Privacy Policy
Effective 1 January 2025 · Updated quarterly
XUDONG PHILIPPINES INC.(“XUDONG,” “we,” “us”) operates xdpigo.com. This policy explains what information we collect, why, and how to exercise your rights under GDPR (EU) and the Philippine Data Privacy Act of 2012 (RA 10173).
1. What we collect
- RFQ form: name, company, business email, phone (optional), country (optional), service interest, project requirements, file attachments (drawings, BOM, schematics).
- Technical support form: name, company, email, issue type, description, optional attachments.
- Newsletter: business email only (opt-in, double opt-in confirmation).
- Server logs: IP address, user-agent, referer, timestamp — kept 90 days for security.
- Analytics cookies (only with consent): Google Analytics 4 anonymous identifiers.
2. Why we collect it
- To respond to your RFQ within 12 hours and prepare a quote (legitimate interest, GDPR Art. 6(1)(f); contract preparation, Art. 6(1)(b)).
- To resolve technical questions or warranty claims.
- To improve our website (analytics) — only with explicit consent.
- To send commercial proposals and follow-ups (legitimate interest; opt-out available in every email).
3. Drawings, BOMs, and other IP-sensitive attachments
Files you upload to the RFQ or contact form are transmitted to Formspree.io (HTTPS, AES-256 at rest) and forwarded to our internal Vault server (encrypted, access-controlled, audit-logged). We do not share files with anyone outside XUDONG. Drawing access is per-account; only the named account engineer and their direct line lead have read access. We sign a mutual NDA on every active RFQ within 4 business hours.
4. Cookies
Strictly necessary cookies (form submission, security) are always on. Analytics (GA4) cookies require explicit consent through our cookie banner — you can change your choice at any time on our Cookie Policy page.
5. Third parties we use
- Formspree.io — form delivery (USA, GDPR DPA in place)
- Google LLC — Analytics 4 + Google Tag Manager (only with consent)
- Cloudflare R2 — image CDN (no personal data)
- Vercel — hosting (USA, GDPR-compliant DPA)
6. Retention
RFQ records and quotes are kept 7 years (PH BIR + automotive PPAP requirement). Email correspondence is kept the lifetime of the customer relationship. Analytics anonymized data is kept 14 months. Server logs 90 days.
7. Your rights
You can request: access to your data, correction, deletion, portability, and to object to direct marketing. Email sales@xdpigo.com with subject “PRIVACY REQUEST.” We respond within 30 days.
8. International transfers
Data may be transferred between the Philippines, China and the United States to support our four factories and US office. Standard Contractual Clauses (EU SCCs 2021/914) are in place with all processors handling EU data.
9. Contact
XUDONG PHILIPPINES INC.Data Protection Officer
Lot 12, Block 16, Phase IV, Cavite Economic Zone
Rosario, Cavite 4106, Philippines
sales@xdpigo.com