Privacy Policy
Effective Date: June 1, 2022
Last Updated: March 1, 2026
Website: https://www.bsiteelevator.com (the “Site”)
Data Controller: Bsite Elevator Co., Ltd. (“Bsite Elevator,” “we,” “us,” or “our”)
Registered Address: No.3185 Xizha Rd, Dachuangang, Zhenze, Wujiang, Suzhou, China
Contact for Privacy Matters:
Email: betty@bsite-elevator.com
Phone: (+86) 138 1489 0623
Data Protection Officer (if applicable): N/A
This Privacy Policy applies to the website bsiteelevator.com operated by Bsite Elevator Co., Ltd., a global supplier of dumbwaiters, service lifts, and food elevators. This policy explains how we collect, use, share, store and protect personal data of our business customers, partners, website visitors and users (“you” or “your”), in compliance with the General Data Protection Regulation (GDPR), UK GDPR, California Consumer Privacy Act (CCPA/CPRA) and other applicable global data protection laws.
1. Information We Collect
We collect only data necessary for B2B sales, order fulfillment and customer relationship management (in line with the data minimization principle).
1.1 Data Provided Directly by You
When you create an account, request a quote, place an order or contact us:
- Contact Data: Full name, job title, company name, business email address, business phone number, company address, VAT/tax number
- Account Data: Username, password (stored in encrypted form), account preferences
- Transaction & Order Data: Purchase history, order details, shipping/billing addresses, invoice information, payment details (processed by third parties; we do not store full card data)
- Communication Data: Messages, inquiries, support tickets, feedback
- Marketing Preferences: Consent to receive newsletters, product updates and promotional materials
1.2 Automatically Collected Data (via Cookies & Technologies)
When you visit or use the Site:
- Technical Data: IP address, browser type, device type, operating system, referring/exit pages, timestamps, clickstream data
- Usage Data: Pages viewed, products browsed or downloaded, forms submitted, website interactions
- Location Data: Country/region (derived from IP address; not precise GPS location)
- Cookie & Tracking Data: See Section 6 – Cookies and Similar Technologies
1.3 Data from Third Parties
- Your contact and company information provided by business partners, distributors or agents
- Payment processors, logistics providers, CRM platforms (e.g., Salesforce, HubSpot)
- Public sources (company websites, business registries) for B2B business development
2. How We Use Your Data
We process your data only for specified and legitimate B2B purposes.
2.1 Core Business Purposes
- Contract Performance: Process quotations, orders, invoices, payments, delivery and shipment of dumbwaiter products
- Customer Support: Respond to inquiries, resolve issues, provide technical assistance and manage warranty services
- Account Management: Administer your B2B account, verify identity and maintain records
- B2B Sales & Prospecting: Identify potential corporate clients and introduce products (based on legitimate interests)
2.2 Marketing & Communication
- Send non-marketing transactional messages (order confirmations, shipping alerts)
- Send marketing communications (new products, promotions, industry updates) only if you opt in or provide consent
- Optimize website experience and product recommendations with consent or based on legitimate interests
2.3 Legal & Security Purposes
- Comply with tax, accounting and legal obligations (e.g., retaining invoices for 7–10 years)
- Prevent fraud, unauthorized transactions and cyber threats; secure the Site and systems
- Resolve disputes and enforce our Terms of Service
2.4 Analytics & Improvement
- Analyze website usage to optimize functionality, user experience and product offerings
- Generate aggregated and anonymized business reports
3. Legal Bases for Processing (GDPR / UK GDPR)
We rely on the following lawful bases:
- Contractual Necessity: To perform our B2B contract or order with you
- Legitimate Interests: B2B sales, customer service, fraud prevention and data analytics (we have conducted legitimate interest assessments)
- Consent: For marketing emails, non-essential cookies and personalized advertising (you may withdraw consent at any time)
- Legal Obligation: To meet tax, accounting and regulatory requirements
4. Data Sharing & Recipients
We share data only with trusted third parties to the extent necessary.
4.1 Service Providers
- Payment Processors: PayPal, Stripe, Wise, credit card gateways (PCI DSS compliant)
- Logistics Providers: DHL, FedEx, UPS and local freight forwarders
- Cloud Hosting: AWS, Google Cloud, Shopify/WooCommerce hosting
- CRM & Email Services: HubSpot, Salesforce, Mailchimp
- Analytics Tools: Google Analytics, Hotjar (subject to consent)
- IT & Security Services: Cloudflare, cybersecurity tools
4.2 Other Disclosures
- Legal Requirements: When required by law, court order or regulatory request
- Business Transfers: In the event of mergers, acquisitions or asset sales (data remains protected)
- No Sale of Data: We do not sell your personal data to third parties for monetary value (CCPA/CPRA)
5. International Data Transfers
As a global business, your data may be transferred to:
- The European Economic Area (EEA), United Kingdom, United States, China and other countries
- Transfers are carried out under EU Standard Contractual Clauses (SCCs) or approved adequacy decisions
- All partners maintain GDPR‑equivalent data protection standards
6. Cookies & Similar Technologies
6.1 Types of Cookies
- Essential Cookies: Required for website operation (cart, login, security) – cannot be disabled
- Functional Cookies: Remember preferences, language and form details
- Analytics Cookies: Measure traffic, usage and performance (Google Analytics) – require consent
- Marketing/Advertising Cookies: Track campaign performance and personalized ads (Facebook Pixel, LinkedIn Insights) – require explicit consent
6.2 Cookie Controls
- You may manage or delete cookies through your browser settings
- Our cookie consent banner allows you to accept or decline non-essential cookies
- Detailed Cookie Policy: [Link to separate Cookie Policy page]
7. Data Retention
We retain data only for as long as necessary:
- Account & Contact Data: Until account deletion plus mandatory legal retention periods (tax: 7–10 years)
- Order & Transaction Data: 7–10 years for tax and legal compliance
- Marketing Data: Until you unsubscribe or withdraw consent
- Technical & Analytics Data: 90 days (anonymized thereafter)
- Retention criteria: legal obligations, contract performance, legitimate business interests
8. Data Security
We protect your data using:
- Encryption: TLS/SSL for transmission; AES‑256 for storage
- Access Controls: Role‑based access permissions and staff training
- Secure Infrastructure: Firewalls, intrusion detection and regular backups
- Third‑Party Standards: PCI DSS, ISO 27001 certified providers
- Breach Notification: Notify users and authorities within 72 hours if required by law
9. Your Data Protection Rights
Under GDPR, UK GDPR and CCPA, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion (“right to be forgotten”) where required by law
- Restriction: Request restriction of processing your data
- Data Portability: Receive data in a machine‑readable format
- Object: Object to processing (e.g., direct marketing)
- Withdraw Consent: At any time, without affecting the lawfulness of prior processing
- Lodge a Complaint: With your local data protection authority
How to Exercise Your Rights
- Submit requests to: betty@bsite-elevator.com
- Provide: full name, company, email and proof of identity
- We will respond within 30 days (extendable by 60 days for complex requests)
- No fee for reasonable requests; a fee may apply for excessive or repetitive requests
10. B2B Specific Provisions
This Site is intended for business users only, not individual consumers:
- We process business contact data (name, work email, company information)
- B2B prospecting is based on legitimate interests under Article 6(1)(f) GDPR
- Commercial outreach includes a clear link to this policy
- We do not knowingly collect data from individuals acting in a personal or consumer capacity
11. Children’s Privacy
This Site is not intended for children under the age of 16. We do not knowingly collect information from minors.
12. Changes to This Policy
- We may update this policy. Material changes will be posted on the Site with 30 days’ prior notice
- Continued use of the Site after the update constitutes acceptance of the revised policy
13. Contact Us
For questions about this Privacy Policy or to exercise your rights:
Email: betty@bsite-elevator.com
Address: No.3185 Xizha Rd, Dachuangang, Zhenze, Wujiang, Suzhou, China
Phone: (+86) 138 1489 0623