Privacy Policy
Effective Date: January 1, 2026 | Last Updated: July 30, 2026
1. Introduction
This Privacy Policy describes how Soaring Wave, operating under the legal entity Kunming Xiang Fei Lan Trading Co., Ltd. with its registered address at No.91 Xin Yuan Road, Dong Hua Street, Pan Long District, Kunming - 650000, China (CN), and reachable via email at info@soaringwave.lol and by telephone at +19363399528, collects, uses, stores, shares, and protects personal information obtained through our website located at https://www.soaringwave.lol and any associated services, applications, and communication channels collectively referred to as the Services. Soaring Wave is committed to protecting your privacy and ensuring that your personal data is handled in a safe, lawful, and responsible manner in full compliance with applicable data protection regulations including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Personal Information Protection Law of the Peoples Republic of China (PIPL), and other relevant privacy legislation based on your jurisdiction.
By accessing or using our website, engaging with our computer systems design services, subscribing to our newsletters, submitting inquiries through our contact forms, or otherwise interacting with Soaring Wave in any capacity, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy. If you do not agree with any part of this policy, you must discontinue use of our Services immediately. We encourage you to review this Privacy Policy periodically, as it may be updated from time to time to reflect changes in our practices, legal obligations, or operational requirements. Your continued use of the Services following the posting of any modifications constitutes acceptance of those changes.
2. Information We Collect
2.1 Personal Information You Provide Directly
We collect personal information that you voluntarily provide to us when you interact with our Services. This includes but is not limited to your full name, email address, telephone number, company name, job title, physical mailing address, industry sector, project requirements and specifications, and any other information you choose to share when filling out contact forms, requesting a consultation, subscribing to our mailing list, registering for an account, participating in surveys, or communicating with our support team. We also collect information you provide when you enter into a contractual relationship with Soaring Wave for the provision of computer systems design, integrated systems engineering, or IT consulting services.
2.2 Information Collected Automatically
When you visit our website, certain information is automatically collected through standard internet technologies including cookies, web beacons, server logs, and similar tracking mechanisms. This automatically collected information may include your Internet Protocol (IP) address, browser type and version, operating system, device type and manufacturer, screen resolution, referring and exit pages, date and time stamps, pages viewed and time spent on each page, clickstream data, search queries entered on our site, language preferences, time zone settings, and approximate geographic location derived from your IP address. We use this data to analyze website traffic patterns, improve site performance, enhance user experience, diagnose technical issues, and maintain the security and integrity of our systems.
2.3 Business and Transactional Information
If you engage Soaring Wave for professional services, we collect business-related information necessary to fulfill our contractual obligations. This includes project specifications, technical requirements documentation, system architecture designs, network topology information, software configuration data, security assessment reports, billing and invoicing details, payment information processed through secure third-party payment processors, and communications records including emails, meeting notes, and project correspondence. We treat all business and project-related information with the highest degree of confidentiality and employ stringent security measures to protect it from unauthorized access or disclosure.
3. How We Use Your Information
Soaring Wave uses the information we collect for the following purposes. To provide, maintain, and improve our computer systems design, integrated systems engineering, IT consulting, and related professional services. To process and respond to your inquiries, requests, and communications in a timely and efficient manner. To fulfill contractual obligations and deliver the services you have requested from us. To send administrative information including confirmations, invoices, technical notices, updates, security alerts, and support messages. To personalize your experience on our website and deliver content and service offerings relevant to your interests and industry sector. To communicate with you about promotions, upcoming events, new service offerings, and other news about products and services offered by Soaring Wave that we believe may be of interest to you, provided you have consented to receive such communications. To conduct research, analysis, and surveys to better understand our client base, improve service delivery, and develop new solutions. To detect, prevent, and address technical issues, fraudulent activity, security breaches, and violations of our Terms of Service. To comply with applicable laws, regulations, legal processes, and enforceable governmental requests. To establish, exercise, or defend against legal claims in court or administrative proceedings.
4. Legal Basis for Processing
Our legal basis for collecting and using your personal information depends on the specific context in which we collect it and the applicable data protection laws of your jurisdiction. We will normally collect personal information from you only where we have your consent to do so, where the processing is necessary for the performance of a contract with you, where the processing is necessary for compliance with a legal obligation to which we are subject, or where the processing is necessary for the purposes of our legitimate interests or those of a third party, provided those interests are not overridden by your data protection rights and fundamental freedoms. In certain limited circumstances, we may also have a legal obligation to collect personal information from you or may otherwise need the personal information to protect your vital interests or those of another natural person.
5. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, understand user behavior, and deliver relevant content. Cookies are small text files stored on your device by your web browser that contain data about your browsing session and preferences. We use essential cookies that are strictly necessary for the operation of our website including session management and security features. We use analytics cookies to collect information about how visitors use our site including which pages are most frequently visited, how users navigate through the site, and whether users encounter error messages. We use functionality cookies that allow our website to remember choices you make such as your language preference, region, and customized settings. We may use advertising and targeting cookies to deliver advertisements that are more relevant to you and your interests. You can control and manage cookies through your browser settings. Most browsers allow you to refuse, delete, or selectively accept cookies. Please note that disabling certain categories of cookies may affect the functionality and performance of our website and some features may not work as intended. For more detailed information about the specific cookies we use and their purposes, please contact us at info@soaringwave.lol.
6. Data Sharing and Disclosure
Soaring Wave does not sell, rent, lease, or otherwise disclose your personal information to third parties for their direct marketing purposes without your explicit consent. We may share your information with trusted third-party service providers and business partners who perform services on our behalf, including cloud hosting and infrastructure providers, email communication platforms, customer relationship management systems, analytics and data processing services, payment processors, professional advisors including legal counsel and accounting firms, and IT security and maintenance contractors. All third-party service providers are contractually bound to process your data only on our documented instructions, implement appropriate technical and organizational security measures, and comply with applicable data protection laws. We require all third parties to respect the security of your personal data and to treat it in accordance with the law.
We may also disclose your information if required to do so by law or in response to valid requests by public authorities including courts, law enforcement agencies, or regulatory bodies. We may disclose your information to enforce our Terms of Service, to protect the rights, property, or safety of Soaring Wave, our clients, or others, or in connection with a merger, acquisition, reorganization, or sale of all or a portion of our assets, in which case you will be notified via email or a prominent notice on our website of any change in ownership or uses of your personal information.
7. International Data Transfers
Your information may be transferred to and processed in countries other than the country in which you reside. Our servers and offices are located in China, and our third-party service providers may operate in various jurisdictions around the world including the United States, the European Union, Singapore, and other locations. These countries may have data protection laws that differ from the laws in your country and may not provide the same level of protection. When we transfer personal data internationally, we implement appropriate safeguards to ensure that your information remains protected in accordance with this Privacy Policy and applicable law. These safeguards include the use of standard contractual clauses approved by relevant regulatory authorities, binding corporate rules for intra-group transfers, and certifications under approved data protection frameworks. By using our Services, you consent to the transfer of your information to our facilities and those third parties with whom we share it as described in this Privacy Policy.
8. Data Retention
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. The specific retention period depends on the nature of the information and the purposes for which it is processed. Business and project records are typically retained for the duration of the client relationship plus a period of up to seven years following the completion of services to comply with tax, accounting, and legal requirements. Website usage data and analytics information are retained for a period of up to twenty-six months. Marketing and communication data are retained until you withdraw your consent or object to the processing. When personal information is no longer needed for the purposes for which it was collected, we will securely delete, destroy, or anonymize it in accordance with our data disposal procedures and applicable legal requirements.
9. Data Security
Soaring Wave implements and maintains industry-standard technical, administrative, and physical security measures designed to protect your personal information from unauthorized access, alteration, disclosure, or destruction. Our security measures include but are not limited to encryption of data in transit using Transport Layer Security (TLS) protocols, encryption of data at rest using industry-standard encryption algorithms, network firewalls and intrusion detection and prevention systems, regular vulnerability assessments and penetration testing, multi-factor authentication for access to sensitive systems, role-based access controls and principle of least privilege, employee background checks and mandatory security awareness training, physical access controls to our data centers and office facilities, regular security audits and compliance assessments, and comprehensive incident response and disaster recovery plans. While we strive to protect your personal information using commercially reasonable means, no method of electronic transmission over the internet or electronic storage is one hundred percent secure. We cannot guarantee the absolute security of your data and you acknowledge that you provide your information at your own risk.
10. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights regarding your personal information. These rights may include the right to access your personal data and obtain a copy of the information we hold about you, the right to rectify or correct inaccurate or incomplete personal data, the right to request erasure of your personal data under certain circumstances also known as the right to be forgotten, the right to restrict or object to the processing of your personal data, the right to data portability allowing you to receive your data in a structured commonly used and machine-readable format, the right to withdraw consent at any time where we rely on consent to process your personal information, the right to lodge a complaint with a supervisory authority in your jurisdiction, and the right not to be subject to automated decision-making including profiling that produces legal effects concerning you. To exercise any of these rights, please contact us using the contact information provided in Section 14 of this Privacy Policy. We will respond to your request within the timeframes required by applicable law. We may need to verify your identity before processing your request to ensure the security of your personal information.
11. Third-Party Links and Services
Our website may contain links to third-party websites, plugins, applications, and services that are not owned or controlled by Soaring Wave. This Privacy Policy does not apply to those third-party services. We are not responsible for the privacy practices, content, or security of any third-party websites or services. We encourage you to review the privacy policies of any third-party services you access through links on our website. The inclusion of a link to a third-party website does not imply endorsement of that website or its privacy practices by Soaring Wave.
12. Childrens Privacy
Our Services are not directed to individuals under the age of sixteen, and we do not knowingly collect personal information from children under sixteen years of age. If we become aware that a child under sixteen has provided us with personal information without verifiable parental consent, we will take steps to delete such information from our systems as quickly as reasonably possible. If you believe that we may have collected information from a child under sixteen, please contact us immediately using the contact details provided in Section 14.
13. Changes to This Privacy Policy
We reserve the right to update, modify, or replace this Privacy Policy at any time at our sole discretion. When we make material changes to this policy, we will notify you by posting the updated policy on this page with a revised effective date, by sending an email to the address you have provided to us if applicable, or by displaying a prominent notice on our website. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal information. Changes to this Privacy Policy are effective immediately when they are posted on this page. The date at the top of this page indicates when this policy was last revised. Your continued use of the Services after any modifications to this Privacy Policy constitutes your acknowledgment of the modifications and your consent to abide by and be bound by the modified policy.
14. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or your personal information, please contact us using the following details:
Data Controller: Soaring Wave / Kunming Xiang Fei Lan Trading Co., Ltd.
Mailing Address: No.91 Xin Yuan Road, Dong Hua Street, Pan Long District, Kunming - 650000, China (CN)
Email Address: info@soaringwave.lol
Telephone Number: +19363399528
Website: https://www.soaringwave.lol
We take all privacy-related inquiries seriously and will endeavor to respond to your communication within thirty calendar days. If you are not satisfied with our response, you have the right to contact the data protection authority in your jurisdiction.
15. California Privacy Rights
Under the California Consumer Privacy Act (CCPA), California residents have specific rights regarding their personal information. This section describes those rights and explains how to exercise them. California residents have the right to request that we disclose what categories and specific pieces of personal information we have collected about you, the categories of sources from which the personal information is collected, the business or commercial purpose for collecting or selling personal information, and the categories of third parties with whom we share personal information. You have the right to request deletion of personal information we have collected from you, subject to certain exceptions. You have the right to opt out of the sale of your personal information. Soaring Wave does not sell personal information as that term is defined under the CCPA. You have the right not to receive discriminatory treatment for exercising your CCPA rights. To exercise your rights under the CCPA, please contact us using the information in Section 14. We will verify your request using the information associated with your account or prior interactions with us, which may include verifying your email address or requesting additional documentation.
16. European Economic Area and United Kingdom Privacy Rights
If you are located in the European Economic Area (EEA) or the United Kingdom (UK), you have certain rights under the General Data Protection Regulation (GDPR) and the UK GDPR respectively. In addition to the rights described in Section 10, you have the right to withdraw consent at any time where we rely on consent as the legal basis for processing your personal data. You have the right to lodge a complaint with the data protection supervisory authority in your country of residence, place of work, or place of the alleged infringement. You have the right to object to processing of your personal data for direct marketing purposes at any time. You have the right to request restriction of processing of your personal data in certain circumstances including while we verify the accuracy of your data or consider your objection to processing. The personal data we collect from you may be transferred to and processed in countries outside the EEA and UK, including China and the United States. We ensure such transfers comply with applicable data protection laws through the use of appropriate safeguards as described in Section 7 of this policy. Our Data Protection Officer can be contacted at info@soaringwave.lol for any GDPR-related inquiries.
17. China Personal Information Protection Law
In compliance with the Personal Information Protection Law of the Peoples Republic of China (PIPL), Soaring Wave and its operating entity Kunming Xiang Fei Lan Trading Co., Ltd., headquartered at No.91 Xin Yuan Road, Dong Hua Street, Pan Long District, Kunming - 650000, China (CN), processes personal information in accordance with the principles of legality, legitimacy, necessity, and good faith. We provide clear and conspicuous notice regarding the purpose, method, and scope of personal information processing. We obtain separate consent for processing sensitive personal information including financial account data, precise geolocation data, and biometric information. We conduct personal information protection impact assessments for high-risk processing activities. We have appointed a Personal Information Protection Officer responsible for overseeing our compliance with PIPL requirements. Individuals in China have the right to access, correct, delete, and port their personal information, as well as the right to deregister their accounts. To exercise these rights or to file a complaint regarding our data handling practices, please contact us using the details provided in Section 14 of this policy.