Privacy Policy

Effective Date: Oct 2, 2024
Last Updated: May 3, 2026

This Privacy Policy explains how RPD (“we,” “us,” “our”) collects, uses, stores, transfers, and protects information when you visit https://www.rpdmfg.com, submit a Request for Quotation (RFQ), upload technical files (including CAD/CAM files, drawings, and specifications), or otherwise engage with us as a business customer.

We provide custom manufacturing services (CNC machining, sheet metal fabrication, injection molding, and related processes) to business clients worldwide. This Policy is designed to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and China’s Personal Information Protection Law (PIPL).

1. Data Controller and Contact

Controller: Shenzhen RPD Industrial Co., Ltd
Email: engineer@rpdmfg.com
ADD: Jiayu Building, Songgang Sub-district, Bao’an District, 518105, Shenzhen, China
EU Representative (GDPR Art. 27): Ashely
China Representative (PIPL Art. 53): Ashely

For all privacy requests, contact us at the email above.

2.Data We Collect

Category Examples Source

Identity & contact Name, company, job title, business email, phone, country You (RFQ form, account registration, email)

Project & technical CAD/CAM files (STEP, IGES, STL, DWG, DXF, PDF), drawings, tolerances, material specs, quantities, target prices You (file upload, email attachments)

Transaction Purchase orders, invoices, shipping addresses, payment references (no full card numbers stored) You, payment and logistics partners

Technical / log IP address, browser type, device identifiers, referring URL, pages viewed, timestamps Cookies and server logs

Communications Emails, chat messages, meeting notes, support tickets You

Marketing Newsletter subscription status, email open/click events You, our email platform

We do not knowingly collect sensitive personal information or data from individuals under 18.

3. How We Use Your Data and Legal Basis

Purpose GDPR basis PIPL basis CCPA category

Provide quotes, manufacture and ship orders Contract performance, Art. 6(1)(b) Contract necessity, Art. 13(1)(2) Business purpose

Project communication and support Contract / legitimate interest Contract necessity Business purpose

Tax, customs, export-control, accounting compliance Legal obligation, Art. 6(1)(c) Legal obligation Legal compliance

Protect IP, prevent fraud, secure systems Legitimate interest, Art. 6(1)(f) Legitimate interest Security

Send marketing emails Consent, Art. 6(1)(a) Separate consent, Art. 14 Commercial purpose

Analytics and website improvement Consent / legitimate interest Consent Business purpose

We do not sell or “share” personal information for cross-context behavioral advertising as defined under the CCPA/CPRA.

4. CAD Files and Intellectual Property

We understand that your CAD files and technical drawings are confidential and often contain trade secrets.

CAD files are uploaded over HTTPS/TLS and stored on access-controlled servers.
Access is limited to engineering, quoting, and production staff with a need to know, and to qualified manufacturing partners under written confidentiality obligations.
We do not reuse, publish, resell, or train AI models on your files.
We sign NDAs on request before files are uploaded.
Files are not transferred to any third party other than the manufacturing partner and logistics provider assigned to your order.

5. Data Retention

Data Retention period

RFQ files and quotes (no order placed) Up to 24 months, then deleted, unless you request earlier deletion

Order files, drawings, production records 7 years from order completion (tax, warranty, traceability)

Invoices and accounting records 7-10 years (statutory requirement in US, EU, and China)

Account data Until account closure plus 12 months

Marketing data Until you unsubscribe plus 12 months

Website logs 12 months

After the retention period, data is securely deleted or anonymized. You may request earlier deletion under Section 

6. Who We Share Data With

We share data only with:

Manufacturing partners in China and other regions, bound by confidentiality and data protection agreements, to produce your order.
Logistics and customs providers (e.g., DHL, FedEx, UPS, freight forwarders) to ship goods and clear customs.
Payment processors (e.g., bank wire intermediaries, Stripe, PayPal) to receive payment.
IT and cloud service providers (hosting, email, CRM, backup) under data processing agreements.
Professional advisors (lawyers, auditors) under confidentiality.
Government authorities when legally required (tax, customs, export control, court order).
A list of current sub-processors is available on request.

7. International Data Transfers

Our operations involve cross-border transfers between China, the United States, and the European Union:

Website and CRM are hosted on servers located in US.
Manufacturing partners are located in mainland China.
Customer support and engineering staff operate from China and the US.
Safeguards we use:

EU/UK to China or US: Standard Contractual Clauses (SCCs) adopted by the European Commission, plus supplementary measures (encryption in transit and at rest, access controls).
China to US or EU: Standard Contract for Outbound Cross-Border Transfer of Personal Information issued by the CAC, and where required, separate consent and PIPL security assessment.
US (CCPA): Contractual data protection terms with all service providers and contractors.
A copy of the relevant transfer mechanism is available on request.

8. Your Rights

Subject to your jurisdiction, you have the right to:

Access the personal data we hold about you.
Correct inaccurate or incomplete data.
Delete your data (“right to erasure” / “right to deletion”).
Restrict or object to certain processing.
Portability – receive your data in a structured, machine-readable format.
Withdraw consent at any time, where processing is based on consent.
Opt out of marketing by clicking “unsubscribe” in any email.
Non-discrimination for exercising CCPA rights.
Lodge a complaint with your supervisory authority (e.g., your EU member-state DPA, the California Privacy Protection Agency, or the Cyberspace Administration of China).
To exercise any right, email engineer@rpdmfg.com. We respond within 30 days (GDPR), 45 days (CCPA), or 15 working days (PIPL). We may verify your identity before fulfilling the request.

9. Cookies We use:

Strictly necessary cookies – required for the site to function (no consent needed).
Analytics cookies – only with your consent, to measure traffic and improve content.
Functional cookies – to remember preferences.
We do not use advertising or cross-site tracking cookies. See our Cookie Policy for details and to manage preferences.

10. Security

We apply industry-standard technical and organizational measures, including TLS encryption in transit, encryption at rest for CAD files, role-based access control, multi-factor authentication for staff, network monitoring, and regular backups. No system is 100% secure; in the event of a personal-data breach affecting your rights, we will notify you and the relevant authority within the timeframes required by law (72 hours under GDPR).

11. Update Policy

We may update this Policy from time to time. Material changes will be posted on this page with a new “Last Updated” date and, where required, communicated by email.

12. Contact

Privacy questions, requests, or complaints:

Shenzhen RPD Industrial Co., Ltd

ADD: Jiayu Building, Songgang Sub-district, Bao’an District, 518105, Shenzhen, China

Email: engineer@rpdmfg.com​