Privacy Policy

Last updated: 6th November 2025

This Privacy Policy explains how GOLDEN SUPREME WAY LIMITED (“GSW”, “we”, “our”, “us”) collects, uses, shares, and protects your personal data when you visit goldsupremeway.com (the “Site”) or contact us. We operate under Hong Kong’s Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO”) and the Data Protection Principles (DPP1–DPP6).

If you do not agree with this Policy, please do not use the Site.


1) Who we are (Data User)

GOLDEN SUPREME WAY LIMITED
Registered address:

Tai Yau Building, No. 181 Johnston Rd, Wanchai, Hong Kong
 

We are the data user (PDPO terminology) responsible for your personal data collected via the Site and our contact channels.


2) What data we collect

2.1 Data you provide

  • Contact/RFQ data: name, job title, company, email, phone/WhatsApp, country, product interests, specifications, quantities, delivery windows, and any message or files you attach.

  • Business correspondence: emails, meeting notes, contracts, purchase orders, invoices.

  • Careers: CV/resume, cover letters, qualifications (if you apply for a job).

2.2 Data we collect automatically

  • Device & usage: IP address, browser type/version, pages viewed, time on page, referring/exit pages, timestamps, and approximate location (derived from IP).

  • Cookies & similar tech: see Section 7 (Cookies).

2.3 Optional/third-party data

  • Vendor/supplier details you share about a third party (e.g., contact person).

  • Public data from corporate registries, trade directories, or sanctions lists for due diligence.

Note: Please do not submit sensitive data (e.g., health, biometric, racial, religious, union membership) via public forms.


3) Why we collect your data (Purpose & Use) — DPP1, DPP3

We collect and use personal data for the following purposes:

  • RFQ & sales: to respond to inquiries, prepare quotations, qualify specifications, and manage orders.

  • Supplier management: onboarding, due diligence, performance monitoring.

  • Logistics & compliance: shipping, customs, export controls/sanctions screening, certificates (COA/COC/MSDS), quality assurance.

  • Account & support: after-sales service, troubleshooting, and incident handling.

  • Operations & security: fraud prevention, system monitoring, and security logs.

  • Site improvement & analytics: to understand traffic and improve content.

  • Legal & regulatory: to comply with applicable laws, respond to lawful requests, enforce terms.

  • Careers: evaluate and manage applications.

We will not use your data for new purposes incompatible with the above without obtaining your prescribed consent where required by PDPO.


4) Our basis for handling data

While PDPO does not require “legal bases” like GDPR, we handle data in line with PDPO principles and (where relevant) on grounds such as your request (RFQ/contract), our operational needs, and compliance with laws. Where consent is needed (e.g., certain cookies or marketing), we will request it.


5) Who we share data with — DPP3

We may share your data with:

  • Logistics & customs partners (freight forwarders, carriers, customs brokers) for shipping and import/export.

  • Verification & compliance tools (sanctions/export-control screeners, KYC providers) when appropriate.

  • Professional services (IT support, hosting, security, analytics providers; auditors; legal counsel).

  • Manufacturers/suppliers strictly for fulfilling your RFQ/specifications.

  • Authorities where required by law or to exercise/defend legal claims.

We do not sell personal data.


6) International transfers — DPP3, DPP4

Your data may be processed in Hong Kong and other locations (e.g., EMEA, APAC, Americas) where our partners operate. We take reasonable steps to ensure recipients handle data with standards comparable to Hong Kong’s PDPO (contractual safeguards, need-to-know access, confidentiality).


7) Cookies & analytics — DPP1, DPP5

We use cookies and similar technologies to run the Site and understand usage. On your first visit, you will see a cookie banner with the option to accept or manage preferences.

Categories we use:

  • Strictly necessary (always on): security, load balancing, consent status.

  • Functional (optional): remember form inputs, region/language.

  • Analytics (optional): aggregate traffic stats (e.g., pages viewed, time on site).

  • Marketing (optional, if enabled): track campaign performance; we avoid invasive profiling.

Managing cookies: Use the “Cookie Settings” link in the footer or adjust your browser settings. Blocking some cookies may affect Site functionality.

(Optional cookie table example—replace as applicable)

Cookie Type Purpose Duration
consent_status Necessary Stores your cookie choices 6–12 months
_ga / analytics_id Analytics Traffic insights 13 months
wp_* / elementor_* Functional Layout/performance Session–12 months

8) Data retention — DPP2

We keep data only for as long as necessary for the purposes in Section 3, and then securely delete or anonymize it.

Typical retention (guidance; update to your practice):

  • RFQs & correspondence: 2–5 years after last activity.

  • Contracts, invoices, shipping docs: 7 years (accounting/legal).

  • Supplier onboarding/KYC: 5–7 years post relationship end.

  • Careers (unsuccessful): 12 months unless you consent to longer.

  • Security logs: 6–24 months.


9) Your rights — DPP6

Under PDPO, you have the right to:

  • Request access to your personal data we hold (Data Access Request).

  • Request correction of inaccurate data (Data Correction Request).

To make a request, email privacy@goldsupremeway.com with subject “Data Access Request” or “Data Correction Request” and include: your full name, contact details, and details of the data requested. We may require reasonable verification of identity and may charge a reasonable fee for handling a Data Access Request in line with PDPO.

(If you are located in the EEA/UK, you may also have GDPR rights such as deletion/restriction/objection; contact us and we will accommodate where applicable.)


10) Security — DPP4

We implement reasonable technical and organizational measures to protect personal data, including: encrypted transport (HTTPS), access controls based on job role, least-privilege principles, security monitoring, and supplier confidentiality obligations. No method is 100% secure; please use caution when sending information over the internet.


11) Children

This Site is intended for business and professional use. We do not knowingly collect personal data from children.


12) Third-party links

The Site may link to third-party websites or tools. We do not control and are not responsible for their privacy practices. Please review their policies before using those sites.


13) Changes to this Policy — DPP5

We may update this Policy to reflect changes in our practices or the law. We will post the updated version on this page with a new “Last updated” date. Material changes may also be highlighted on the Site.


14) How to contact us

Questions or requests about this Policy or your data?

Email: info@goldsupremeway.com
Post: Privacy Officer, GOLDEN SUPREME WAY LIMITED, Tai Yau Building, No. 181 Johnston Rd, Wanchai, Hong Kong

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD): https://www.pcpd.org.hk/