Legal

Privacy Policy

Last updated: August 11, 2026

Table of Contents
  1. Introduction
  2. Information We Collect
  3. How We Collect Information
  4. Use of Collected Information
  5. Sharing and Disclosure of Information
  6. Data Storage and Security
  7. Data Retention Policy
  8. International Data Transfers
  9. Your Data Protection Rights
  10. Privacy for Children
  11. Cookies and Tracking Technologies
  12. Third Party Services and Links
  13. Data Breach Notification Procedures
  14. Changes to This Privacy Policy
  15. Contact Information

Introduction

Summer Joy, operated by Kunming Xiahuan Trading Co., Ltd., is committed to protecting the privacy of every individual who interacts with our services. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website at summerjoy.mom, engage with our computer systems design and technology consulting services, or otherwise communicate with us through any channel. The developer of this website, Summer Joy, believes that transparent data practices are foundational to building trust. By accessing or using our services, you agree to the collection and use of information in accordance with this policy. If you do not agree with any part of this policy, you should discontinue use of our services and refrain from providing personal data to us.

This policy applies to all information collected through our website, email communications, telephone conversations, and any other interaction with Summer Joy and Kunming Xiahuan Trading Co., Ltd. We encourage you to read this document carefully and to contact us if you have questions about any provision described herein. We have designed this policy to comply with applicable data protection laws including the General Data Protection Regulation framework and similar privacy regimes around the world, while reflecting our own commitment to responsible data stewardship.

Information We Collect

We collect several categories of information to provide and improve our services. The types of information we collect depend on the nature of your interaction with us and the services you request. We only collect information that is necessary and relevant for the purposes described in this policy, and we strive to be transparent about what we collect at every point of data collection.

Personal Identification Information includes your full name, email address, telephone number, company name, job title, and any other identifying details you voluntarily provide when filling out contact forms, requesting consultations, subscribing to communications, or engaging with our client services team. This information is collected only when you choose to provide it to us, and you may decline to provide certain details, though this may limit your ability to use some features of our services.

Technical and Usage Information includes your Internet Protocol address, browser type and version, operating system, referring URLs, pages visited on our website, time and date stamps of visits, time spent on individual pages, and other diagnostic data. This information is collected automatically through standard web server logging and analytics technologies and helps us understand how visitors interact with our website so we can improve its performance and usability.

Communication Data includes the content of messages you send to us through our contact forms, email, telephone, or any other communication channel, as well as metadata about those communications such as timestamps and the medium used. We retain communications to provide continuity in our client relationships and to maintain accurate records of service requests and project discussions.

Business Relationship Data includes details about the organizations you represent, the nature of your technology needs, project specifications, budget parameters, decision-making timelines, and other business context that helps us tailor our computer systems design and consulting services to your requirements. This information is treated as confidential and is used exclusively for service delivery purposes.

How We Collect Information

We collect information through multiple methods, all of which are designed to be transparent and lawful. Our collection practices are limited to what is necessary for the operation of our business and the delivery of our services.

Direct Collection occurs when you voluntarily provide information to us. This happens when you complete a contact form on our website, send us an email, call our telephone number, attend a consultation meeting, subscribe to our newsletter, register for an event, or otherwise communicate with our team. In each case, you are informed of the purpose of collection and you provide the information knowingly and willingly.

Automated Collection occurs through cookies, web beacons, server logs, and similar technologies that record technical information about your device and browsing behavior when you visit our website. This information is collected passively as you navigate through the site. Our automated collection methods are described in greater detail in the Cookies and Tracking Technologies section of this policy.

Third Party Sources may occasionally provide us with information. For example, if a business partner refers you to our services, they may share basic contact information with your consent. We may also receive publicly available business information from commercial databases or professional networking platforms to enhance our understanding of prospective client organizations, always in compliance with applicable data protection laws.

Use of Collected Information

We use the information we collect for a range of legitimate business purposes, all of which are connected to the delivery, improvement, and administration of our computer systems design and technology consulting services. We do not use your personal information for purposes that are incompatible with those described in this policy without first providing notice and, where required, obtaining your consent.

Service Delivery and Fulfillment is our primary use of collected information. We use your contact details to respond to inquiries, provide proposals and quotations, deliver contracted services, manage project workflows, and communicate about project milestones, deliverables, and outcomes. Your business relationship data enables us to allocate the right technical resources and expertise to your engagement.

Website Improvement and Analytics involves using technical and usage data to analyze traffic patterns, identify popular content, detect technical issues, optimize page load performance, and improve the overall user experience of our website. This analysis is performed in aggregate where possible and helps us make data-informed decisions about our online presence.

Communication and Marketing includes sending you service-related announcements, newsletters, technology insights, case studies, event invitations, and other content that may be relevant to your interests. You may opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us directly. We do not send marketing communications to individuals who have not consented to receive them or who have opted out.

Legal Compliance and Protection includes using information as necessary to comply with applicable laws, regulations, and legal processes, to respond to lawful requests from public authorities, to enforce our terms of service and other agreements, to protect our rights and property, and to ensure the safety and security of our systems, our clients, and the public.

Sharing and Disclosure of Information

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes. We may share information in the limited circumstances described below, and only with entities that are contractually bound to protect your information in a manner consistent with this policy.

Service Providers and Vendors may receive access to certain information as necessary to perform services on our behalf. These include cloud hosting providers, email delivery platforms, analytics services, customer relationship management tools, and payment processors. Each service provider is carefully vetted and required to maintain confidentiality and security standards at least as protective as our own. They are permitted to use your information solely for the purpose of providing their contracted services to us.

Business Transfers may involve the transfer of information in connection with a merger, acquisition, reorganization, sale of assets, or similar corporate transaction. In such an event, we will notify you before your personal information is transferred and becomes subject to a different privacy policy, and we will take reasonable steps to ensure the receiving entity honors the commitments made in this policy.

Legal Obligations may require us to disclose information when we believe in good faith that disclosure is necessary to comply with a legal obligation, to protect against legal liability, to investigate potential violations of our terms, or to protect the personal safety of users of our services or the public. We will make reasonable efforts to notify you of such disclosure unless prohibited by law or court order.

Aggregated and De-Identified Data may be shared for research, analysis, marketing, or other business purposes. This data is stripped of all personally identifiable information and cannot reasonably be used to identify any individual. We maintain technical and organizational measures to ensure that de-identification is irreversible.

Data Storage and Security

We implement and maintain administrative, technical, and physical safeguards designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Our security program is built on industry-standard practices and is regularly reviewed and updated to address emerging threats and vulnerabilities.

Our technical measures include encryption of data in transit using Transport Layer Security protocols, encryption of sensitive data at rest, network firewalls and intrusion detection systems, multi-factor authentication for administrative access, regular vulnerability scanning and penetration testing, and comprehensive access logging and monitoring. Our administrative measures include security awareness training for all personnel, strict access controls based on the principle of least privilege, background checks for employees with access to sensitive systems, and documented incident response procedures.

Despite our best efforts, no method of electronic storage or transmission over the Internet is one hundred percent secure. While we strive to protect your personal information using commercially acceptable means, we cannot guarantee its absolute security. You share information with us at your own risk, and we encourage you to take precautions to protect your personal data when you are on the Internet, such as using strong passwords and keeping your software updated.

Data Retention Policy

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our retention periods are determined by the nature of the information, the purposes of processing, and our legal and operational obligations.

Contact and Inquiry Data is retained for up to twenty-four months after your last interaction with us, unless you become an active client, in which case the data is retained as part of our client records for the duration of the business relationship and for a reasonable period thereafter as required for legal and accounting purposes.

Client Project Data including specifications, deliverables, communications, and project artifacts is retained for a minimum of five years after project completion to comply with contractual obligations, professional standards, and applicable statutes of limitations. After this period, data is securely archived or deleted according to our data destruction procedures.

Website Analytics Data is retained in aggregate form indefinitely for trend analysis, while individual session data is retained for no more than twenty-six months. We regularly review our data inventories and delete information that is no longer needed for any legitimate business or legal purpose.

International Data Transfers

Summer Joy operates globally, and your information may be transferred to, stored in, and processed in countries other than the country in which you reside. Our primary operations are based in Kunming, China, and we use cloud infrastructure located in multiple geographic regions to deliver our services. These countries may have data protection laws that differ from the laws in your country of residence.

When we transfer personal information across international borders, we implement appropriate safeguards in accordance with applicable data protection requirements. These safeguards may include entering into standard contractual clauses approved by relevant regulatory authorities, conducting transfer impact assessments, and implementing supplementary technical and organizational measures where necessary to ensure that the level of protection afforded to your personal information is not diminished by the transfer.

By using our services and providing your information to us, you acknowledge and consent to the transfer of your information to countries outside your country of residence, including China, the United States, and other jurisdictions where we or our service providers operate. If you have questions about the specific safeguards applied to a particular transfer, please contact us using the details provided below.

Your Data Protection Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information. We respect these rights and have established processes to facilitate their exercise. The rights described below represent our general commitment to data subject empowerment and may be supplemented by additional rights under your local laws.

Right of Access entitles you to request a copy of the personal information we hold about you and to receive information about how we process it. We will provide this information in a structured, commonly used, and machine-readable format within a reasonable timeframe, typically thirty days.

Right of Rectification allows you to request that we correct any inaccurate or incomplete personal information we hold about you. We will make reasonable efforts to verify the accuracy of the corrected information before implementing the change.

Right of Erasure also known as the right to be deleted, allows you to request that we delete your personal information in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when the data has been processed unlawfully.

Right to Restrict Processing enables you to request that we limit the processing of your personal information in certain situations, such as when you contest the accuracy of the data or object to its processing. During the restriction period, we will store but not otherwise process your data.

Right to Data Portability allows you to request that we transfer your personal information directly to another organization, where technically feasible. This right applies to data you have provided to us and that we process by automated means based on your consent or on a contract.

Right to Object permits you to object to the processing of your personal information for direct marketing purposes or for processing based on our legitimate interests. We will cease processing for such purposes upon receiving your objection unless we can demonstrate compelling legitimate grounds for continued processing.

To exercise any of these rights, please contact us using the email address or mailing address provided in the Contact Information section. We may request verification of your identity before processing your request. We will respond to valid requests within the timeframes required by applicable law and will not discriminate against individuals who exercise their data protection rights.

Privacy for Children

Our website and services are not directed to individuals under the age of sixteen, and we do not knowingly collect personal information from children. If we become aware that a child under the age of sixteen has provided us with personal information without verifiable parental consent, we will take immediate steps to delete such information from our systems.

If you are a parent or guardian and you believe that your child has provided us with personal information, please contact us immediately so that we can take appropriate action. We encourage parents and guardians to monitor the online activities of their children and to educate them about responsible data sharing practices. We support industry efforts to protect the privacy of young people online and comply with applicable privacy regulations regarding children including the Children Online Privacy Protection framework in jurisdictions where it applies.

Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and understand where our visitors come from. A cookie is a small text file that a website stores on your device when you visit it. Cookies allow the website to remember your preferences and actions over a period of time, so you do not have to re-enter them whenever you return to the site or browse from one page to another.

Essential Cookies are necessary for the basic functioning of our website. They enable core features such as page navigation, secure form submissions, and access to protected areas. These cookies do not require your consent and cannot be disabled through our cookie settings because the website cannot function properly without them.

Analytics Cookies help us understand how visitors interact with our website by collecting and reporting information anonymously. We use these cookies to measure page views, track navigation paths, identify pages with high exit rates, and assess the effectiveness of our content. The data collected through analytics cookies is aggregated and does not identify individual visitors.

Functional Cookies allow our website to remember choices you make, such as your preferred language or the region you are in, and provide enhanced, more personalized features. These cookies may be set by us or by third-party providers whose services we have added to our pages.

You can control and manage cookies through your browser settings. Most browsers allow you to view, block, and delete cookies. Please note that if you choose to block all cookies, some parts of our website may not function as intended. You can also set your browser to send a Do Not Track signal, though there is currently no industry consensus on how websites should respond to such signals.

We may also use web beacons, also known as tracking pixels or clear GIFs, which are tiny graphic images embedded in web pages and emails. Web beacons help us determine whether a page has been viewed or an email has been opened, and they work in conjunction with cookies to provide a more complete picture of user engagement.

Third Party Services and Links

Our website may contain links to third-party websites, plugins, and applications that are not owned or controlled by Summer Joy or Kunming Xiahuan Trading Co., Ltd. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices.

We encourage you to review the privacy policies of every third-party website you visit through a link on our site. The inclusion of a link does not imply our endorsement of the linked website or its privacy practices. When you leave our website, the protections described in this Privacy Policy no longer apply, and your interactions with the third-party service are governed by its own terms and policies.

We may use third-party service providers to support various aspects of our business operations, including website hosting, email delivery, analytics, customer support platforms, and cloud infrastructure. These providers have access to personal information only as necessary to perform their functions and are contractually prohibited from using it for any other purpose. We maintain a list of our primary service providers and are happy to share it upon request.

Data Breach Notification Procedures

We have established comprehensive procedures for detecting, investigating, and responding to data breaches. A data breach is defined as a security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal information that we process.

Upon discovering a potential data breach, our incident response team immediately initiates containment measures to prevent further unauthorized access or disclosure. We then conduct a thorough investigation to determine the scope, cause, and impact of the breach, including the categories and approximate number of data subjects affected and the categories and approximate number of personal data records involved.

If we determine that a breach poses a risk to the rights and freedoms of affected individuals, we will notify the relevant supervisory authority within the timeframe required by applicable law, typically within seventy-two hours of becoming aware of the breach. We will also notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms. Our notification will describe the nature of the breach, the likely consequences, the measures we have taken or propose to take to address it, and recommendations for steps individuals can take to protect themselves.

We maintain a breach register that documents all security incidents, regardless of whether they meet the threshold for regulatory notification. This register supports our continuous improvement efforts and helps us refine our security posture over time.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal obligations, or operational requirements. When we make material changes to this policy, we will post the updated version on this page and update the Last Updated date at the top of the document.

For significant changes that materially affect your rights or the way we process your personal information, we will provide additional notice, which may include sending an email notification to the address we have on file for active clients, displaying a prominent notice on our website, or requesting your renewed consent where required by law. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

Your continued use of our website and services after the effective date of any revised Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the revised policy, you should discontinue use of our services and contact us to discuss the disposition of your personal information.

Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information below. We take all privacy inquiries seriously and will respond as promptly as possible, typically within five business days.

Company: Kunming Xiahuan Trading Co., Ltd. (Kunming Xiahuān Màoyì Yǒuxiàn Gōngsī)

Registered Address: Room 1001, 10th Floor, Zhiyuan Building, No. 389 Qingnian Road, Wuhua District, Kunming - 650000, China (CN)

Email: service@summerjoy.mom

Phone: +13093546393

Website: https://www.summerjoy.mom

You also have the right to lodge a complaint with the data protection supervisory authority in your jurisdiction if you believe that our processing of your personal information violates applicable law. While we encourage you to contact us first so that we can address your concerns directly, we respect your right to seek external recourse.

← Back to Homepage

© 2026 Summer Joy. Operated by Kunming Xiahuan Trading Co., Ltd.

Room 1001, 10th Floor, Zhiyuan Building, No. 389 Qingnian Road, Wuhua District, Kunming - 650000, China

Home · Terms of Service