1. Introduction and Scope
This Privacy Policy describes how DragonLights, a technology services brand operated by JiuJiang LongGuangShi Trading Co., Ltd., collects, uses, stores, and protects information obtained from visitors and clients interacting with our website at www.dragonlight.buzz and any related services, applications, or communications channels (collectively referred to as the Services).
DragonLights is committed to respecting your privacy and handling your personal data with transparency and care. Our registered business address is Room 102-8, Building 7, Xiyanglong Resettlement Community, Lianxi District, Jiujiang - 332000, China. For any questions about this policy or your data, you may contact us at care@dragonlight.buzz.
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any provision herein, you should discontinue use of the Services immediately. This policy applies to all individuals whose data we process, including website visitors, prospective clients, active clients, and end users of systems we design and operate on behalf of our clients.
Key Point: DragonLights acts as both a data controller (for information we collect directly for our own business purposes) and a data processor (for information we handle on behalf of our clients in the course of providing technology services). This policy primarily addresses our role as a data controller.
2. Information We Collect
We collect several categories of information to deliver and improve our Services. The specific data points depend on how you interact with us, but generally fall into the following categories.
2.1 Personal Identification Information
This includes your full name, email address, phone number, job title, company name, and physical mailing address. We collect this information when you fill out our contact form, request a consultation, subscribe to communications, or enter into a service agreement with us.
2.2 Business and Project Information
When you engage us for services, we collect details about your organization, your technology stack, project requirements, system architectures, infrastructure configurations, and any documentation or materials you provide to facilitate our work. This may include trade secrets or business-sensitive data that you choose to share with us under the protection of our service agreements.
2.3 Technical and Usage Data
We automatically collect certain technical information when you visit our website. This includes your IP address, browser type and version, operating system, referring URLs, pages visited, time spent on pages, and the date and time of each visit. We also collect device information such as screen resolution, language preferences, and time zone settings.
2.4 Communication Records
We retain records of communications between you and DragonLights, including emails, chat messages, support tickets, call summaries, and meeting notes. These records help us maintain continuity in our client relationships and ensure that project requirements are accurately captured and fulfilled.
2.5 Payment and Billing Data
For clients with paid engagements, we collect billing addresses, payment method identifiers, invoice records, and transaction histories. Full credit card numbers or bank account details are not stored on our servers; payment processing is handled by PCI-compliant third-party payment processors.
3. How We Collect Information
3.1 Direct Collection
The majority of personal data we hold is provided directly by you. This occurs when you complete a form on our website, send us an email, speak with us by phone, engage us in a consulting or development capacity, or sign a service agreement. In each case, you control what information you choose to share.
3.2 Automated Collection
When you visit our website, our servers automatically log standard HTTP request data. We also use cookies and similar technologies to collect usage analytics and session information. Details about our use of cookies are provided in Section 8 of this policy.
3.3 Third-Party Sources
On occasion, we may receive information about you from third-party sources. This may occur when a colleague refers you to us, when your organization lists you as a point of contact, or when publicly available professional profiles (such as LinkedIn or corporate websites) are consulted during our due diligence process. We only use such information to the extent necessary for legitimate business purposes.
4. How We Use Collected Data
4.1 Service Delivery
The primary purpose for which we process personal data is to deliver the technology services you have requested. This includes communicating about project status, delivering deliverables, conducting technical assessments, and providing ongoing support and maintenance. Without this processing, we would be unable to fulfill our contractual obligations.
4.2 Business Operations
We use collected data to manage our business relationship with you, including invoicing, payment processing, contract management, and internal record-keeping. We also use aggregated and anonymized data for business planning, capacity forecasting, and service improvement.
4.3 Communication and Marketing
With your consent or within the bounds of legitimate interest, we may send you information about our services, technology insights, case studies, or event invitations. You may opt out of marketing communications at any time by clicking the unsubscribe link in any email or by contacting us directly.
4.4 Security and Compliance
We process data to monitor and maintain the security of our systems, detect and prevent fraud or unauthorized access, and comply with legal obligations that apply to our business operations.
5. Legal Basis for Processing
Under applicable data protection regulations, including the General Data Protection Regulation (GDPR) where applicable, we rely on the following legal bases for processing personal data.
5.1 Contractual Necessity
Processing is necessary to perform a contract with you, or to take steps at your request before entering into a contract. This includes processing required to deliver services you have requested and to manage the client relationship.
5.2 Legitimate Interests
We process data where we have a legitimate business interest that is not overridden by your data protection rights. Legitimate interests include improving our services, conducting business analytics, ensuring network and information security, and communicating with existing clients about related services.
5.3 Consent
Where required by law, we obtain your explicit consent before processing your data for specific purposes, such as sending marketing communications to prospective clients or placing non-essential cookies on your device. You may withdraw consent at any time.
5.4 Legal Obligation
We process data where necessary to comply with applicable laws, regulations, court orders, or governmental requests. This may include tax reporting, anti-fraud obligations, and responding to lawful requests from public authorities.
6. Data Storage and Security
6.1 Storage Infrastructure
Data is stored on secure servers located in controlled-access data centers. We use reputable cloud infrastructure providers that maintain industry-standard certifications including ISO 27001, SOC 2, and PCI DSS where applicable. Data may be stored across multiple geographic regions to ensure availability and resilience, subject to the data transfer provisions described in Section 12.
6.2 Security Measures
We implement a comprehensive set of technical and organizational security measures to protect your data. These include encryption at rest using AES-256, encryption in transit using TLS 1.3, multi-factor authentication for administrative access, role-based access controls, regular vulnerability scanning, intrusion detection systems, and periodic security audits.
6.3 Incident Response
In the event of a data breach that affects your personal information, we will notify you and the relevant supervisory authorities within the timeframes required by applicable law. Our incident response plan includes containment, forensic investigation, remediation, and post-incident review to prevent recurrence.
6.4 No Absolute Guarantee
While we employ robust security practices, no method of electronic storage or transmission is completely secure. We cannot guarantee absolute security of your data. You share information with us at your own risk, and we encourage you to take appropriate precautions on your end, including using strong passwords and keeping your devices secure.
7. Data Sharing and Disclosure
7.1 Service Providers and Subprocessors
We engage third-party service providers to assist with aspects of our business operations. These include cloud hosting providers, payment processors, email delivery services, analytics platforms, and collaboration tools. Each provider is bound by contractual obligations to process data only on our instructions and to maintain confidentiality and security standards consistent with this policy.
7.2 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of all or a portion of DragonLights or JiuJiang LongGuangShi Trading Co., Ltd., personal data may be transferred to the successor entity. You will be notified of any such change and given the opportunity to exercise your rights regarding your data.
7.3 Legal Disclosures
We may disclose personal data if required by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, to investigate fraud, or to respond to a government request.
7.4 No Sale of Personal Data
DragonLights does not sell, rent, or trade personal data to third parties for their own marketing or commercial purposes. We do not monetize your personal information through data brokerage or similar activities.
8. Cookies and Tracking Technologies
8.1 What Cookies Are
Cookies are small text files placed on your device by websites you visit. They are widely used to make websites function efficiently and to provide information to site operators. We also may use similar technologies such as web beacons, pixels, and localStorage.
8.2 Types of Cookies We Use
Essential cookies are necessary for the website to function and cannot be disabled in our systems. They are typically set in response to actions you take, such as setting privacy preferences or filling out forms. Analytics cookies help us understand how visitors interact with our website by collecting and reporting information anonymously. Functional cookies enable enhanced functionality such as remembering your preferences.
8.3 Managing Cookie Preferences
Most web browsers allow you to control cookies through their settings. You can typically configure your browser to block cookies, delete existing cookies, or alert you when cookies are being placed. However, disabling certain cookies may impact the functionality of our website. For more detailed information about managing cookies, consult your browsers help documentation.
8.4 Do Not Track Signals
Our website currently does not respond to Do Not Track signals sent by browsers. However, we honor Global Privacy Control (GPC) signals where legally required. We continue to monitor developments in this area and may update our practices as industry standards evolve.
9. Data Retention
9.1 Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. The specific retention period varies by data category and processing purpose. Generally, client project data is retained for the duration of the engagement plus a period of five years thereafter for legal and business record-keeping purposes.
9.2 Criteria for Determining Retention
When determining retention periods, we consider the nature and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the data, whether those purposes can be achieved through other means, and applicable legal, regulatory, tax, accounting, and reporting requirements.
9.3 Data Deletion
Upon expiration of the applicable retention period, personal data is securely deleted or anonymized. Deletion methods include secure digital erasure for electronic records and secure shredding for any physical copies. You may also request earlier deletion of your data as described in Section 10.
10. Your Data Protection Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data. We will respond to requests to exercise these rights within the timeframes required by applicable law, typically within 30 days.
10.1 Right of Access
You have the right to request confirmation of whether we process your personal data, and if so, to receive a copy of that data along with information about how it is being processed.
10.2 Right to Rectification
You have the right to request correction of inaccurate personal data we hold about you, and to have incomplete data completed by providing a supplementary statement.
10.3 Right to Erasure
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, or when you withdraw consent on which processing is based.
10.4 Right to Restrict Processing
You have the right to request restriction of processing in certain situations, such as when you contest the accuracy of your data or object to processing, pending verification.
10.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller without hindrance from us, where processing is based on consent or contract and carried out by automated means.
10.6 Right to Object
You have the right to object to processing of your personal data that is based on our legitimate interests. You also have an absolute right to object to processing for direct marketing purposes at any time.
10.7 Exercising Your Rights
To exercise any of these rights, please contact us at care@dragonlight.buzz. We may need to verify your identity before processing your request. If you believe we have not adequately addressed your concern, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction.
11. Children's Privacy
Our Services are not directed at individuals under the age of 16, and we do not knowingly collect personal data from children. If we become aware that a child under 16 has provided us with personal data without verifiable parental consent, we will take steps to delete such information from our systems promptly. If you believe we may have inadvertently collected data from a child, please contact us immediately at care@dragonlight.buzz so that we can take appropriate action.
We do not condition participation in any activity or service on the disclosure of more personal information than is reasonably necessary. All data collection practices described in this policy apply only to individuals who are legally capable of providing informed consent according to applicable laws.
12. International Data Transfers
DragonLights and JiuJiang LongGuangShi Trading Co., Ltd. are based in China, and our primary data processing activities occur within China and other jurisdictions where our cloud infrastructure providers maintain data centers. If you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with data transfer restrictions, your personal data may be transferred to and processed in countries that may not provide the same level of data protection as your home jurisdiction.
When we transfer personal data across international borders, we implement appropriate safeguards in accordance with applicable data protection laws. These safeguards may include the use of Standard Contractual Clauses approved by relevant regulatory authorities, assessments of the legal framework in the destination country, and contractual obligations imposed on data recipients to ensure a substantially equivalent level of protection.
By using our Services and providing your personal data, you consent to the transfer of your information to countries outside your country of residence, including China, and you acknowledge that such transfers are necessary for the provision of our Services.
13. Third-Party Services
Our website and Services may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party services and are not responsible for their privacy practices. When you leave our website or interact with third-party content, we encourage you to read the privacy policy of every service you visit.
We use several third-party services in the operation of our business, including but not limited to cloud infrastructure providers, email service providers, analytics platforms, payment processors, and productivity tools. A current list of material subprocessors is available upon request by emailing care@dragonlight.buzz. We enter into data processing agreements with all subprocessors that handle personal data on our behalf.
14. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the Last Updated date at the top of this page and provide a prominent notice on our website. For clients with active engagements, we will also notify you via email of material changes that affect our processing of your data.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of our Services after any changes to this policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you should discontinue use of the Services and contact us to discuss any concerns about your data.
We maintain a version history of this Privacy Policy internally. If you require a copy of a previous version for legal or audit purposes, please contact us and we will provide it within a reasonable timeframe.
15. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the details below. We take all privacy inquiries seriously and will respond as promptly as possible.
Data Controller: JiuJiang LongGuangShi Trading Co., Ltd.
Registered Address: Room 102-8, Building 7, Xiyanglong Resettlement Community, Lianxi District, Jiujiang - 332000, China
Email: care@dragonlight.buzz
Phone: +1 (531) 365-8527
Website: www.dragonlight.buzz
For data subjects in the EEA or UK who have concerns about our data practices that we have not been able to resolve, you have the right to lodge a complaint with the data protection supervisory authority in your country of residence or the UK Information Commissioner's Office (ICO).