Website: agentguangzhou.com (the “Site”)
Operator and data controller: StartOfSmart Hong Kong Limited
Version: 1.0, effective 9 September 2026
This Privacy Policy explains what personal data we collect when you use the Site or contact us, why we collect it, what legal grounds we rely on, who receives it, how long we keep it, and what rights you have. It is written to meet the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), the Hong Kong Personal Data (Privacy) Ordinance (PDPO), the California Consumer Privacy Act as amended by the CPRA (CCPA), and, where Chinese partner data is involved, the Personal Information Protection Law of the People’s Republic of China (PIPL). Where a local law gives you more protection than this policy describes, the local law applies.
The Site offers business to business sourcing services. Most people who contact us do so on behalf of a company. Personal data of a business contact (for example your name, business email and phone number) is still personal data and is protected under this policy.
1. Who we are
Controller: StartOfSmart Hong Kong Limited
Company registration number (Hong Kong): available on request
Registered address: Unit 7, 21/F, Yen Sheng Centre, 64 Hoi Yuen Road, Kowloon East, Hong Kong SAR
Privacy contact email: [email protected]
StartOfSmart Hong Kong Limited decides why and how your personal data is processed and is therefore the “controller” under the GDPR and UK GDPR, and the “data user” under the PDPO. Sourcing staff and inspection partners in mainland China act on our instructions.
2. Representative in the EU and the UK
Article 27 GDPR requires a controller that is not established in the EU, but that offers services to people in the EU or monitors their behaviour there, to designate a representative in an EU member state. Article 27 UK GDPR contains the same rule for the UK. The representative is a local contact point for data subjects and for supervisory authorities.
We have assessed that our processing of EU and UK personal data is occasional and low risk within the meaning of Article 27(2)(a) GDPR and UK GDPR, and we have therefore not appointed a representative. You can contact us directly at [email protected].
3. What personal data we collect and where it comes from
3.1 Data you give us
When you fill in a “request a quote”, “book a call” or “first trip” form, send us an email, or message us on WhatsApp, we collect what you choose to provide, typically:
- name and, where given, job title and company name
- email address
- telephone number (including your WhatsApp number when you write to us there)
- country or location
- preferred date and time for a call or a trip
- the content of your message: products you are looking for, quantities, target prices, budget, timing, and any files or photos you attach
- for a first trip or factory visit: travel dates, arrival city and, if you provide it for hotel or transport bookings, passport details
3.2 Data collected automatically
When you visit the Site, our hosting and security provider Cloudflare and our web server record technical data:
- IP address, approximate location derived from it, browser type, operating system, language settings, screen size, referring page, pages viewed and time of visit
- security identifiers such as the Cloudflare
__cf_bmcookie used to tell humans from automated traffic - cookie consent choices stored by the Complianz consent tool
- if you opt in to browser push notifications, a push subscription token issued by your browser and handled by WonderPush (see section 6)
If we enable an analytics tool such as Microsoft Clarity or a Meta pixel, it will be listed in the Cookie Policy and switched on only after you give consent in the cookie banner. As at the effective date of this policy, no such tool is active.
3.3 Data from other sources
- WhatsApp / Meta. When you contact us via a wa.me link or our WhatsApp number, WhatsApp shows us your phone number, profile name and profile photo as set in your WhatsApp account.
- Business partners. If a colleague, freight forwarder or supplier passes us your contact details in the course of an order, we receive them from that partner.
- Public sources. We may look up your company on public registers or its own website to verify a business enquiry.
We do not deliberately collect special category data (health, religion, political opinions and similar). Please do not include such data in your messages.
4. Purposes and legal bases
Under the GDPR and UK GDPR we need a legal basis for each purpose. The table below lists each purpose, the data used, and the basis. Under the PDPO, PIPL and CCPA the same purposes apply and are the purposes notified at collection.
| Purpose | Data used | Legal basis (GDPR / UK GDPR Art. 6) |
|---|---|---|
| Answering your enquiry, preparing a quote, scheduling a call | Contact details, message content | Art. 6(1)(b), steps at your request before entering a contract; where you write on behalf of a company, Art. 6(1)(f), our legitimate interest in responding to a business enquiry |
| Providing sourcing, inspection, consolidation and trip services once agreed | Contact details, order details, travel details | Art. 6(1)(b), performance of a contract |
| Sharing your requirements with candidate suppliers, inspectors and forwarders in China | Company name, product requirements, and where needed your name and contact details | Art. 6(1)(b), performance of a contract; Art. 6(1)(f), our legitimate interest in fulfilling your request through third parties |
| Keeping accounting, tax and customs records | Invoices, contract documents, shipping documents | Art. 6(1)(c), legal obligation under Hong Kong law, and Art. 6(1)(f) for record keeping relating to other jurisdictions |
| Running and securing the Site, preventing abuse, diagnosing faults | Technical data in 3.2 | Art. 6(1)(f), our legitimate interest in a secure and working website |
| Sending browser push notifications | Push token | Art. 6(1)(a), your consent, which you can withdraw at any time in your browser settings |
| Optional analytics or advertising measurement, if enabled | Cookie identifiers, usage data | Art. 6(1)(a), consent given via the cookie banner |
| Sending you occasional updates about our services after we have worked together | Business email address | Art. 6(1)(f), legitimate interest in maintaining a business relationship, subject to the right to object; where required by local e-marketing law, your consent |
| Establishing, exercising or defending legal claims | Any relevant data | Art. 6(1)(f), our legitimate interest in protecting our legal position |
Where we rely on legitimate interest we have weighed that interest against your interests and rights and concluded that the processing is what a business contact would reasonably expect. You can ask for a summary of that assessment.
Where the Swiss FADP applies, the same purposes apply; the FADP does not require a listed legal basis but requires that processing is proportionate and transparent, which this policy is designed to ensure.
5. WhatsApp as a communication channel
We use WhatsApp, a service of Meta Platforms, to talk to customers because it is the channel most of our customers prefer. You should know:
- When you click a wa.me link or message our number, WhatsApp and Meta process your data under their own terms and privacy policy, independently of us. Meta is a separate controller for that processing. Messages are end to end encrypted in transit but Meta still receives metadata (numbers, times, device information).
- Our WhatsApp account is operated from Hong Kong and mainland China. Your messages, name, number and any photos you send are therefore transferred outside the EU, UK and Switzerland (see section 8).
- We keep WhatsApp conversations for the periods in section 9. Our staff may forward relevant parts of a conversation to suppliers or inspectors to carry out your request, but never your phone number or personal details unless that is necessary and you would reasonably expect it.
- You can choose email or a form instead of WhatsApp at any time.
6. Who receives your data
We share personal data only with parties that need it for the purposes above.
Service providers (processors) acting on our instructions:
- Brevo (Sendinblue SAS, France). Form submissions are delivered to our mailbox through Brevo’s transactional email service. Brevo stores a copy of each message in its sending logs for a limited time. Brevo is an EU company and processes data under a data processing agreement.
- WonderPush (France). Delivers browser push notifications if you opt in. WonderPush stores the push token and the delivery statistics.
- Cloudflare, Inc. (USA, with EU operations). Provides DNS, content delivery, TLS and protection against attacks for the Site. Cloudflare sees all traffic to the Site, including IP addresses, and sets the
__cf_bmsecurity cookie. Transfers to Cloudflare in the USA are covered by the EU-US Data Privacy Framework and by Standard Contractual Clauses. - cdnjs (operated by Cloudflare). Serves the Font Awesome icon library. Your browser sends your IP address to cdnjs when it loads the icons.
- Complianz (Really Simple Plugins B.V., Netherlands). Provides the cookie consent tool. Consent records are stored in your browser and on our server; Complianz itself does not receive your personal data.
- Web hosting provider: Amazon Web Services EMEA SARL (EC2, London region, United Kingdom), which stores the Site and its database.
- Email provider for our mailbox: Google LLC (Gmail / Google Workspace).
Independent recipients (separate controllers):
- Meta Platforms (WhatsApp). See section 5.
- Suppliers, factories, inspection companies, freight forwarders and customs agents in China and elsewhere, to the extent needed to source, inspect, ship or clear your goods. We share the minimum needed, usually your company name and requirements, and your name and contact details only where the partner must contact you directly, for example a forwarder arranging delivery.
- Professional advisers, banks and insurers where needed to process payments, insure shipments or handle disputes.
- Public authorities, where the law requires it, for example customs declarations or a lawful request from a court or regulator.
We do not sell personal data and we do not share it with third parties for their own marketing.
7. International transfers
StartOfSmart Hong Kong Limited is based in Hong Kong and its sourcing team works in mainland China. Neither Hong Kong nor mainland China has an adequacy decision from the European Commission, the UK government or the Swiss Federal Council. This means that when you send us data from the EU, UK or Switzerland, it is transferred to a “third country”.
We rely on the following safeguards:
- Necessity for the contract (Art. 49(1)(b) GDPR, Art. 49(1)(b) UK GDPR, Art. 17(1)(a) FADP). Sourcing goods in China at your request cannot be performed without moving your requirements and contact details to China. This transfer is necessary for the contract you asked us to perform or the steps you asked us to take before a contract.
- Standard Contractual Clauses. Where we use processors outside the EU or UK, or share data with independent partners in a way that is not strictly necessary for your contract, we use the European Commission’s Standard Contractual Clauses (Decision 2021/914) and, for UK data, the UK International Data Transfer Addendum. The Swiss version of the clauses is used for Swiss data.
- Data Privacy Framework. For Cloudflare and any other US provider certified under the EU-US Data Privacy Framework and its UK and Swiss extensions.
- Contractual and technical measures. Encrypted transport (TLS), encrypted messaging, access limited to the staff and partners working on your request, and partner agreements that restrict use of the data to the purpose we share it for.
You can request a copy of the safeguards we rely on by writing to [email protected].
Data of Chinese partners (PIPL). When a supplier or other partner in mainland China gives us personal data of its staff (for example a factory contact’s name, phone number and WeChat ID), we process it under PIPL as well as under the PDPO. We collect only what is needed to carry out the order, we inform the individual of the purpose, and we do not transfer that data outside China except to our customer and to our Hong Kong office as needed to perform the order, on the basis of contractual necessity under Article 13(2) PIPL.
Data of Russian visitors. If you are in Russia, note that our servers and mailboxes are outside Russia. We process your enquiry only for the purpose you raise it and do not build databases of Russian citizens’ data beyond the record of your enquiry and any resulting contract.
8. How long we keep your data
| Category | Retention period | Reason |
|---|---|---|
| Enquiries that do not lead to a contract (forms, emails, WhatsApp threads) | 24 months from the last message | To follow up on open enquiries and to answer repeat questions |
| Contracts, quotes that were accepted, invoices, shipping and customs documents | 7 years from the end of the financial year in which the contract ended | Hong Kong Inland Revenue Ordinance record keeping requirement (7 years) and defence of legal claims |
| Travel and passport details supplied for a trip | Deleted within 90 days after the trip ends, unless part of an invoice record | Needed only for bookings |
| Brevo transactional email logs | 30 days in Brevo, after which only our mailbox copy remains | Brevo default retention for sending logs |
| Server and Cloudflare security logs | Up to 30 days | Security and fault diagnosis |
| Cookie consent record | 12 months, after which the banner asks again | Proof of consent |
| Push notification subscription | Until you unsubscribe or the browser revokes the token, with inactive tokens purged after 12 months | Delivery of notifications you asked for |
| Data subject to a legal hold or dispute | Until the dispute is finally resolved | Defence of legal claims |
When a period ends we delete or anonymise the data. Backups are overwritten on a rolling cycle of at most 30 days.
9. Your rights
Depending on where you live, you have the following rights. We honour them for everyone regardless of location unless the law prevents it.
- Access: to receive a copy of the personal data we hold about you and information about how we use it.
- Rectification: to have inaccurate data corrected or incomplete data completed.
- Erasure: to have your data deleted where we no longer need it, where you withdraw consent, or where you object and we have no overriding grounds. We may keep data required for tax records or legal claims.
- Restriction: to ask us to stop using your data while a dispute about accuracy or lawfulness is resolved.
- Portability: to receive data you gave us in a structured, machine readable format, where processing is based on consent or contract.
- Objection: to object to processing based on legitimate interest, and to object at any time to direct marketing, which we will then stop.
- Withdraw consent: where processing is based on consent (push notifications, optional analytics), you can withdraw it at any time without affecting the lawfulness of earlier processing. Use the cookie banner settings or your browser’s notification settings, or write to us.
- Not to be subject to automated decisions: we make no decisions about you by purely automated means that have legal or similarly significant effects.
- Complain: to lodge a complaint with a supervisory authority. In the EU this is the authority of the member state where you live or work (list at edpb.europa.eu). In the UK it is the Information Commissioner’s Office (ico.org.uk). In Switzerland it is the Federal Data Protection and Information Commissioner. In Hong Kong it is the Office of the Privacy Commissioner for Personal Data (pcpd.org.hk). We would appreciate the chance to resolve your concern first.
To exercise a right, email [email protected] with “Privacy request” in the subject line. We will reply within one month (GDPR and UK GDPR), 40 days (PDPO) or 45 days (CCPA), whichever applies, and may ask you to confirm your identity. Requests are free unless they are manifestly unfounded or excessive.
10. California residents: notice at collection
This section applies if you are a California resident and the CCPA applies to us. In the past 12 months we have collected the following categories of personal information: identifiers (name, email, phone number, IP address); commercial information (products enquired about, quotes, orders); internet activity (pages viewed, technical data); geolocation at country or city level derived from IP address; and professional information (company, job title). The sources, purposes and recipients are described in sections 3, 4 and 6. Retention periods are in section 8.
We do not sell personal information and we do not share it for cross context behavioural advertising. We have not done so in the preceding 12 months. We do not knowingly collect personal information of consumers under 16.
California residents have the right to know, delete, correct, and to opt out of sale or sharing (not applicable as we do none), and the right not to be discriminated against for exercising these rights. You may use an authorised agent. Contact [email protected] to make a request.
11. Children
The Site and our services are aimed at businesses and adults. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
12. Security
We protect personal data with measures appropriate to the risk, including TLS encryption for the Site and email transport, Cloudflare protection against attacks, access to mailboxes and messaging accounts limited to named staff with two factor authentication, encrypted devices, and partner agreements that restrict use of shared data. No method of transmission or storage is completely secure. If a breach is likely to result in a risk to you, we will inform you and the relevant authority as the law requires.
13. Links to other websites
The Site may link to suppliers, trade fairs, WhatsApp and other third party websites. Their privacy practices are their own. Read their policies before providing data.
14. Changes to this policy
We may update this policy when our services, providers or the law change. The version number and effective date at the top show the current version. For material changes affecting how we use data you have already given us, we will notify you by email or a notice on the Site before the change takes effect. Earlier versions are available on request.
15. Contact
StartOfSmart Hong Kong Limited
Unit 7, 21/F, Yen Sheng Centre, 64 Hoi Yuen Road, Kowloon East, Hong Kong SAR
Email: [email protected]
WhatsApp: +86 136 6892 2294
If you write to us about privacy, please use email rather than WhatsApp so that the request is recorded in a channel we fully control.