Privacy Policy
Effective Date: August 1, 2026 | Last Updated: August 1, 2026
1. Introduction
This Privacy Policy describes how Anqing BoatReach Trading Co., Ltd., operating under the brand name BoatReach (referred to as we, us, or our throughout this document), collects, uses, stores, discloses, and protects information obtained from visitors and clients of our website located at https://www.boatreach.lat (the Website). The developer and operator of this Website is BoatReach, which serves as both the technology platform provider and the professional services brand behind this privacy framework. As a professional computer systems design and technology consulting firm, we understand that privacy is not merely a compliance checkbox—it is a foundational design principle that must be embedded into every layer of a modern digital service.
BoatReach specializes in systems architecture, systems integration, cloud infrastructure engineering, DevOps automation, technology strategy consulting, cybersecurity assessment, and data analytics platform design. In the course of delivering these services, we interact with a wide range of technical and business information, and we recognize that earning and maintaining the trust of our clients, partners, and website visitors is an essential component of our professional practice. This Privacy Policy is intended to provide complete transparency about our data handling practices, to explain the choices available to you regarding your personal information, and to describe the safeguards we have put in place to protect that information in an increasingly complex digital landscape.
By accessing or using the Website, you acknowledge that you have read, understood, and agree to be bound by the terms of this Privacy Policy. If you do not agree with any part of this policy, you should discontinue use of the Website immediately. This policy applies to all information collected through the Website, through email and telephone communications initiated by you, and through any other interaction you may have with BoatReach in the context of our consulting engagement workflow, including but not limited to video conferences, shared document repositories, project management platforms, and technical discovery sessions. We encourage you to read this document in its entirety and to contact us with any questions before proceeding to use our services.
This policy is designed to comply with applicable data protection laws and regulations across multiple jurisdictions, including but not limited to the General Data Protection Regulation (GDPR) in the European Economic Area and the United Kingdom, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the Personal Information Protection Law (PIPL) of the Peoples Republic of China. We have structured our data governance framework to meet the highest common standard among these regimes, reflecting our belief that strong privacy protections are universally valuable regardless of where a client or visitor may be located. BoatReach is committed to continuous improvement of its privacy program, and we regularly review and update our practices to remain aligned with evolving legal requirements and industry best practices.
2. Information We Collect
The types of information we collect depend on how you interact with our Website and our services. Below we describe in detail the categories of data we may gather, the methods by which we gather it, and the specific purposes associated with each category. In all cases, we adhere to the principle of data minimization: we collect only what is necessary, we collect it only for specified and legitimate purposes, and we do not retain it beyond the period required to serve those purposes.
2.1 Information You Provide Voluntarily
When you engage with our Website and services, you may voluntarily provide several categories of personal and business information. We take care to design our data collection touchpoints to be transparent and to provide you with clear context about why each piece of information is requested.
Contact Form Submissions. Our Website includes a contact form through which prospective clients can initiate an inquiry about our systems design and consulting services. When you submit this form, we collect your full name, your email address, your company or organization name (if you choose to provide it), the specific service area you are interested in (such as systems architecture, cloud migration, DevOps automation, cybersecurity assessment, or data analytics), and the free-text project description or message that you compose. This information is collected for the express purpose of understanding your needs, evaluating whether and how BoatReach can be of assistance, and enabling a member of our consulting team to respond to you with a tailored and meaningful reply. We do not use contact form information for any unrelated purpose, and we do not add form submitters to marketing lists without their explicit and separate consent.
Email Communications. If you send an email directly to mail@boatreach.lat, we collect your email address, the subject line and body of your message, any attachments you include, and any metadata transmitted by your email client (such as timestamps and routing information). These communications are retained as part of our business correspondence records. For clients with whom we have an active engagement, email correspondence forms a critical component of the project record and is used to document technical decisions, design rationale, timeline agreements, and deliverable specifications.
Telephone Inquiries. If you call us at +1 (959) 595-3935, we may collect your phone number through caller identification and may record notes about the content of your inquiry, including the nature of the systems design challenge you are facing, your timeline, your budget parameters, and any technical context you share. We do not record phone calls unless we explicitly inform you and obtain your consent before doing so. Handwritten or digital notes from telephone conversations are treated as personal information and are subject to the same retention and security controls described elsewhere in this policy.
Consulting Engagement Data. Once a formal client relationship is established, we may collect additional categories of information necessary for the delivery of our professional services. This may include business requirements documents, system architecture diagrams, network topology information, source code repositories (where access is granted for review purposes), infrastructure-as-code templates, database schemas, API specifications, security assessment findings, project management records, billing and invoicing details, and communication preferences. All such information is collected and processed under the terms of a separate services agreement or statement of work executed between BoatReach and the client.
2.2 Information Collected Automatically
When you visit our Website, certain technical information is collected automatically through standard web protocols and server-side logging mechanisms. This type of collection is inherent to the operation of any modern website and does not require any action on your part. We collect this information to ensure the security, stability, and performance of our Website, and to gain aggregated insights that help us improve the experience for all visitors.
Server Log Data. Our web hosting infrastructure, which is provided by Google Firebase Hosting, automatically records standard server log entries for each request made to our Website. These log entries may include your Internet Protocol (IP) address, the date and time of your request, the specific URL or resource path you accessed, the HTTP method and status code returned by the server, the size of the response payload, the referring URL (if your browser transmitted one), and the user-agent string that identifies your browser type, version, and operating system. This log data is used for security monitoring, traffic analysis, capacity planning, and troubleshooting. Log data is stored in aggregate form and is not used to build individual visitor profiles or to track browsing behavior across sessions.
Device and Browser Information. In addition to server logs, we may collect information about the device you use to access our Website, including the hardware model, operating system name and version, screen resolution, installed browser plugins, and language preferences. This information helps us ensure that our Website renders correctly across the diverse range of devices and browsers used by professionals in the systems design and technology consulting industry. For example, we may notice that a significant portion of our visitors use a particular screen resolution and adjust our layout breakpoints accordingly; or we may observe that a certain browser version accounts for the majority of rendering issues and prioritize a fix.
Usage Patterns and Engagement Metrics. We analyze aggregate, anonymized patterns of Website usage to understand which pages are most frequently visited, how long visitors typically spend reading specific content, which navigation paths are most common, and where visitors tend to exit the Website. These metrics are collected at the aggregate level and do not identify individual visitors. For a systems design consultancy like BoatReach, understanding how potential clients discover and interact with our content is valuable for refining our messaging, improving our service descriptions, and ensuring that the information architecture of our Website aligns with the expectations of the engineering leaders, CTOs, and technology decision-makers who constitute our primary audience.
2.3 Information from Third-Party Sources
In some circumstances, we may receive information about you from third-party sources. This may occur when a colleague or business associate refers you to BoatReach and shares your contact information with your consent, or when we conduct publicly available research as part of preparing for a prospective client engagement. We may also receive information from professional networking platforms, industry directories, or conference attendee lists where you have made your information publicly available or where a mutual connection facilitates an introduction. In all such cases, we will inform you of the source of the information and will only use it for the purpose of establishing or developing a professional relationship with you, consistent with the nature of our consulting practice. If you prefer that we not retain information obtained from such sources, you may contact us and we will delete it in accordance with our data subject request procedures.
2.4 Information We Do Not Collect
We consciously and deliberately refrain from collecting certain categories of information. We do not collect sensitive personal data as defined under applicable data protection laws, including but not limited to government-issued identification numbers (such as social security numbers, passport numbers, or national ID numbers), financial account credentials or payment card details (our invoicing is handled through standard business banking channels and does not involve online payment processing through the Website), biometric or genetic data, health or medical information, information about political opinions, religious or philosophical beliefs, trade union membership, or data concerning an individuals sex life or sexual orientation. We do not knowingly collect any personal information from individuals under the age of 16. We do not collect precise geolocation data beyond the coarse geographic region implied by an IP address, which is logged automatically as part of standard server operations. By explicitly delineating what we do not collect, we aim to give you confidence that your interaction with BoatReach carries a limited and well-defined privacy footprint.
3. Cookies and Tracking Technologies
Cookies are small text files that a website places on your device to store information about your visit. Tracking technologies encompass a broader category of mechanisms—including web beacons, pixels, local storage objects, and device fingerprinting scripts—that can be used to monitor user behavior across websites. Our approach to these technologies is deliberately conservative and privacy-respecting, reflecting our professional orientation as systems architects who understand the technical implications of tracking infrastructure.
3.1 Essential Cookies
Our Website uses only essential cookies that are strictly necessary for its technical operation. These cookies serve a narrow set of functions: maintaining session state so that the server can associate consecutive requests from the same browser, preserving your navigation preferences during a single visit, and securing form submissions against cross-site request forgery attacks. Essential cookies do not track your browsing activity across sessions or across other websites, they do not collect personal information for marketing or advertising purposes, and they are deleted when you close your browser (session cookies) or after a short, fixed duration.
Specifically, our essential cookies may include a session identifier that enables the server to process form submissions correctly, a security token that validates the authenticity of requests made to our server, and a cookie-consent flag that records your acknowledgment of our cookie practices so that the notification banner is not displayed repeatedly. None of these cookies contain personal identifiers or persist beyond their immediate functional necessity. They are a minimal technical prerequisite for operating a secure and reliable web application, analogous to the memory registers that a CPU uses to maintain state during computation.
3.2 Analytics
We may use privacy-focused analytics tools that measure aggregate Website traffic and engagement without building individual user profiles or deploying persistent tracking cookies. Any analytics data we collect is aggregated and anonymized at the earliest technically feasible stage in the processing pipeline. We do not use analytics services that rely on browser fingerprinting techniques, that combine our data with data from other websites to build cross-site behavioral profiles, or that enable retargeting or behavioral advertising campaigns.
If we deploy analytics instrumentation, it will be limited to measuring page view counts, session duration ranges, approximate geographic distribution of visitors (at the country or city level, derived from anonymized IP address prefixes), referrer sources, and device category breakdowns (desktop, tablet, mobile). These metrics help us understand whether our content is reaching the intended audience of systems design professionals and technology decision-makers, and whether our Website is performing adequately across different network conditions and device types. We will never use analytics data to identify, profile, or make decisions about individual visitors.
3.3 Third-Party Services
Our Website loads web fonts from Google Fonts to deliver consistent and professional typography across all devices and platforms. When your browser requests these font files from the Google Fonts content delivery network, Google may receive standard HTTP request information, including your IP address, the URL of the referring page, and your browser user-agent string. The use of this data by Google is governed by the Google Privacy Policy. We have selected Google Fonts because it enables efficient font delivery through a globally distributed CDN, reducing page load times and improving the reading experience for visitors in all geographic regions. We do not embed third-party advertising networks, social media sharing widgets with embedded tracking, behavioral profiling scripts, or any other surveillance-oriented technologies on our Website.
3.4 Your Cookie Choices
You have full control over how your browser handles cookies and similar technologies. All major web browsers—including Chrome, Firefox, Safari, Edge, and Brave—provide settings that allow you to block all cookies, block only third-party cookies, delete cookies when you close your browser, or manage cookie permissions on a site-by-site basis. You may also use private browsing or incognito mode, which typically prevents cookies from persisting beyond the browsing session. If you choose to block all cookies, certain functional elements of our Website (such as form submission mechanisms that rely on session tokens) may not operate as intended, but the informational content of the Website will remain fully accessible. For detailed guidance on configuring cookie settings, please refer to the help documentation provided by your browser vendor.
4. How We Use Your Information
The information we collect serves a clearly defined set of purposes, each of which is tied to a legitimate operational need or a legal obligation. We do not use your information in ways that are incompatible with the purposes described in this policy, and we do not repurpose data collected for one function to serve an unrelated function without first notifying you and, where required by law, obtaining your consent. Below we detail each purpose category, the specific types of data involved, and the legal basis on which we rely for that processing activity.
Service Delivery and Client Engagement. The primary purpose for which we collect information is to deliver the consulting and systems design services that our clients request. When a prospective client submits an inquiry through our contact form or reaches out via email or telephone, we use the provided information to understand the nature of the project, assess the technical scope, assemble an appropriate response team, and prepare a preliminary proposal or scoping document. For active client engagements, we use project-related information—including technical specifications, architecture diagrams, configuration files, meeting notes, and correspondence—to execute the agreed-upon scope of work, manage project timelines, allocate personnel resources, track deliverables, and ensure quality control. This processing is based on our legitimate interest in operating our business and, where a formal engagement agreement exists, on the performance of a contract.
Website Operation and Improvement. We use aggregated, anonymized usage data—including page view counts, traffic sources, device categories, browser types, and navigation paths—to monitor and improve the performance, design, content, and technical infrastructure of our Website. For example, if aggregate data reveals that visitors frequently abandon the Website at a particular page, we may investigate whether the page has a usability issue, a broken link, or content that does not meet visitor expectations. If we observe that a growing share of traffic originates from mobile devices, we may prioritize responsive design improvements. This processing is based on our legitimate interest in maintaining an effective and informative online presence that serves the needs of the systems design community.
Business Communication and Relationship Development. We use contact information to respond to inquiries, to follow up on initial consultations, to send proposals and statements of work, and to maintain ongoing communication with clients and prospective clients throughout the consulting engagement lifecycle. We may also use email to share relevant industry insights, case studies, technology trend analyses, and information about new service offerings, but only where the recipient has explicitly requested or consented to receive such communications. Every marketing or informational email we send includes a clear and functional unsubscribe mechanism that allows the recipient to opt out of future communications with a single action. This processing is based on our legitimate interest in developing and maintaining professional relationships and, where consent is the applicable legal basis, on that consent.
Security, Fraud Prevention, and Legal Compliance. We use server log data, access records, and traffic patterns to monitor the security and integrity of our Website, to detect and respond to unauthorized access attempts, distributed denial-of-service attacks, malicious bot activity, and other security threats, and to investigate potential violations of our Terms of Service. We also process and retain certain categories of information as necessary to comply with applicable legal obligations, including tax record-keeping requirements, corporate governance and reporting obligations, and lawful requests from judicial or regulatory authorities. This processing is based on our legal obligations and our legitimate interest in protecting our systems, our data, and the interests of our clients.
No Automated Decision-Making. BoatReach does not use automated decision-making systems—including profiling algorithms, machine learning models, or artificial intelligence tools—to make decisions that produce legal effects concerning individuals or similarly significant impacts. Every substantive decision related to client engagements, including project scoping, resource allocation, deliverable acceptance, and billing, is made by qualified human professionals exercising their expertise and judgment. Our systems design philosophy extends to our own operations: we believe that technology should augment and support human decision-making, not replace it, and this principle is reflected in how we handle personal information.
5. Data Sharing and Disclosure
We do not monetize your personal information. We do not operate as a data broker, and we do not build dossiers on individuals for sale or transfer to third parties. The limited circumstances in which we may share information are described below, and in every case the sharing is driven by operational necessity, legal obligation, or the protection of legitimate interests.
5.1 Service Providers and Infrastructure Partners
We engage trusted third-party service providers to perform specific functions that support our operations. These providers include Google Firebase for web hosting and server infrastructure, a domain name registrar for managing the boatreach.lat domain, and email service providers that facilitate our business communications. These providers are contractually bound to process data only in accordance with our documented instructions, to maintain confidentiality and security standards at least as protective as those described in this policy, and to delete or return data upon termination of the service relationship. We conduct due diligence on all service providers before engagement and periodically review their security and privacy practices to ensure ongoing compliance.
In the context of a consulting engagement, additional service providers may be involved—such as cloud platform providers whose infrastructure we configure on behalf of a client, collaboration tools used for project management and document sharing, or specialized software tools required for systems analysis and testing. In these cases, the client typically has an independent relationship with the provider, and our role is to configure, integrate, or assess the provider within the architecture we are designing. We handle client data within these platforms strictly in accordance with the terms of the applicable services agreement.
5.2 Legal Disclosures
We may disclose your information if we are required to do so by applicable law, regulation, legal process, or binding governmental request. This includes responding to valid subpoenas, court orders, search warrants, or requests from law enforcement agencies or regulatory authorities with jurisdiction over Anqing BoatReach Trading Co., Ltd. Where legally permissible, we will make reasonable efforts to notify you of any such disclosure request before complying, so that you may have the opportunity to seek a protective order or other legal remedy. We may also disclose information where we believe in good faith that disclosure is necessary to protect the rights, property, or physical safety of BoatReach, our employees, our clients, or members of the public.
5.3 Business Transfers
In the event that Anqing BoatReach Trading Co., Ltd. undergoes a merger, acquisition, corporate reorganization, sale of all or substantially all of its assets, or a similar business transfer, the personal information we hold may be among the assets transferred to the successor entity. In such an event, we will provide prominent notice on our Website and, where we have an active client relationship, via direct communication, so that affected individuals are informed of the change in ownership or control and can make informed decisions about their continued engagement with the successor entity. The successor entity will be bound by the terms of this Privacy Policy or by a policy that provides no less protection for your personal information.
5.4 What We Do Not Do
To be explicit and unambiguous: we do not sell, rent, lease, trade, or exchange personal information for monetary or other valuable consideration. We do not share your information with data brokers, advertising networks, consumer marketing platforms, or any entity whose primary business is the commercialization of personal data. We do not allow third-party ad servers or ad networks to serve advertisements or collect information on our Website. We do not participate in programmatic advertising exchanges, real-time bidding systems, or audience segmentation platforms. Our business model is built on delivering professional systems design and consulting services, not on exploiting personal data for advertising revenue. This principle is fundamental to our identity as a consulting firm and is not subject to change based on business circumstances.
6. Data Retention
We retain personal information only for as long as is necessary to fulfill the specific purposes for which it was collected, or as required to comply with applicable legal, tax, and regulatory obligations. Our retention schedule is designed to balance the operational need to maintain records of client engagements and business correspondence against the privacy interest in limiting the persistence of personal data.
Contact Form Submissions. Inquiries submitted through our contact form, including associated name and contact details, are retained for a period of two years from the date of the most recent correspondence. If the inquiry leads to a formal client engagement, the data is incorporated into the client project record and retained in accordance with the client project data retention period described below. If the inquiry does not lead to an engagement, the data is deleted or anonymized at the end of the two-year period unless a longer retention is required by applicable law.
Client Project Data. Information collected and generated in the course of a client engagement—including technical specifications, architecture documentation, configuration files, code reviews, meeting notes, communication records, and deliverable artifacts—is retained for the duration of the engagement plus seven years following the completion or termination of the engagement. This retention period is driven by multiple considerations: the need to maintain records for potential follow-on engagements where historical context is valuable, professional liability and errors-and-omissions insurance requirements, tax and financial audit requirements under Chinese corporate law, and the client interest in having a referenceable archive of their systems design documentation. At the end of the retention period, client project data is securely deleted, or, where deletion is impractical due to backup system architecture, is placed beyond operational use and logically isolated pending eventual destruction through backup media rotation.
Server Logs. Web server access logs and related technical telemetry are retained for a maximum of ninety days. This duration is sufficient to support security incident investigation, performance trend analysis, and capacity planning, but is short enough to limit the privacy exposure associated with log data. At the end of each ninety-day cycle, logs are permanently purged from active storage systems. Backup copies may persist for an additional thirty days as part of our standard infrastructure backup rotation before being overwritten.
Email Correspondence. Business email correspondence is retained for the duration of the business relationship to which it pertains, plus an additional three years. This retention enables us to reference past discussions about technical decisions, project scope changes, and deliverable agreements, which is valuable when clients return for additional consulting work or when questions arise about prior engagements. Email that is not associated with an active or past client relationship—such as general inquiries that did not lead to an engagement—is retained for a maximum of two years.
When personal information reaches the end of its applicable retention period, we take reasonable steps to securely delete it from our active systems. The deletion process may involve cryptographic erasure, physical destruction of storage media, or overwriting with random data patterns, depending on the storage technology involved. Where immediate deletion is not technically feasible due to backup architecture—such as when data resides on append-only backup tapes or immutable cloud storage snapshots—we ensure that the data is logically quarantined and will be irretrievably destroyed through the normal operation of the backup retention cycle.
7. Data Security
Protecting your information is a core responsibility that we take seriously at every level of our technology stack and organizational structure. As systems design professionals, we understand that security is not a product that can be bought and installed, but rather an emergent property of sound architecture, rigorous engineering, and continuous vigilance. Our security program encompasses technical controls, organizational policies, personnel practices, and incident response capabilities.
Transmission Security. All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS) with strong cipher suites. We enforce HTTPS for all pages on our Website through HTTP Strict Transport Security (HSTS) headers, which instruct browsers to never connect to our domain over unencrypted HTTP. We monitor the TLS certificate lifecycle to ensure timely renewal and to prevent any lapse in encryption coverage. We also configure our servers to disable older, vulnerable versions of TLS and to reject cipher suites known to be weak or compromised, ensuring that the encryption protecting your data in transit meets modern cryptographic standards.
Infrastructure Security. Our Website is hosted on Google Firebase, which provides a globally distributed, fully managed hosting platform with security controls that include network firewalls, DDoS protection, automated patch management, and physical security for data center facilities. Access to our hosting configuration, deployment pipelines, and server-side resources is restricted to authorized personnel through strong authentication mechanisms, including multi-factor authentication and role-based access control. All administrative access is logged and subject to periodic audit review. We maintain separate environments for development, staging, and production to ensure that code changes are tested and validated before being exposed to the public Internet, reducing the risk of misconfiguration or vulnerability introduction.
Access Control and Authorization. Access to personal information within our organization is granted on a strict need-to-know basis. Only personnel whose job functions require access to specific categories of data—such as a consulting team lead who needs client project information to prepare a deliverable, or a systems administrator who needs server access to diagnose a performance issue—are authorized to retrieve, view, or process that data. We implement role-based access controls, maintain access provisioning and deprovisioning procedures that are triggered by personnel onboarding and offboarding events, and conduct periodic access reviews to ensure that permissions remain aligned with current job responsibilities.
Organizational Practices. All BoatReach personnel and contractors with access to personal information are required to acknowledge and comply with our internal data protection policies. We conduct privacy and security awareness training for relevant team members, covering topics such as data classification, secure communication practices, phishing recognition, password hygiene, and incident reporting procedures. We maintain a documented incident response plan that defines roles, escalation paths, communication protocols, and remediation steps for potential data security incidents. The plan is reviewed and tested periodically to ensure its effectiveness and to incorporate lessons learned from industry developments and internal exercises.
Continuous Improvement. Security is not static, and neither is our approach to it. We regularly assess our security posture through vulnerability scanning, configuration reviews, and threat modeling exercises. We monitor security advisories and vulnerability disclosures relevant to our technology stack and apply patches and mitigations on a risk-prioritized schedule. As the threat landscape evolves—with new attack vectors, exploit techniques, and adversary capabilities emerging continuously—we adapt our defenses accordingly. While no organization can guarantee absolute security, we are committed to maintaining a level of protection that is appropriate for the nature of the information we handle and consistent with the expectations of a professional systems design consultancy.
8. International Data Transfers
BoatReach is headquartered in Anqing, Anhui Province, in the Peoples Republic of China, and our web hosting infrastructure is provided by Google Firebase, which operates data centers in multiple geographic regions around the world. As a result, when you use our Website or engage our services, your personal information may be transferred to, stored in, and processed in countries other than the country in which you reside, including China and the United States. These countries may have data protection laws that differ from those applicable in your jurisdiction, and those differences may affect the scope of rights and remedies available to you.
We take appropriate and legally recognized safeguards to ensure that your personal information receives a level of protection that is substantially equivalent to the protection it would receive in your home jurisdiction, regardless of where the processing occurs. For transfers from the European Economic Area or the United Kingdom to countries that have not been recognized as providing an adequate level of data protection, we rely on standard contractual clauses approved by the European Commission or the UK Information Commissioner Office, supplemented by additional technical and organizational measures as necessary to address any risks identified through transfer impact assessments.
For clients and visitors in China, we process personal information in accordance with the Personal Information Protection Law (PIPL), including its provisions governing cross-border data transfers. For clients and visitors in other jurisdictions, we apply a consistent set of data protection standards that draws on the most protective elements of the GDPR, CCPA/CPRA, and PIPL frameworks—an approach that reflects our belief that strong privacy protections are not geographically contingent. By submitting your personal information to us, you acknowledge and consent to the transfer, storage, and processing of that information across international borders in accordance with the safeguards described in this policy.
If you have specific questions about the legal mechanisms governing a particular data transfer, or if you wish to obtain a copy of the standard contractual clauses or other transfer instruments we rely upon, please contact us using the information provided in Section 11. We are committed to transparency regarding cross-border data flows and will respond to such inquiries promptly and substantively.
9. Your Rights and Choices
Depending on the data protection laws applicable in your jurisdiction of residence, you may have certain legal rights regarding the personal information we hold about you. We respect and facilitate these rights, and we have established internal procedures to handle data subject requests in a timely, transparent, and legally compliant manner. The specific rights available to you may include:
- Right of Access. You have the right to request confirmation of whether we are processing your personal information and, if so, to obtain a copy of that information along with details about the categories of data processed, the purposes of processing, the recipients or categories of recipients with whom the data has been shared, the anticipated retention period or criteria used to determine it, the source of the data if it was not collected directly from you, and the existence of any automated decision-making processes. We will provide this information in a concise, transparent, and easily accessible format, typically within one month of receiving a verified request.
- Right of Rectification. If you believe that the personal information we hold about you is inaccurate or incomplete, you have the right to request that we correct or supplement it. Where appropriate, we will also notify any third-party recipients of your data of the rectification, unless doing so would involve disproportionate effort.
- Right of Erasure (Right to be Forgotten). You may request that we delete your personal information under certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, when you withdraw consent and there is no other legal basis for processing, when you object to processing and there are no overriding legitimate grounds, or when the data has been unlawfully processed. This right is subject to important limitations: we may retain data where necessary for compliance with legal obligations, for the establishment or defense of legal claims, or for reasons of public interest.
- Right to Restrict Processing. You may request that we temporarily or permanently limit the processing of your personal information in specific situations, such as when you contest the accuracy of the data, when the processing is unlawful but you oppose erasure and request restriction instead, when we no longer need the data but you require it for legal claims, or when you have objected to processing pending verification of our legitimate grounds.
- Right to Data Portability. Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal information in a structured, commonly used, and machine-readable format, and to transmit that data to another data controller without hindrance from us. Where technically feasible, you may also request that we transmit the data directly to another controller on your behalf.
- Right to Object. Where we process your personal information based on legitimate interests, you have the right to object to such processing on grounds relating to your particular situation. Upon receiving an objection, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defense of legal claims. You also have an absolute right to object to the processing of your data for direct marketing purposes at any time.
- Right to Withdraw Consent. Where our processing of your personal information is based on your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any processing that occurred before the withdrawal. We will honor your withdrawal promptly and will cease the processing activity for which consent was withdrawn, unless another legal basis for the processing exists.
- Right to Non-Discrimination. We will not discriminate against you for exercising any of the rights described in this section. Exercising your privacy rights will not result in denial of services, different pricing, degraded quality of service, or any other adverse treatment. This commitment applies regardless of your jurisdiction of residence.
To exercise any of the rights described above, please contact us using the contact details provided in Section 11 of this policy. To protect your privacy and the security of your data, we may need to verify your identity before processing your request. Verification may involve confirming details that we already hold about you, such as your email address or a previous interaction you have had with us. We will respond to your request within the timeframe prescribed by applicable law—typically one month, extendable by an additional two months for complex or voluminous requests—and will inform you of any extension and the reasons for it within the initial one-month period. If we are unable to fulfill your request, we will explain the reasons for our inability to do so and inform you of any available avenues of appeal or complaint.
If you are not satisfied with our response to a data subject request or with our data practices generally, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction. We encourage you to contact us first so that we may have the opportunity to address your concerns directly, but you are under no obligation to do so before approaching a regulatory authority.
10. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy from time to time to reflect changes in our data processing practices, our service offerings, our legal obligations, or the technological environment in which we operate. The nature and frequency of updates will vary: some changes may be minor clarifications or formatting improvements, while others may be substantive modifications that alter the scope, purpose, or legal basis of our data processing activities.
When we make material changes to this policy, we will update the Effective Date and Last Updated date displayed at the top of the page and, where appropriate and feasible, provide additional notice through a prominent banner on our Website, through direct email notification to clients with whom we have an active relationship, or through other communication channels reasonably calculated to reach affected individuals. For changes that materially affect your rights or that require your explicit consent under applicable law, we will obtain such consent before applying the updated policy to your data. Your continued use of the Website following the posting of an updated policy constitutes your acknowledgment of and agreement to the revised terms, unless the changes are of a nature that requires affirmative consent.
We encourage you to review this Privacy Policy periodically—we recommend bookmarking this page and revisiting it at least once per quarter—to stay informed about how we are protecting your information. Our commitment to transparency extends to the evolution of our privacy practices over time. If you have questions about any change to this policy or wish to understand the rationale behind a particular update, you are welcome to contact us for clarification. We maintain an internal change log of policy revisions for reference and audit purposes, and we can provide a summary of material changes upon request.
11. Contact Information
If you have any questions, concerns, inquiries, or requests regarding this Privacy Policy, our data handling practices, or your privacy rights, we encourage you to contact us. We are committed to responsive and transparent communication with all individuals who entrust us with their personal information. Our contact details are as follows:
Anqing BoatReach Trading Co., Ltd.Room 101, Building 5, Kangjuli
Huazhong Road, Yingjiang District
Anqing City, 246000
China
Data Protection Inquiries: mail@boatreach.lat
Phone: +1 (959) 595-3935
We aim to acknowledge all privacy-related inquiries within three business days and to provide a substantive response within the timeframe required by applicable law. If your inquiry involves a request to exercise data subject rights, please refer to Section 9 for additional details about the verification and response process.
We are committed to resolving any concerns or complaints about our collection, use, or disclosure of personal information. If you believe that your privacy rights have been violated, we encourage you to raise the matter with us directly so that we may investigate and, where appropriate, remediate the issue. If you are not satisfied with our response, you may have the right to lodge a complaint with the data protection supervisory authority in your jurisdiction of residence, in your place of work, or in the place where the alleged infringement occurred. Contact details for data protection authorities in the European Economic Area and the United Kingdom are available through the European Data Protection Board website, and details for other jurisdictions are typically available through government portals.
12. Jurisdiction-Specific Provisions
In addition to the generally applicable terms set forth throughout this Privacy Policy, the following provisions apply to individuals located in specific jurisdictions. These provisions supplement—and do not replace or limit—the protections described elsewhere in this policy. In the event of any conflict between a jurisdiction-specific provision and a general provision, the jurisdiction-specific provision will govern with respect to individuals in that jurisdiction to the extent required by applicable law.
12.1 European Economic Area (EEA) and United Kingdom
If you are located in the EEA or the United Kingdom, the data controller responsible for your personal information is Anqing BoatReach Trading Co., Ltd., a company incorporated under the laws of the Peoples Republic of China with its registered office at Room 101, Building 5, Kangjuli, Huazhong Road, Yingjiang District, Anqing City, 246000, China. Our legal bases for processing your personal information are set out in Section 4 of this policy and include the performance of a contract, compliance with legal obligations, and our legitimate interests in operating our consulting business, provided that such interests are not overridden by your fundamental rights and freedoms. Where we rely on legitimate interests, we have conducted and documented a balancing test to ensure that the interests we pursue are proportionate and do not unjustifiably impact your privacy.
You have the rights described in Section 9 of this policy, including the rights of access, rectification, erasure, restriction, portability, and objection. You also have the right to lodge a complaint with the data protection supervisory authority in your EU member state of residence, your place of work, or the place of the alleged infringement. The lead supervisory authority for our cross-border processing activities can be identified based on our establishment outside the EEA and the international scope of our operations; we are happy to assist you in identifying the appropriate supervisory authority if you contact us with your specific circumstances.
12.2 California Residents
If you are a resident of California, you have additional rights under the California Consumer Privacy Act of 2018 (CCPA) as amended by the California Privacy Rights Act of 2020 (CPRA), collectively referred to as California privacy law. Under these laws, you have the right to know what categories and specific pieces of personal information we have collected about you in the preceding twelve months, the categories of sources from which that information was collected, the business or commercial purpose for collecting or sharing the information, and the categories of third parties with whom we have shared the information.
You also have the right to request deletion of your personal information, subject to exceptions prescribed by California law. You have the right to correct inaccurate personal information. You have the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising purposes; however, we do not sell personal information as defined under California law, nor do we share it for cross-context behavioral advertising, so there is no sale or sharing to opt out of. You have the right to limit the use and disclosure of sensitive personal information, though we do not collect or process sensitive personal information as defined under California law. You have the right to non-discrimination for exercising any of your California privacy rights. To exercise your California privacy rights, please contact us using the details provided in Section 11. We will respond to verifiable consumer requests within the timeframe required by California law—typically forty-five days, extendable by an additional forty-five days where reasonably necessary.
12.3 China Residents
As a company incorporated and operating in the Peoples Republic of China, we comply fully with the Personal Information Protection Law (PIPL), the Cybersecurity Law, and the Data Security Law of China. Under the PIPL, you have rights that include the right to know and to decide on matters relating to your personal information, the right to access and copy your personal information, the right to request correction or supplementation of inaccurate or incomplete information, the right to request deletion of personal information under specified circumstances, the right to request that we explain our personal information processing rules, and the right to object to processing and to withdraw consent.
We have appointed a data protection responsible person who oversees our compliance with Chinese data protection laws and who serves as a point of contact for Chinese residents with questions or concerns about our data practices. This individual can be reached through the email address and telephone number provided in Section 11. If you believe that our processing of your personal information has infringed your rights under the PIPL, you may file a complaint with the Cyberspace Administration of China or another competent authority. We are committed to cooperating with regulatory inquiries and to resolving complaints in good faith.
13. Third-Party Websites and Services
Our Website may contain links to third-party websites, platforms, tools, or resources that are not owned, operated, or controlled by Anqing BoatReach Trading Co., Ltd. These links are provided solely for your convenience and informational purposes. When you click on a link to a third-party website, you are leaving our Website, and the privacy practices, data collection policies, and terms of use of that third party will govern your interaction—not this Privacy Policy.
We do not exercise control over the content, security, or privacy practices of third-party websites, and we make no representations or warranties regarding them. The inclusion of a link does not constitute our endorsement of the linked website, its operator, or its practices. We encourage you to review the privacy policy of every website you visit, particularly before providing any personal information. If you encounter a link on our Website that you believe leads to a platform with questionable privacy or security practices, please bring it to our attention and we will evaluate whether the link should be removed or accompanied by additional context.
Common categories of third-party services that may be linked from our Website or referenced in our consulting materials include cloud platform providers (such as Amazon Web Services, Google Cloud Platform, and Microsoft Azure), open-source project repositories (such as GitHub and GitLab), industry standards organizations (such as ISO, NIST, and IEEE), and professional community platforms. These organizations have their own privacy policies, and we recommend familiarizing yourself with them if your engagement with BoatReach leads you to interact with their platforms.
14. Client Project Confidentiality
As a professional systems design and consulting firm, we are entrusted with sensitive technical and business information belonging to our clients. This information—which may include proprietary system architectures, trade secrets, strategic business plans, unreleased product specifications, security vulnerability assessments, internal infrastructure documentation, and source code—is subject to confidentiality obligations that extend well beyond the protections described in this Privacy Policy. The handling of client project information is governed by the terms of individual services agreements, statements of work, and non-disclosure agreements executed between BoatReach and each client, which provide stronger and more specific protections than this general privacy framework.
We maintain strict information barriers between client engagements. Consultants assigned to one client project do not have access to the confidential information of another client unless explicit authorization has been granted—for example, where two clients have entered into a joint venture or partnership and both have consented to shared access. Our internal systems, communication channels, and document repositories are organized to enforce this segregation by design, not merely by policy. We consider the confidentiality of client information to be a cornerstone of our professional reputation and a prerequisite for the trust that our clients place in us when they share their most critical technical and strategic information.
In the event of a data security incident that affects client project information, our notification obligations are governed by the terms of the applicable services agreement, which may require faster notification timelines and more detailed forensic reporting than those described in Section 17 of this policy. We encourage prospective clients to discuss confidentiality requirements during the scoping phase of an engagement so that appropriate contractual protections can be put in place before any sensitive information is shared.
15. Privacy for Children
Our Website is not designed, intended, or directed at individuals under the age of 18. We do not knowingly collect, solicit, or process personal information from anyone under the age of 16, and we do not offer services to minors. The professional systems design and consulting services we provide are inherently oriented toward businesses and adult professionals, and we have no commercial reason to engage with children through our Website or services.
If we become aware that we have inadvertently collected personal information from an individual under the age of 16 without verified parental consent, we will take immediate steps to delete that information from our systems. If you are a parent or legal guardian and you believe that your child has provided personal information to us through our Website or any other channel, please contact us promptly using the contact details provided in Section 11 so that we can investigate and, if confirmed, remove the data. We also encourage parents and guardians to monitor their children internet usage and to instruct them never to provide personal information through websites without permission.
We do not condition participation in any activity or service on the provision of more personal information than is reasonably necessary, and we do not use any information that may relate to children for marketing or advertising purposes under any circumstances. If applicable law in your jurisdiction establishes an age threshold different from 16, the higher threshold will apply to your interaction with our Website to the extent required by that law.
16. Do Not Track Signals
Some web browsers offer a Do Not Track (DNT) setting that sends a signal to websites indicating the user preference not to be tracked across websites over time. The DNT signal is transmitted as an HTTP header field and is designed to provide a simple, universal mechanism for expressing privacy preferences. However, there is currently no consensus among industry participants, standards bodies, or regulators about how websites should interpret and respond to DNT signals, and no legally binding standard governs DNT implementation.
Given the absence of a standardized interpretation framework, our Website does not currently alter its data collection or processing practices in response to DNT signals. This does not mean that we track you: as described throughout this policy, we do not engage in cross-site tracking, behavioral advertising, or user profiling regardless of whether a DNT signal is present. Our data collection practices are already aligned with the privacy preferences that a DNT signal is intended to express. If a widely adopted industry or regulatory standard for responding to DNT signals emerges in the future, we will evaluate and, where appropriate, implement compliance with that standard. We will update this section of our Privacy Policy to reflect any changes in our DNT practices.
17. Data Breach Notification
We maintain an incident response plan designed to detect, contain, and remediate security incidents involving personal information. In the unfortunate event of a data breach—defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal information transmitted, stored, or otherwise processed by us—we will activate our incident response procedures without delay.
Our incident response process includes the following key steps: immediate containment to prevent further unauthorized access or data loss; forensic investigation to determine the scope, cause, and impact of the breach; assessment of the risk to affected individuals based on the nature, sensitivity, and volume of data involved; remediation of the underlying vulnerability or misconfiguration that enabled the breach; and notification to affected individuals and relevant regulatory authorities as required by applicable law. For breaches affecting individuals in the EEA or the United Kingdom, we will notify the competent supervisory authority within seventy-two hours of becoming aware of the breach, where feasible and where the breach is likely to result in a risk to the rights and freedoms of individuals. For breaches posing a high risk, we will also notify affected individuals without undue delay.
For breaches affecting client project information, we will follow the notification procedures specified in the applicable services agreement, which may impose additional or more stringent requirements. We maintain breach documentation records, including the facts surrounding the incident, its effects, and the remedial actions taken, as required by applicable data protection laws. We continuously refine our incident response capabilities based on lessons learned from tabletop exercises, industry case studies, and the evolving threat landscape.
18. Data Minimization and Purpose Limitation
Data minimization and purpose limitation are not merely legal requirements—they are engineering principles that we apply to the design of our information systems. The principle of data minimization holds that we should collect only the personal information that is directly relevant and strictly necessary for the specified purposes of processing. The principle of purpose limitation holds that personal information collected for one purpose should not be repurposed for an unrelated purpose without the consent of the data subject or a clear legal basis.
We operationalize these principles through several concrete practices. When designing a new data collection touchpoint—such as a contact form field, an email intake process, or a project documentation template—we first identify the specific purpose the data will serve and then determine the minimum set of data fields required to achieve that purpose. We reject requests to add data collection fields that are merely nice-to-have rather than strictly necessary. We periodically audit our data inventories to identify information that is no longer needed, has exceeded its retention period, or was collected for a purpose that has since been fulfilled, and we initiate deletion or anonymization of such data.
We also apply purpose limitation by maintaining clear documentation of the purposes for which each category of personal information is processed and ensuring that access to that information is restricted to personnel and systems that require it for those purposes. If we contemplate using existing data for a new purpose that is not compatible with the original purpose of collection, we will conduct an assessment to determine whether the new purpose is compatible and, where required by law, will notify you and obtain your consent before proceeding. These practices are part of our broader commitment to data governance that respects both the letter and the spirit of privacy regulations.