Home›Privacy Policy
DATA PROTECTION

Privacy, with clarity.

This notice explains how personal information submitted through the EA GLOVE website is handled. It is a working draft for the site preview and must be finalized before the site is offered to EU visitors.

Draft updated 25 September 2026
Built around your enquiryThe current site uses your form details to receive and respond to B2B product requests. No advertising or analytics scripts are present in the checked application code.
Company review required before public launch

Confirm the controller's legal address and monitored privacy email, hosting and access locations, retention schedule, any EU representative requirement, and the mechanism for transfers outside the EEA. This draft is not a declaration of GDPR compliance.

1. Who is responsible

The proposed data controller for the enquiry service is Zhejiang East Asia Glove Co., Ltd. (浙江东亚手套有限公司), the manufacturer presented on this website.

The project brief lists the address as No. 2488 Haifeng Road, Taizhou Bay New Area, Taizhou, Zhejiang, China. The brief also says to verify the English address against the business licence before launch.

Privacy contact email and, if required, an EU representative: to be confirmed before publication.

2. Information we collect

When you submit an enquiry, the form asks for your name, email address and international-format phone number. You may also provide your company, country or region, product requirements and a message. Product pages can prefill the model you are enquiring about.

The current enquiry database stores those submitted fields and the submission time. It does not have an application field for your IP address. The eventual hosting provider may process standard connection logs; its identity, log fields and retention must be confirmed before launch.

3. Why we use the information

We use enquiry details to review your request, discuss products, samples, documents or an OEM project, and maintain the related business correspondence. The required fields are needed to identify and reply to the person making the request; if you do not provide them, the form cannot be submitted.

Proposed GDPR legal basis for ordinary B2B enquiries: legitimate interests in responding to business requests (Article 6(1)(f)). If a request is made by an individual to take steps before a contract with that individual, Article 6(1)(b) may also be relevant. The final basis and any legitimate-interests assessment require company/legal review.

The current application does not send marketing emails and does not make decisions based solely on automated processing or profiling.

4. Cookies and technical data

The checked application code does not add advertising pixels, analytics scripts, or optional cookies. It does not currently show a cookie-consent banner because there are no optional tracking technologies to approve in this version. The production host and any services added later must be checked separately.

The Contact page offers an optional interactive map. It does not contact OpenStreetMap until you select “Load interactive map”. At that point your browser requests map content from OpenStreetMap Foundation services, which may receive technical connection data such as your IP address. You can read the OpenStreetMap Foundation privacy policy before loading the map.

If analytics, advertising or other non-essential technologies are introduced, this notice and a consent mechanism must be updated before those technologies run for visitors where prior consent is required.

5. Sharing and international transfers

Enquiry details are intended for authorized staff handling product and sales requests. A local Node preview stores them in a private SQLite database. A Cloudflare Workers deployment uses a D1 database once its binding is configured. No email provider, CRM, ad platform or analytics provider is connected to the enquiry endpoint at present.

The public hosting provider, processing locations, any access from China and any onward transfers are not yet finalized. If EEA personal data is transferred outside the EEA, the final notice must describe the applicable transfer basis and how to obtain information about safeguards. No particular safeguard is claimed in this draft.

6. How long we keep data

A retention period and deletion process have not yet been set. Neither the local SQLite database nor a Cloudflare D1 deployment automatically deletes enquiries. A defined retention schedule and any exceptions for legal obligations must be approved and implemented before public launch.

7. Your rights

Where the GDPR applies and subject to its conditions, you may request access to, correction or erasure of your personal data, restriction of processing, object to processing based on legitimate interests, and request data portability where applicable. You may also lodge a complaint with a competent EEA data-protection supervisory authority.

A monitored contact channel for privacy-rights requests must be confirmed before this notice is published. Please do not use the sales enquiry form as a substitute for that channel.

For general guidance, see the European Data Protection Board's rights guidance.

8. Contact and changes

We will update this page when the company confirms its privacy contact, hosting arrangements, retention period, recipients and any cross-border safeguards. The date at the top identifies this draft version.

Do not publish this draft as a final privacy notice or begin EU-targeted paid campaigns until the open items above have been reviewed.