Authority (e.g., DPC Ireland or your country's DPA).

8. How We Protect Your Information

We implement appropriate technical and organizational security measures including:

  • TLS 1.3 encryption for all data in transit (HTTPS)
  • AES-256 encryption for sensitive data at rest
  • Role-based access control (RBAC) and multi-factor authentication (MFA) for staff
  • Regular security audits and penetration testing
  • ISO 27001-aligned information security management

9. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Art. 33. If the breach is likely to result in a high risk to your rights, we will also notify you without undue delay (GDPR Art. 34).

10. Children's Privacy

Our website is intended for business customers and professionals. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child, please contact us immediately for deletion.

11. Updates to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email (if we have your contact details) and by posting a prominent notice on our website 30 days before taking effect. The "Last Updated" date at the top indicates when the policy was last revised.

12. Contact Us

For any questions about this Privacy Policy, to exercise your data subject rights, or to file a complaint, please contact our Data Protection Officer:

You may also use our contact form for general inquiries.