BrightSeek

Privacy Policy

Effective Date: August 3, 2025 | Last Updated: August 3, 2025

1. Introduction

BrightSeek, developed and operated by Kunming DaSuoHao Trading Co., Ltd., located at Attach 1-PL, No. 228 Renmin East Road, Tuodong Street, Panlong District, Kunming, Yunnan 650000, China, is committed to protecting the privacy and personal data of all individuals who interact with our website, https://www.brightseek.hair, and our professional services. This Privacy Policy explains in clear and comprehensive terms how we collect, use, store, share, and safeguard your information when you engage with BrightSeek for computer systems design and related services.

Your trust is foundational to our practice. We design and operate our information handling practices with the same precision and care that we apply to our systems architecture engagements. This policy describes the full lifecycle of data within our environment and the rights you hold over your personal information under applicable data protection laws, including but not limited to the Personal Information Protection Law of the Peoples Republic of China, the General Data Protection Regulation of the European Union, and other relevant statutes.

By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any portion of this document, please discontinue use of our website and services and contact us with any concerns at serve@brightseek.hair.

BrightSeek provides computer systems design, network infrastructure architecture, cloud computing strategy, database engineering, cybersecurity consulting, and technical advisory services. The nature of these services requires us to process certain categories of information, including technical specifications, system configurations, business requirements, and limited personal data necessary for client communication and project delivery. We treat all such information with strict confidentiality and apply industry-standard protections at every stage of processing.

2. Information We Collect

We collect information that you voluntarily provide to us when you interact with our website, submit inquiries, engage our services, or communicate with our team. We also collect certain information automatically through standard web technologies as you navigate our digital properties. The categories of information we may collect are detailed below.

Contact and Identity Information: When you submit a contact form, request a consultation, or initiate a project engagement, we may collect your full name, email address, phone number, company name, job title, and physical address. This information enables us to respond to your inquiries, prepare proposals, and manage ongoing client relationships.

Professional and Technical Information: In the course of providing systems design and consulting services, we may receive technical documentation, system architecture diagrams, network topology maps, infrastructure specifications, database schemas, code repositories, and other materials that describe your technical environment. While much of this information is not personal in nature, it may contain or be linked to identifiers that constitute personal data under applicable law.

Communication Records: We retain copies of email correspondence, meeting notes, project briefs, and other communications exchanged between you and our engineering and advisory teams. These records support project continuity, quality assurance, and our ability to deliver consistent service across engagements.

Website Usage Data: When you visit our website, our servers automatically log certain technical information including your IP address, browser type and version, operating system, referring URL, pages visited, time spent on each page, and the date and time of your visit. This data is collected through server logs and does not, by itself, identify individual visitors.

Device and Browser Information: We may collect information about the device you use to access our website, including device type, screen resolution, language settings, and time zone. This information helps us optimize the presentation and performance of our digital content.

Payment and Billing Information: For clients who engage our paid services, we collect billing contact details and transaction records. We do not directly store credit card numbers or full financial account details. Payment processing is handled through secure third-party payment processors that comply with PCI DSS standards.

3. How We Collect Information

We employ multiple collection methods, each designed to be transparent and proportionate to the purpose for which the information is gathered. Our collection practices are structured to minimize data collection to what is strictly necessary for service delivery and legitimate business operations.

Direct Collection from You: The primary source of personal data is information you provide directly. This occurs when you complete a contact form on our website, send an email to any BrightSeek address, participate in a discovery call or project meeting, submit technical documentation for review, or enter into a service agreement with us. In each case, you control the scope and content of the information you share, and we provide clear notice at the point of collection regarding how the information will be used.

Automated Collection Through Website Technology: Our website uses server-side logging and standard web analytics to collect usage data automatically. This collection occurs without any active input from you and begins when your browser establishes a connection to our servers. We do not use fingerprinting techniques, behavioral tracking across third-party sites, or other invasive collection technologies. The automated data we collect is limited to the standard HTTP request headers and server log fields.

Collection from Third-Party Sources: In limited circumstances, we may receive information about you from third-party sources. This may include information from publicly available professional directories, technology partner referrals, or event registration platforms where you have consented to information sharing. When we receive data from third parties, we verify that the source has appropriate legal authority to share the information and that the sharing complies with applicable data protection requirements.

Collection Through Client Engagements: During the delivery of professional services, our engineering teams may access, review, and document information about your technical systems. This access is governed by the terms of our service agreements and confidentiality provisions. Information collected in this context is used solely for the purpose of delivering the contracted services and is not repurposed for any other use without your explicit consent.

4. How We Use Your Information

BrightSeek uses collected information for clearly defined purposes that align with our service offerings and legitimate business interests. We do not sell, rent, or trade personal information to any third party for their own marketing purposes. Every use of personal data is assessed against the principles of data minimization, purpose limitation, and storage limitation.

Service Delivery and Client Support: We use contact information and technical documentation to deliver the computer systems design, consulting, and advisory services you have requested. This includes preparing proposals, conducting architecture reviews, producing design documents, managing project workflows, and providing ongoing technical support throughout the engagement lifecycle.

Communication and Inquiry Response: When you contact us through our website or by email, we use the information you provide to respond to your inquiry, schedule consultations, send requested information about our services, and maintain a record of our correspondence for quality and continuity purposes.

Website Operation and Improvement: We analyze aggregated website usage data to understand how visitors interact with our content, identify technical issues, measure the performance of our digital properties, and make informed decisions about content and feature improvements. This analysis is performed on anonymized or pseudonymized data wherever feasible.

Legal Compliance and Protection: We may use and disclose information as necessary to comply with applicable laws, regulations, legal processes, or governmental requests. We also reserve the right to use information to protect the rights, property, and safety of BrightSeek, our clients, and the public, including for fraud prevention and information security purposes.

Business Operations: We use billing and transactional information for invoicing, payment processing, financial reporting, and tax compliance. We also use aggregated and anonymized engagement data for internal business analysis, capacity planning, and service development.

Under applicable data protection laws, including the Personal Information Protection Law of China and the GDPR, we rely on specific legal bases for processing personal data. The applicable basis depends on the nature of the data, the purpose of processing, and your relationship with BrightSeek.

Contractual Necessity: When you engage our services, we process personal data as necessary to perform our contractual obligations to you. This includes processing contact information for project communication, technical data for service delivery, and billing information for payment processing. Without this processing, we would be unable to fulfill our service commitments.

Consent: For certain processing activities, we rely on your explicit and informed consent. This includes sending marketing communications, using non-essential cookies, and processing data beyond what is strictly necessary for service delivery. You may withdraw consent at any time by contacting us at serve@brightseek.hair. Withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal.

Legitimate Interests: We process certain personal data based on our legitimate business interests, provided that such interests are not overridden by your fundamental rights and freedoms. Legitimate interests include improving our website and services, ensuring network and information security, preventing fraud, and conducting business analytics. We conduct a balancing test for each processing activity that relies on this basis.

Legal Obligation: We process personal data as required to comply with applicable legal obligations, including tax laws, financial reporting requirements, regulatory mandates, and responses to lawful requests from public authorities.

6. Data Storage and Retention

BrightSeek stores personal data on secure servers located in controlled-access data center facilities. We implement layered physical, technical, and administrative controls to protect stored data against unauthorized access, alteration, disclosure, or destruction.

Storage Location: Our primary data storage infrastructure is located within the Peoples Republic of China. For certain technical operations, including content delivery and availability, data may be cached or mirrored in geographically distributed locations. In all cases, we ensure that data storage locations comply with applicable data residency requirements and that appropriate safeguards are in place for cross-border data transfers.

Retention Periods: We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable law. The specific retention period depends on the category of data and the purpose of processing. Contact and inquiry data is typically retained for 24 months from the date of last interaction. Client engagement records, including project documentation and correspondence, are retained for the duration of the client relationship plus 5 years to support warranty obligations, legal defense, and regulatory compliance. Website usage logs are retained for 12 months and then permanently deleted or fully anonymized.

Data Deletion: When personal data reaches the end of its retention period, or when you request deletion, we securely erase the data from our active systems and backups through a documented deletion process. We use industry-standard data sanitization techniques to ensure that deleted data cannot be recovered. Backup media is cycled on a schedule that ensures deleted data is purged from all backup copies within 90 days.

7. Data Sharing and Disclosure

BrightSeek limits the sharing and disclosure of personal data to circumstances that are necessary for service delivery, required by law, or authorized by you. We maintain a strict data sharing governance framework that requires review and approval for any disclosure of personal data outside of BrightSeek.

Service Providers and Sub-processors: We engage carefully selected third-party service providers to support our operations. These providers may include cloud hosting services, email delivery platforms, payment processors, and analytics tools. Each service provider is bound by contractual data processing agreements that require them to process personal data only on our documented instructions, implement appropriate security measures, and comply with applicable data protection laws. A current list of sub-processors is available upon request.

Legal and Regulatory Disclosures: We may disclose personal data in response to valid legal process, including subpoenas, court orders, search warrants, or regulatory demands. We evaluate each request carefully and disclose only the minimum information necessary to comply. Where legally permissible, we provide notice to affected individuals before making any such disclosure.

Business Transfers: In the event of a merger, acquisition, restructuring, or sale of all or a portion of our assets, personal data may be transferred as part of the transaction. We will notify affected individuals and provide choices regarding their data before any such transfer occurs and before personal data becomes subject to a different privacy policy.

With Your Consent: We may share personal data with third parties for purposes not described in this policy when we have obtained your explicit consent to do so. You retain the right to withdraw consent for any such sharing at any time.

Aggregated and De-identified Data: We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify any individual. Such data may be used for industry research, published case studies with client permission, or technical publications.

8. International Data Transfers

BrightSeek operates globally and may transfer personal data across national borders as necessary to deliver our services and manage our operations. We take specific measures to ensure that international data transfers comply with applicable legal requirements and that your data receives an equivalent level of protection regardless of where it is processed.

When we transfer personal data from the European Economic Area, the United Kingdom, or other jurisdictions with data transfer restrictions, we implement appropriate safeguards. These safeguards may include Standard Contractual Clauses approved by the European Commission, adequacy decisions where applicable, binding corporate rules, or other legally recognized transfer mechanisms. We assess the laws and practices of the destination country to ensure that the transfer does not undermine the effectiveness of the safeguards we have put in place.

For transfers of personal data originating from the Peoples Republic of China, we comply with the cross-border data transfer requirements under the Personal Information Protection Law, including conducting security assessments, obtaining required certifications, and entering into standard contractual terms where applicable. We also implement supplementary technical measures such as encryption and pseudonymization to protect data during cross-border transit.

9. Data Security Measures

Security is at the core of our professional practice, and we apply the same rigorous standards to protecting personal data that we recommend to our clients for their critical systems. Our security program is built on a defense-in-depth model that layers multiple controls to protect against a broad spectrum of threats.

Technical Controls: We employ encryption in transit using TLS 1.3 for all web traffic and API communications. Data at rest is encrypted using AES-256 encryption. Our network is segmented with firewalls, intrusion detection and prevention systems, and continuous monitoring. Access to production systems requires multi-factor authentication and is logged and audited. We conduct regular vulnerability assessments and penetration testing to identify and remediate potential weaknesses.

Administrative Controls: Access to personal data is granted on a need-to-know basis and is reviewed quarterly. All personnel with access to personal data receive mandatory privacy and security training. We maintain a documented incident response plan that is tested annually through tabletop exercises and simulations. Background checks are conducted on all personnel prior to granting access to systems containing personal data.

Physical Controls: Our data center facilities employ 24/7 security personnel, biometric access controls, video surveillance, and environmental monitoring. Physical access is restricted to authorized personnel and is logged through electronic access control systems.

Incident Response: In the event of a data breach involving personal data, we will notify affected individuals and relevant regulatory authorities within the timeframes required by applicable law. Our notification will describe the nature of the breach, the categories of data affected, the measures we have taken to address the breach, and the steps affected individuals can take to protect themselves.

10. Your Rights and Choices

Under applicable data protection laws, you hold a set of rights concerning your personal data. BrightSeek respects and facilitates the exercise of these rights. To submit a request, please contact us at serve@brightseek.hair. We will respond to verified requests within the timeframes prescribed by law, typically within 30 days.

Right of Access: You have the right to request confirmation of whether we process your personal data and, if so, to obtain a copy of the personal data we hold about you, along with information about how and why we process it.

Right of Rectification: If the personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it. We will make the necessary corrections without undue delay.

Right of Erasure: You may request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when the data has been unlawfully processed. This right is subject to legal obligations that may require us to retain certain data.

Right to Restrict Processing: You may request that we limit the processing of your personal data in specific situations, including while we verify the accuracy of contested data or while we assess a objection to processing based on legitimate interests.

Right to Data Portability: Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to have that data transmitted directly to another controller where technically feasible.

Right to Object: You may object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before the withdrawal.

Right to Complain: You have the right to lodge a complaint with the relevant data protection supervisory authority if you believe that our processing of your personal data violates applicable law. We encourage you to contact us first so that we can address your concerns directly.

11. Cookies and Tracking Technologies

BrightSeek uses a minimal set of cookies and similar technologies to ensure the proper functioning of our website and to understand aggregate usage patterns. We do not deploy tracking cookies for behavioral advertising, profiling, or cross-site tracking purposes.

Essential Cookies: These cookies are necessary for the website to function properly. They enable core functionality such as page navigation, security features, and access to secure areas. The website cannot function properly without these cookies, and they do not require consent under most data protection frameworks. Essential cookies do not store any personally identifiable information.

Analytics Cookies: We use privacy-focused analytics tools that collect aggregated and anonymized data about how visitors interact with our website. These tools do not use cookies that track individuals across sessions or across different websites. The data collected includes page view counts, referral sources, broad geographic regions derived from anonymized IP addresses, and device categories. No individual browsing behavior is tracked or profiled.

Managing Cookies: Most web browsers allow you to control cookies through their settings. You can configure your browser to block all cookies, delete existing cookies, or alert you when cookies are being set. Please note that blocking essential cookies may impact the functionality and performance of our website. For detailed instructions on managing cookies, consult your browsers help documentation.

Do Not Track Signals: Our website honors Do Not Track signals sent by your browser. When we detect a DNT signal, we disable any non-essential data collection and limit our logging to the minimum necessary for security and operational purposes.

12. Third-Party Services

Our website and services may include links to third-party websites, plugins, or embedded content. This Privacy Policy applies solely to information collected by BrightSeek. We do not control and are not responsible for the privacy practices of third-party services.

When you follow a link to a third-party website or interact with third-party content embedded on our pages, that third party may collect information about you. We encourage you to review the privacy policies of any third-party services before providing them with your personal information. BrightSeek does not endorse, screen, or approve the privacy practices of any linked third-party services.

Our service delivery may involve recommending or integrating third-party software, platforms, or infrastructure components. In such cases, the third-party providers privacy practices apply to their respective products. BrightSeek is not responsible for the data handling practices of third-party products we recommend or implement on behalf of clients.

13. Childrens Privacy

BrightSeeks website and services are directed at business professionals, organizations, and adults seeking computer systems design and related technical services. We do not knowingly collect, use, or disclose personal information from children under the age of 16. If we become aware that we have inadvertently collected personal data from a child under the age of 16 without verifiable parental consent, we will take immediate steps to delete that information from our systems.

If you are a parent or guardian and believe that your child has provided personal information to us, please contact us immediately at serve@brightseek.hair. We will investigate the matter and, if confirmed, remove the information from our records without undue delay.

14. Changes to This Privacy Policy

BrightSeek reserves the right to update or modify this Privacy Policy at any time to reflect changes in our practices, legal obligations, or service offerings. When we make material changes, we will post the updated policy on this page and update the Effective Date at the top of the document.

For material changes that significantly affect how we process your personal data, we will provide additional notice. This notice may take the form of a prominent banner on our website, an email notification to clients and contacts, or other appropriate communication channels. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

Your continued use of our website and services after the effective date of any revised Privacy Policy constitutes your acknowledgment and acceptance of the updated terms. If you do not agree with the revised policy, you should discontinue use of our website and services and contact us regarding the disposition of your data.

15. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact us through any of the following channels:

Email: serve@brightseek.hair
Phone: +13858553942
Postal Address: Kunming DaSuoHao Trading Co., Ltd., Attach 1-PL, No. 228 Renmin East Road, Tuodong Street, Panlong District, Kunming, Yunnan 650000, China
Website: https://www.brightseek.hair

We are committed to addressing all privacy inquiries promptly and thoroughly. Please allow up to 5 business days for an initial response. For complex requests requiring detailed investigation, we will provide a timeline for resolution within that initial response period.

If you are located in the European Economic Area or the United Kingdom and have an unresolved privacy concern, you may contact your local data protection authority. If you are located in the Peoples Republic of China, you may contact the Cyberspace Administration of China or other relevant regulatory body.

This Privacy Policy was last reviewed and updated on August 3, 2025. It supersedes all prior versions and is the sole governing document for BrightSeeks data privacy practices.