Privacy Policy

CSG

Website Privacy & Data Protection Policy

Effective Date: [December 5th, 2025]  |  Version 1.0

Applies to: https://www.csgfuture.com

 

Your Privacy Matters to Us

CSG Smart Science &Technology Co., Ltd. ("CSG", "we", "us", "our") is committed to respecting and protecting your privacy. This Privacy & Data Protection Policy ("Policy") explains what personal data we collect when you use our website at https://www.csgfuture.com (the "Website"), how we use it, who we share it with, how we keep it safe, and the rights you have over your data. CSG is a company incorporated in the People's Republic of China, with its registered address at No. 777, Sizhuan Road, Shanghai, China. This Website is directed exclusively at users outside the People's Republic of China.

 

. Regional Addenda

We tailor our practices to comply with specific regional regulations. If you reside in one of the following regions, please refer to the applicable addendum for details on your specific rights and our legal bases for processing your data:

 

Region

Applicable Addendum / Framework

European Economic Area (EEA) & EU

EU/EEA Addendum — GDPR (Regulation 2016/679). Our EU Representative under Art. 27 GDPR:

United Kingdom (UK)

UK Addendum — UK GDPR & Data Protection Act 2018.

United States of America

US Addendum — CCPA/CPRA (California) and applicable state laws. See also 'Do Not Sell or Share' notice in website footer.

Kingdom of Saudi Arabia

KSA Addendum — Personal Data Protection Law (PDPL) enforced by SDAIA. Cross-border transfers require SDAIA-compliant safeguards.

United Arab Emirates

UAE Addendum — Federal PDPL (Decree-Law No. 45/2021). Processing of UAE residents' data is subject to this law regardless of our location.

Other Jurisdictions

This global Policy applies. We strive to apply the highest applicable standard across all regions.

 


Table of Contents

1. Personal Data We Collect

2. How We Use Your Personal Data

3. Legal Bases for Processing

4. Cookies and Similar Technologies

5. Third-Party Services and Social Plugins

6. Sharing of Personal Data

7. Cross-Border Transfer of Personal Data

8. How We Protect Your Personal Data

9. Data Retention and Deletion

10. Your Rights and Choices

11. Special Protections for Minors

12. Automated Decision-Making and Profiling

13. Data Breach Notification

14. Updates to This Policy

15. Contact Us & Data Protection Officer

 


1. Personal Data We Collect

Personal data means any information relating to an identified or identifiable natural person. Depending on how you interact with the Website, we may collect the following categories:

 

1.1 Data You Provide Directly

Field

Details

Account Registration

Name, email address, password, country/region, company name, job title, phone number (optional). Collected when you create a user account.

Lead Generation / Contact Forms

Name, work email, phone, country, city, company, inquiry type, description of requirements, products of interest, purchase timeline (optional), budget (optional), energy type requirement, how you heard about CSG. Collected via forms on the Website.

Marketing Subscription

Name, email, country, city (optional), postal code (optional), company (optional), topics of interest. Collected when you subscribe to marketing communications.

Event / Webinar Registration

Name, email, company, country, product/service of interest, date of attendance. Collected when you register for CSG events.

Event Surveys / Questionnaires

Email, survey responses (open-ended and closed questions). Collected when you complete event feedback forms.

Customer Service – Email

Email content including sender, recipient, timestamp, and the substance of your inquiry. Collected when you contact us by email.

Customer Service – Phone

Call recording (only with your explicit prior consent), call metadata (number, time, duration). Collected when you contact our customer service line.

 

1.2 Data We Collect Automatically

When you visit the Website, the following data is automatically collected for security and performance purposes:

Field

Details

Log Data

IP address, browser type and version, operating system, referring URL, pages viewed, time zone, session duration, source channel tag, website interaction score.

Cookie & Tracker Data

Cookie identifiers, advertising IDs, pixel data from social and analytics platforms. See Section 4 for full details.

Device & Connection Data

Device type, screen resolution, network routing information, language preference.

 

1.3 Data We Do Not Collect

CSG does not seek to collect special categories of personal data (sensitive data) such as racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, or financial account details through this Website. If you voluntarily disclose such information (e.g. in a free-text field), we will handle it with heightened care and apply appropriate safeguards.

 


2. How We Use Your Personal Data

We process your personal data only for specified, explicit, and legitimate purposes. The table below sets out each processing activity, its purpose, legal basis, data involved, recipients, and retention period.

 

2.1 User Account Registration

Field

Details

Purpose

To create and maintain your user account; to provide account-linked services on the Website.

Legal Basis

Contractual Necessity (Art. 6(1)(b) GDPR): processing is necessary to perform the user account contract. Without this data, we cannot create your account.

Personal Data

Name, email, password (hashed), country/region, company, phone (if provided), auto-generated user ID, creation/modification/login timestamps, activation status.

Recipients

Hosting and IT infrastructure service providers (under Data Processing Agreements).

Retention

For the duration of the account. Upon account deletion, data is anonymised within 30 days (see Section 9).

 

2.2 Lead Generation

Field

Details

Purpose

To respond to your product/service enquiry; to manage and develop our commercial relationship; to improve our products and services.

Legal Basis

Legitimate Interests (Art. 6(1)(f) GDPR): responding to enquiries and maintaining commercial relationships. For residents of jurisdictions where Legitimate Interests is not recognised as a standalone basis (e.g. certain GCC countries), we rely on your consent provided at the time of form submission. You have the right to object to processing under Legitimate Interests at any time (see Section 10.6).

Personal Data

Name, email, phone, country, city, company, inquiry type, description of requirements, products of interest, purchase timeline (optional), budget (optional), energy type requirement, acquisition channel.

Recipients

CRM and customer service third-party providers (under Data Processing Agreements).

Retention

Active leads: reviewed every 18 months from last engagement. If no commercial relationship develops and no engagement for 18 months: securely deleted or anonymised. If a commercial relationship results: retained for the duration of the relationship plus 10 years for legal/tax/warranty obligations.

 

2.3 Marketing Email Subscription

Field

Details

Purpose

To send you product updates, event invitations, industry insights, and promotional communications aligned with your stated interests, where you have opted in to receive such communications.

Legal Basis

Consent (Art. 6(1)(a) GDPR and equivalent under Saudi Arabia PDPL, UAE PDPL): explicit opt-in at the time of subscription. For jurisdictions where Legitimate Interests is recognised as sufficient for B2B marketing communications (e.g. certain EU member states under ePrivacy rules), we may rely on that basis where you have a prior commercial relationship with CSG and the communication is relevant to your business activities, subject to your right to object at any time. You may withdraw your consent or object to processing at any time without affecting the lawfulness of prior processing (see Section 10.7).

Personal Data

Name, work email address, country, company (optional), topics of interest, consent timestamp, consent source (e.g. form URL), and IP address at time of subscription.

Recipients

Email marketing service providers (under Data Processing Agreements).

Retention

Until you withdraw consent or unsubscribe. Unsubscribe requests are processed within 10 business days. Consent records (including withdrawal records) are retained for 5 years for compliance purposes.

 

2.4 Proactive Marketing Communications (Outbound Email)

Field

Details

Purpose

To send product information, company updates, and promotional materials by email to prospective business customers who have not previously subscribed, where we have a legitimate basis to do so.

Legal Basis

Legitimate Interests (Art. 6(1)(f) GDPR) for EU/UK B2B contacts where the communication is relevant to the recipient's role or business activities, and where our interest in promoting our services does not override the recipient's rights. Explicit Consent for contacts in Saudi Arabia (PDPL), UAE (PDPL), and other jurisdictions requiring prior consent for commercial communications. We will not send proactive marketing emails to recipients in jurisdictions requiring prior consent unless that consent has been obtained and documented.

Personal Data

Name, business email address, company name, job title, country, and any prior interaction data indicating relevance.

Recipients

Email marketing and CRM service providers (under Data Processing Agreements).

Retention

Active contacts: reviewed every 18 months. Opt-out and suppression records retained indefinitely to honour unsubscribe requests. If no engagement or commercial relationship within 18 months, contact data is deleted or anonymised.

Your Rights

Every outbound marketing email will include: (i) clear identification of CSG as the sender; (ii) a physical or registered address; (iii) a clear and functional unsubscribe/opt-out mechanism; and (iv) the ability to opt out of all future marketing communications. Opt-out requests are processed within 10 business days. You may also contact us at privacy@csgfuture.com to be added to our suppression list.

 

2.5 Event / Webinar Registration

Field

Details

Purpose

To process your event registration; to communicate event details; to conduct post-event follow-up and analysis.

Legal Basis

Contractual Necessity (Art. 6(1)(b) GDPR) for event-related communications; Legitimate Interests for post-event analysis.

Personal Data

Name, email, company, country, product/service of interest, date.

Recipients

Event management service providers (under Data Processing Agreements).

Retention

12 months from the date of the event for post-event communication and analysis; thereafter anonymised or deleted.

 

2.6 Event Surveys

Field

Details

Purpose

To collect feedback to improve events, products, and services.

Legal Basis

Consent (Art. 6(1)(a) GDPR).

Personal Data

Email, survey responses.

Recipients

Survey platform service providers (under Data Processing Agreements).

Retention

12 months from the date of survey completion, then deleted.

 

2.7 Customer Service – Email

Field

Details

Purpose

To respond to your enquiry; to fulfil contractual obligations where the communication relates to an existing contract.

Legal Basis

Contractual Necessity (Art. 6(1)(b) GDPR) where applicable; Legitimate Interests (Art. 6(1)(f) GDPR) for general enquiries.

Personal Data

Email content including sender, recipient, timestamp.

Recipients

Customer service platform providers (under Data Processing Agreements).

Retention

6 months from the date of the email interaction for general enquiries; up to 10 years where the email relates to a contractual or warranty matter.

 

2.8 Customer Service – Phone Recording

Field

Details

Purpose

To accurately process your enquiry; for quality assurance; for staff training.

Legal Basis

Explicit Consent (Art. 6(1)(a) GDPR). Before any recording begins, you will be clearly informed and asked for your explicit consent. If you do not consent, the call will proceed unrecorded and this will not affect the service provided to you.

Personal Data

Call recording, call metadata (number, time, duration), personal data mentioned during the call.

Recipients

Customer service platform providers (under Data Processing Agreements).

Retention

6 months from the date of the call.

 

2.9 Website Security and Performance

Field

Details

Purpose

To ensure the security, stability, and proper functioning of the Website; to diagnose errors and prevent fraud.

Legal Basis

Legitimate Interests (Art. 6(1)(f) GDPR): ensuring a secure and operational website. For jurisdictions where Legitimate Interests may not be available, this processing is technically necessary for the operation of the service.

Personal Data

Log Data: source IP, time zone, request date/time, browser type, OS, pages viewed, referrer URL, session events, source channel tag.

Recipients

Website hosting and security service providers (under Data Processing Agreements).

Retention

90 days from the date of collection, unless a security incident requires longer retention for investigation purposes.



3. Legal Bases for Processing

Under the GDPR and equivalent laws, we must have a valid legal basis for each processing activity. The primary bases we rely on are:

 

Legal Basis

When We Use It

Consent

Marketing email subscriptions; phone call recording; analytics, functional, and advertising cookies (where prior consent is required by applicable law, including in EU/EEA, UK, Saudi Arabia, and UAE). Outbound marketing communications to contacts in Saudi Arabia and UAE. You may withdraw consent at any time.

Contractual Necessity

Account registration; event registration; fulfilment of purchase-related enquiries. Processing is necessary to perform our agreement with you.

Legitimate Interests

Lead generation responses; B2B outbound marketing emails to EU/UK contacts (where relevant to their role and business); website security; post-event analysis; fraud prevention. We have conducted a Legitimate Interests Assessment (LIA) and concluded our interests do not override your fundamental rights. You have the right to object at any time.

Legal Obligation

Compliance with tax, accounting, statutory retention, and other mandatory legal requirements.

 


4. Cookies and Similar Technologies

We use cookies and similar tracking technologies on our Website. A cookie is a small text file stored on your device when you visit a website. We use the following categories of cookies:

 

Category

Purpose

Consent Requirement by Region

Strictly Necessary

Essential for the Website to function (e.g. session management, security). Cannot be disabled without impairing the Website.

No consent required in any jurisdiction — technically necessary for service delivery.

Performance / Analytics

Measure Website traffic, identify popular pages, and analyse user behaviour to improve the Website.

EU/EEA: explicit opt-in required (ePrivacy Directive + GDPR). UK: explicit opt-in required; purely aggregate analytics may qualify for opt-out under DUAA 2025 if no cross-site tracking is involved. Saudi Arabia / UAE: explicit opt-in required (PDPL). USA: opt-out mechanism sufficient (no prior consent required under most US state laws). Australia / Others: notice + opt-out sufficient.

Functional

Remember your preferences (e.g. language, country selection) and personalise your experience.

EU/EEA/UK: consent required if beyond strictly necessary. Other regions: generally no prior consent required if clearly disclosed.

Targeting / Advertising

Used by advertising partners to build interest profiles and serve relevant advertisements on third-party sites.

Explicit opt-in consent required in EU/EEA, UK, Saudi Arabia, and UAE. Opt-out mechanism sufficient in USA and most other markets. You may opt out at any time via cookie settings.

 

We use a cookie consent management platform (CMP) to manage your preferences. Where you are located in a jurisdiction requiring prior consent (EU/EEA, UK, Saudi Arabia, UAE), our Website will display a cookie consent banner requiring your active opt-in before any non-essential cookies are placed. Where opt-out is the applicable standard (USA and most other markets), non-essential cookies may be set by default but you may withdraw at any time via the cookie settings panel.

You can manage or withdraw your cookie consent at any time by clicking the "Cookie Settings" link in the footer of our Website. Disabling certain cookies may affect Website functionality. Your consent preferences are re-requested annually or when material changes occur to our cookie usage.

 

 

5. Third-Party Services and Social Plugins

Our Website incorporates social plugins from LinkedIn, Instagram, Facebook, X (Twitter), and YouTube. These plugins are deactivated by default. No data is transmitted to the respective network operators unless and until you choose to activate the plugin by clicking on it.

Once activated, the social network may receive information about your visit and associate it with your account on that network (if you are logged in). We have no control over data collected by third-party networks after plugin activation. We recommend reviewing the privacy policies of those networks before activating any plugin.

If you use third-party links on our Website, those external websites have their own privacy practices for which we are not responsible.

Where we use third-party analytics or advertising tools (e.g. Google Analytics, LinkedIn Insight Tag), these are disclosed in our Cookie Policy and managed via our cookie consent platform.

 


6. Sharing of Personal Data

6.1 Service Providers

We share your personal data with carefully selected third-party service providers who assist us in operating the Website and delivering our services, including:

 Cloud hosting and infrastructure providers (Alibaba Cloud, Hong Kong)

 CRM and customer service platforms

 Email marketing platforms

 Event management and survey platforms

 Website analytics and security providers

 Customer support platforms

 

All service providers are engaged under written Data Processing Agreements (DPAs) or equivalent binding contracts that: (i) restrict processing to our documented instructions; (ii) require appropriate technical and organisational security measures; (iii) impose confidentiality obligations; (iv) require prior approval for sub-processing; and (v) mandate compliance with applicable data protection laws. We conduct periodic reviews of our service providers' compliance.

 

6.2 Affiliates and Group Companies

We may share your personal data within the CSG group of companies for the purposes described in this Policy. All intra-group transfers are subject to the same data protection standards and, where required, are governed by intra-group data transfer agreements.

 

6.3 Government and Law Enforcement

We may disclose personal data to government authorities, regulators, or law enforcement agencies where required by applicable law, a court order, or for the protection of our legitimate legal interests, provided that such disclosure is consistent with applicable data protection law and the minimum necessary data is disclosed.

 

6.4 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or part of our business or assets, your personal data may be transferred to the relevant third party, subject to that party committing to protect your personal data in a manner consistent with this Policy.

 

6.5 We Do Not Sell Your Personal Data

CSG does not sell, rent, or trade your personal data to third parties for their own independent marketing or commercial purposes.

 

US Residents — Do Not Sell or Share

If you are a California resident (or resident of another US state with applicable opt-out rights), you may opt out of the 'sale' or 'sharing' of your personal data for cross-context behavioural advertising purposes. Please use the 'Do Not Sell or Share My Personal Information' link in the footer of our Website, or contact us at privacy@csgfuture.com.

 

 

7. Cross-Border Transfer of Personal Data

As a company registered in the People's Republic of China operating a globally accessible website with infrastructure hosted in Hong Kong SAR, your personal data may be transferred to and processed in countries other than your country of residence. This includes transfers to Hong Kong SAR (our primary hosting location), mainland China (where our registered entity and some personnel are located), and other countries where our service providers operate.

 

We ensure that all cross-border transfers of personal data are subject to appropriate safeguards, which may include:

 Adequacy decisions: transfers to countries or territories recognised by the relevant authority (e.g. the European Commission, UK ICO, or Saudi Arabia's SDAIA) as providing an adequate level of data protection.

 Standard Contractual Clauses (SCCs): European Commission-approved SCCs (Implementing Decision 2021/914) or UK International Data Transfer Agreements (IDTAs) for transfers of EEA/UK personal data to Hong Kong SAR and other third countries. Hong Kong SAR does not currently benefit from an EU or UK adequacy decision; accordingly, SCCs supplemented by a Transfer Impact Assessment (TIA) are the applicable transfer mechanism.

 Binding Corporate Rules (BCRs) or equivalent intra-group transfer mechanisms where applicable.

 Saudi Arabia PDPL: transfers of KSA residents' data outside the Kingdom are conducted in accordance with SDAIA's Regulation on Personal Data Transfer Outside the Kingdom (updated September 2024), including obtaining any necessary approvals or relying on applicable exemptions recognised by SDAIA.

 

China PIPL Notice (Internal Processing)

CSG is registered in the People's Republic of China. Where personal data collected from individuals outside China is accessed or processed by our personnel or internal systems located in mainland China, such processing is governed by China's Personal Information Protection Law (PIPL) and the CAC Provisions on Regulating and Promoting Cross-Border Data Flows (effective 22 March 2024). We have implemented the appropriate cross-border transfer mechanism required under PIPL (Standard Contractual Clauses recognised by the Cyberspace Administration of China, or other applicable pathway) for any such transfers.

 

Our Website infrastructure is operated by a third-party cloud hosting provider with servers located in Hong Kong SAR. This provider acts as a data processor on our behalf under a Data Processing Agreement (DPA) that incorporates Standard Contractual Clauses and requires the provider to maintain appropriate technical and organisational security measures.

 

You may request a copy of the applicable safeguards governing transfers of your personal data by contacting us at privacy@csgfuture.com. We will respond within 30 days.

 

 

8. How We Protect Your Personal Data

CSG implements appropriate technical and organisational security measures designed to protect your personal data from unauthorised access, disclosure, alteration, or destruction. These measures include:

 Transport Layer Security (TLS/HTTPS) encryption for all data in transit.

 Encryption of data at rest for sensitive categories of personal data.

 Role-based access controls and the principle of least privilege for systems holding personal data.

 Regular security assessments and penetration testing of the Website.

 Staff training on data protection and information security.

 Incident response procedures, including breach detection and notification protocols (see Section 13).

 

No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at privacy@csgfuture.com.



9. Data Retention and Deletion

We retain personal data only for as long as necessary to fulfil the purposes described in Section 2, to comply with our legal obligations (e.g. tax and accounting requirements, statutory limitation periods), to resolve disputes, and to enforce our agreements. The specific retention periods for each processing activity are set out in Section 2.

 

Upon expiry of the applicable retention period, or upon a valid deletion request (see Section 10.3), we will securely delete or irreversibly anonymise your personal data. Where immediate deletion is not technically feasible, the data will be securely isolated from active processing until deletion is possible.

 

Account Deletion

When you request deletion of your account, your personal data will be anonymised within 30 days of your request. During this period, your account will be deactivated and your data will not be used for any active processing. After anonymisation, no data linked to your identity will be retained, except where we have a separate legal obligation to do so (e.g. transaction records for tax purposes).

 

 

10. Your Rights and Choices

Depending on your country or region of residence, you may have some or all of the following rights. We are committed to honouring these rights regardless of your location, subject to applicable law. To exercise any of these rights, please contact us at privacy@csgfuture.com. We will respond within the timeframe required by the applicable law of your jurisdiction (e.g. 30 days under GDPR; 15 business days under Saudi Arabia PDPL).

 

Right

Description

Access (Right to Know)

Request a copy of the personal data we hold about you, including information on how it is processed.

Rectification (Correction)

Request correction of inaccurate or incomplete personal data.

Erasure (Right to Delete)

Request deletion of your personal data under certain conditions: the data is no longer necessary; you withdraw consent and no other basis applies; you have successfully objected; or applicable law requires deletion.

Restriction of Processing

Request that we limit processing of your data while accuracy is disputed, or while an objection is being assessed.

Data Portability

Receive your personal data in a structured, machine-readable format, where processing is based on consent or contract and carried out by automated means.

Right to Object

Object to processing based on Legitimate Interests (including profiling) or direct marketing. Where you object to direct marketing, we will cease such processing immediately.

Withdraw Consent

Where processing is based on your consent, withdraw it at any time. Withdrawal does not affect the lawfulness of prior processing. You can unsubscribe from marketing emails via the 'Unsubscribe' link in every email.

Non-Discrimination (US)

You will not be discriminated against for exercising your privacy rights (e.g. refused service or given a lower quality of service).

Opt-Out of Sale/Sharing (US)

California and other US state residents may opt out of the 'sale' or 'sharing' of personal data for targeted advertising. Use the footer link or contact privacy@csgfuture.com.

Lodge a Complaint

You have the right to lodge a complaint with the supervisory authority competent for your jurisdiction, including: EU: your national Data Protection Authority; UK: Information Commissioner's Office (ICO); Saudi Arabia: SDAIA; UAE: Federal Authority for Identity, Citizenship, Customs and Port Security (ICP) / relevant authority; USA: State Attorney General.

 

 

11. Special Protections for Minors

The Website is directed at business professionals and is not intended for use by children or minors. We do not knowingly collect or process personal data from individuals under the following ages: under 16 years (EU/UK); under 13 years (USA — COPPA); under 18 years (Saudi Arabia — PDPL). If you are a parent or guardian and believe that your child has provided us with personal data, please contact us immediately at privacy@csgfuture.com and we will delete such data promptly (and in any event within 15 business days of notification).

 

 

12. Automated Decision-Making and Profiling

Our Website collects Website interaction data including a behavioural scoring indicator derived from your browsing activity. This scoring is used to prioritise internal follow-up activities and improve Website performance. It does not constitute a solely automated decision that produces legal or similarly significant effects on you.

We do not make any decisions about you (including decisions about whether to provide services, set pricing, or evaluate your creditworthiness) based solely on automated processing, without human review and oversight. If this practice changes, we will update this Policy and, where required by applicable law (e.g. GDPR Art. 22), we will seek your explicit consent or implement other appropriate safeguards.

 

 

13. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will:

 Notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (GDPR Art. 33; UK GDPR; Saudi Arabia PDPL Art. 25 — within 72 hours of discovery).

 Where the breach is likely to result in a high risk to affected individuals, notify those individuals directly without undue delay, in clear and plain language describing the nature of the breach and the steps we are taking.

 Maintain a breach register documenting all breaches, including those not requiring notification.

 

We maintain a documented incident response procedure and have appointed a dedicated point of contact for data security incidents. For urgent security concerns, please contact: privacy@csgfuture.com.

 

 

14. Updates to This Policy

We may update this Policy from time to time to reflect changes in our data practices, applicable laws, or regulatory guidance. When we make material changes, we will:

 Post the updated Policy on our Website with a new 'Effective Date'.

 Notify registered users by email at least 30 days before the changes take effect, where the changes affect how we process their personal data.

 Where changes require renewed consent (e.g. new processing activities based on consent), we will request your consent again before commencing such processing.

 

We encourage you to review this Policy periodically. Your continued use of the Website after the effective date of a revised Policy constitutes acceptance of the changes, to the extent permitted by applicable law.

 

 

15. Contact Us

For any questions, requests, complaints, or concerns about this Policy or our data practices, please contact us using the details below. We are committed to addressing your concerns promptly and in accordance with applicable law.

Email: info@csgfuture.com

Website: https://www.csgfuture.com/


Appendix: Key Definitions

Term

Definition

Personal Data

Any information relating to an identified or identifiable natural person ('data subject').

Processing

Any operation performed on personal data, including collection, recording, storage, use, disclosure, or deletion.

Data Controller

The entity that determines the purposes and means of processing personal data. CSG is the data controller for this Website.

Data Processor

An entity that processes personal data on behalf of the controller (e.g. our service providers).

GDPR

The EU General Data Protection Regulation (2016/679).

UK GDPR

The UK version of the GDPR as retained and amended by the Data Protection Act 2018.

CCPA/CPRA

California Consumer Privacy Act and California Privacy Rights Act.

PDPL (KSA)

Saudi Arabia Personal Data Protection Law, enforced by SDAIA from 14 September 2024.

PDPL (UAE)

UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.

PIPL

China Personal Information Protection Law (2021).

SCCs

Standard Contractual Clauses — contractual safeguards approved by the European Commission for cross-border data transfers.

DPO

Data Protection Officer — a designated individual responsible for overseeing data protection strategy and compliance.

LIA

Legitimate Interests Assessment — a documented balancing test performed to justify processing under the Legitimate Interests basis.

 

© 2025 CSG. All rights reserved.

This Policy applies to the CSG Website at https://www.csgfuture.com. It does not apply to any other CSG products, services, or offline activities unless specifically stated.

Contact us

Stay up-to-date on the latest innovations and product announcements from CSG