Back to the main site
EN ZH JA KO AR
Legal / Privacy Policy

Privacy Policy

How Silicraft Industrial collects, uses, retains, and protects information from visitors, prospects, customers, and suppliers across all jurisdictions in which we operate.

Effective15 September 2026
FrameworksGDPR · CCPA · PIPL · LGPD
ControllerSilicraft Industrial Co., Ltd.
DPO contact[email protected]

1. Scope

This Policy applies to silicraft.lumorb.com, the live chat service, email correspondence with [email protected] or [email protected], RFQ form submissions, and any offline engagement with our engineering, quality, and account teams.

2. Data we collect

We collect (a) identity and contact data you provide in our RFQ form or chat — name, company, business email, phone, country, industry, target grade, and your message; (b) technical data automatically — IP address, user agent, locale, referring URL, browser fingerprint, and timestamps; (c) content you provide — drawings, CAD files, photographs, and reference material uploaded via the RFQ dropzone or chat attachments; (d) conversation data — chat transcripts, recorded only when you opt in.

3. Purposes and legal basis

We process your data to (a) respond to your inquiry and provide an engineering quotation (contract performance); (b) maintain a record of communications and quoting history (legitimate interest); (c) comply with FDA, ISO, customs, and trade-control recordkeeping (legal obligation); (d) improve our website and chat service quality (legitimate interest, balanced against your rights).

4. Retention

Inquiry records are retained for 7 years to satisfy ISO 13485 recordkeeping, FDA 21 CFR Part 820, and customs audit requirements. Personal contact data on dormant accounts is anonymised after 3 years of inactivity. Chat transcripts are kept for 90 days unless you request longer retention for an active RFQ.

5. Sharing

We share your data only with (a) our hosting and email infrastructure provider (auraos.lumorb.com); (b) Resend, our transactional email delivery provider; (c) Cloudflare, our CDN and DDoS protection provider; (d) professional advisors (auditors, lawyers, customs brokers) under NDA. We do not sell your personal data.

6. International transfers

We operate from China with infrastructure in Hong Kong SAR, the United States (Cloudflare edge), and Singapore. When transferring personal data across jurisdictions we rely on (a) Standard Contractual Clauses approved by the European Commission, (b) execution of the China Standard Contract for cross-border transfers, and (c) vendor-side data-residency controls.

7. Your rights

Subject to applicable law you have the right to (a) access the personal data we hold about you; (b) correct inaccurate or incomplete data; (c) request deletion, subject to our legal retention obligations; (d) restrict or object to processing; (e) portability of data you provided to us; (f) withdraw consent where processing is based on consent. To exercise these rights, write to [email protected].

8. Cookies

We use only strictly necessary first-party cookies for session continuity (locale preference, CSRF token). We do not use marketing cookies or third-party tracking.

9. Security

Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access is role-scoped and audited. Drawings uploaded through the inquiry form are stored in our project bucket with bucket-level ACLs.

10. Children

Our services are not directed to children under 16. We do not knowingly collect personal data from children.

11. Changes to this Policy

Material changes are announced by updating the "Effective" date above. Continued use after the effective date constitutes acceptance.

12. Complaints

For data-protection complaints, write to [email protected]. EU residents may also lodge a complaint with their supervisory authority. California residents may contact the California Attorney General.

© 2026 Silicraft Industrial Co., Ltd. All rights reserved. [email protected]