Privacy Policy
1. Introduction
Rain Green, operating through the registered entity 昆明润翠商贸有限公司, is committed to protecting the privacy and security of every individual who interacts with our website at www.raingreen.lat and our related services. This Privacy Policy explains in detail how we collect, use, store, share, and safeguard your personal information. By accessing or using our website and services, you acknowledge that you have read and understood the practices described in this policy.
We design our data practices to comply with applicable privacy laws and regulations, including the principles of transparency, data minimization, purpose limitation, and accountability. Our approach reflects the same engineering rigor we apply to our computer systems design services: every data flow is intentional, documented, and secured.
This policy applies to all individuals who visit our public website, submit inquiries through any of our communication channels, engage with us for professional consulting services, or otherwise interact with Rain Green in a capacity where personal data may be collected. It covers data processing activities conducted in both digital and offline contexts, including email correspondence, telephone communications, in-person meetings, and any written documentation exchanged during the course of a client engagement or pre-engagement dialogue.
We recognize that privacy expectations vary across cultures, jurisdictions, and individual preferences. Our commitment to data protection is not merely a matter of regulatory compliance; it is a foundational value embedded in how we design systems and conduct business relationships. As a company whose core expertise lies in computer systems architecture and IT infrastructure, we bring a uniquely informed perspective to the challenge of securing information in an increasingly interconnected digital landscape. Every technical decision we make, from server configuration to encryption protocol selection, is guided by the principle that your trust is the most valuable asset we hold.
The terminology used throughout this document follows internationally recognized data protection frameworks. Terms such as personal data, processing, data controller, and data subject carry meanings consistent with the definitions established by major privacy regulations including the General Data Protection Regulation of the European Union and the Personal Information Protection Law of the Peoples Republic of China. Where applicable, we also reference standards from the California Consumer Privacy Act and other regional frameworks to ensure comprehensive coverage for our diverse client base.
2. Information We Collect
2.1 Information You Provide Directly
When you contact us via email at help@raingreen.lat, submit an inquiry through our website, or engage with us for service consultations, we may collect the following categories of information:
- Your full name or the name of your designated contact person
- Your email address and any alternative contact email addresses
- Your telephone number, including country code
- The name and details of your organization or company
- Your job title or role within your organization
- The content of your inquiry, project brief, or technical requirements
- Any attachments or supporting documents you choose to share
The provision of most categories of personal information is voluntary; however, certain information is necessary for us to respond effectively to your inquiry or to enter into a service agreement. For example, without a valid email address, we cannot send you a project proposal or technical assessment. Without your organizational details, we cannot tailor our recommendations to your specific operational context. You always retain control over what information you choose to share, and we will clearly indicate when the provision of particular data is a prerequisite for the requested service.
During the course of a client engagement, additional categories of information may be collected through ongoing communication and project documentation. This may include technical specifications, system architecture diagrams, network configuration details, access credentials for managed systems (where applicable), user account information for provisioned services, and billing and payment details. All such information is collected with the explicit purpose of fulfilling our contractual obligations and delivering the agreed-upon services to the highest professional standard.
We also collect information during face-to-face meetings, video conferences, and telephone calls with prospective and existing clients. Notes taken during these interactions, whether digital or handwritten, are treated with the same level of confidentiality as any other personal data. Recordings of calls or meetings are made only with your prior knowledge and consent, and are used solely for internal reference and quality assurance purposes unless otherwise agreed in writing.
2.2 Information Collected Automatically
When you browse our website, our servers may automatically record certain technical information for operational and security purposes. This includes:
- Your IP address and inferred geographic region
- Browser type and version, operating system, and device type
- Referring URLs and the pages you visit on our site
- Timestamps of your visits and the duration of each session
- HTTP status codes and error logs for debugging purposes
The automatic collection of server access logs is a standard industry practice essential for maintaining the security, stability, and performance of any web-based service. These logs enable our operations team to identify and respond to denial-of-service attacks, brute-force login attempts, vulnerability scanning activity, and other security threats in real time. Without this data, we would be unable to fulfill our duty of care to protect both our infrastructure and the data entrusted to us by our clients.
We do not use any form of device fingerprinting, browser canvas fingerprinting, or other advanced tracking techniques that seek to uniquely identify a device or browser across sessions and websites. The automatic data we collect is limited to what our web server software records by default and is not enriched, combined, or cross-referenced with data from external sources for profiling purposes. We believe that effective security monitoring does not require invasive surveillance of individual browsing behavior.
3. Cookies and Tracking Technologies
Our website at www.raingreen.lat does not currently deploy any third-party advertising cookies, behavioral tracking scripts, or social media pixels. We use only strictly necessary technical cookies that are essential for the secure operation of our website. These cookies do not store any personally identifiable information and are not used for marketing or profiling purposes.
We do not use analytics cookies, fingerprinting scripts, or any form of cross-site tracking. If this practice changes in the future, we will update this policy and, where required by law, seek your prior consent before deploying any non-essential tracking technologies.
For clarity, a strictly necessary cookie is one that is essential for a website to function correctly and securely. Examples include cookies used to maintain session state during form submissions, to remember cookie consent preferences, or to support load balancing across multiple servers. These cookies do not collect information that could be used for marketing purposes and are typically deleted when you close your browser session. If we ever introduce analytics or preference cookies, we will provide a detailed cookie notice explaining each category, its purpose, its duration, and the data it processes.
Most modern web browsers allow you to manage cookie settings through their preferences or settings panels. You can typically choose to block all cookies, block only third-party cookies, delete existing cookies, or be notified each time a website attempts to set a cookie. Please be aware that blocking all cookies, including strictly necessary ones, may affect the functionality and security of websites you visit, including ours. We recommend reviewing your browser documentation for instructions tailored to your specific software version and platform.
In addition to cookies, we have explicitly chosen not to integrate any third-party analytics platforms such as Google Analytics, any customer relationship management tracking beacons, any retargeting pixels, or any social media sharing buttons that silently transmit visitor data to external platforms. This architectural decision reflects our belief that a business website should serve its visitors without treating them as data assets to be mined. We encourage our clients and fellow technology professionals to consider the privacy implications of every external dependency they introduce into their web properties.
4. How We Use Your Information
Every piece of information we collect serves a specific, documented purpose. We do not collect data speculatively or without a clear operational need. The purposes for which we process your information include:
- Service Delivery: To assess your technical requirements, prepare proposals, and deliver the computer systems design and IT consulting services you have requested
- Communication: To respond to your inquiries, provide project updates, and maintain an ongoing professional relationship
- Operational Integrity: To monitor server performance, detect and prevent security incidents, and ensure the reliability of our infrastructure
- Legal Compliance: To fulfill our obligations under applicable laws, regulations, and lawful requests from government authorities
- Business Operations: To maintain internal records, manage billing and invoicing, and support quality assurance processes
Beyond these core purposes, we may also use anonymized and aggregated data derived from server logs and service usage patterns for internal research and development. This aggregated data contains no personally identifiable information and cannot be reverse-engineered to identify any individual or organization. We use such data to inform infrastructure capacity planning, to identify performance bottlenecks, to optimize network routing, and to guide strategic decisions about technology stack evolution.
We do not use your personal information for automated decision-making or profiling that produces legal effects or similarly significant impacts. No algorithm, machine learning model, or automated system at Rain Green makes decisions about your eligibility for services, pricing, or contractual terms without meaningful human review. Where any form of automation is used in our internal workflows, it serves an assistive function only and the final decision always rests with a qualified human professional who evaluates the full context of each situation.
If we ever intend to use your personal information for a purpose that is materially different from those described in this policy at the time of collection, we will notify you in advance and, where required by law, obtain your explicit consent before proceeding. We maintain an internal data processing register that maps every category of personal data we hold to its specific purpose, legal basis, retention period, and access controls. This register is reviewed quarterly to ensure accuracy and completeness.
5. Legal Basis for Processing
We process personal data only when we have a valid legal basis to do so. Depending on the nature of the interaction and your jurisdiction, the applicable legal bases may include:
- Contractual Necessity: Processing is necessary to perform a contract with you or to take steps at your request prior to entering into a contract
- Legitimate Interests: Processing is necessary for our legitimate business interests, such as improving our services, securing our systems, and responding to inquiries, provided those interests are not overridden by your rights
- Legal Obligation: Processing is necessary to comply with a legal or regulatory obligation to which we are subject
- Consent: Where required by law, we will obtain your explicit consent before processing your data for specific purposes
The concept of legitimate interests requires a careful balancing exercise that weighs our business purposes against the potential impact on your privacy rights. We conduct and document this balancing assessment for every processing activity that relies on legitimate interests as its legal basis. Factors considered include the reasonable expectations you would have based on your relationship with us, the nature of the data being processed, the safeguards we have implemented, and the availability of less intrusive alternatives. You have the right to object to processing based on legitimate interests at any time, and we will promptly reevaluate the processing in light of your objection.
For processing activities governed by Chinese law, including the Personal Information Protection Law and the Cybersecurity Law, we ensure compliance with local requirements regarding consent, data localization, cross-border transfer assessments, and the appointment of personnel responsible for personal information protection. For clients and website visitors located in the European Economic Area, the United Kingdom, or other jurisdictions with comprehensive data protection legislation, we apply the legal bases recognized under the applicable regulatory framework and respect the full range of data subject rights guaranteed by those laws.
Where we rely on consent as the legal basis for processing, such consent is obtained through a clear affirmative action that is freely given, specific, informed, and unambiguous. We maintain records of consent, including what the individual was told at the time, how and when consent was obtained, and the scope of the consent granted. You may withdraw consent at any time, and withdrawal is as easy as giving consent. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal took effect.
6. Data Sharing and Disclosure
Rain Green does not sell, rent, trade, or otherwise monetize your personal information. We treat your data as confidential business information and disclose it only in the following limited circumstances:
- Service Providers: We may engage trusted third-party vendors for essential business functions such as cloud hosting, email delivery, and payment processing. These providers are contractually bound to process data solely on our instructions and to implement appropriate security measures
- Legal Requirements: We may disclose information when required by law, court order, or governmental regulation, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others
- Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction, subject to the same privacy protections
- With Your Consent: We may share your information for any other purpose with your explicit authorization
Our relationships with service providers are governed by written data processing agreements that clearly define the subject matter, duration, nature, and purpose of processing, the types of personal data involved, and the obligations and rights of each party. Every service provider undergoes a security and privacy assessment before engagement and is subject to periodic compliance audits during the term of the agreement. We require all processors to implement technical and organizational measures that meet or exceed the standards we apply internally.
In the case of legal disclosure requests, we evaluate each request carefully before responding. We require that any request for personal data from a government or law enforcement agency be made in writing, identify the specific legal authority under which the request is made, and describe the particular information sought with reasonable specificity. Where we are legally permitted to do so, we will notify you of the request before disclosing your information, giving you an opportunity to seek a protective order or other legal remedy. We do not voluntarily participate in any mass surveillance or bulk data collection programs.
We maintain a log of all disclosures of personal data to third parties, including the identity of the recipient, the categories of data disclosed, the date of disclosure, and the legal basis for the disclosure. This log is reviewed periodically by our data protection personnel and is available for inspection by supervisory authorities upon lawful request. We have never received a National Security Letter, a FISA order, or any equivalent compulsory disclosure instrument from any government.
7. Cross-Border Data Transfers
Rain Green is based in Kunming, Yunnan Province, China, and our primary data processing activities occur within China. However, in the course of delivering our services — particularly for international clients — your information may be accessed from or transferred to servers located in other countries. When we transfer personal data across borders, we implement appropriate safeguards such as standard contractual clauses, data processing agreements, and technical encryption measures to ensure that your information receives an equivalent level of protection regardless of where it is processed.
For transfers of personal data from the European Economic Area or the United Kingdom to countries that have not been recognized as providing an adequate level of data protection, we rely on the Standard Contractual Clauses approved by the European Commission or the International Data Transfer Agreement issued by the UK Information Commissioner, as applicable. We conduct transfer impact assessments to evaluate the laws and practices of the destination country and, where necessary, implement supplementary technical, contractual, and organizational measures to bring the level of protection up to the standard required by the originating jurisdiction.
For transfers of personal data out of China, we comply with the requirements of the Personal Information Protection Law, including conducting personal information protection impact assessments for cross-border transfers, entering into standard contracts with overseas recipients as prescribed by the Cyberspace Administration of China, and obtaining separate consent for cross-border transfers where required. We maintain a register of all cross-border data transfers, documenting the categories of data, the destination country, the recipient, the purpose of the transfer, and the safeguards applied.
Where our service delivery model involves remote access to client systems located in other countries, we ensure that access is conducted through encrypted channels, is subject to multi-factor authentication, and is logged in detail. Any data that is temporarily cached, buffered, or processed in transit during such remote access sessions is handled in accordance with the data protection terms agreed with the client and is not retained beyond the duration of the session unless specifically required for the engagement.
8. Data Retention
We retain your personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our retention periods are determined by the following criteria:
- The duration of our professional relationship with you and any ongoing service obligations
- Statutory retention requirements under Chinese commercial and tax law, which typically require retention of business records for a minimum of five years
- The period during which legal claims may arise in connection with our services
- Operational necessity for system security logs, which are retained on a rolling basis not exceeding twelve months
When personal information is no longer required, we securely delete or anonymize it using industry-standard data destruction methods.
Our approach to data retention is guided by the principle of storage limitation: we do not hoard data indefinitely simply because storage is cheap. Each category of personal data in our possession has a defined retention schedule that is documented in our data processing register. At the expiration of the retention period, data is either irreversibly anonymized so that it can no longer be attributed to any individual, or it is securely destroyed using methods appropriate to the storage medium involved. For physical documents, this means cross-cut shredding or secure incineration. For digital records, this means cryptographic erasure, secure overwrite procedures, or physical destruction of storage media as appropriate.
There are circumstances in which we may need to retain certain personal data beyond the standard retention periods. These include situations where data is subject to a legal hold in connection with actual or anticipated litigation or regulatory investigation, where data is needed to establish, exercise, or defend legal claims, or where data must be preserved for archival purposes in the public interest, scientific or historical research, or statistical purposes, subject to appropriate safeguards. In such cases, the affected data is segregated from active processing environments and access is restricted to authorized personnel on a need-to-know basis.
Inactive client records — those where the professional relationship has concluded and no ongoing obligations remain — are reviewed annually. If the statutory retention period has elapsed and no legal hold applies, the records are securely disposed of. We maintain a destruction log documenting what was destroyed, when, by whom, and under what authority.
9. Security Measures
As a computer systems design and IT services company, information security is at the core of our professional expertise. We implement a defense-in-depth security architecture to protect your personal data, including:
- Encryption in Transit: All data exchanged with our website is encrypted using TLS 1.3 with strong cipher suites
- Encryption at Rest: Stored data is encrypted using AES-256 encryption standards
- Access Controls: Role-based access control with multi-factor authentication for all administrative systems
- Network Security: Firewall rules, intrusion detection systems, and regular penetration testing
- Audit Logging: Comprehensive logging of all access to personal data with automated anomaly detection
- Employee Training: All personnel with access to personal data receive mandatory privacy and security training
- Incident Response: A documented incident response plan with defined escalation procedures and notification protocols
Our security program is designed around the principle of layered defenses, meaning that the failure or compromise of any single control does not result in a breach of the protected data. Each layer addresses a different threat vector and is independently monitored. For example, even if an attacker were to bypass network perimeter controls, they would still face application-level authentication, database-level encryption, and file-system-level access restrictions. This approach recognizes that no security control is infallible and that resilience comes from redundancy and defense in depth.
We conduct independent security assessments on a regular basis, including external penetration testing performed by qualified third-party security firms, internal vulnerability scanning of all production systems, and code reviews of any custom software components we deploy. Findings from these assessments are tracked in a risk register, prioritized by severity, and remediated within defined service-level timeframes. Critical vulnerabilities are addressed within forty-eight hours, high-severity findings within one week, and lower-severity items are incorporated into scheduled maintenance cycles.
Our physical security measures are equally rigorous. Servers and network equipment are housed in access-controlled facilities with biometric authentication, twenty-four-hour video surveillance, environmental monitoring, redundant power supplies, and fire suppression systems. Physical access to production environments is limited to a small number of vetted senior personnel, and all physical access events are logged and reviewed. We maintain business continuity and disaster recovery plans that are tested at least annually through tabletop exercises and live failover drills.
10. Data Breach Notification
In the unlikely event of a data breach involving your personal information, we will take the following steps without undue delay:
- Contain the breach and implement immediate remedial measures to prevent further unauthorized access
- Conduct a thorough forensic investigation to determine the scope, cause, and impact of the breach
- Notify affected individuals directly via email or other available contact methods if the breach poses a risk to their rights and freedoms
- Notify relevant supervisory authorities as required by applicable data protection laws
- Document all findings and implement corrective actions to prevent recurrence
We define a personal data breach as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed. This definition encompasses not only malicious external attacks but also accidental internal incidents such as misdirected emails, lost devices, or inadvertent exposure of data through misconfiguration. Our incident response plan treats all such events with equal seriousness and applies consistent investigative and notification procedures regardless of the cause.
For breaches affecting individuals in jurisdictions with mandatory breach notification laws — including the European Economic Area, the United Kingdom, and an increasing number of U.S. states — we will notify the competent supervisory authority within the timeframe prescribed by the applicable law, which is typically seventy-two hours from the time we become aware of the breach. Where notification to the authority within that timeframe is not feasible, we will provide the required information in phases without further undue delay, together with an explanation for the delay. Our breach notification to affected individuals will describe, in clear and plain language, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures we have taken or propose to take to address the breach and mitigate its possible adverse effects.
We maintain a breach register documenting all personal data breaches, whether or not they meet the threshold for notification to authorities or affected individuals. Each entry includes the facts relating to the breach, its effects, the remedial action taken, and the rationale for any decision not to notify. This register is available for inspection by supervisory authorities and is reviewed at least quarterly by senior management as part of our information security governance process.
11. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of Access: You may request a copy of the personal data we hold about you
- Right of Rectification: You may request that we correct any inaccurate or incomplete personal data
- Right of Erasure: You may request that we delete your personal data, subject to legal retention requirements
- Right to Restrict Processing: You may request that we limit how we process your data in certain circumstances
- Right to Data Portability: You may request a copy of your data in a structured, machine-readable format
- Right to Object: You may object to processing based on legitimate interests or for direct marketing purposes
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time
To exercise any of these rights, please contact us at help@raingreen.lat. We will respond to your request within thirty calendar days and will not charge a fee unless the request is manifestly unfounded or excessive.
When you submit a request to exercise your data subject rights, we may need to verify your identity before processing the request. This verification process is designed to prevent unauthorized access to personal data and typically involves confirming details that you have previously provided to us, such as your email address, telephone number, or the reference number of a prior engagement. In some cases, particularly where the request involves sensitive data or could affect the rights of other individuals, we may require additional proof of identity. We will only use the information you provide during verification for the purpose of confirming your identity and will delete it promptly once verification is complete.
The right of erasure, sometimes referred to as the right to be forgotten, is not absolute. There are circumstances in which we may be required to retain certain personal data despite a valid erasure request. These circumstances include compliance with legal obligations, the establishment or defense of legal claims, the exercise of the right of freedom of expression and information, and reasons of public interest in the area of public health. Where we determine that an exception applies, we will explain our reasoning to you in writing and will continue to limit processing to what is strictly necessary for the purpose of the exception.
We do not discriminate against individuals who exercise their privacy rights. Exercising your rights will not result in denial of services, different pricing, different quality levels, or any other adverse treatment. We view the exercise of privacy rights as a legitimate and welcome expression of personal autonomy, not as a burden or inconvenience. Every request is handled by trained personnel who understand both the legal requirements and the importance of respectful, empathetic communication.
12. Children and Privacy
Our website and services are not directed at individuals under the age of eighteen. We do not knowingly collect personal information from children. If we become aware that a person under eighteen has provided us with personal data without verifiable parental consent, we will take immediate steps to delete such information from our systems. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at help@raingreen.lat.
The age threshold of eighteen years reflects a considered assessment of the nature of our services. As a provider of enterprise-grade computer systems design and IT consulting, our services are inherently business-to-business in character and are not relevant, appropriate, or marketed to minors. We do not design our website interface, content, or communication style to appeal to individuals under eighteen, and we do not offer products, services, or experiences that would be of interest to children.
Although we do not target minors, we recognize that age verification on the open internet is imperfect. If a minor nevertheless accesses our website and submits personal data through contact forms or email, we consider that data to have been provided without proper authority. Upon notification or discovery, our response protocol includes immediate suspension of processing of the minor data, notification to the parent or guardian if contact information is available, deletion of the data from all active and backup systems within fourteen days, and documentation of the incident in our data protection records.
We support the objectives of laws such as the Children Online Privacy Protection Act in the United States and equivalent provisions in other jurisdictions. While our website does not fall within the scope of such laws because it is not directed at children, we have chosen to apply child-protective principles as a matter of best practice. We encourage parents and educators to engage with children about responsible online behavior and to use parental control tools where appropriate.
13. Third-Party Links
Our website may contain links to third-party websites, platforms, or resources. This Privacy Policy applies solely to information collected by Rain Green through our own website and services. We are not responsible for the privacy practices, content, or security of any third-party sites. We encourage you to review the privacy policies of any external website you visit through links on our site.
Any hyperlinks we include on our website are provided for informational convenience and do not constitute an endorsement, sponsorship, or recommendation of the linked website, its operators, its products, or its services. We do not exercise any control over the content, availability, or data practices of external sites. The inclusion of a link does not imply that we have verified the accuracy or lawfulness of the linked content, and we disclaim any liability arising from your access to or use of third-party resources.
When you click a link that takes you away from www.raingreen.lat, you should be aware that the third party may use its own cookies, web beacons, and other tracking technologies to collect information about your visit. We recommend that you look for the privacy policy or privacy notice link on any website you visit, particularly before submitting any personal information. A responsible approach to online privacy includes developing the habit of checking who operates the website you are on and how they handle your data, regardless of how you arrived there.
14. Do Not Track Signals
Our website does not respond to Do Not Track browser signals at this time. However, as stated in Section 3 of this policy, we do not deploy behavioral tracking cookies or engage in cross-site tracking regardless of whether a Do Not Track signal is present. As industry standards for Do Not Track signals evolve, we will review our approach and update this policy accordingly.
The Do Not Track mechanism was developed by the World Wide Web Consortium as a way for browser users to express a preference regarding online tracking. A browser sends a DNT HTTP header with a value of 1 to indicate that the user prefers not to be tracked. However, the initiative has not achieved universal adoption; there is no consensus among industry participants, regulators, or standards bodies on what constitutes tracking or how websites should respond to the signal. Major browsers continue to support the setting, but many have deprecated or hidden it in favor of other privacy features such as Intelligent Tracking Prevention and Enhanced Tracking Protection.
Because we do not engage in the kind of behavioral tracking that the DNT signal was designed to address, our decision not to alter behavior in response to the signal has no practical impact on your privacy when visiting our website. You are not being tracked for advertising or profiling purposes whether the signal is present or absent. We support the development of clear, enforceable standards that give individuals meaningful control over online tracking, and we will implement such standards when they achieve the necessary level of maturity, interoperability, and regulatory clarity.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal obligations, or operational requirements. When we make material changes, we will:
- Post the updated policy on this page with a revised effective date
- Provide a notice on our homepage for a period of at least thirty days following the update
- Notify you directly via email if the changes significantly affect how we handle your personal data
We encourage you to review this policy periodically to stay informed about how we protect your information. Your continued use of our website and services after any changes constitutes your acceptance of the updated policy.
A change is considered material if it involves new categories of personal data collected, new purposes for which data is used, new categories of recipients with whom data is shared, a significant change in retention periods, or a expansion of the legal bases relied upon for processing. Changes that are purely editorial, grammatical, or organizational in nature, or that improve clarity without altering the substance of our commitments, are not considered material and may be made without advance notice.
We maintain a version history of this policy in our internal records, enabling us to provide previous versions upon request. This allows you to understand how our privacy commitments have evolved over time and to verify the terms that were in effect at any particular point in our relationship. Where changes are made in response to new legal requirements, we will identify the relevant legislation or regulatory guidance in our internal change log, even if we do not include that level of detail in the public policy text.
16. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact us using the following details:
Rain Green / 昆明润翠商贸有限公司
Address: 西山区马街街道丰和苑9号楼1单元301CC, 昆明市 650000, China
Email: help@raingreen.lat
Phone: +15863555929
Website: www.raingreen.lat
We are committed to resolving any privacy concerns promptly and fairly. If you are not satisfied with our response, you may have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction.
When you contact us with a privacy-related inquiry, it will be routed to our designated data protection personnel, who are trained to handle such matters with professionalism, confidentiality, and respect. We aim to acknowledge all privacy inquiries within two business days and to provide a substantive response within fourteen calendar days. Complex inquiries requiring internal investigation or legal review may take longer, in which case we will keep you informed of our progress and provide an estimated timeline for resolution.
Our business hours are Monday through Friday, 09:00 to 18:00 China Standard Time (UTC+8), excluding Chinese public holidays. Communications received outside of business hours will be processed on the next business day. For time-sensitive privacy matters, we recommend email as the most reliable contact method, as it creates a written record of your inquiry and enables us to route it efficiently to the appropriate personnel regardless of time of day.
If you choose to exercise your privacy rights as described in Section 11, please include as much detail as possible in your initial communication. Identifying the specific right you wish to exercise, the categories of data your request concerns, and the context in which you provided us with your data (for example, through a website inquiry or a specific client engagement) will help us process your request more efficiently. You do not need to provide a reason for exercising your rights, and we will never ask you to justify your decision to make a privacy request.