1. General principles and scope
- This statement applies to all information clients provide to the Company through www.crisscrossmetals.com, email, telephone, instant messaging and similar channels.
-
“Client information” includes:
- basic corporate information about the client;
- personal information of the client's contacts;
- transaction data such as enquiries, quotations, orders, contracts, logistics and payments;
- records of communications between the parties and other business-related information.
- The Company collects and uses client information only for lawful purposes such as business communication, quotation, order processing, production scheduling, logistics and delivery, after-sales service, reconciliation and settlement, and compliance review.
2. Network information security
- Encrypted transmission When clients submit information through this website we use encryption protocols such as HTTPS/TLS, reducing the risk of interception or tampering in transit.
- Encrypted storage Sensitive personal information and transaction data are encrypted or de-identified when stored. Sensitive fields such as passwords and payment details are not held in plain text.
- Access control We apply the principle of least privilege: only personnel who need client information for their role may access it, and we manage the permissions of the accounts concerned.
- Security controls We run baseline protections such as a firewall at the server and website level, and carry out security checks and system updates as circumstances require.
- Backup and recovery We back up client information to reduce the risk of data loss from system failure, operator error and similar causes.
- Security incident response In the event of an information security incident we will activate our response plan immediately, take remedial action, and notify affected clients and regulators promptly as required by applicable law.
3. Personal privacy protection
-
What we collect
We may collect the following personal information:
- name, company name and job title;
- telephone number, email address, country/region and address;
- enquiry content, product requirements and messages;
- technical information such as website logs, IP address and cookies.
-
Purposes of use
We collect personal information mainly in order to:
- respond to enquiries and provide quotations;
- conclude and perform contracts;
- arrange production, logistics and after-sales service;
- verify client identity and carry out credit and compliance checks;
- improve the website experience and client service.
- Limits on use We will not use client personal information for marketing unrelated to the purposes above without the client's prior consent. Where marketing messages are sent, we will provide an opt-out or unsubscribe mechanism.
-
Limits on sharing with third parties
We do not sell, lease, exchange or unlawfully disclose client personal information to unrelated third parties. We share it only where:
- the client has given explicit consent;
- required by law, regulation, a judicial authority or a regulator;
- it is necessary to perform the contract, in which case it is shared with payment institutions, logistics providers, IT service providers, auditors and similar parties, who are required to accept equivalent confidentiality obligations.
- Cookies and website technical information We may use cookies and similar technologies to improve site functionality, compile visit statistics and maintain site security. Clients can refuse cookies through their browser settings, though some site functions may then be affected.
- Your rights Clients and their contacts have the right under applicable law to request access to, correction or deletion of, or restriction of the processing of their personal information, or to withdraw consent. We will respond within a reasonable period. Contact details are in section 9.
4. Disclosure of transaction data
- What counts as transaction data Transaction data includes, without limitation, order details, product specifications, quantities, prices, payment terms, delivery information, invoices, customs documents and related commercial correspondence.
- General duty of confidentiality All transaction data is treated as confidential. The Company will not disclose specific transaction data to any third party without the client's written consent.
-
Permitted exceptions
The Company may disclose transaction data, to the extent necessary, where:
- the client has given written consent;
- disclosure is required by law, regulation, a judicial or administrative authority, or a regulator;
- disclosure is necessary to perform the contract, to service providers such as banks, payment institutions, logistics and customs agents, auditors and legal advisers, subject to confidentiality terms or equivalent obligations;
- it is necessary to prevent fraud, safeguard transaction security, or protect the lawful rights and interests of the Company or the client.
- Disclosure principles Where disclosure is unavoidable we follow the principle of the least, necessary and narrowest scope, and will endeavour to notify the client in advance unless notification is prohibited by law.
- Anonymised data Data that has been anonymised so that no particular client can be identified may be used for business analysis, industry statistics and internal research, and is not treated as disclosure of client information.
5. Company information disclosure
- Client information is a trade secret The Company treats client lists, client contact details, pricing strategy, trading terms and product parameters as trade secrets and does not make them public.
- Information the Company provides To conclude and perform contracts the Company may provide clients with necessary company information such as its business licence, bank account details, quality certificates and product certifications. Clients should use such information only for the purpose of that transaction and must not publish it or use it for other purposes without authorisation.
-
External disclosure involving client information
Where client information must be disclosed for reasons such as listing, audit, financing, litigation or a government investigation, the Company will:
- disclose only the minimum information required by law or the regulator;
- require the recipient to accept confidentiality obligations;
- notify the client in advance where the law permits.
- Separate confidentiality agreements Clients requiring a higher standard of confidentiality for the Company's information or the parties' transaction information may enter into a separate non-disclosure agreement (NDA) with the Company.
6. Retention and destruction
- Client information is retained for the duration of the business relationship and for the minimum period required by laws and regulations.
- Once the retention period has passed we delete or anonymise client information; paper records are destroyed securely.
- Where a client requests deletion of personal information and no statutory retention obligation applies, we will delete it or cease using it in accordance with the law.
7. Third-party links
This website may contain links to third-party sites. The privacy and information security policies of those sites are not governed by this statement. We recommend clients read the relevant statements before visiting them.
8. Updates to this statement
The Company may update this statement in response to changes in the law, business adjustments or security needs. Updated versions will be published on this website and, where necessary, notified to clients by email or on-site notice.
9. Contact
If you have questions about this statement, or wish to exercise rights relating to personal information, you can reach us at:
- Email otto@crisscrossmetals.com
- Company Chengdu Kuangye Zongheng Mining Technology Consulting Co., Ltd., China
10. Governing law and disclaimer
- This statement, and any dispute arising from the protection of client information, is governed by the laws of the People's Republic of China.
- The Company has adopted reasonable, industry-standard security measures to protect client information; however, given the open nature of the internet, we cannot guarantee absolute security in transmission and storage.
- The Company is not liable for breach or damages where information is disclosed through no fault of its own — for example due to force majeure, government action, telecommunications carrier failure, malicious third-party attack, or causes attributable to the client. The Company will nevertheless make reasonable efforts to remediate and will discharge its notification duties under the law.
The Chinese version of this statement prevails. Versions in other languages are provided for reference only; in case of any discrepancy, the Chinese version governs.