1. Introduction
yilanfangtrade.com ("we", "us", "our", or the "Company") is a research-driven engineering studio headquartered at the Bristol & Bath Science Park in the United Kingdom. We design, develop, and publish minimalist, privacy-first digital products — including mobile applications distributed through the Apple App Store, Google Play Store, and our own digital channels.
This Privacy Policy (the "Policy") describes how we collect, use, disclose, and safeguard your information when you visit our websites (including yilanfangtrade.com and any subdomain), use our mobile applications (the "Apps"), engage with our services, or otherwise interact with us. Please read this Policy carefully. By accessing or using our services, you agree to the terms of this Policy.
We are committed to the principles of data minimisation, purpose limitation, storage limitation, and privacy by default and by design. Wherever technically feasible, our products are engineered to process data locally on your device, eliminating the need for cloud transmission.
We do not sell personal data. We do not share personal data with third parties for their own marketing purposes. We minimise the data we collect. We default to local processing wherever possible.
2. Definitions
For the purposes of this Policy:
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or erasure.
- "Data Subject" means the individual whose Personal Data is being processed.
- "Controller" means the entity that determines the purposes and means of processing Personal Data. We are the Controller.
- "Processor" means an entity that processes Personal Data on behalf of the Controller.
- "Services" means our websites, applications, products, and any related services.
- "User" or "you" means any individual accessing or using our Services.
3. Scope & Applicability
This Policy applies to:
- Our website at yilanfangtrade.com and all subdomains.
- Our mobile applications published on the Apple App Store and Google Play Store, including but not limited to: FlowMate, VaultWorth, PosturePro, HomeKeep, IdeaShards, and BudgetPulse.
- Any beta, preview, or early access versions of our products.
- Email, contact form, and other communications with us.
- Any other services where this Policy is referenced.
This Policy does not apply to third-party websites, services, or applications that we do not control, even if they are linked from our Services. We encourage you to review the privacy policies of any third-party services you access.
4. Data We Collect
We collect the minimum information necessary to provide our Services. The categories of data we may collect include:
4.1 Data You Provide Directly
- Contact Form Submissions: When you contact us through our website or email, you may provide your name, email address, company name, and the content of your message.
- Newsletter Subscription: Email address for our optional quarterly newsletter.
- Support Communications: Information you share when contacting support@yilanfangtrade.com.
- Application Content (App Store Products): For our mobile applications, content you create within the App (documents, notes, recordings, budgets, etc.) is stored locally on your device unless you explicitly opt-in to a cloud sync feature. We do not have access to this content.
4.2 Data Collected Automatically
- Server Logs: IP address, browser type and version, operating system, referring URL, pages visited, time and date of visit, time spent on pages. Retained for 90 days maximum.
- Device Information: Device type, operating system version, language settings (for our Apps).
- Crash Reports: Anonymous crash data when an App malfunctions, if you have opted in to share diagnostics.
4.3 Data We Do NOT Collect
- Persistent device identifiers for advertising (we do not use IDFA/GAID for cross-app tracking)
- Precise geolocation data (GPS coordinates)
- Biometric data (beyond what is stored locally in the device's secure enclave for your own authentication)
- Contact lists, calendar entries, or photos from your device
- Microphone or camera recordings (beyond what is explicitly recorded within an App and stored locally)
- Purchase history outside of App Store transactions (handled by Apple/Google)
5. How We Use Data
We use the limited data we collect for the following purposes:
- To respond to your inquiries and provide customer support.
- To deliver and maintain our Services.
- To send you our newsletter (only if you have explicitly subscribed).
- To analyse aggregated, anonymised usage patterns to improve our products.
- To detect, prevent, and address technical issues, fraud, or illegal activities.
- To comply with applicable legal obligations.
- To enforce our Terms of Service and other agreements.
6. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we process Personal Data on the following legal bases:
- Consent (Art. 6(1)(a) GDPR): When you have given clear consent for us to process your Personal Data for a specific purpose (e.g., newsletter subscription).
- Contract (Art. 6(1)(b) GDPR): When processing is necessary for the performance of a contract with you (e.g., providing requested services).
- Legitimate Interests (Art. 6(1)(f) GDPR): When processing is necessary for our legitimate interests, provided these are not overridden by your fundamental rights and freedoms (e.g., server logs for security, anonymised analytics).
- Legal Obligation (Art. 6(1)(c) GDPR): When processing is necessary for compliance with a legal obligation to which we are subject.
7. Data Sharing
We do not sell, rent, or trade your Personal Data. We share Personal Data only in the following limited circumstances:
- Service Providers: Trusted third-party vendors who assist us in operating our Services (hosting, email delivery), bound by confidentiality and data processing agreements.
- Advertising Networks: As detailed in Section 8, our Apps may integrate third-party advertising SDKs that collect data automatically when you view or interact with ads.
- Legal Requirements: When required by law, court order, or governmental authority, or to protect our rights, property, or safety.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with appropriate notice to you.
- With Your Consent: For any other purpose disclosed at the time of collection with your explicit consent.
8. Advertising Networks & Monetisation Platforms
Our mobile applications published on the Apple App Store and Google Play Store may integrate third-party advertising networks to support free tiers and to display relevant advertisements. These integrations may involve the automatic collection of certain device and usage information to deliver, measure, and improve advertising.
Our advertising integrations follow platform-specific consent frameworks (App Tracking Transparency on iOS, User Messaging Platform / Privacy & Messaging on Android). You can manage advertising preferences through your device settings and the in-app consent dialogs.
8.1 Types of Advertisements Served
Our Apps may serve the following ad formats, where supported by the advertising network and your device's consent settings:
- Banner Ads: Standard rectangular advertisements displayed within designated areas of the App interface.
- Interstitial Ads: Full-screen advertisements displayed at natural transition points in the App (e.g., between content views, on completion of a task).
- Rewarded Video Ads: Optional video advertisements that users may choose to view in exchange for in-app rewards, premium features, or content unlocks.
- Native Ads: Advertisements designed to match the look and feel of the App's organic content.
- Open (Splash) Screen Ads: Full-screen advertisements displayed during App launch or return to foreground.
- App Open Ads: Special format displayed when the App is brought to the foreground.
- Rewarded Interstitial Ads: Interstitials that offer a reward for viewing.
8.2 Advertising & Mediation Platforms We May Integrate
The following advertising platforms may be integrated into our Apps. Each platform operates under its own privacy policy, and may collect device identifiers, advertising IDs (subject to your consent), coarse location, app usage data, and other information to deliver personalised (or non-personalised) ads. We use Google AdMob as our primary mediation platform, which dynamically serves ads from the networks below.
Primary Ad Networks
- Google AdMob & Google AdSense: Mobile and web ad serving by Google. Privacy: policies.google.com/privacy. Users may opt out of personalised advertising via adssettings.google.com.
- Meta Audience Network (Facebook): Meta's mobile ad network. Privacy: facebook.com/policy.php. Ad preferences: facebook.com/adpreferences.
- Unity Ads: Unity Technologies' ad mediation platform. Privacy: unity.com/legal/privacy-policy.
- AppLovin (and AppLovin MAX): Mobile ad mediation platform. Privacy: applovin.com/privacy.
- ironSource: Ad mediation and analytics. Privacy: is.com/privacypolicy.
- Vungle (now part of Liftoff): Video ad network. Privacy: liftoff.io/privacy-policy.
- Chartboost (now part of LoopMe): Mobile ad network and programmatic exchange. Privacy: chartboost.com/privacy.
- Pangle (TikTok For Business / Bytedance): Mobile ad network. Privacy: pangleglobal.com/privacy-and-policy.
- Mintegral: Mobile programmatic ad platform. Privacy: mintegral.com/en/privacy.
- InMobi: Mobile ad platform. Privacy: inmobi.com/privacy-policy.
Additional Ad Networks & Programmatic Exchanges
- Tapjoy: Rewarded ad and offerwall network. Privacy: tapjoy.com/legal/generic/privacy-policy.
- AdColony (now part of Digital Turbine): Mobile video ad network. Privacy: adcolony.com/privacy-policy.
- Smaato (now part of Verve Group): Real-time ad exchange. Privacy: smaato.com/privacy.
- Digital Turbine (Fyber, HeyZap): Mobile ad mediation. Privacy: digitalturbine.com/privacy-policy.
- StartApp: Mobile ad network and SDK provider. Privacy: startapp.com/privacy-policy.
- MobFox (now part of Verve Group): Mobile ad serving. Privacy: mobfox.com/privacy-policy.
- Persona.ly: Mobile programmatic DSP. Privacy: persona.ly/privacy-policy.
- Adikteev: App retargeting and user acquisition. Privacy: adikteev.com/privacy-policy.
- Yahoo Ads / Verizon Media: Programmatic display advertising. Privacy: yahooinc.com/privacy-policy.
- Microsoft Advertising (Bing Ads, Xandr): Search and display advertising. Privacy: privacy.microsoft.com.
- Amazon Advertising: Amazon's ad network. Privacy: amazon.com/privacy.
- Criteo: Retargeting and personalised advertising. Privacy: criteo.com/privacy.
- Taboola: Native advertising and content recommendation. Privacy: taboola.com/privacy-policy.
- Outbrain: Native content recommendation. Privacy: outbrain.com/legal/privacy.
Attribution & Analytics Partners (Supporting Advertising)
- AppsFlyer: Mobile attribution and marketing analytics. Privacy: appsflyer.com/legal/privacy-policy.
- Adjust: Mobile measurement and fraud prevention. Privacy: adjust.com/privacy-policy.
- Kochava: Attribution and analytics. Privacy: kochava.com/privacy-policy.
- Branch: Deep linking and attribution. Privacy: branch.io/policies/privacy-policy.
- Singular: Marketing attribution. Privacy: singular.net/privacy-policy.
- Tenjin: Mobile analytics. Privacy: tenjin.com/privacy-policy.
- Firebase Analytics (Google): App analytics. Privacy: firebase.google.com/support/privacy.
- Mixpanel: Product analytics. Privacy: mixpanel.com/legal/privacy-policy.
- Amplitude: Product analytics. Privacy: amplitude.com/privacy.
8.3 Information Collected by Advertising Networks
When advertising is served within our Apps, the advertising networks may collect the following types of information, typically via SDKs integrated into the App:
- Advertising identifiers (IDFA on iOS, GAID/AdID on Android) — only when you have granted consent through the device-level consent prompt.
- Device information: device type, operating system and version, language, screen size, time zone.
- Network information: IP address, carrier, network type, Wi-Fi information.
- App information: bundle ID, app version, session length, in-app events (subject to consent).
- Coarse location (country, region, city) inferred from IP — not precise GPS location.
- Ad interaction data: impressions, clicks, video views, completions.
- Crash logs and performance data.
8.4 Your Choices & Controls
You have the following options to manage advertising personalisation:
- iOS — App Tracking Transparency: When prompted, you may choose "Ask App Not to Track" or grant tracking permission per-app. You can change this anytime via Settings → Privacy & Security → Tracking.
- Android — Advertising ID: Settings → Privacy → Ads → "Delete advertising ID" or "Opt out of Ads Personalisation".
- Reset Advertising ID: Both platforms allow you to reset your advertising ID, which breaks the linkage between your data and any previous profiles.
- Limit Ad Tracking: Both platforms allow you to enable "Limit Ad Tracking" (iOS) or "Opt out of interest-based ads" (Android).
- Platform Controls: Google offers ad personalisation controls at adssettings.google.com; Meta at facebook.com/adpreferences.
- Network Advertising Initiative: Some networks participate in the NAI opt-out tool at optout.networkadvertising.org.
- Digital Advertising Alliance: Opt-out via youradchoices.com.
8.5 Children's Privacy in Advertising
Our Apps are not directed to children under 13 (or higher ages as required by local law). We do not serve personalised advertising to known children. Where required by law (e.g., COPPA, UK Age-Appropriate Design Code), we treat all users under the applicable age threshold as children and disable interest-based advertising entirely. See Section 16 for more details.
8.6 EU/UK Users & Consent
For users in the European Economic Area (EEA), the United Kingdom, and Switzerland, we use Google's User Messaging Platform (UMP) to obtain consent for personalisation of ads (in compliance with the EU ePrivacy Directive and GDPR). Non-personalised ads are served if consent is not granted.
9. Cookies & Tracking Technologies
9.1 Cookies We Use
Our website uses a minimal set of cookies. Categories include:
- Strictly Necessary Cookies: Required for the website to function (e.g., session cookies, security cookies). Cannot be disabled.
- Functional Cookies: Remember your preferences (e.g., language, theme). Optional.
- Analytics Cookies: We may use privacy-respecting analytics (such as a self-hosted or cookie-less analytics solution) to understand aggregate usage. No personally identifiable information is collected through analytics.
- Advertising Cookies: We do not currently use advertising cookies on our website. Our Apps use the consent frameworks described in Section 8.
9.2 Cookie Management
You can control cookies through your browser settings. Most browsers allow you to refuse or accept cookies, delete existing cookies, and set preferences for specific websites. Note that disabling cookies may affect website functionality.
9.3 Do Not Track / Global Privacy Control
We honour Do Not Track (DNT) signals and Global Privacy Control (GPC) signals where technically feasible. When such signals are detected, we will disable non-essential cookies and advertising personalisation. See Section 18 for more information.
9.4 Third-Party Cookies
Some third-party services (such as embedded video players or fonts) may set their own cookies. These are governed by the respective third party's privacy policy. We minimise our use of such third-party embeds.
10. App Store Compliance
10.1 Apple App Store
Our Apps published on the Apple App Store comply with:
- Apple's App Store Review Guidelines.
- Apple's App Tracking Transparency (ATT) framework: we will display the ATT prompt before any data is shared with advertising networks for tracking purposes.
- Apple's requirement to declare privacy practices via the App Privacy Details on the App Store product page.
- Apple's Security and Privacy Guidelines for iOS.
10.2 Google Play Store
Our Apps distributed on Google Play comply with:
- Google Play Developer Content Policy.
- Google Play Developer Distribution Agreement.
- Google Play Families Policy (for Apps accessed by children).
- User Data Policy, including the requirement to declare data practices.
10.3 Privacy Nutrition Labels
We accurately declare the data practices of our Apps in the App Privacy section of the Apple App Store and the Data Safety section of Google Play. These declarations are kept current with each release that introduces new data practices.
11. Data Retention
We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.
- Contact Form & Support Inquiries: Retained for up to 3 years after last contact, then deleted.
- Newsletter Subscriptions: Retained until you unsubscribe.
- Server Logs: Retained for up to 90 days, then aggregated or deleted.
- Local App Data: Stored on your device, under your control. We do not have access.
- Anonymised Analytics: Retained indefinitely in aggregate form.
Upon expiry of the retention period, Personal Data is securely deleted or irreversibly anonymised.
12. Data Security
We implement appropriate technical and organisational measures to protect your Personal Data, including:
- Encryption in transit (HTTPS/TLS 1.3) for all website communications.
- Encryption at rest for stored data.
- Access controls limiting access to Personal Data on a need-to-know basis.
- Regular security audits and penetration testing.
- Secure development practices throughout the software development lifecycle.
- Incident response procedures, including notification within 72 hours in case of a Personal Data breach affecting EU/UK users (per GDPR Art. 33).
- For Apps: on-device encryption with hardware-backed keys (Secure Enclave on iOS, Keystore on Android).
13. International Data Transfers
We are headquartered in the United Kingdom. When Personal Data is transferred outside the UK/EEA (for example, to service providers or advertising partners located in the United States), we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs): Approved by the European Commission and the UK ICO for transfers from the EEA/UK to third countries.
- UK International Data Transfer Agreement (IDTA): For transfers from the UK.
- Adequacy Decisions: Reliance on European Commission or UK ICO adequacy decisions where available (e.g., for transfers to the United States under the EU-US Data Privacy Framework).
- Data Privacy Framework: Some of our service providers are certified under the EU-US Data Privacy Framework.
14. Your Rights
Regardless of where you are located, you have the following rights regarding your Personal Data:
- Right of Access: Request a copy of the Personal Data we hold about you.
- Right of Rectification: Request that we correct inaccurate or incomplete data.
- Right of Erasure ("Right to be Forgotten"): Request that we delete your Personal Data, subject to legal exceptions.
- Right to Restrict Processing: Request that we limit how we process your data.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time.
- Right to Lodge a Complaint: Lodge a complaint with a supervisory authority.
To exercise these rights, contact us at contact@yilanfangtrade.com. We will respond within 30 days (or earlier where required by law).
15. Regional-Specific Rights & Compliance
15.1 European Economic Area (EEA) & United Kingdom — GDPR & UK GDPR
If you are in the EEA or UK, you have the rights described in Section 14. The relevant supervisory authorities are listed below for reference:
- UK: Information Commissioner's Office (ICO), ico.org.uk
- EU: Your national Data Protection Authority. A list is available at edpb.europa.eu.
We comply with the EU-U.S. Data Privacy Framework Principles where applicable, and the UK Extension thereto.
15.2 California, USA — CCPA / CPRA
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know what Personal Data is collected, used, shared, or sold.
- Right to delete Personal Data collected from you.
- Right to opt-out of the sale or sharing of Personal Data. We do not sell Personal Data.
- Right to correct inaccurate Personal Data.
- Right to limit the use of sensitive Personal Data (where applicable).
- Right to non-discrimination for exercising your CCPA rights.
California "Shine the Light" (Cal. Civ. Code § 1798.83): We do not share Personal Data with third parties for their direct marketing purposes.
15.3 Canada — PIPEDA & Quebec Law 25
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Law 25. Canadian residents have rights of access, correction, and withdrawal of consent. Complaints may be lodged with the Office of the Privacy Commissioner of Canada.
15.4 Brazil — LGPD
We comply with the Lei Geral de Proteção de Dados (LGPD). Brazilian residents have rights of access, correction, anonymisation, portability, elimination, and information about sharing. The Data Protection Authority is the ANPD.
15.5 South Africa — POPIA
We comply with the Protection of Personal Information Act (POPIA). South African residents may lodge complaints with the Information Regulator.
15.6 Australia — Privacy Act 1988 & APPs
We comply with the Australian Privacy Principles (APPs). Complaints may be lodged with the Office of the Australian Information Commissioner (OAIC).
15.7 New Zealand — Privacy Act 2020
We comply with the New Zealand Privacy Act 2020. Complaints may be lodged with the Office of the Privacy Commissioner.
15.8 Singapore — PDPA
We comply with the Personal Data Protection Act 2012 (PDPA). The PDPC administers the Act.
15.9 Hong Kong — PDPO
We comply with the Personal Data (Privacy) Ordinance (PDPO).
15.10 Japan — APPI
We comply with the Act on the Protection of Personal Information (APPI). The Personal Information Protection Commission (PPC) oversees compliance.
15.11 South Korea — PIPA
We comply with the Personal Information Protection Act (PIPA). The Personal Information Protection Commission oversees compliance.
15.12 India — DPDP Act 2023
We comply with the Digital Personal Data Protection Act 2023 (DPDP). The Data Protection Board of India handles complaints.
15.13 China — PIPL
Where applicable, we comply with the Personal Information Protection Law (PIPL) of the People's Republic of China. The Cyberspace Administration of China (CAC) oversees compliance.
15.14 Russia — Federal Law 152-FZ
Where applicable, we comply with the Federal Law on Personal Data (No. 152-FZ). Personal data of Russian citizens is processed and stored on servers within the Russian Federation where required by law.
15.15 Switzerland — FADP
We comply with the revised Federal Act on Data Protection (FADP). The Federal Data Protection and Information Commissioner (FDPIC) oversees compliance.
15.16 Other Jurisdictions
We extend GDPR-equivalent protections to all users regardless of jurisdiction, where commercially reasonable. For specific questions about your jurisdiction, contact contact@yilanfangtrade.com.
16. Children's Privacy (COPPA & Equivalents)
Our Services are not directed to children under 13 years of age (or higher where required by local law). We do not knowingly collect Personal Data from children.
16.1 United States — COPPA
We comply with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13. Our Apps that may be accessed by children are categorised accordingly in the App Store and Play Store. Where our Apps are likely to be accessed by children:
- We do not serve interest-based advertising.
- We do not include behavioural analytics that track individual users.
- We do not include social features that allow communication with other users.
- We do not permit in-app purchases without verifiable parental consent.
16.2 EU/UK — GDPR & Age-Appropriate Design Code
We treat users under 16 (or under 13 in some EU member states) as children requiring additional protection. We have implemented the following safeguards consistent with the ICO's Age-Appropriate Design Code (AADC):
- Best interests of the child as a primary consideration.
- Data protection impact assessments for services likely to be accessed by children.
- Default settings that prioritise privacy.
- No behavioural profiling of children.
- Clear, age-appropriate language in notices.
16.3 Other Jurisdictions
We respect age-of-consent thresholds in all jurisdictions where we operate, including Australia's Online Safety Act, India's DPDP Act (under 18), Korea's PIPA (under 14), and China's PIPL (under 14).
16.4 Parental Rights
If you believe we have collected information from a child in violation of this Policy, please contact us at contact@yilanfangtrade.com. We will promptly delete the information.
17. Age Restrictions by Country & App Store
17.1 Apple App Store Age Ratings
Our Apps are rated per Apple's age rating system. The minimum age to download and use our Apps from the App Store is determined by Apple's age-gating for your country (typically 13+ in most regions, 4+ for non-restricted Apps).
17.2 Google Play Store Age Restrictions
Our Apps on Google Play comply with the platform's age requirements. Some Apps may require users to be at least 13 (or higher in certain jurisdictions).
17.3 Age of Digital Consent by Country
| Country / Region | Age of Consent |
|---|---|
| United Kingdom | 13 |
| EU member states (most) | 16 (13-16 by member state) |
| United States (COPPA) | 13 |
| California, USA | 13 (or 16 for sharing data) |
| Canada (Quebec) | 14 |
| Canada (other provinces) | 13 |
| Australia | 15 (under new Online Privacy reforms) |
| Brazil | 13 |
| Japan | 18 (or under parental consent) |
| South Korea | 14 |
| Singapore | 13 |
| Hong Kong | 18 (for contractual capacity) |
| India | 18 |
| China | 14 |
| South Africa | 18 |
| New Zealand | 16 (under new Privacy Act reforms) |
| Russia | 18 |
If you are below the age of consent in your jurisdiction, you must have a parent or legal guardian's permission to use our Services or accept this Policy.
18. Do Not Track & Global Privacy Control
We honour the following signals from your browser or device:
- Do Not Track (DNT): The DNT browser header indicating your preference not to be tracked.
- Global Privacy Control (GPC): A technical specification enabling users to signal privacy preferences globally.
- Apple App Tracking Transparency: When you choose "Ask App Not to Track" on iOS.
- Android Advertising ID Opt-Out: When you opt-out of personalised ads on Android.
When these signals are received, we treat them as a valid opt-out of sale or sharing of Personal Data, and we will not serve personalised advertising. Where required by law (e.g., CCPA, Connecticut, Virginia, Colorado, Utah), we honour GPC as a universal opt-out mechanism.
19. Changes to This Privacy Policy
We may update this Policy from time to time. The "Last Updated" date at the top of this Policy reflects when the most recent changes took effect. Material changes will be notified through:
- A prominent notice on our website.
- An in-app notification (for our Apps).
- An email to subscribers (for material changes affecting newsletter subscribers).
Your continued use of our Services after changes take effect constitutes acceptance of the revised Policy. If you do not agree to the changes, you may stop using our Services and request deletion of your data.
20. Contact Us & Data Protection Officer
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact us:
yilanfangtrade.com
Bristol & Bath Science Park
Dirac Crescent, Emersons Green
Bristol BS16 7FR, United Kingdom
Email (Privacy): contact@yilanfangtrade.com
Email (Support): support@yilanfangtrade.com
Data Protection Officer: Available via the privacy email above.
We aim to respond to all privacy inquiries within 30 days. If your inquiry is urgent, please indicate this in the subject line.
21. UK GDPR Specific Notice (Supplementary)
This section supplements the main Policy for users in the United Kingdom under the UK GDPR and the Data Protection Act 2018:
- UK GDPR Representative: Our company is established in the UK; we act as both Controller and main point of contact.
- International Transfers: Where Personal Data is transferred outside the UK, we use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, supplemented by transfer impact assessments where required.
- ICO Registration: We are registered with the Information Commissioner's Office. Registration details are available on request.
- Right of Complaint to ICO: You have the right to lodge a complaint with the ICO at ico.org.uk/make-a-complaint.
- Age-Appropriate Design Code: For services likely to be accessed by children, we comply with the ICO's AADC.
22. EEA GDPR Specific Notice (Supplementary)
This section supplements the main Policy for users in the European Economic Area under the GDPR (Regulation (EU) 2016/679):
- Article 27 Representative: For users in the EEA, our company acts as Controller; for any processing where a representative is required, contact us at contact@yilanfangtrade.com.
- Cross-Border Processing: Some of our service providers are based in the United States. Transfers are protected by Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented by technical and organisational measures.
- EDPB Complaints: You may complain to your national Data Protection Authority, listed at edpb.europa.eu.
- ePrivacy Directive: Where cookies or similar tracking technologies are used, we comply with the ePrivacy Directive (2002/58/EC) as transposed in EU member state law.
Document Version: 3.2 · Effective: 15 March 2026
© yilanfangtrade.com. This Privacy Policy is governed by the laws of England and Wales.