1. Overview
ChinaMed Directory ("we," "our," "us") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data when you visit our website at chinamed-directory.pages.dev or purchase our digital content.
This policy applies to information collected through our website and services. It does not apply to information collected by third parties, including hospitals listed in our directory and our payment processor (Paddle).
2. Data Controller
The data controller responsible for your personal data is:
Kuang Shan
Chengdu, Sichuan, China
Email: [email protected]
3. Information We Collect
3.1 Information You Provide
- Contact Form Submissions: When you contact us via our contact form or email, we collect your name, email address, and any information you include in your message.
- Purchase Information: When you make a purchase, Paddle (our Merchant of Record) collects your payment details. We do not receive or store your full credit card number, CVV, or bank account details. We receive limited transaction data from Paddle, including: purchase confirmation, transaction ID, last four digits of payment card, and billing country.
3.2 Information Collected Automatically
When you visit our website, we and our hosting provider (Cloudflare) may automatically collect:
- Server Log Data: IP address, browser type and version, operating system, referring/exit pages, date/time of visit, pages viewed, and time spent on pages.
- Security Data: Cloudflare processes data for security purposes, including DDoS protection and bot detection. See Cloudflare's Privacy Policy.
3.3 Cookies
Our website does not use tracking cookies for advertising or analytics purposes. Cloudflare may place strictly necessary security cookies as part of its CDN and security services. These cookies are essential for the operation of the website and do not track you across other sites.
4. How We Use Information
We use the information we collect for the following purposes:
- Service Delivery: To provide and maintain the website, process and fulfill your purchases, and grant access to purchased content.
- Customer Support: To respond to your inquiries, provide support, and address issues with purchased content.
- Security: To detect, prevent, and address fraud, abuse, and technical issues.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
- Aggregate Analytics: To analyze aggregated, anonymized traffic data to improve our content and user experience. This data cannot be used to identify individual users.
5. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contractual Necessity: Processing necessary to fulfill a purchase and provide access to purchased content.
- Legitimate Interests: Processing for security, fraud prevention, and aggregate analytics, where our interests do not override your rights.
- Consent: Where you have explicitly provided consent (e.g., subscribing to communications).
- Legal Obligation: Processing required to comply with applicable laws.
6. Data Sharing & Disclosure
6.1 Service Providers
We share data with the following service providers who process data on our behalf:
- Paddle.com Market Limited — Payment processing and Merchant of Record services. When you make a purchase, Paddle collects and processes your payment information. See Paddle's Privacy Policy.
- Cloudflare, Inc. — Website hosting, CDN, and security services. See Cloudflare's Privacy Policy.
6.2 No Sale of Data
We do not sell, trade, rent, or otherwise transfer your personal data to third parties for their marketing or commercial purposes.
6.3 Legal Disclosure
We may disclose data if required to do so by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
7. Data Retention
- Contact Form Data: Retained for the period necessary to resolve your inquiry, plus up to 12 months for reference.
- Transaction Records: Retained for the period required by applicable tax and accounting laws (typically 5-7 years).
- Server Logs: Typically retained for up to 30 days by Cloudflare for operational and security purposes.
8. Data Security
We implement reasonable technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction. These measures include: SSL/TLS encryption for all data in transit, access controls limiting data access to authorized personnel, and regular security reviews. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your data ("right to be forgotten").
- Restriction: Request restriction of processing under certain circumstances.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You may also have the right to lodge a complaint with your local data protection authority.
10. International Data Transfers
Our website is hosted on Cloudflare's global infrastructure, which may involve transferring data to servers located outside your country of residence. We take appropriate safeguards to ensure your data receives an adequate level of protection in accordance with applicable data protection laws.
11. Children's Privacy
Our Service is not directed at children under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us for immediate removal.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Material changes will be communicated via a notice on our website. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
13. Contact
For questions, concerns, or to exercise your data rights, contact us at:
Email: [email protected]
Data Controller: Kuang Shan, Chengdu, Sichuan, China