1. Introduction and Overview

2. Information We Collect

We collect several types of information from and about users of our website and services. The types of information we may collect include but are not limited to the following categories:

Personal Identification Information: This includes your full name, email address, telephone number, company name, job title, and mailing address. We collect this information when you voluntarily submit it through our contact forms, email communications, or during consultation sessions with our team.

Technical and Usage Data: When you access our website, our servers automatically collect certain technical information. This includes your Internet Protocol address, browser type and version, operating system, device type, referring URLs, pages visited, time and date of visits, time spent on pages, and other diagnostic data. This information helps us understand how visitors interact with our website and enables us to improve our services.

Communication Records: When you contact us via email, telephone, or through our online contact form, we may retain records of those communications. This includes the content of your messages, our responses, and any attachments or documents you share with us in the course of our engagement.

Project and Business Information: During the course of providing computer systems design and integration services, we may collect technical specifications, business requirements, system architecture details, infrastructure configurations, and other operational data relevant to the services we are engaged to perform.

Payment and Transaction Data: For clients who engage our paid services, we may collect billing information, payment details, and transaction records. Please note that we do not store full credit card numbers or sensitive payment credentials on our own servers. Payment processing is handled through secure third-party payment processors in compliance with industry standards.

We do not knowingly collect special categories of personal data, such as information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning your sex life or sexual orientation, unless such information is voluntarily provided by you.

3. How We Collect Information

We employ various methods to collect information from and about you. Understanding these collection methods is important for transparency and informed consent.

Direct Collection: The primary method by which we collect information is directly from you when you voluntarily provide it. This occurs when you fill out and submit our online contact form, send us an email to hello@oriolesong.hair, call our phone number at +12722423634, register for an account, or provide information during a consultation or service engagement with our team members.

Automatic Collection: As you navigate through and interact with our website, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns. These technologies include cookies, server logs, web beacons, and similar tracking mechanisms. The information collected automatically is primarily statistical data and does not directly identify you as an individual.

Third-Party Sources: In some circumstances, we may receive information about you from third-party sources. This may include analytics providers such as Google Analytics, advertising networks, search information providers, and our technology partners. We ensure that any third parties from whom we receive data have obtained it lawfully and have the right to share it with us.

Client Engagement Data: When we are engaged to provide computer systems design and integration services, additional information may be collected through site visits, technical assessments, system audits, documentation reviews, and interviews with your personnel. This information is collected solely for the purpose of delivering the contracted services.

4. How We Use Your Information

We use the information we collect for various business purposes, each designed to enhance your experience and improve our service delivery. The specific purposes for which we process your information include the following:

Service Delivery and Client Support: We use your information to provide, maintain, and improve our computer systems design and related services. This includes processing your requests, communicating with you about project progress, responding to your inquiries, and providing technical support and customer service.

Website Operation and Improvement: Technical and usage data is used to operate, maintain, and improve our website. We analyze usage patterns to optimize page layouts, enhance navigation, identify and fix technical issues, and develop new features and functionality that better serve our visitors.

Communication and Marketing: With your consent where required by law, we may use your contact information to send you updates about our services, industry insights, newsletters, promotional materials, and other information that may be of interest to you. You may opt out of receiving marketing communications at any time by following the unsubscribe instructions included in each communication or by contacting us directly.

Legal Compliance and Protection: We may use your information as necessary to comply with applicable laws, regulations, legal processes, or governmental requests. We may also use information to enforce our Terms of Service, protect our rights and property, protect the safety of our users and the public, and detect, prevent, or address fraud, security, or technical issues.

Business Operations: Your information supports essential business functions including billing and invoicing, contract management, resource planning, quality assurance, and internal reporting. We may also use aggregated and anonymized data for business analytics and strategic planning purposes.

Personalization: We may use information to personalize your experience on our website and to tailor our communications and recommendations based on your interests, industry, and previous interactions with OrioleSong.

We will not use your personal information for purposes other than those disclosed in this Privacy Policy without first obtaining your explicit consent, unless otherwise required or permitted by applicable law.

6. Data Storage and Retention

We retain personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable laws and regulations. Our retention practices are designed to balance operational needs with privacy considerations.

Retention Criteria: The criteria we use to determine appropriate retention periods include the duration of our ongoing relationship with you, the nature and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process your information, whether we can achieve those purposes through other means, and applicable legal, regulatory, tax, accounting, or other requirements.

Retention Periods: Contact form submissions and email correspondence are typically retained for a period of two years following the last communication, unless a client relationship is established, in which case information is retained in accordance with our client data retention schedule. Technical and usage data collected through automatic means is generally retained for a maximum period of twenty-six months. Financial and transaction records are retained for the period required by applicable tax and accounting laws, typically seven years.

Data Minimization: We are committed to the principle of data minimization. We collect only the information that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. We periodically review our data holdings and securely delete or anonymize information that is no longer needed.

Storage Locations: Your information is stored on secure servers maintained by our hosting providers. We take reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy. Our primary data storage facilities are located in the United States and Asia-Pacific regions, with appropriate safeguards in place for cross-border data transfers.

7. Data Security Measures

We implement and maintain appropriate technical, administrative, and physical security measures designed to protect your personal information from unauthorized access, disclosure, alteration, and destruction. Our security practices are regularly reviewed and updated to address emerging threats and evolving industry standards.

Technical Safeguards: We employ industry-standard encryption protocols, including Transport Layer Security, to protect data transmitted between your browser and our servers. Our systems are protected by firewalls, intrusion detection and prevention systems, and regular vulnerability scanning. Access to personal data is restricted through role-based access controls and strong authentication mechanisms.

Administrative Safeguards: Our personnel are trained on data protection and privacy best practices. Access to personal information is limited to employees, contractors, and agents who have a legitimate business need to access such information and who are bound by confidentiality obligations. We maintain a comprehensive information security policy that governs the handling of personal data throughout our organization.

Physical Safeguards: Our servers and data storage infrastructure are housed in secure facilities with controlled access, environmental controls, and redundant power and connectivity. Physical access to data centers is restricted to authorized personnel and monitored through surveillance and access logging systems.

Third-Party Security: When we engage third-party service providers who may have access to personal data, we conduct due diligence to ensure they maintain appropriate security measures. Our agreements with such providers include contractual obligations to protect personal data in accordance with applicable laws and our standards.

Despite our best efforts, no method of electronic storage or transmission over the Internet is completely secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. We encourage you to take steps to protect your own information, such as using strong passwords and keeping your login credentials confidential.

8. Your Data Protection Rights

Depending on your jurisdiction and applicable data protection laws, you may have certain rights regarding your personal information. We are committed to respecting and facilitating the exercise of these rights. The rights that may be available to you include the following:

Right of Access: You have the right to request confirmation of whether we process your personal data and, if so, to obtain a copy of the personal data we hold about you, along with certain information about how we use it. We will provide this information in a commonly used electronic format unless you request otherwise.

Right to Rectification: You have the right to request that we correct any inaccurate personal data we hold about you and to have incomplete personal data completed. We encourage you to keep your information up to date and to notify us promptly of any changes.

Right to Erasure: In certain circumstances, you have the right to request the deletion of your personal data. This right applies when the data is no longer necessary for the purposes for which it was collected, when you withdraw consent, when you object to processing, when processing is unlawful, or when deletion is required by law. However, we may retain certain information as required or permitted by applicable law.

Right to Restriction: You have the right to request the restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data, when processing is unlawful, or when we no longer need the data but you require it for legal claims.

Right to Data Portability: Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller without hindrance from us.

Right to Object: You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes and processing based on legitimate interests. If you object to processing for direct marketing, we will cease such processing promptly.

Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing before the withdrawal.

Right to Complain: You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data violates applicable data protection laws. We encourage you to contact us first so that we can address your concerns directly.

To exercise any of these rights, please contact us using the information provided in the Contact Information section below. We will respond to your request within the timeframe required by applicable law. We may need to verify your identity before processing certain requests to protect your privacy and security.

9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance user experience, analyze website traffic, and support essential website functions. This section explains what cookies are, how we use them, and your choices regarding their use.

What Are Cookies: Cookies are small text files that are placed on your computer or mobile device when you visit a website. They are widely used to make websites work more efficiently and to provide information to website owners. Cookies may be session cookies, which expire when you close your browser, or persistent cookies, which remain on your device for a set period or until you delete them manually.

Types of Cookies We Use: Our website uses essential cookies that are necessary for the basic operation of the site, including navigation and access to secure areas. We also use analytics cookies, which help us understand how visitors interact with our website by collecting and reporting information anonymously. These cookies allow us to measure and improve the performance of our site. We may also use functionality cookies that enable enhanced personalization and remember your preferences on subsequent visits.

Third-Party Cookies: Some cookies on our website may be set by third-party services that appear on our pages. For example, we may use analytics services such as Google Analytics, which set their own cookies to track website usage. These third parties may use the information collected through cookies in accordance with their own privacy policies. We do not control these third-party cookies and recommend that you review the privacy policies of these services for more information.

Your Cookie Choices: Most web browsers automatically accept cookies, but you can usually modify your browser settings to decline cookies if you prefer. You can typically configure your browser to notify you when you receive a cookie, giving you the opportunity to decide whether to accept it, or to block all cookies or only third-party cookies. Please note that disabling cookies may affect the functionality of our website and limit your ability to use certain features.

Do Not Track Signals: Some browsers offer a Do Not Track feature that signals to websites that you do not want to have your online activities tracked. Our website currently does not respond to Do Not Track signals due to the lack of an industry-wide standard for interpreting such signals. However, we provide you with other options to manage cookie preferences as described in this section.

10. Third-Party Services and External Links

Our website and services may contain links to third-party websites, plugins, and applications. We may also engage third-party companies and individuals to facilitate our services, provide services on our behalf, perform service-related activities, or assist us in analyzing how our services are used.

Links to External Websites: Our website may include links to external websites that are not operated by us. If you click on a third-party link, you will be directed to that third party site. We strongly advise you to review the privacy policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Service Providers: We may engage third-party service providers to perform functions on our behalf, including hosting and server infrastructure, analytics, email delivery, customer relationship management, payment processing, and marketing assistance. These service providers have access to personal information only as necessary to perform their functions and are contractually obligated to maintain the confidentiality and security of your information.

Analytics Partners: We use analytics services, including Google Analytics, to collect and process statistical data about website usage. These services may use cookies and similar technologies to collect information about your interactions with our website. The data collected is aggregated and anonymized and is used solely for the purpose of analyzing and improving our website performance.

Business Transfers: In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your personal information may be transferred as part of the transaction. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.

Legal Disclosures: We may disclose your personal information to third parties if we believe that such disclosure is necessary to comply with a legal obligation, to protect and defend our rights or property, to prevent or investigate possible wrongdoing in connection with our services, to protect the personal safety of users of our services or the public, or to protect against legal liability.

11. International Data Transfers

OrioleSong operates globally, and your information may be transferred to, stored, and processed in countries other than the country in which you reside. By using our website and services, you acknowledge that your information may be transferred to our facilities and those third parties with whom we share it as described in this Privacy Policy.

The data protection laws in the countries to which your information is transferred may differ from those in your country of residence. In certain circumstances, courts, law enforcement agencies, regulatory agencies, or security authorities in those other countries may be entitled to access your personal information.

When we transfer personal data across international borders, we implement appropriate safeguards to ensure that your information receives an adequate level of protection. These safeguards may include data transfer agreements incorporating standard contractual clauses approved by relevant regulatory authorities, verification that the recipient country has been deemed to provide an adequate level of data protection, or reliance on your explicit consent for the transfer.

By submitting your personal information to us, you consent to the transfer, storage, and processing of your information in countries outside your country of residence, including the United States and other jurisdictions in which we or our service providers operate.

12. Privacy for Children

Our website and services are not directed to individuals under the age of eighteen. We do not knowingly collect, use, or disclose personal information from anyone under the age of eighteen. We take the protection of children and their privacy very seriously.

If we become aware that we have collected personal data from a child under the age of eighteen without verification of parental consent, we will take immediate steps to delete that information from our servers. We encourage parents and guardians to monitor their children and minors online activity and to instruct their children never to provide personal information through the internet without their permission.

If you are a parent or guardian and you believe that your child has provided us with personal information without your consent, please contact us immediately using the information provided in the Contact Information section below. We will work with you to address the situation promptly and ensure the deletion of any unauthorized information.

We also recommend that parents and guardians use parental control tools and privacy settings available through web browsers, internet service providers, and device manufacturers to help create a safer online environment for children.

13. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, technology, legal obligations, or other operational requirements. We encourage you to periodically review this page for the latest information on our privacy practices.

When we make material changes to this Privacy Policy, we will notify you by prominently posting a notice on our website prior to the change becoming effective, and updating the effective date at the top of this policy. We may also notify you via email or through other direct communication channels if we have your contact information on file.

Changes to this Privacy Policy will become effective immediately upon posting unless otherwise specified. Your continued use of our website and services after any modification to this Privacy Policy will constitute your acknowledgment of the modifications and your consent to abide by and be bound by the updated policy.

If we make material changes to how we treat your personal information, or to the Privacy Policy as a whole, we will endeavor to provide you with reasonable notice of such changes. We will archive previous versions of this Privacy Policy for your review upon request.

15. Data Breach Notification Procedures

We have established procedures to detect, investigate, and respond to data breaches in a timely and effective manner. In the unfortunate event of a data breach involving your personal information, we are committed to taking prompt and appropriate action.

Detection and Investigation: We maintain monitoring systems and incident response protocols designed to detect potential security incidents and data breaches. Upon detection of a suspected breach, we will immediately initiate an investigation to determine the scope, nature, and impact of the incident, as well as the categories and approximate number of individuals and records affected.

Containment and Remediation: Upon confirmation of a data breach, we will take immediate steps to contain the breach and prevent further unauthorized access or disclosure. We will also implement remediation measures to address the root cause of the breach and strengthen our security posture to reduce the risk of recurrence.

Notification to Affected Individuals: If we determine that a data breach poses a risk to your rights and freedoms, we will notify you without undue delay. Our notification will describe the nature of the breach, the categories and approximate number of affected records, the likely consequences, the measures we have taken or propose to take to address the breach, and recommendations for steps you can take to protect yourself. We will also provide contact information for our data protection team for further inquiries.

Notification to Authorities: Where required by applicable law, we will notify the relevant data protection supervisory authority of a data breach within the prescribed timeframe, providing all required details about the incident and our response measures.

Record Keeping: We maintain an internal record of all data breaches, regardless of whether notification to individuals or authorities was required, including the facts relating to the breach, its effects, and the remedial actions taken. These records are available for review by relevant supervisory authorities upon request.

16. Contact Information and Enquiries

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please do not hesitate to contact us. We are committed to addressing your inquiries promptly and thoroughly.

Company Name: Suizhou Miaoying Culture Media Co., Ltd.

Brand Name: OrioleSong

Industry: Computer Systems Design and Related Services

Registered Address: No. 452 Jiefang West Road, Nanjing Subdistrict, Zengdu District, Suizhou - 441300, China (CN)

Email Address: hello@oriolesong.hair

Phone Number: +12722423634

Website: https://www.oriolesong.hair

We aim to acknowledge all inquiries within two business days and to provide a substantive response within thirty calendar days. If your inquiry is complex or requires additional investigation, we will inform you of the expected timeline for a complete response.

You also have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction if you believe that our processing of your personal data violates applicable law. However, we encourage you to contact us first so that we may have the opportunity to resolve your concern directly.

This Privacy Policy was last updated and is effective as of January 1, 2024.