Legal & Compliance

Privacy Policy

How Green Element collects, uses, and protects your personal data--in compliance with GDPR, CCPA, and PIPEDA.

GDPR Compliant CCPA Compliant PIPEDA Compliant Effective Date: July 28, 2026

Overview

Green Element ("we," "our," or "us") is committed to protecting the privacy and security of personal data we collect through our website, marketing communications, trade events, and business interactions.

This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights available to you under applicable data protection laws, including:

  • GDPR -- EU General Data Protection Regulation (EU) 2016/679, applicable to individuals in the European Economic Area (EEA) and United Kingdom.
  • CCPA/CPRA -- California Consumer Privacy Act and California Privacy Rights Act, applicable to California residents.
  • PIPEDA -- Personal Information Protection and Electronic Documents Act, applicable to individuals in Canada.

B2B Context: Our website and services are directed at business professionals--pool equipment brands, distributors, contractors, and system integrators. We do not knowingly market to or collect data from private consumers or minors.

Data Controller

The data controller responsible for your personal data is:

Shenzhen Green Element Pool Equipment CO.,LTD

Shenzhen, Guangdong Province, People's Republic of China

Email: privacy@sunshineaura.com

Website: www.sunshineaura.com

For EU/EEA and UK data subjects, where required by applicable law, we have designated a representative or Data Protection Officer. Please direct all data protection enquiries to privacy@sunshineaura.com.

Data We Collect

We collect personal data only to the extent necessary for legitimate business purposes. The categories of data we may collect include:

3.1 Data You Provide Directly

  • Business contact information: name, job title, company name, business email address, telephone number, country/region.
  • Enquiry and project details: product requirements, pool specifications, OEM/ODM project briefs, sample requests, and quotation requests submitted via our contact forms.
  • Communications: emails, live chat messages, or correspondence you send to us.
  • Event and trade show data: business cards, badge scans, and meeting notes collected at industry events.

3.2 Data Collected Automatically

  • Device and browser data: IP address, browser type and version, operating system, device type.
  • Usage data: pages visited, time on site, referral source, click paths, and session duration collected via cookies and similar technologies.
  • Log data: server logs including access timestamps and error logs.

3.3 Data from Third Parties

  • Business information from LinkedIn, trade directories, or industry databases used for B2B outreach.
  • Analytics and advertising data from platforms such as Google Ads, Meta for Business, and LinkedIn Campaign Manager.

We do not collect or process special categories of personal data (sensitive data) as defined under GDPR Article 9, nor do we collect payment card or financial account information directly through this website.

How We Use Your Data

We use the personal data we collect for the following purposes:

  • Responding to enquiries: Processing quotation requests, product enquiries, OEM/ODM project discussions, and sample requests.
  • Business communications: Sending product catalogues, technical datasheets, pricing updates, and company news relevant to your business.
  • Marketing and advertising: Displaying targeted advertisements on platforms including Google Search, Google Display Network, Meta (Facebook/Instagram), and LinkedIn, based on your consent or our legitimate business interests.
  • Remarketing: Re-engaging website visitors who have shown interest in our products or services, using cookie-based audience lists.
  • Website improvement: Analysing usage patterns to improve website content, navigation, and user experience.
  • CRM and sales pipeline management: Recording and managing business relationships and sales activities.
  • Legal compliance: Meeting obligations under applicable laws including export controls, anti-money-laundering, and trade regulations.
  • Security and fraud prevention: Protecting our website, systems, and business from unauthorised access or fraudulent activity.

We do not sell, rent, or trade personal data to third parties for their own marketing purposes.

Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies. We obtain your consent before placing non-essential cookies, in accordance with the EU ePrivacy Directive and applicable national laws.

6.1 Cookie Categories

  • Strictly Necessary: Essential for the website to function. Cannot be disabled. No consent required.
  • Analytics & Performance: Help us understand how visitors interact with our website (e.g., Google Analytics 4). Require consent in EU/EEA/UK.
  • Advertising & Targeting: Used to deliver relevant advertisements and measure campaign performance across platforms including Google Ads, Meta Pixel, and LinkedIn Insight Tag. Require consent in EU/EEA/UK.
  • Functional: Remember your preferences such as language or region. May require consent.

6.2 Third-Party Advertising Technologies

We use the following advertising and tracking tools, subject to your consent preferences:

  • Google Ads & Google Analytics 4: Conversion tracking, remarketing audiences, and website analytics. Data processed under Google's privacy policy. Google may transfer data to the US under Standard Contractual Clauses.
  • Meta Pixel (Facebook/Instagram): Conversion tracking and Custom Audience targeting for B2B advertising campaigns. Data processed under Meta's Data Processing Terms.
  • LinkedIn Insight Tag: B2B audience targeting, lead generation, and conversion tracking on LinkedIn. Data processed under LinkedIn's privacy policy.

Managing Cookies: You can manage or withdraw your consent at any time using our Cookie Preference Centre (accessible via the cookie banner or footer link), or by adjusting your browser settings. Withdrawing consent does not affect the lawfulness of processing prior to withdrawal.

6.3 Do Not Track

Our website does not currently respond to "Do Not Track" browser signals. We rely on our consent management platform for user preference management.

Data Sharing & Disclosure

We may share your personal data with the following categories of recipients, strictly for the purposes described in this policy:

7.1 Service Providers (Data Processors)

We engage trusted third-party service providers who process data on our behalf under binding data processing agreements:

  • CRM and email marketing platforms (e.g., HubSpot, Mailchimp)
  • Website hosting and cloud infrastructure providers
  • Analytics platforms (Google Analytics)
  • Advertising platforms (Google Ads, Meta, LinkedIn)
  • Customer support and live chat tools
  • Translation and localisation services

7.2 Business Partners

Where you engage with us in the context of a joint project, trade event, or referral arrangement, we may share relevant contact information with authorised business partners, subject to appropriate confidentiality obligations.

7.3 Legal and Regulatory Authorities

We may disclose personal data where required by law, court order, regulatory authority, or to protect the rights, property, or safety of Green Element, our customers, or others.

7.4 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the acquiring entity, subject to equivalent privacy protections.

We do not sell personal data. This applies to California residents under CCPA/CPRA, and is our global policy.

International Data Transfers

Green Element is headquartered in Shenzhen, China. When we collect personal data from individuals in the EEA, UK, or Canada, that data may be transferred to and processed in China or other countries that may not provide the same level of data protection as your home jurisdiction.

For transfers of EEA/UK personal data, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs): EU Commission-approved SCCs (2021) incorporated into contracts with processors and sub-processors outside the EEA.
  • UK International Data Transfer Agreements (IDTAs): For transfers from the United Kingdom.
  • Adequacy decisions: Where the European Commission or UK ICO has recognised the destination country as providing adequate protection.

For transfers involving our advertising partners (Google, Meta, LinkedIn), these companies maintain their own transfer mechanisms, including SCCs and Binding Corporate Rules. We verify these mechanisms are in place before engaging such partners.

You may request a copy of the relevant transfer safeguards by contacting privacy@sunshineaura.com.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our general retention periods are:

Data Category Retention Period
Active business contacts and CRM records Duration of business relationship + 3 years
Enquiries and quotation requests (no order placed) 2 years from last contact
Marketing email subscription records Until unsubscribe + 1 year (consent records retained 3 years)
Website analytics data (Google Analytics) 14 months (GA4 default; configurable)
Transaction and contractual records 7 years (statutory accounting requirements)
Cookie consent records 3 years from consent

Upon expiry of the applicable retention period, data is securely deleted or anonymised in accordance with our data retention schedule.

Your Rights -- EU / EEA / UK (GDPR)

If you are located in the EEA or United Kingdom, you have the following rights under the GDPR and UK GDPR:

Right of Access
Obtain a copy of your personal data and information about how it is processed.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data in certain circumstances ("right to be forgotten").
Right to Restriction
Request that we restrict processing of your data in certain circumstances.
Right to Portability
Receive your data in a structured, machine-readable format and transfer it to another controller.
Right to Object
Object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent, without affecting prior processing.
Right to Lodge a Complaint
File a complaint with your local supervisory authority (e.g., your national DPA or the UK ICO).

To exercise any of these rights, please submit a written request to privacy@sunshineaura.com. We will respond within 30 days. We may request verification of your identity before processing your request.

Automated Decision-Making: We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects (GDPR Article 22).

Your Rights -- California Residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, our business purposes, and the categories of third parties with whom we share it.
  • Right to Delete: Request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: We do not sell personal information. We do not share personal information for cross-context behavioural advertising without consent. You may opt out of any such sharing by contacting us.
  • Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information as defined under CPRA in the course of our B2B operations.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.

11.1 Categories of Personal Information Collected (CCPA)

In the preceding 12 months, we have collected the following CCPA categories of personal information:

  • Identifiers: Name, business email, phone number, IP address.
  • Commercial information: Products or services enquired about.
  • Internet or other electronic network activity: Browsing history on our website, interaction with advertisements.
  • Geolocation data: Country/region inferred from IP address.
  • Professional or employment-related information: Job title, company name.

11.2 Submitting a CCPA Request

To submit a verifiable consumer request, contact us at privacy@sunshineaura.com with the subject line "CCPA Privacy Request." We will respond within 45 days. You may designate an authorised agent to submit requests on your behalf.

Your Rights -- Canadian Residents (PIPEDA)

If you are a resident of Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation:

  • Right of Access: Request access to your personal information held by us and information about how it has been or may be used.
  • Right to Correction: Request correction of inaccurate personal information.
  • Right to Withdraw Consent: Withdraw consent to the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions and reasonable notice.
  • Right to Complain: Lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC) at www.priv.gc.ca.

We collect, use, and disclose personal information only with your knowledge and consent, except where permitted or required by law. We designate an individual responsible for compliance with PIPEDA--contact privacy@sunshineaura.com for privacy-related enquiries.

Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, or disclosure. Our security measures include:

  • TLS/SSL encryption for all data transmitted to and from our website.
  • Access controls and role-based permissions for internal systems.
  • Regular security assessments and vulnerability reviews.
  • Data processing agreements with all third-party processors requiring equivalent security standards.
  • Staff training on data protection and information security practices.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware, and affected individuals without undue delay, as required by GDPR Article 33-34 and equivalent laws.

Minors

Our website and services are directed exclusively at business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected personal data from a minor, we will take prompt steps to delete such data. If you believe a minor has submitted personal data to us, please contact privacy@sunshineaura.com.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Effective Date" at the top of this page.
  • Post a prominent notice on our website homepage or send an email notification to known contacts where required by law.
  • Where required by GDPR, obtain fresh consent for materially changed processing activities.

We encourage you to review this policy periodically. Your continued use of our website following the posting of changes constitutes your acknowledgement of those changes.

Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our privacy team:

General Enquiries

info@sunshineaura.com

Postal Address

Shenzhen Green Element Pool Equipment CO.,LTD
Shenzhen, Guangdong
People's Republic of China

We aim to respond to all privacy-related requests within 30 days. If you are unsatisfied with our response, you have the right to escalate your complaint to the relevant supervisory authority in your jurisdiction:

  • EU/EEA: Your national Data Protection Authority (find yours at edpb.europa.eu)
  • United Kingdom: Information Commissioner's Office (ICO) -- ico.org.uk
  • California: California Privacy Protection Agency (CPPA) -- cppa.ca.gov
  • Canada: Office of the Privacy Commissioner of Canada -- priv.gc.ca

This Privacy Policy was last updated on July 28, 2026.
© 2026 Shenzhen Green Element Pool Equipment CO.,LTD. All rights reserved.