HYSTOU Privacy Policy
Last Updated: January 29, 2026
At HYSTOU, we are committed to protecting the privacy and security of our business partners and customers. This Privacy Policy outlines how we manage the personal data we collect in accordance with applicable laws, including GDPR (Europe) and CCPA (USA).
1. Data Security Measures
We implement industry-standard technical and organizational measures to protect your data:
- Full-site SSL/TLS encryption for secure browser-server communication.
- Core systems certified under ISO 27001 with annual third-party audits.
- Sensitive data stored using AES-256 encryption and hierarchical access controls (keys managed by a dedicated security team).
- Regular penetration testing and vulnerability assessments.
2. Information Collection Scope
We collect necessary information through the following methods:
1. Active Submission (B2B & B2C)
- Account & Orders: Name, Company Name (for B2B), VAT Number, Shipping address, email, phone number.
- Payment Info: Encrypted payment data (processed securely via payment gateways).
- Support: Communication records regarding technical support and inquiries.
2. Automatic Collection
- Device Info: IP address, device model, OS version, browser type.
- Behavioral Logs: Visit timestamps, page interactions (see Cookie Policy).
3. Data Usage Purposes & Legal Basis
Data is strictly used for the following purposes under GDPR legal grounds:
- Order Fulfillment: To process payments, deliver Mini PCs, and handle customs clearance (Legal Basis: Performance of Contract).
- Technical Support: To provide warranty services and driver updates (Legal Basis: Performance of Contract).
- Compliance: To maintain financial records for tax authorities (Legal Basis: Legal Obligation).
- Product Improvement: Anonymized analytics to improve our website performance (Legal Basis: Legitimate Interest).
4. Cookie Policy
- Functional Cookies: Essential for language preferences and cart contents.
- Analytical Cookies: Anonymous traffic analysis via Google Analytics.
- Advertising Cookies: Personalized ads (disabled by default; requires your consent).
You can manage your preferences via our Cookie Consent Banner or your browser settings.
5. International Data Transfers
Important Notice for International Customers:
HYSTOU is headquartered in Shenzhen, China. By placing an order or using our services, you acknowledge that your personal information will be transferred to, stored, and processed in China.
We take appropriate steps to ensure your data is treated securely and in accordance with this Privacy Policy and applicable laws. For data transfers from the EEA/UK, we rely on Standard Contractual Clauses (SCCs) and strict internal data access controls.
6. Third-Party Services
We partner with trusted third-party service providers. We have signed Data Processing Agreements (DPAs) with them to ensure compliance.
- Payment Processors: PayPal, Stripe. (Please refer to their respective privacy policies).
- Logistics Partners: DHL, FedEx, UPS (For shipping and delivery updates).
- Cloud Providers: AWS, Alibaba Cloud (For secure server hosting).
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Transaction Records: Retained for 5-7 years to satisfy tax and accounting audits.
- Marketing Data: Retained until you opt-out or unsubscribe.
- Inactive Accounts: Data may be anonymized or deleted after a specific period of inactivity.
8. Your Data Rights
Under applicable laws (GDPR, CCPA), you have specific rights regarding your personal data:
| Right Type | Details | Response Time |
|---|---|---|
| Access | Obtain a copy of the data we hold about you. | Within 30 days |
| Rectification | Request correction of inaccurate or incomplete data. | Without undue delay |
| Deletion | Request data deletion (“Right to be forgotten”), subject to legal retention obligations. | Within 30 days |
| Opt-Out | Unsubscribe from marketing emails via the link in the footer of our emails. | Immediate / Up to 7 days |
CCPA Note for California Residents: HYSTOU does not sell your personal information to third parties. You have the right to request disclosure of data collection categories from the past 12 months.
9. Updates & Contact
We may update this policy periodically. Major changes will be notified via email or website announcements.
Contact Us:
- Email: operations@hystou.com
- Address: 10th Floor, Building A1, Sanhuan Technology Building, Guangming District, Shenzhen, China
- Phone: +86 755 8920 8532 / +86 136 3259 1271 (Mon-Fri 9:00-18:00 GMT+8)
- Complaints: You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
