Legal
Privacy Policy
Effective date: 1 January 2025 — Version 1.0
This Policy governs the collection, use, and protection of personal data by Shenzhen Clear Science & Technology Co., Ltd (KELIER) in connection with the kelier.co website, hosted within the European Union.
Contents
1. Introduction and Scope
This Privacy Policy ("Policy") is issued by Shenzhen Clear Science & Technology Co., Ltd, trading as KELIER ("KELIER", "we", "our", or "us"), a limited liability company incorporated under the laws of the People's Republic of China, with registered address at Room 2301, Building 1B, Zhihuijiayuan, Baolong Street, Longgang District, Shenzhen, Guangdong Province 518100, China.
Our website (https://kelier.co) and all associated digital services and communications (collectively, the "Services") are hosted on server infrastructure located within the European Union. Accordingly, the processing of personal data through our Services is subject to the General Data Protection Regulation ("GDPR") as the primary regulatory framework, in addition to other applicable data protection laws worldwide.
This Policy applies globally to all visitors, prospective clients, business contacts, enquirers, and any other individuals ("Data Subjects" or "you") who interact with our Services, regardless of their country or region of residence. It describes what personal data we collect, why we collect it, how we use and protect it, how long we retain it, with whom we share it, and what rights you have in relation to it.
This Policy reflects our commitment to compliance with, among others: the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679); the UK GDPR and the Data Protection Act 2018; the Personal Information Protection Law of the People's Republic of China (PIPL, effective 1 November 2021) and the Network Security Law of the PRC; the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA); Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation; Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD, Law No. 13,709/2018); Singapore's Personal Data Protection Act 2012 (PDPA); Thailand's Personal Data Protection Act B.E. 2562 (2019); Japan's Act on the Protection of Personal Information (APPI), as amended; Australia's Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs); South Korea's Personal Information Protection Act (PIPA); India's Digital Personal Data Protection Act 2023 (DPDPA); and the Swiss revised Federal Act on Data Protection (revDSG, effective 1 September 2023).
Where applicable law imposes higher standards than those described herein, the higher standard shall prevail. This Policy does not constitute a contractual offer and does not create legally enforceable rights beyond those conferred by applicable law. By using our Services, you acknowledge that you have read, understood, and accept the practices described in this Policy.
2. Definitions
For the purposes of this Policy, the following terms have the meanings set out below:
"Personal Data" means any information relating to an identified or identifiable natural person, including any data that can directly or indirectly identify an individual. This includes, without limitation, names, email addresses, telephone numbers, IP addresses, device identifiers, and online identifiers. The term "personal information" and "personal information" as used in non-GDPR jurisdictions are used interchangeably with Personal Data in this Policy.
"Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, storage, organisation, structuring, use, disclosure, dissemination, restriction, erasure, or destruction.
"Data Controller" (or "Controller") means the entity that determines the purposes and means of Processing Personal Data. For Processing activities carried out through our Services, KELIER is the Data Controller.
"Data Processor" (or "Processor") means an entity that Processes Personal Data on behalf of and under the instructions of a Data Controller.
"Sensitive Personal Data" (also called "Special Categories of Personal Data" under GDPR) means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data processed for identification purposes, health data, or data concerning a person's sex life or sexual orientation. We do not intentionally collect Sensitive Personal Data through our Services.
"Data Subject" means an identified or identifiable natural person whose Personal Data is being Processed.
"Third Party" means any natural or legal person, public authority, agency, or body other than KELIER, its personnel, and the Data Subject.
"EEA" means the European Economic Area, comprising the 27 EU Member States plus Iceland, Liechtenstein, and Norway.
"Adequacy Decision" means a formal decision by the European Commission confirming that a third country, territory, or sector provides an essentially equivalent level of data protection to that guaranteed within the EEA.
"Standard Contractual Clauses" or "SCCs" means the standard data protection clauses adopted or approved by the European Commission pursuant to Article 46(2)(c) or (d) of the GDPR, as amended or updated from time to time.
3. Identity of the Data Controller and Data Protection Contact
The Data Controller responsible for your Personal Data collected through the Services is:
Shenzhen Clear Science & Technology Co., Ltd (KELIER) Room 2301, Building 1B, Zhihuijiayuan, Baolong Street, Longgang District, Shenzhen, Guangdong Province 518100, People's Republic of China Email: contact@kelier.co Website: https://kelier.co
Although we are not currently required by applicable law to appoint a Data Protection Officer ("DPO"), we have designated a Privacy Contact responsible for overseeing our data protection compliance programme, managing Data Subject requests, and serving as the point of contact for supervisory authorities. You may contact our Privacy Contact at contact@kelier.co for any queries relating to this Policy or the exercise of your rights. We will respond to all enquiries within the timeframes prescribed by applicable law, and in any event within 30 calendar days of receipt.
For Data Subjects located in the European Union or the United Kingdom, in addition to contacting us directly, you have the right to lodge a complaint with the competent supervisory authority in your country of residence (see Section 19 for a list of supervisory authorities).
4. Categories of Personal Data We Collect
We collect and Process the following categories of Personal Data, depending on the nature of your interaction with our Services:
Identity and Contact Data: first name; last name; job title; company or organisation name; business email address; telephone number; postal address; country of residence or operation.
Enquiry and Commercial Data: the content of consultation requests, project enquiries, and messages you submit through our website forms; details of your industrial or operational requirements as voluntarily disclosed; records of correspondence between you and KELIER.
Technical and Device Data: Internet Protocol (IP) address (collected in truncated or pseudonymised form where feasible); browser type and version; operating system and platform; device type and screen resolution; time zone and language settings; referring URL; pages visited on our site; session duration and click-path data collected via server-side logging.
Usage and Analytics Data: aggregated and anonymised data about how visitors interact with our website, including which sections are viewed, navigation paths, and session counts. Where this data is collected in a form that could identify individuals, it is treated as Personal Data.
Cookie and Similar Technology Data: data collected through technically necessary cookies, as described in Section 11 of this Policy.
We do not intentionally collect Sensitive Personal Data (Special Categories of Personal Data under GDPR) through our Services. If you inadvertently include such data in an enquiry or message, we will treat it with the highest degree of care and delete it as soon as it is no longer required for the purpose for which it was submitted. We do not collect payment card information or bank account details through our website.
5. How We Collect Your Personal Data
We collect Personal Data through the following means:
Direct Collection: Personal Data you actively provide to us, for example when you complete and submit a consultation request form, contact us via email, request product documentation, or otherwise initiate communication with our team.
Automatic Collection: Certain Technical and Device Data is collected automatically when you visit our website. This occurs through our web server logs, which record standard HTTP request metadata including IP address, browser identity string, request path, and response codes. This data is collected for security monitoring, performance analysis, and fraud prevention purposes.
Cookies and Similar Technologies: Technically necessary cookies may collect limited session-level data. Please refer to Section 11 for full details. We do not deploy advertising networks, social media tracking pixels, or third-party behavioural analytics scripts.
We do not purchase Personal Data from data brokers, scrape Personal Data from third-party platforms, or otherwise obtain Personal Data from sources other than those listed above without your knowledge.
6. Legal Bases for Processing Personal Data (GDPR Article 6)
For individuals located in the EEA, the United Kingdom, and Switzerland, all Processing of Personal Data is carried out on one of the following lawful bases under Article 6 of the GDPR:
(a) Legitimate Interests (Article 6(1)(f) GDPR): We rely on legitimate interests as our primary lawful basis for Processing enquiry and contact data in order to respond to business enquiries, maintain accurate records of potential commercial relationships, and protect our systems from abuse. Before relying on this basis, we conduct a Legitimate Interests Assessment ("LIA") to ensure that our interests are not overridden by the Data Subject's fundamental rights and freedoms. Our legitimate interest is the operation of a professional B2B industrial services business.
(b) Performance of a Contract or Pre-Contractual Steps (Article 6(1)(b) GDPR): Where you have requested a consultation, proposal, or technical evaluation, we Process your Personal Data to take steps at your request prior to entering into a contract, and (once a commercial relationship is established) to perform our obligations under that contract.
(c) Compliance with Legal Obligations (Article 6(1)(c) GDPR): We may Process Personal Data where necessary to comply with applicable law, including tax law, accounting obligations, export control regulations, sanctions screening requirements, and responses to lawful orders from competent authorities.
(d) Consent (Article 6(1)(a) GDPR): Where we rely on consent as a lawful basis, for example in relation to optional marketing communications, we will request your explicit, freely given, specific, informed, and unambiguous consent before commencing such Processing. You may withdraw your consent at any time without affecting the lawfulness of Processing carried out before withdrawal.
We do not rely on vital interests (Article 6(1)(d)) or public tasks (Article 6(1)(e)) as lawful bases for our Processing activities.
7. Purposes of Processing
The table below sets out, for each category of Personal Data, the specific purposes for which it is Processed and the corresponding lawful basis:
Identity and Contact Data — Purpose: Responding to consultation and product enquiries; maintaining business contact records; preparing proposals and quotations. Lawful Basis: Legitimate Interests; Pre-Contractual Steps.
Enquiry and Commercial Data — Purpose: Technical evaluation of project requirements; preparation of engineering assessments; tracking and managing the business development pipeline. Lawful Basis: Legitimate Interests; Pre-Contractual Steps; Contract Performance.
Technical and Device Data (server logs) — Purpose: Information security monitoring; detection and prevention of cyberattacks, denial-of-service attacks, and unauthorised access; debugging and performance optimisation; abuse prevention. Lawful Basis: Legitimate Interests; Legal Obligation.
Usage and Analytics Data (aggregated) — Purpose: Understanding how visitors navigate our website in order to improve its structure and content. Lawful Basis: Legitimate Interests.
Cookie Data — Purpose: Essential website session management; security token validation. Lawful Basis: Legitimate Interests (for strictly necessary cookies); Consent (for any non-essential cookies, if deployed in future).
All Categories — Purpose: Compliance with export control laws, anti-money laundering obligations, sanctions screening, and lawful requests from governmental or regulatory authorities. Lawful Basis: Legal Obligation.
We do not use Personal Data collected through our website for purposes other than those described in this Policy. If we wish to Process your Personal Data for a new purpose that is incompatible with the original purpose, we will notify you and, where required by applicable law, seek your prior consent.
8. International Transfers of Personal Data
Our Services are hosted on server infrastructure located within the European Union. Accordingly, Personal Data collected through our Services is primarily stored and Processed within the EEA. However, because our personnel and management team are located in the People's Republic of China, certain Processing activities — including review of enquiry submissions, preparation of technical responses, and internal business administration — involve transferring Personal Data to China.
China does not currently benefit from an EU Adequacy Decision. Where we transfer Personal Data from the EEA to China, we implement appropriate safeguards as required by Article 46 of the GDPR, which may include Standard Contractual Clauses (SCCs) adopted by the European Commission (Commission Implementing Decision (EU) 2021/914, as updated), supplementary technical measures, and transfer impact assessments carried out in accordance with the guidance of the European Data Protection Board ("EDPB").
Where we engage third-party service providers ("Sub-Processors") established outside the EEA (see Section 13), we ensure that appropriate safeguards are in place prior to any transfer, including (as applicable): SCCs; Adequacy Decisions; Binding Corporate Rules; adherence to approved certification mechanisms; or derogations under Article 49 GDPR where such conditions are met.
For transfers to the United Kingdom following Brexit, we rely on the UK International Data Transfer Agreement ("IDTA") or the UK Addendum to the EU SCCs, as published by the UK Information Commissioner's Office ("ICO").
With respect to PIPL compliance: where we transfer personal information of Chinese citizens outside of the PRC, we comply with the relevant provisions of the PIPL, including (where required) completing a security assessment administered by the Cyberspace Administration of China ("CAC"), or obtaining separate consent for the cross-border transfer, as applicable based on the volume and sensitivity of data transferred.
You may request a copy of the safeguards we rely on for international transfers by contacting us at contact@kelier.co.
9. Data Retention
We retain Personal Data only for as long as is necessary to fulfil the purposes for which it was collected, to comply with legal obligations, to resolve disputes, and to enforce our agreements. The following retention periods apply:
Enquiry and Contact Records (consultation requests, email correspondence): We retain these records for a period of three (3) years from the date of last meaningful interaction. This period reflects our legitimate interest in maintaining complete business development records and corresponds to applicable statutes of limitation for commercial claims in relevant jurisdictions.
Contract and Pre-Contract Documentation (proposals, technical evaluations, quotations): Retained for a period of seven (7) years from the date of the last transaction or the end of any resulting contractual relationship, in accordance with applicable accounting, tax, and commercial record-keeping requirements.
Server Log Data (IP addresses, access logs): Retained for no more than ninety (90) days from the date of collection, after which logs are permanently deleted or irreversibly anonymised. Where a log record forms part of an active security investigation, it may be retained for the duration of the investigation and any resulting proceedings.
Website Analytics Data (aggregated and anonymised): Retained indefinitely in anonymised, non-identifying form. Once data is genuinely and irreversibly anonymised, it is no longer Personal Data for the purposes of data protection law.
Cookie Data: Session cookies expire when you close your browser. Persistent cookies (if any) are deleted in accordance with the expiry period disclosed in our Cookie Notice (see Section 11).
When the applicable retention period expires, Personal Data is securely deleted, destroyed, or irreversibly anonymised in accordance with our internal data disposal procedures. You may request earlier deletion of your Personal Data by exercising your Right to Erasure as described in Section 12, subject to any overriding legal obligations.
10. How We Protect Your Personal Data
We implement and maintain a comprehensive programme of technical and organisational security measures designed to protect your Personal Data against unauthorised or unlawful Processing, accidental loss, destruction, or damage. These measures are reviewed and updated on a regular basis in light of evolving threats and applicable legal requirements.
Technical Measures include: encryption of all data in transit using TLS 1.2 or higher; encryption of stored Personal Data using industry-standard encryption algorithms; server infrastructure hosted within ISO 27001-certified and SOC 2-compliant EU data centres; strict access controls implementing the principle of least privilege; multi-factor authentication for all administrative access; regular automated vulnerability scanning and periodic penetration testing conducted by qualified third parties; intrusion detection and prevention systems; and automated off-site backup procedures.
Organisational Measures include: limiting access to Personal Data to personnel who require it for their specific role; written confidentiality obligations and non-disclosure agreements with all staff and contractors who have access to Personal Data; data protection training for all relevant personnel; documented data processing procedures and internal privacy governance policies; data protection impact assessments ("DPIAs") carried out for Processing activities that are likely to result in a high risk to Data Subjects; a documented data breach response procedure; and due diligence assessments for all Sub-Processors.
Notwithstanding the foregoing, no method of electronic transmission or storage is completely secure. While we use commercially reasonable efforts to protect your Personal Data, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach (where required by GDPR Article 33) and will notify affected Data Subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34).
11. Cookies and Similar Tracking Technologies
Our website uses cookies and similar technologies. A "cookie" is a small text file placed on your device by a web server that enables the server to recognise your device on subsequent visits. We use cookies only to the extent strictly necessary for the technical operation of our website.
Strictly Necessary Cookies: These cookies are essential for the website to function and cannot be switched off in our systems. They are usually set in response to actions you take, such as setting your privacy preferences, logging in, or filling in forms. Without these cookies, services you have asked for cannot be provided. Because they are strictly necessary, they do not require your consent under Recital 47 of the GDPR and equivalent provisions.
We do not currently deploy the following types of cookies: (a) Performance or Analytics Cookies that collect information about how visitors use our website; (b) Functionality Cookies that enable enhanced features and personalisation; (c) Targeting or Advertising Cookies that are set by advertising partners to build profiles of your interests; or (d) Social Media Cookies set by social media networks to track your use of their features.
If we introduce any non-essential cookies in the future, we will update this Policy and our Cookie Notice, and will obtain your prior consent through a compliant consent management mechanism before setting such cookies. You will be able to withdraw your consent at any time with effect for the future.
You may configure your browser to refuse all or some cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of our website may become inaccessible or not function properly. For further information about managing cookies, please visit www.allaboutcookies.org.
Do Not Track (DNT): Some browsers include a DNT feature that signals to websites that you do not wish to be tracked. Our website currently does not alter its practices in response to DNT signals, as there is no widely accepted standard for interpreting such signals. We will update this section if a recognised standard is adopted.
12. Your Rights as a Data Subject
Subject to the conditions and limitations set out in applicable law, Data Subjects whose Personal Data is Processed by us in the context of the GDPR have the following rights. These rights also apply, with any necessary adaptations, under analogous provisions of PIPL, CCPA/CPRA, LGPD, PIPA, PDPA, and other applicable legislation.
(a) Right of Access (GDPR Article 15): You have the right to obtain confirmation as to whether or not we are Processing your Personal Data, and if so, to receive a copy of that data together with certain supplementary information about our Processing activities, including the purposes of Processing, the categories of data Processed, the recipients or categories of recipients to whom data has been disclosed, and the anticipated retention period.
(b) Right to Rectification (GDPR Article 16): You have the right to require us to correct inaccurate Personal Data relating to you without undue delay, and to have incomplete Personal Data completed.
(c) Right to Erasure / Right to be Forgotten (GDPR Article 17): You have the right to request the deletion of your Personal Data where: the data is no longer necessary for the purpose for which it was collected; you have withdrawn your consent and there is no other lawful basis for Processing; you have objected to Processing and there are no overriding legitimate grounds; the data has been unlawfully Processed; or deletion is required by EU or Member State law. This right is subject to exemptions for compliance with legal obligations and the establishment, exercise, or defence of legal claims.
(d) Right to Restriction of Processing (GDPR Article 18): You have the right to require us to restrict the Processing of your Personal Data in certain circumstances, including where you contest the accuracy of the data (pending verification), where Processing is unlawful but you prefer restriction to deletion, or where you have objected to Processing pending determination of whether our legitimate grounds override your interests.
(e) Right to Data Portability (GDPR Article 20): Where Processing is based on consent or contract performance and is carried out by automated means, you have the right to receive your Personal Data in a structured, commonly used, and machine-readable format, and to transmit that data to another Controller without hindrance from us.
(f) Right to Object (GDPR Article 21): You have the right to object at any time to the Processing of your Personal Data where that Processing is based on our legitimate interests (Article 6(1)(f)) or for direct marketing purposes. Where you object on grounds relating to your particular situation, we will cease Processing unless we can demonstrate compelling legitimate grounds that override your interests, or where Processing is necessary for the establishment, exercise, or defence of legal claims. Where you object to Processing for direct marketing purposes, we will immediately cease such Processing.
(g) Right Not to be Subject to Automated Decision-Making (GDPR Article 22): You have the right not to be subject to a decision based solely on automated Processing — including profiling — that produces legal or similarly significant effects concerning you. We do not currently use solely automated decision-making in our Processing activities.
(h) Right to Withdraw Consent: Where Processing is based on your consent, you have the right to withdraw that consent at any time with effect for the future. Withdrawal of consent does not affect the lawfulness of Processing carried out prior to withdrawal.
To exercise any of the above rights, please submit a written request to contact@kelier.co. We may ask you to provide proof of identity before processing your request, in order to protect the security of your Personal Data and prevent fraudulent access requests. We will respond within one calendar month of receipt of a valid request; where the request is complex or numerous, we may extend this period by a further two months, in which case we will notify you of the extension within the first month. There is no charge for exercising your rights, except in cases of manifestly unfounded or excessive requests, where we may charge a reasonable fee or decline to act.
13. Additional Rights by Jurisdiction
In addition to the rights described in Section 12, Data Subjects in certain jurisdictions have supplementary rights as follows:
California, United States (CCPA/CPRA): California residents have the right to know what Personal Information we collect, use, disclose, and sell (we do not sell Personal Information); the right to delete Personal Information we hold about them; the right to correct inaccurate Personal Information; the right to opt-out of the sale or sharing of Personal Information for cross-context behavioural advertising (not applicable as we do not engage in such activities); the right to limit the use and disclosure of Sensitive Personal Information (we do not collect Sensitive Personal Information as defined under CCPA/CPRA); and the right to non-discrimination for exercising their rights. To submit a CCPA/CPRA request, contact contact@kelier.co. We will verify requests by matching information provided against our records.
People's Republic of China (PIPL): Individuals whose personal information is Processed under the PIPL have the right to know how their personal information is handled; the right to decide and restrict or refuse personal information handling; the right to access and copy their personal information; the right to correct or supplement inaccurate or incomplete personal information; the right to transfer personal information to a designated handler; and the right to request deletion in accordance with PIPL Articles 47–48. Where we handle personal information of Chinese citizens, we implement appropriate security measures and, where required by law, conduct a personal information protection impact assessment ("PIPIA"). For cross-border transfers of personal information of Chinese citizens, we comply with the requirements of PIPL Chapter III, including CAC security assessment obligations where applicable.
Brazil (LGPD): Data Subjects whose personal data is Processed under the LGPD have the right of confirmation of the existence of processing; access; correction of incomplete, inaccurate, or outdated data; anonymisation, blocking, or deletion of unnecessary or excessive data; data portability; deletion of personal data processed on the basis of consent; information about third parties with whom personal data has been shared; information about the possibility of not providing consent and its consequences; and revocation of consent. LGPD-related requests may be submitted to contact@kelier.co.
Canada (PIPEDA): Canadian residents may request access to their Personal Information and have the right to challenge the accuracy and completeness of their information and have it amended as appropriate. They may also withdraw consent for the collection, use, or disclosure of their Personal Information, subject to legal or contractual restrictions.
Australia (Privacy Act 1988): Australian individuals have the right to access and correct Personal Information held about them in accordance with the Australian Privacy Principles. We will provide access within a reasonable period and at no cost unless the request is unreasonable.
South Korea (PIPA): Korean data subjects have rights of access, correction, deletion, suspension of processing, and withdrawal of consent. We will process requests within 10 days of receipt, or 30 days in complex cases.
Japan (APPI): Japanese individuals have the right to request disclosure, correction, addition, deletion, suspension of use, suspension of provision to third parties, and notification of the purpose of use of their personal information held by us.
14. Children's Privacy
Our Services are directed exclusively at business professionals and enterprise clients in the industrial and energy sectors. We do not knowingly collect or solicit Personal Data from any person under the age of 16 (or such higher age as may be required by applicable law in the relevant jurisdiction).
In accordance with the United States Children's Online Privacy Protection Act (COPPA), we do not knowingly collect Personal Data from children under the age of 13. Under the GDPR, where we rely on consent as a lawful basis, consent from a child is only valid if the child is at least 16 years old; for children under 16, consent must be given or authorised by a holder of parental responsibility.
In the People's Republic of China, the Processing of personal information of minors under the age of 14 is subject to the Provisions on the Protection of Children's Personal Information in the Cyberspace (2019), which require parental or guardian consent. We do not knowingly collect personal information of Chinese minors.
If we become aware that we have inadvertently collected Personal Data from a child below the applicable age threshold, we will take immediate steps to delete such data. If you believe we may have collected Personal Data from a minor, please contact us immediately at contact@kelier.co.
15. Third-Party Services and Sub-Processors
We engage certain third-party service providers ("Sub-Processors") who Process Personal Data on our behalf in order to operate and improve our Services. All Sub-Processors are engaged under written data processing agreements that impose obligations equivalent to or more stringent than those imposed on us by applicable data protection law.
Categories of Sub-Processors we engage include: cloud hosting and infrastructure providers (our server infrastructure is located within the EU); email delivery service providers; security and monitoring service providers; and PDF document hosting services. We do not share Personal Data with Sub-Processors for their own independent purposes; they may only Process Personal Data in accordance with our instructions.
We do not sell your Personal Data to any third party. We do not share your Personal Data with advertising networks, data brokers, or third-party analytics companies for behavioural profiling purposes.
We may disclose Personal Data to competent governmental, law enforcement, or regulatory authorities where we are legally required to do so, or where we have a good-faith belief that such disclosure is necessary to comply with a legal obligation, protect and defend the rights or property of KELIER, prevent or investigate possible wrongdoing in connection with our Services, or protect the personal safety of users of our Services or the public.
In the event of a merger, acquisition, reorganisation, divestiture, dissolution, or sale of all or a portion of KELIER's assets, Personal Data may be transferred to the relevant successor entity, subject to the same level of protection as described in this Policy. We will notify you prior to your Personal Data being transferred and becoming subject to a different privacy policy.
16. Marketing Communications
We do not send unsolicited commercial electronic messages. Any marketing or promotional communications we send are directed exclusively at existing business contacts who have enquired about or engaged with our products or services, where permitted under the "soft opt-in" provisions of applicable law (including the UK Privacy and Electronic Communications Regulations 2003 as amended, and equivalent provisions in other jurisdictions), or where we have obtained your prior explicit consent.
You may unsubscribe from marketing communications at any time by clicking the "unsubscribe" link included in every marketing email, or by contacting us at contact@kelier.co with the subject line "Unsubscribe". We will process your unsubscribe request within 10 business days. Unsubscribing from marketing communications will not affect any transactional or operational communications related to an active business relationship.
In jurisdictions where the prior consent of the recipient is required for all commercial electronic messages (including Canada under CASL and countries with equivalent opt-in requirements), we will only send marketing communications where we have obtained valid prior consent in accordance with applicable law.
17. Automated Decision-Making and Profiling
We do not make decisions that produce legal or similarly significant effects on Data Subjects based solely on automated Processing, including profiling, within the meaning of Article 22 of the GDPR. All material decisions affecting Data Subjects involve human review and oversight.
We do not use Personal Data collected through our Services to create behavioural profiles of individuals for advertising, credit-scoring, employment, insurance, or any other purpose that would constitute solely automated decision-making. If we introduce such processing in the future, we will update this Policy, provide you with prior notice, and, where required by law, seek your explicit consent or ensure that adequate safeguards are in place.
18. Data Breach Notification
We maintain a documented Personal Data Breach Response Procedure. In the event of a Personal Data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority (in the first instance, the supervisory authority in the EU Member State where our Services are hosted) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.
Where the breach is likely to result in a high risk to the rights and freedoms of affected Data Subjects, we will also notify those individuals directly without undue delay, providing them with a clear and plain-language description of the nature of the breach, the categories and approximate number of Data Subjects affected, the likely consequences of the breach, and the measures taken or proposed to address the breach and mitigate its possible adverse effects (GDPR Article 34).
We comply with equivalent breach notification obligations under other applicable laws, including the notification requirements of the PRC Network Security Law and PIPL (notification to the CAC and affected individuals within applicable timeframes), the CCPA/CPRA (notification to affected California residents and the California Attorney General where required), and other jurisdiction-specific requirements.
19. Supervisory Authorities
If you are located in the EEA or the UK and you are dissatisfied with how we handle your Personal Data or a request to exercise your rights, you have the right to lodge a complaint with the competent data protection supervisory authority. The following is a non-exhaustive list of relevant supervisory authorities:
European Union — The competent authority is the supervisory authority of the EU Member State where our Services are hosted, as well as the supervisory authority of your country of habitual residence or place of work. A full list of EU supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
United Kingdom — Information Commissioner's Office (ICO): ico.org.uk
People's Republic of China — Cyberspace Administration of China (CAC): cac.gov.cn
United States (California) — California Privacy Protection Agency (CPPA): cppa.ca.gov
Canada — Office of the Privacy Commissioner of Canada (OPC): priv.gc.ca
Brazil — Autoridade Nacional de Proteção de Dados (ANPD): gov.br/anpd
Australia — Office of the Australian Information Commissioner (OAIC): oaic.gov.au
Japan — Personal Information Protection Commission (PPC): ppc.go.jp
South Korea — Personal Information Protection Commission (PIPC): pipc.go.kr
Singapore — Personal Data Protection Commission (PDPC): pdpc.gov.sg
Switzerland — Federal Data Protection and Information Commissioner (FDPIC): edoeb.admin.ch
We request that you contact us in the first instance before lodging a complaint with a supervisory authority, as we may be able to resolve the issue directly and more efficiently.
20. Changes to This Privacy Policy
We reserve the right to update or modify this Policy at any time to reflect changes in our data processing practices, applicable law, or regulatory guidance. The effective date displayed at the top of this page will be updated whenever material changes are made.
Where changes are material — meaning they would meaningfully affect the way we use or share your Personal Data, or your rights in relation to it — we will provide prior notice by posting a prominent notice on our website homepage for a minimum period of 30 days before the changes take effect, and/or by sending a notification to the email address associated with your enquiry record where we hold one.
For non-material changes (such as typographical corrections, clarifications, or changes required by law with immediate effect), the updated Policy will be posted without prior notice. Your continued use of our Services after the effective date of any update constitutes your acknowledgement of the changes.
Version History: Version 1.0 — Effective 1 January 2025 — Initial publication.
21. How to Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or the Processing of your Personal Data, please contact our Privacy team:
Privacy Contact Shenzhen Clear Science & Technology Co., Ltd (KELIER) Room 2301, Building 1B, Zhihuijiayuan, Baolong Street, Longgang District, Shenzhen, Guangdong Province 518100, People's Republic of China Email: contact@kelier.co Website Contact Form: https://kelier.co/contact
We are committed to resolving privacy concerns promptly and transparently. We will acknowledge all written privacy enquiries within five (5) business days and will provide a substantive response within the timeframe required by applicable law.
For related policies, see our Terms of Service and our Corporate Policy Manual.
