CSG
Website Privacy & Data Protection Policy
Effective Date: [December 5th, 2025] | Version 1.0
Applies to: https://www.csgfuture.com
Your Privacy Matters to Us CSG Smart Science &Technology Co., Ltd. ("CSG", "we", "us", "our") is committed to respecting and protecting your privacy. This Privacy & Data Protection Policy ("Policy") explains what personal data we collect when you use our website at https://www.csgfuture.com (the "Website"), how we use it, who we share it with, how we keep it safe, and the rights you have over your data. CSG is a company incorporated in the People's Republic of China, with its registered address at No. 777, Sizhuan Road, Shanghai, China. This Website is directed exclusively at users outside the People's Republic of China. |
. Regional Addenda
We tailor our practices to comply with specific regional regulations. If you reside in one of the following regions, please refer to the applicable addendum for details on your specific rights and our legal bases for processing your data:
Region | Applicable Addendum / Framework |
European Economic Area (EEA) & EU | EU/EEA Addendum — GDPR (Regulation 2016/679). Our EU Representative under Art. 27 GDPR: |
United Kingdom (UK) | UK Addendum — UK GDPR & Data Protection Act 2018. |
United States of America | US Addendum — CCPA/CPRA (California) and applicable state laws. See also 'Do Not Sell or Share' notice in website footer. |
Kingdom of Saudi Arabia | KSA Addendum — Personal Data Protection Law (PDPL) enforced by SDAIA. Cross-border transfers require SDAIA-compliant safeguards. |
United Arab Emirates | UAE Addendum — Federal PDPL (Decree-Law No. 45/2021). Processing of UAE residents' data is subject to this law regardless of our location. |
Other Jurisdictions | This global Policy applies. We strive to apply the highest applicable standard across all regions. |
Table of Contents
1. Personal Data We Collect
2. How We Use Your Personal Data
3. Legal Bases for Processing
4. Cookies and Similar Technologies
5. Third-Party Services and Social Plugins
6. Sharing of Personal Data
7. Cross-Border Transfer of Personal Data
8. How We Protect Your Personal Data
9. Data Retention and Deletion
10. Your Rights and Choices
11. Special Protections for Minors
12. Automated Decision-Making and Profiling
13. Data Breach Notification
14. Updates to This Policy
15. Contact Us & Data Protection Officer
1. Personal Data We Collect
Personal data means any information relating to an identified or identifiable natural person. Depending on how you interact with the Website, we may collect the following categories:
Field | Details |
Account Registration | Name, email address, password, country/region, company name, job title, phone number (optional). Collected when you create a user account. |
Lead Generation / Contact Forms | Name, work email, phone, country, city, company, inquiry type, description of requirements, products of interest, purchase timeline (optional), budget (optional), energy type requirement, how you heard about CSG. Collected via forms on the Website. |
Marketing Subscription | Name, email, country, city (optional), postal code (optional), company (optional), topics of interest. Collected when you subscribe to marketing communications. |
Event / Webinar Registration | Name, email, company, country, product/service of interest, date of attendance. Collected when you register for CSG events. |
Event Surveys / Questionnaires | Email, survey responses (open-ended and closed questions). Collected when you complete event feedback forms. |
Customer Service – Email | Email content including sender, recipient, timestamp, and the substance of your inquiry. Collected when you contact us by email. |
Customer Service – Phone | Call recording (only with your explicit prior consent), call metadata (number, time, duration). Collected when you contact our customer service line. |
When you visit the Website, the following data is automatically collected for security and performance purposes:
Field | Details |
Log Data | IP address, browser type and version, operating system, referring URL, pages viewed, time zone, session duration, source channel tag, website interaction score. |
Cookie & Tracker Data | Cookie identifiers, advertising IDs, pixel data from social and analytics platforms. See Section 4 for full details. |
Device & Connection Data | Device type, screen resolution, network routing information, language preference. |
CSG does not seek to collect special categories of personal data (sensitive data) such as racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, or financial account details through this Website. If you voluntarily disclose such information (e.g. in a free-text field), we will handle it with heightened care and apply appropriate safeguards.
2. How We Use Your Personal Data
We process your personal data only for specified, explicit, and legitimate purposes. The table below sets out each processing activity, its purpose, legal basis, data involved, recipients, and retention period.
Field | Details |
Purpose | To create and maintain your user account; to provide account-linked services on the Website. |
Legal Basis | Contractual Necessity (Art. 6(1)(b) GDPR): processing is necessary to perform the user account contract. Without this data, we cannot create your account. |
Personal Data | Name, email, password (hashed), country/region, company, phone (if provided), auto-generated user ID, creation/modification/login timestamps, activation status. |
Recipients | Hosting and IT infrastructure service providers (under Data Processing Agreements). |
Retention | For the duration of the account. Upon account deletion, data is anonymised within 30 days (see Section 9). |
Field | Details |
Purpose | To respond to your product/service enquiry; to manage and develop our commercial relationship; to improve our products and services. |
Legal Basis | Legitimate Interests (Art. 6(1)(f) GDPR): responding to enquiries and maintaining commercial relationships. For residents of jurisdictions where Legitimate Interests is not recognised as a standalone basis (e.g. certain GCC countries), we rely on your consent provided at the time of form submission. You have the right to object to processing under Legitimate Interests at any time (see Section 10.6). |
Personal Data | Name, email, phone, country, city, company, inquiry type, description of requirements, products of interest, purchase timeline (optional), budget (optional), energy type requirement, acquisition channel. |
Recipients | CRM and customer service third-party providers (under Data Processing Agreements). |
Retention | Active leads: reviewed every 18 months from last engagement. If no commercial relationship develops and no engagement for 18 months: securely deleted or anonymised. If a commercial relationship results: retained for the duration of the relationship plus 10 years for legal/tax/warranty obligations. |
Field | Details |
Purpose | To send you product updates, event invitations, industry insights, and promotional communications aligned with your stated interests, where you have opted in to receive such communications. |
Legal Basis | Consent (Art. 6(1)(a) GDPR and equivalent under Saudi Arabia PDPL, UAE PDPL): explicit opt-in at the time of subscription. For jurisdictions where Legitimate Interests is recognised as sufficient for B2B marketing communications (e.g. certain EU member states under ePrivacy rules), we may rely on that basis where you have a prior commercial relationship with CSG and the communication is relevant to your business activities, subject to your right to object at any time. You may withdraw your consent or object to processing at any time without affecting the lawfulness of prior processing (see Section 10.7). |
Personal Data | Name, work email address, country, company (optional), topics of interest, consent timestamp, consent source (e.g. form URL), and IP address at time of subscription. |
Recipients | Email marketing service providers (under Data Processing Agreements). |
Retention | Until you withdraw consent or unsubscribe. Unsubscribe requests are processed within 10 business days. Consent records (including withdrawal records) are retained for 5 years for compliance purposes. |
Field | Details |
Purpose | To send product information, company updates, and promotional materials by email to prospective business customers who have not previously subscribed, where we have a legitimate basis to do so. |
Legal Basis | Legitimate Interests (Art. 6(1)(f) GDPR) for EU/UK B2B contacts where the communication is relevant to the recipient's role or business activities, and where our interest in promoting our services does not override the recipient's rights. Explicit Consent for contacts in Saudi Arabia (PDPL), UAE (PDPL), and other jurisdictions requiring prior consent for commercial communications. We will not send proactive marketing emails to recipients in jurisdictions requiring prior consent unless that consent has been obtained and documented. |
Personal Data | Name, business email address, company name, job title, country, and any prior interaction data indicating relevance. |
Recipients | Email marketing and CRM service providers (under Data Processing Agreements). |
Retention | Active contacts: reviewed every 18 months. Opt-out and suppression records retained indefinitely to honour unsubscribe requests. If no engagement or commercial relationship within 18 months, contact data is deleted or anonymised. |
Your Rights | Every outbound marketing email will include: (i) clear identification of CSG as the sender; (ii) a physical or registered address; (iii) a clear and functional unsubscribe/opt-out mechanism; and (iv) the ability to opt out of all future marketing communications. Opt-out requests are processed within 10 business days. You may also contact us at privacy@csgfuture.com to be added to our suppression list. |
Field | Details |
Purpose | To process your event registration; to communicate event details; to conduct post-event follow-up and analysis. |
Legal Basis | Contractual Necessity (Art. 6(1)(b) GDPR) for event-related communications; Legitimate Interests for post-event analysis. |
Personal Data | Name, email, company, country, product/service of interest, date. |
Recipients | Event management service providers (under Data Processing Agreements). |
Retention | 12 months from the date of the event for post-event communication and analysis; thereafter anonymised or deleted. |
Field | Details |
Purpose | To collect feedback to improve events, products, and services. |
Legal Basis | Consent (Art. 6(1)(a) GDPR). |
Personal Data | Email, survey responses. |
Recipients | Survey platform service providers (under Data Processing Agreements). |
Retention | 12 months from the date of survey completion, then deleted. |
Field | Details |
Purpose | To respond to your enquiry; to fulfil contractual obligations where the communication relates to an existing contract. |
Legal Basis | Contractual Necessity (Art. 6(1)(b) GDPR) where applicable; Legitimate Interests (Art. 6(1)(f) GDPR) for general enquiries. |
Personal Data | Email content including sender, recipient, timestamp. |
Recipients | Customer service platform providers (under Data Processing Agreements). |
Retention | 6 months from the date of the email interaction for general enquiries; up to 10 years where the email relates to a contractual or warranty matter. |
Field | Details |
Purpose | To accurately process your enquiry; for quality assurance; for staff training. |
Legal Basis | Explicit Consent (Art. 6(1)(a) GDPR). Before any recording begins, you will be clearly informed and asked for your explicit consent. If you do not consent, the call will proceed unrecorded and this will not affect the service provided to you. |
Personal Data | Call recording, call metadata (number, time, duration), personal data mentioned during the call. |
Recipients | Customer service platform providers (under Data Processing Agreements). |
Retention | 6 months from the date of the call. |
Field | Details |
Purpose | To ensure the security, stability, and proper functioning of the Website; to diagnose errors and prevent fraud. |
Legal Basis | Legitimate Interests (Art. 6(1)(f) GDPR): ensuring a secure and operational website. For jurisdictions where Legitimate Interests may not be available, this processing is technically necessary for the operation of the service. |
Personal Data | Log Data: source IP, time zone, request date/time, browser type, OS, pages viewed, referrer URL, session events, source channel tag. |
Recipients | Website hosting and security service providers (under Data Processing Agreements). |
Retention | 90 days from the date of collection, unless a security incident requires longer retention for investigation purposes. |
3. Legal Bases for Processing
Under the GDPR and equivalent laws, we must have a valid legal basis for each processing activity. The primary bases we rely on are:
Legal Basis | When We Use It |
Consent | Marketing email subscriptions; phone call recording; analytics, functional, and advertising cookies (where prior consent is required by applicable law, including in EU/EEA, UK, Saudi Arabia, and UAE). Outbound marketing communications to contacts in Saudi Arabia and UAE. You may withdraw consent at any time. |
Contractual Necessity | Account registration; event registration; fulfilment of purchase-related enquiries. Processing is necessary to perform our agreement with you. |
Legitimate Interests | Lead generation responses; B2B outbound marketing emails to EU/UK contacts (where relevant to their role and business); website security; post-event analysis; fraud prevention. We have conducted a Legitimate Interests Assessment (LIA) and concluded our interests do not override your fundamental rights. You have the right to object at any time. |
Legal Obligation | Compliance with tax, accounting, statutory retention, and other mandatory legal requirements. |
4. Cookies and Similar Technologies
We use cookies and similar tracking technologies on our Website. A cookie is a small text file stored on your device when you visit a website. We use the following categories of cookies:
Category | Purpose | Consent Requirement by Region |
Strictly Necessary | Essential for the Website to function (e.g. session management, security). Cannot be disabled without impairing the Website. | No consent required in any jurisdiction — technically necessary for service delivery. |
Performance / Analytics | Measure Website traffic, identify popular pages, and analyse user behaviour to improve the Website. | EU/EEA: explicit opt-in required (ePrivacy Directive + GDPR). UK: explicit opt-in required; purely aggregate analytics may qualify for opt-out under DUAA 2025 if no cross-site tracking is involved. Saudi Arabia / UAE: explicit opt-in required (PDPL). USA: opt-out mechanism sufficient (no prior consent required under most US state laws). Australia / Others: notice + opt-out sufficient. |
Functional | Remember your preferences (e.g. language, country selection) and personalise your experience. | EU/EEA/UK: consent required if beyond strictly necessary. Other regions: generally no prior consent required if clearly disclosed. |
Targeting / Advertising | Used by advertising partners to build interest profiles and serve relevant advertisements on third-party sites. | Explicit opt-in consent required in EU/EEA, UK, Saudi Arabia, and UAE. Opt-out mechanism sufficient in USA and most other markets. You may opt out at any time via cookie settings. |
We use a cookie consent management platform (CMP) to manage your preferences. Where you are located in a jurisdiction requiring prior consent (EU/EEA, UK, Saudi Arabia, UAE), our Website will display a cookie consent banner requiring your active opt-in before any non-essential cookies are placed. Where opt-out is the applicable standard (USA and most other markets), non-essential cookies may be set by default but you may withdraw at any time via the cookie settings panel.
You can manage or withdraw your cookie consent at any time by clicking the "Cookie Settings" link in the footer of our Website. Disabling certain cookies may affect Website functionality. Your consent preferences are re-requested annually or when material changes occur to our cookie usage.
5. Third-Party Services and Social Plugins
Our Website incorporates social plugins from LinkedIn, Instagram, Facebook, X (Twitter), and YouTube. These plugins are deactivated by default. No data is transmitted to the respective network operators unless and until you choose to activate the plugin by clicking on it.
Once activated, the social network may receive information about your visit and associate it with your account on that network (if you are logged in). We have no control over data collected by third-party networks after plugin activation. We recommend reviewing the privacy policies of those networks before activating any plugin.
If you use third-party links on our Website, those external websites have their own privacy practices for which we are not responsible.
Where we use third-party analytics or advertising tools (e.g. Google Analytics, LinkedIn Insight Tag), these are disclosed in our Cookie Policy and managed via our cookie consent platform.
6. Sharing of Personal Data
We share your personal data with carefully selected third-party service providers who assist us in operating the Website and delivering our services, including:
• Cloud hosting and infrastructure providers (Alibaba Cloud, Hong Kong)
• CRM and customer service platforms
• Email marketing platforms
• Event management and survey platforms
• Website analytics and security providers
• Customer support platforms
All service providers are engaged under written Data Processing Agreements (DPAs) or equivalent binding contracts that: (i) restrict processing to our documented instructions; (ii) require appropriate technical and organisational security measures; (iii) impose confidentiality obligations; (iv) require prior approval for sub-processing; and (v) mandate compliance with applicable data protection laws. We conduct periodic reviews of our service providers' compliance.
We may share your personal data within the CSG group of companies for the purposes described in this Policy. All intra-group transfers are subject to the same data protection standards and, where required, are governed by intra-group data transfer agreements.
We may disclose personal data to government authorities, regulators, or law enforcement agencies where required by applicable law, a court order, or for the protection of our legitimate legal interests, provided that such disclosure is consistent with applicable data protection law and the minimum necessary data is disclosed.
In the event of a merger, acquisition, restructuring, or sale of all or part of our business or assets, your personal data may be transferred to the relevant third party, subject to that party committing to protect your personal data in a manner consistent with this Policy.
CSG does not sell, rent, or trade your personal data to third parties for their own independent marketing or commercial purposes.
US Residents — Do Not Sell or Share If you are a California resident (or resident of another US state with applicable opt-out rights), you may opt out of the 'sale' or 'sharing' of your personal data for cross-context behavioural advertising purposes. Please use the 'Do Not Sell or Share My Personal Information' link in the footer of our Website, or contact us at privacy@csgfuture.com. |
7. Cross-Border Transfer of Personal Data
As a company registered in the People's Republic of China operating a globally accessible website with infrastructure hosted in Hong Kong SAR, your personal data may be transferred to and processed in countries other than your country of residence. This includes transfers to Hong Kong SAR (our primary hosting location), mainland China (where our registered entity and some personnel are located), and other countries where our service providers operate.
We ensure that all cross-border transfers of personal data are subject to appropriate safeguards, which may include:
• Adequacy decisions: transfers to countries or territories recognised by the relevant authority (e.g. the European Commission, UK ICO, or Saudi Arabia's SDAIA) as providing an adequate level of data protection.
• Standard Contractual Clauses (SCCs): European Commission-approved SCCs (Implementing Decision 2021/914) or UK International Data Transfer Agreements (IDTAs) for transfers of EEA/UK personal data to Hong Kong SAR and other third countries. Hong Kong SAR does not currently benefit from an EU or UK adequacy decision; accordingly, SCCs supplemented by a Transfer Impact Assessment (TIA) are the applicable transfer mechanism.
• Binding Corporate Rules (BCRs) or equivalent intra-group transfer mechanisms where applicable.
• Saudi Arabia PDPL: transfers of KSA residents' data outside the Kingdom are conducted in accordance with SDAIA's Regulation on Personal Data Transfer Outside the Kingdom (updated September 2024), including obtaining any necessary approvals or relying on applicable exemptions recognised by SDAIA.
China PIPL Notice (Internal Processing) CSG is registered in the People's Republic of China. Where personal data collected from individuals outside China is accessed or processed by our personnel or internal systems located in mainland China, such processing is governed by China's Personal Information Protection Law (PIPL) and the CAC Provisions on Regulating and Promoting Cross-Border Data Flows (effective 22 March 2024). We have implemented the appropriate cross-border transfer mechanism required under PIPL (Standard Contractual Clauses recognised by the Cyberspace Administration of China, or other applicable pathway) for any such transfers. |
Our Website infrastructure is operated by a third-party cloud hosting provider with servers located in Hong Kong SAR. This provider acts as a data processor on our behalf under a Data Processing Agreement (DPA) that incorporates Standard Contractual Clauses and requires the provider to maintain appropriate technical and organisational security measures.
You may request a copy of the applicable safeguards governing transfers of your personal data by contacting us at privacy@csgfuture.com. We will respond within 30 days.
8. How We Protect Your Personal Data
CSG implements appropriate technical and organisational security measures designed to protect your personal data from unauthorised access, disclosure, alteration, or destruction. These measures include:
• Transport Layer Security (TLS/HTTPS) encryption for all data in transit.
• Encryption of data at rest for sensitive categories of personal data.
• Role-based access controls and the principle of least privilege for systems holding personal data.
• Regular security assessments and penetration testing of the Website.
• Staff training on data protection and information security.
• Incident response procedures, including breach detection and notification protocols (see Section 13).
No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at privacy@csgfuture.com.
9. Data Retention and Deletion
We retain personal data only for as long as necessary to fulfil the purposes described in Section 2, to comply with our legal obligations (e.g. tax and accounting requirements, statutory limitation periods), to resolve disputes, and to enforce our agreements. The specific retention periods for each processing activity are set out in Section 2.
Upon expiry of the applicable retention period, or upon a valid deletion request (see Section 10.3), we will securely delete or irreversibly anonymise your personal data. Where immediate deletion is not technically feasible, the data will be securely isolated from active processing until deletion is possible.
Account Deletion When you request deletion of your account, your personal data will be anonymised within 30 days of your request. During this period, your account will be deactivated and your data will not be used for any active processing. After anonymisation, no data linked to your identity will be retained, except where we have a separate legal obligation to do so (e.g. transaction records for tax purposes). |
10. Your Rights and Choices
Depending on your country or region of residence, you may have some or all of the following rights. We are committed to honouring these rights regardless of your location, subject to applicable law. To exercise any of these rights, please contact us at privacy@csgfuture.com. We will respond within the timeframe required by the applicable law of your jurisdiction (e.g. 30 days under GDPR; 15 business days under Saudi Arabia PDPL).
Right | Description |
Access (Right to Know) | Request a copy of the personal data we hold about you, including information on how it is processed. |
Rectification (Correction) | Request correction of inaccurate or incomplete personal data. |
Erasure (Right to Delete) | Request deletion of your personal data under certain conditions: the data is no longer necessary; you withdraw consent and no other basis applies; you have successfully objected; or applicable law requires deletion. |
Restriction of Processing | Request that we limit processing of your data while accuracy is disputed, or while an objection is being assessed. |
Data Portability | Receive your personal data in a structured, machine-readable format, where processing is based on consent or contract and carried out by automated means. |
Right to Object | Object to processing based on Legitimate Interests (including profiling) or direct marketing. Where you object to direct marketing, we will cease such processing immediately. |
Withdraw Consent | Where processing is based on your consent, withdraw it at any time. Withdrawal does not affect the lawfulness of prior processing. You can unsubscribe from marketing emails via the 'Unsubscribe' link in every email. |
Non-Discrimination (US) | You will not be discriminated against for exercising your privacy rights (e.g. refused service or given a lower quality of service). |
Opt-Out of Sale/Sharing (US) | California and other US state residents may opt out of the 'sale' or 'sharing' of personal data for targeted advertising. Use the footer link or contact privacy@csgfuture.com. |
Lodge a Complaint | You have the right to lodge a complaint with the supervisory authority competent for your jurisdiction, including: EU: your national Data Protection Authority; UK: Information Commissioner's Office (ICO); Saudi Arabia: SDAIA; UAE: Federal Authority for Identity, Citizenship, Customs and Port Security (ICP) / relevant authority; USA: State Attorney General. |
11. Special Protections for Minors
The Website is directed at business professionals and is not intended for use by children or minors. We do not knowingly collect or process personal data from individuals under the following ages: under 16 years (EU/UK); under 13 years (USA — COPPA); under 18 years (Saudi Arabia — PDPL). If you are a parent or guardian and believe that your child has provided us with personal data, please contact us immediately at privacy@csgfuture.com and we will delete such data promptly (and in any event within 15 business days of notification).
12. Automated Decision-Making and Profiling
Our Website collects Website interaction data including a behavioural scoring indicator derived from your browsing activity. This scoring is used to prioritise internal follow-up activities and improve Website performance. It does not constitute a solely automated decision that produces legal or similarly significant effects on you.
We do not make any decisions about you (including decisions about whether to provide services, set pricing, or evaluate your creditworthiness) based solely on automated processing, without human review and oversight. If this practice changes, we will update this Policy and, where required by applicable law (e.g. GDPR Art. 22), we will seek your explicit consent or implement other appropriate safeguards.
13. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will:
• Notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (GDPR Art. 33; UK GDPR; Saudi Arabia PDPL Art. 25 — within 72 hours of discovery).
• Where the breach is likely to result in a high risk to affected individuals, notify those individuals directly without undue delay, in clear and plain language describing the nature of the breach and the steps we are taking.
• Maintain a breach register documenting all breaches, including those not requiring notification.
We maintain a documented incident response procedure and have appointed a dedicated point of contact for data security incidents. For urgent security concerns, please contact: privacy@csgfuture.com.
14. Updates to This Policy
We may update this Policy from time to time to reflect changes in our data practices, applicable laws, or regulatory guidance. When we make material changes, we will:
• Post the updated Policy on our Website with a new 'Effective Date'.
• Notify registered users by email at least 30 days before the changes take effect, where the changes affect how we process their personal data.
• Where changes require renewed consent (e.g. new processing activities based on consent), we will request your consent again before commencing such processing.
We encourage you to review this Policy periodically. Your continued use of the Website after the effective date of a revised Policy constitutes acceptance of the changes, to the extent permitted by applicable law.
15. Contact Us
For any questions, requests, complaints, or concerns about this Policy or our data practices, please contact us using the details below. We are committed to addressing your concerns promptly and in accordance with applicable law.
Email: info@csgfuture.com
Website: https://www.csgfuture.com/
Appendix: Key Definitions
Term | Definition |
Personal Data | Any information relating to an identified or identifiable natural person ('data subject'). |
Processing | Any operation performed on personal data, including collection, recording, storage, use, disclosure, or deletion. |
Data Controller | The entity that determines the purposes and means of processing personal data. CSG is the data controller for this Website. |
Data Processor | An entity that processes personal data on behalf of the controller (e.g. our service providers). |
GDPR | The EU General Data Protection Regulation (2016/679). |
UK GDPR | The UK version of the GDPR as retained and amended by the Data Protection Act 2018. |
CCPA/CPRA | California Consumer Privacy Act and California Privacy Rights Act. |
PDPL (KSA) | Saudi Arabia Personal Data Protection Law, enforced by SDAIA from 14 September 2024. |
PDPL (UAE) | UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. |
PIPL | China Personal Information Protection Law (2021). |
SCCs | Standard Contractual Clauses — contractual safeguards approved by the European Commission for cross-border data transfers. |
DPO | Data Protection Officer — a designated individual responsible for overseeing data protection strategy and compliance. |
LIA | Legitimate Interests Assessment — a documented balancing test performed to justify processing under the Legitimate Interests basis. |
© 2025 CSG. All rights reserved.
This Policy applies to the CSG Website at https://www.csgfuture.com. It does not apply to any other CSG products, services, or offline activities unless specifically stated.