Thank you for using the GridLead website and online service (https://www.gridlead.tech, the “Service”) operated by us (the “Platform” or “we”). This Privacy Policy explains how we collect, use, store, share and protect personal information when you register, log in, use the workspace or submit a sales enquiry, and the rights you have. By registering an account, logging in or using the Service, you confirm that you have read and agree to this Policy.
We recognise the importance of personal information and will protect it with diligence and good faith. This Policy also applies to the personal information of your prospective customers (“Lead Contacts”) synchronised to the Platform from third-party social media (currently Facebook; WhatsApp and other channels may be added later) after your authorised connection.
1Information We Collect
To provide the account, multi-account collaboration, social-media inquiry aggregation and customer-information services, we collect:
- Account information: the name, company name, mobile phone number (used as your login account) and email address (optional, used to receive proposal documents) you provide upon registration, together with your password; your role (owner / sales), regional group and sales-representative identifier are recorded by the Platform based on the account relationship;
- Sales-enquiry information: the name, company, job title, country/dialling code and phone number, email, estimated purchase volume, target markets (multi-select), product capabilities of interest (multi-select) and requirement description you submit via the “Contact Sales” page;
- Business conversation data: inquiry conversations, messages, your replies, handling status (new / replied / quoted / meeting arranged) and Lead Contact profiles (contact, company, country, WhatsApp, email, business type, import experience, trade-fair participation, products of interest, quantity, source, owner) synchronised from social-media channels after your authorisation;
- Sign-in and security information: login session data, “remember password” preference, and the phone number and verification-code records used for password recovery;
- Technical and log information: access time, IP address, browser type and device information.
2How We Use Information
- To create and manage your account and provide sign-in, password recovery and session persistence;
- To respond to your enquiry: a dedicated sales consultant will contact you within 24 hours with a proposal and quotation;
- To provide the social-media inquiry inbox, customer information display, conversation status workflow and multi-account collaboration features;
- To display and assign business data to sub-accounts of your organisation within the scope authorised by the primary account;
- To conduct security, anti-fraud and compliance audits;
- To improve product features within the scope of your consent;
- To fulfil legal obligations or legitimate requests from competent authorities.
3Lawful Basis for Processing
Our lawful bases for processing include: your consent or the Lead Contact’s consent, performance of a contract with you (providing the requested Service), compliance with legal obligations, and our legitimate interests (such as ensuring Service security and continuous improvement), balanced against the impact on individuals’ rights. Connecting a social-media channel to obtain inquiry data requires your authorisation with both the relevant platform and the Platform.
4Data Storage (Special Note on the Demo Release)
Production release: information will be stored on servers with physical and logical access controls and retained only for the minimum period necessary to achieve the processing purpose or as required by law. After account closure we will delete or anonymise your personal information within a reasonable period, unless a longer retention is required by law.
Demo release (current status): the current website is a front-end demonstration. Account, conversation and enquiry data are stored only in the local storage of your browser (localStorage keys include gl_users, gl_session, gl_remember, gl_code, gl_contacts, gl_fb_replies) and are not persistently retained on our servers. Such data: may be lost if you clear browser data or change device or browser; and may be visible to subsequent visitors on the same device and browser. You may delete it at any time by clearing site data. In the demo release passwords are stored with reversible encoding rather than production-grade hashing — please do not reuse a password from any important account.
5Multi-Account Permissions and Data Visibility
- Primary account (owner): typically the person in charge of the registered organization; may view all business conversations and customer profiles of the organization, view the dashboard and manage sub-accounts;
- Sub-accounts (sales): sales-representative accounts configured by the primary account or the operator; may only view and handle business data of their assigned regional group (e.g. Asia-Pacific, Middle East, Latin America, Europe & Africa, Central Asia);
- Within an organization, the primary account may access and manage business data handled by its sub-accounts; the organization is the controller of that business data and must ensure its use complies with this Policy and applicable law;
- Roles and regional groupings may be adjusted by the primary account or the operator; adjustments do not change the ownership rules of existing data.
6Information Sharing and Third Parties
We do not sell your personal information to any third party. We may share necessary information with contractually bound service providers in the following circumstances:
- Social media platforms: when you use the Facebook (or other) channel integration, data is transmitted and returned via the platform’s official API and is subject to the data policies of Meta and the relevant platform; you must also comply with those platforms’ terms;
- Cloud and infrastructure providers: for computing, storage, network and security services;
- Legal requirements: where required by law or by legitimate requests from competent authorities.
Information submitted via “Contact Sales” is used solely for our sales consultants to contact you and will not be used for unrelated marketing.
7Cross-Border Data Transfer
The Service is operated by an entity based in China. If you are located outside China or use overseas social-media channels, your data may be transferred to and processed in China. In accordance with Article 38 of the Personal Information Protection Law (PIPL), we will conduct cross-border transfers through one or a combination of: personal information protection certification, standard contractual clauses, or a security assessment by the national cyberspace administration, and only after obtaining separate consent. Where applicable, we will inform you of the overseas recipient’s identity, contact details, purposes and means of processing, and how individuals may exercise their rights. For EU data subjects, transfers will rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) under the GDPR; for Brazil, we take account of the LGPD.
8Data Security
The production release will implement TLS 1.2+ transport encryption, encryption at rest (AES-256), salted password hashing, role-based access control (primary/sub-account isolation) and operation audit logs, with periodic security assessments. The security measures of the current demo release are as described in Section 4 and are subject to the corresponding limitations. No transmission over the internet is completely secure; in the event of a security incident we will notify you and the relevant regulator in a timely manner as required by law.
9Cookies and Local Storage
We use necessary browser local storage (localStorage) to keep login sessions, preferences and demonstration business data (key names in Section 4) so the Service can operate. You may manage or clear site data via your browser settings; after clearing you will need to sign in again and demonstration data will be deleted. The current release uses no advertising or tracking cookies.
10Your Rights
You have the following rights regarding your personal information, exercisable via the contact details at the end of this Policy:
- Right to know and decide: to be informed of processing and to restrict it;
- Right of access and copy: to obtain a copy of your personal information;
- Right to rectify: to correct inaccurate information;
- Right to erasure: to request deletion where provided by law (EU data subjects have the “right to be forgotten”); in the demo release you may clear browser site data yourself;
- Right to data portability: to receive and transfer your information in a structured, machine-readable format;
- Right to withdraw consent: to withdraw prior consent at any time, without affecting processing before withdrawal;
- Right to complain: to lodge a complaint with a supervisory authority.
For Lead Contacts whose data you authorise to be connected, we will assist them in exercising their rights; as the data provider you must ensure they are informed and have consented.
11Minors
The Service is intended for businesses and professional foreign-trade personnel and is not directed at individuals under 16. If we inadvertently collect information about a minor, we will delete it promptly.
12Policy Updates
We may update this Policy from time to time (including terms for newly added features). Material changes will be communicated via in-product notice or email. Continued use of the Service constitutes acceptance of the updates.
13Contact Us
If you have any questions about this Policy or wish to exercise your rights, please contact:
- Operating Entity: Shenzhen Hangdian Power Co., Ltd.
- Email: enzozz@szkekj.com