Privacy Policy

This Privacy Policy governs the collection, storage, processing, sharing, and protection of personal data of users accessing our website, purchasing our products (electric vehicle charging equipment), and using our services. It complies with the EU General Data Protection Regulation (GDPR 2016/679) and the UK General Data Protection Regulation (UK GDPR, aligned with DPA 2018). By using our website and services, you consent to the practices described in this policy, as updated from time to time.


1. Definitions

  • Personal Data: Any information that can identify a living individual (e.g., name, email, phone number, address, payment details, IP address, device ID, cookie identifiers).
  • Data Controller: EVDANCE (we/us/our), the entity determining how and why personal data is processed.
  • Data Subject: You, the individual whose personal data is collected and processed.
  • GDPR: EU Regulation 2016/679 (for EU/EEA users) and UK GDPR (for UK users, retained EU law).
  • PECR: Privacy and Electronic Communications Regulations 2003 (UK), governing cookies and electronic communications.
  • Cookies: Small text files stored on your device when visiting our website, used to enhance user experience and collect browsing data.

2. Personal Data We Collect & Legal Bases for Processing

We collect personal data only for specific, stated purposes and rely on valid legal bases under GDPR (Article 6). We adhere to data minimisation (collect only necessary data) and storage limitation (delete data when no longer needed) principles.

2.1 Data Collected Directly from You

Data Category Specific Information Purpose of Processing Legal Basis
Identity Data Full name, username, customer ID Account creation, order processing, customer identification Contract Necessity (performance of sales/service contract)
Contact Data Email address, phone number, delivery address, billing address Order fulfillment, customer support, post-sales communication, return processing Contract Necessity; Legitimate Interest (efficient customer service)
Payment Data Payment method, transaction ID, billing details (we do not store full card numbers) Payment processing, fraud prevention, order verification Contract Necessity; Legal Obligation (tax/audit compliance)
Account Data Password (encrypted), order history, return records, warranty information Account management, order tracking, warranty support, return processing Contract Necessity; Legitimate Interest (account security)
Support Data Messages, feedback, inquiry content, support ticket details Resolving customer issues, improving products/services Legitimate Interest (customer support); Consent (if you provide optional feedback)

2.2 Data Collected Automatically (via Website & Cookies)

  • Technical Data: IP address, device type, browser type, operating system, website access time, page views, click behavior, referring URLs.
  • Cookie Data: Cookie IDs, browsing preferences, session data (detailed in Section 7).
  • Purpose: Website optimization, user experience improvement, traffic analytics, fraud detection, personalized service delivery.
  • Legal Basis: Consent (for non-essential cookies/analytics); Legitimate Interest (essential cookies for website functionality).

2.3 Data We Do Not Collect

  • We do not collect sensitive special category data (e.g., race, religion, health data) unless explicitly required by law and you provide explicit written consent.
  • We also do not collect data from children under 16 without parental consent.

3. How We Use Your Personal Data

We process your personal data only for the purposes stated in this policy and will not repurpose data without additional consent.

Key usage scenarios:

  • Process and fulfill your orders (including shipping, delivery, and return processing).
  • Provide customer support, handle inquiries, returns, refunds, and warranty claims.
  • Manage user accounts, verify identity, and ensure account security.
  • Comply with legal obligations (e.g., tax reporting, responding to regulatory requests, fraud prevention).
  • Optimize website functionality, analyze user behavior, and improve product/service quality.
  • Send administrative communications (e.g., order confirmations, shipping updates, return status notifications).
  • Send marketing communications (only with your explicit consent; you may opt out at any time).

3.1 Automated Decision-Making and Profiling

We do not engage in purely automated decision-making or profiling that produces legal or similarly significant effects on you under GDPR Article 22 (e.g., we do not use fully automated algorithms to reject orders or determine dynamic user pricing without human intervention).


4. Data Sharing & Disclosure

We do not sell, rent, or lease your personal data to third parties for commercial purposes. We share data only when necessary and require third parties to comply with GDPR and sign data processing agreements (DPAs).

4.1 Authorized Third-Party Service Providers

We share limited data with service providers acting as data processors on our behalf:

  • Payment Processors: To process payments and prevent fraud (e.g., PayPal, Stripe).
  • Logistics & Carriers: To fulfill orders and deliver products (e.g., DHL, Royal Mail, Amazon Logistics).
  • IT & Hosting Providers: To maintain our website, servers, and data storage (e.g., AWS, Shopify).
  • Analytics Providers: To analyze website traffic and user behavior (e.g., Google Analytics, Facebook Pixel).
  • Customer Support Tools: To manage inquiries and support tickets.

4.2 Legal & Regulatory Disclosures

We may disclose your personal data if required by law (e.g., in response to a court order, regulatory request, or legal proceeding) or to protect our legal rights, safety, or public interest.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of all/part of our business, your personal data may be transferred as part of the transaction. We will notify you via email or prominent website notice before any such transfer and ensure compliance with GDPR.


5. Data Retention Period

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law.

Retention periods:

  • Order & Transaction Data: Retained for 7 years after order completion (legal obligation for tax/audit compliance).
  • Account Data: Retained until you request account deletion (we will delete/anononymize data within 30 days of your request).
  • Support & Inquiry Data: Retained for 3 years after resolving your inquiry (legitimate interest for follow-up support).
  • Cookie & Analytics Data: Retained for 12 months after collection (you may clear cookies via browser settings at any time).
  • Marketing Data: Retained until you opt out of marketing communications.

After the retention period, we permanently delete or anonymize your personal data in compliance with GDPR.


6. Data Security

We implement industry-standard technical and organizational security measures to protect your personal data from unauthorized access, loss, theft, alteration, or destruction (GDPR Article 32).

Key security practices:

  • Encryption of data in transit (SSL/TLS) and at rest (AES-256).
  • Access controls (role-based permissions, multi-factor authentication for admin accounts).
  • Regular security audits, vulnerability assessments, and staff training.
  • Data breach notification: In the event of a personal data breach likely to risk your rights/freedoms, we will notify you and the relevant supervisory authority within 72 hours of detection (GDPR Article 33).

7. Cookie Policy (GDPR & PECR Compliant)

We use cookies and similar tracking technologies (pixels, web beacons) on our website. This section complies with EU ePrivacy Directive and UK PECR.

7.1 What Are Cookies?

Cookies are small text files stored on your device (computer, smartphone, tablet) when you visit our website. They help us recognize your device, remember your preferences, and improve your browsing experience.

7.2 Types of Cookies We Use

We categorize cookies into Essential Cookies (no consent required) and Non-Essential Cookies (consent required under GDPR/PECR):

Cookie Type Purpose Consent Required Retention Period
Essential Cookies Enable website functionality (e.g., session management, cart persistence, login security). Without these cookies, the website may not function properly. ❌ Not required (exempt under PECR) Session (deleted when browser closes) / 30 days
Analytics Cookies Collect anonymous data on website usage (e.g., page views, traffic sources, user behavior) to optimize the site. ✅ Yes (consent via cookie banner) 12 months
Functional Cookies Remember your preferences (e.g., language, region, login status) for a personalized experience. ✅ Yes (consent via cookie banner) 6 months
Marketing Cookies Track browsing activity for personalized advertising (e.g., Google Ads, Facebook Ads). ✅ Yes (consent via cookie banner) 12 months

7.3 Cookie Consent & Management

  • Consent Mechanism: We use a GDPR-compliant cookie banner on our website. Non-essential cookies are not set until you provide explicit, affirmative consent (no pre-ticked boxes; silence/inactivity does not constitute consent).
  • Withdraw Consent: You may withdraw your consent for non-essential cookies at any time via our website’s Cookie Preference Center (link in footer) or your browser settings (delete existing cookies and block future cookies).
  • Impact of Withdrawal: Withdrawing consent for non-essential cookies will not affect your ability to use our website or purchase products.

7.4 Third-Party Cookies

We use third-party cookies from trusted providers (e.g., Google Analytics, Facebook). These third parties are data controllers for their cookie data, and their use of your data is governed by their own privacy policies. We ensure third parties comply with GDPR and sign DPAs.


8. Your GDPR Data Subject Rights

As a data subject under EU GDPR and UK GDPR, you have the following enforceable rights (Articles 12–23). You may exercise these rights free of charge by contacting us at contact@evdances.com:

  • Right to Access: Request a copy of your personal data we hold and details of how we process it.
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data when no longer necessary, or if you withdraw consent (subject to legal exceptions).
  • Right to Restriction of Processing: Request restriction of your data processing in specific cases (e.g., data accuracy disputes).
  • Right to Data Portability: Request transfer of your personal data to another data controller in a machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or direct marketing (we will stop processing unless we have a compelling legal reason).
  • Right to Withdraw Consent: Withdraw consent for data processing (e.g., non-essential cookies, marketing) at any time (does not affect lawfulness of processing before withdrawal).
  • Right to Complain: Lodge a complaint with a data protection supervisory authority (e.g., ICO in the UK, CNIL in France) if you believe we have violated GDPR.

8.1 Exercising Your Rights

  • Submit requests via email to contact@evdances.com with the subject line "GDPR Data Subject Request".
  • We will respond to valid requests within 1 month (extendable by 2 months for complex requests; we will notify you of the extension).
  • We may verify your identity to protect your data security.

9. International Data Transfers

Our website and services are hosted on servers located within the EU/EEA and UK. In limited cases, we may transfer your personal data to countries outside the EU/EEA/UK (third countries).

9.1 GDPR Compliance for Transfers

For transfers to third countries, we ensure compliance with GDPR Article 44 by:

  • Using Standard Contractual Clauses (SCCs) approved by the European Commission (for EU transfers).
  • Complying with UK International Data Transfer Agreement (IDTA) (for UK transfers).
  • Verifying the third country has an adequacy decision from the European Commission or UK government.

You may request a copy of our SCCs/IDTA by contacting us at contact@evdances.com.


10. Marketing Communications

We will send you marketing emails/SMS only if you provide explicit consent during account creation or checkout. You may opt out of marketing communications at any time via:

  • The "Unsubscribe" link in our marketing emails.
  • Updating your account preferences on our website.
  • Contacting us at contact@evdances.com.

We will not send you marketing communications without your consent, and we will honor opt-out requests within 48 hours.


11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements (e.g., GDPR amendments). We will notify you of material changes via:

  • A prominent notice on our website homepage.
  • Email notification (to registered users).

The "Effective Date" at the top of this policy will be revised. Your continued use of our website and services after the effective date constitutes acceptance of the updated policy.


12. Contact Us & Data Protection Representatives

For questions, concerns, or requests related to this Privacy Policy, GDPR compliance, or your personal data, you can contact our dedicated data protection management infrastructure:

  • Data Controller: EVDANCE
  • Email: contact@evdances.com
  • Address: A1 Building, Fuhai Subdistrict, Haoye Road No.31, Bao'an District, Shenzhen, 518103, CN

12.1 Data Protection Officer (DPO) Statement

Considering the nature and scale of our data processing operations, EVDANCE is not legally mandated to appoint a mandatory Data Protection Officer (DPO) under GDPR Article 37. All privacy concerns, inquiries, and data subject requests are directly handled by our internal Privacy Compliance Team via the contact email specified above.

12.2 EU & UK Legal Representatives (GDPR Article 27)

Since EVDANCE is located outside the European Union and the United Kingdom, and directly offers products to consumers in these markets, we acknowledge our obligation under Article 27 of both EU GDPR and UK GDPR to designate legal representatives in these territories. You may contact our regional representatives regarding any personal data matters:

  • EU Legal Representative: Registration in progress
  • UK Legal Representative: Registration in progress

If you are unsatisfied with our response, you may also contact a data protection supervisory authority (e.g., the Information Commissioner's Office (ICO) in the UK) to lodge a formal complaint.