Effective Date: Oct 2, 2024
Last Updated: May 3, 2026
This Privacy Policy explains how RPD (“we,” “us,” “our”) collects, uses, stores, transfers, and protects information when you visit https://www.rpdmfg.com, submit a Request for Quotation (RFQ), upload technical files (including CAD/CAM files, drawings, and specifications), or otherwise engage with us as a business customer.
We provide custom manufacturing services (CNC machining, sheet metal fabrication, injection molding, and related processes) to business clients worldwide. This Policy is designed to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and China’s Personal Information Protection Law (PIPL).
1. Data Controller and Contact
Controller: Shenzhen RPD Industrial Co., Ltd
Email: engineer@rpdmfg.com
ADD: Jiayu Building, Songgang Sub-district, Bao’an District, 518105, Shenzhen, China
EU Representative (GDPR Art. 27): Ashely
China Representative (PIPL Art. 53): Ashely
For all privacy requests, contact us at the email above.
2.Data We Collect
Category Examples Source
Identity & contact Name, company, job title, business email, phone, country You (RFQ form, account registration, email)
Project & technical CAD/CAM files (STEP, IGES, STL, DWG, DXF, PDF), drawings, tolerances, material specs, quantities, target prices You (file upload, email attachments)
Transaction Purchase orders, invoices, shipping addresses, payment references (no full card numbers stored) You, payment and logistics partners
Technical / log IP address, browser type, device identifiers, referring URL, pages viewed, timestamps Cookies and server logs
Communications Emails, chat messages, meeting notes, support tickets You
Marketing Newsletter subscription status, email open/click events You, our email platform
We do not knowingly collect sensitive personal information or data from individuals under 18.
3. How We Use Your Data and Legal Basis
Purpose GDPR basis PIPL basis CCPA category
Provide quotes, manufacture and ship orders Contract performance, Art. 6(1)(b) Contract necessity, Art. 13(1)(2) Business purpose
Project communication and support Contract / legitimate interest Contract necessity Business purpose
Tax, customs, export-control, accounting compliance Legal obligation, Art. 6(1)(c) Legal obligation Legal compliance
Protect IP, prevent fraud, secure systems Legitimate interest, Art. 6(1)(f) Legitimate interest Security
Send marketing emails Consent, Art. 6(1)(a) Separate consent, Art. 14 Commercial purpose
Analytics and website improvement Consent / legitimate interest Consent Business purpose
We do not sell or “share” personal information for cross-context behavioral advertising as defined under the CCPA/CPRA.
4. CAD Files and Intellectual Property
We understand that your CAD files and technical drawings are confidential and often contain trade secrets.
CAD files are uploaded over HTTPS/TLS and stored on access-controlled servers.
Access is limited to engineering, quoting, and production staff with a need to know, and to qualified manufacturing partners under written confidentiality obligations.
We do not reuse, publish, resell, or train AI models on your files.
We sign NDAs on request before files are uploaded.
Files are not transferred to any third party other than the manufacturing partner and logistics provider assigned to your order.
5. Data Retention
Data Retention period
RFQ files and quotes (no order placed) Up to 24 months, then deleted, unless you request earlier deletion
Order files, drawings, production records 7 years from order completion (tax, warranty, traceability)
Invoices and accounting records 7-10 years (statutory requirement in US, EU, and China)
Account data Until account closure plus 12 months
Marketing data Until you unsubscribe plus 12 months
Website logs 12 months
After the retention period, data is securely deleted or anonymized. You may request earlier deletion under Section
6. Who We Share Data With
We share data only with:
Manufacturing partners in China and other regions, bound by confidentiality and data protection agreements, to produce your order.
Logistics and customs providers (e.g., DHL, FedEx, UPS, freight forwarders) to ship goods and clear customs.
Payment processors (e.g., bank wire intermediaries, Stripe, PayPal) to receive payment.
IT and cloud service providers (hosting, email, CRM, backup) under data processing agreements.
Professional advisors (lawyers, auditors) under confidentiality.
Government authorities when legally required (tax, customs, export control, court order).
A list of current sub-processors is available on request.
7. International Data Transfers
Our operations involve cross-border transfers between China, the United States, and the European Union:
Website and CRM are hosted on servers located in US.
Manufacturing partners are located in mainland China.
Customer support and engineering staff operate from China and the US.
Safeguards we use:
EU/UK to China or US: Standard Contractual Clauses (SCCs) adopted by the European Commission, plus supplementary measures (encryption in transit and at rest, access controls).
China to US or EU: Standard Contract for Outbound Cross-Border Transfer of Personal Information issued by the CAC, and where required, separate consent and PIPL security assessment.
US (CCPA): Contractual data protection terms with all service providers and contractors.
A copy of the relevant transfer mechanism is available on request.
8. Your Rights
Subject to your jurisdiction, you have the right to:
Access the personal data we hold about you.
Correct inaccurate or incomplete data.
Delete your data (“right to erasure” / “right to deletion”).
Restrict or object to certain processing.
Portability – receive your data in a structured, machine-readable format.
Withdraw consent at any time, where processing is based on consent.
Opt out of marketing by clicking “unsubscribe” in any email.
Non-discrimination for exercising CCPA rights.
Lodge a complaint with your supervisory authority (e.g., your EU member-state DPA, the California Privacy Protection Agency, or the Cyberspace Administration of China).
To exercise any right, email engineer@rpdmfg.com. We respond within 30 days (GDPR), 45 days (CCPA), or 15 working days (PIPL). We may verify your identity before fulfilling the request.
9. Cookies We use:
Strictly necessary cookies – required for the site to function (no consent needed).
Analytics cookies – only with your consent, to measure traffic and improve content.
Functional cookies – to remember preferences.
We do not use advertising or cross-site tracking cookies. See our Cookie Policy for details and to manage preferences.
10. Security
We apply industry-standard technical and organizational measures, including TLS encryption in transit, encryption at rest for CAD files, role-based access control, multi-factor authentication for staff, network monitoring, and regular backups. No system is 100% secure; in the event of a personal-data breach affecting your rights, we will notify you and the relevant authority within the timeframes required by law (72 hours under GDPR).
11. Update Policy
We may update this Policy from time to time. Material changes will be posted on this page with a new “Last Updated” date and, where required, communicated by email.
12. Contact
Privacy questions, requests, or complaints:
Shenzhen RPD Industrial Co., Ltd
ADD: Jiayu Building, Songgang Sub-district, Bao’an District, 518105, Shenzhen, China
Email: engineer@rpdmfg.com
