1. Who we are1. 我们是谁

Guo Jun International Pte Ltd ("Guo Jun", "we", "us") is a private limited company incorporated in Singapore with registered address at 3 Temasek Avenue, Centennial Tower #21, Singapore 039190. UEN: 202618764C. We are the data controller responsible for the personal data processed through this website (guojuninternational.com.sg) and our cross-border advisory services. Guo Jun International Pte Ltd(下称"Guo Jun"、"我们")是在新加坡注册成立的私人有限公司,注册地址为 3 Temasek Avenue, Centennial Tower #21, Singapore 039190,UEN:202618764C。我们是通过本网站(guojuninternational.com.sg)及跨境顾问服务所处理个人数据的数据控制者。

2. Personal data we collect2. 我们收集的个人数据

We collect personal data in three ways:我们通过三种方式收集个人数据:

A. Directly from youA. 直接从您处收集

  • Contact form data: name, email, organization, region, area of interest, message body.联系表单数据:姓名、邮箱、机构、所在区域、关注业务、留言正文。
  • Newsletter subscription: email address only.邮件订阅:仅邮箱地址。
  • Direct correspondence: any personal data you choose to share via email or phone.直接通信:您通过邮件或电话主动分享的任何个人信息。

B. Automatically when you visitB. 您访问时自动收集

  • Server logs: IP address, user-agent string, timestamp, requested URL, referer. Used for security, abuse detection, and basic analytics.服务器日志:IP 地址、浏览器指纹、时间戳、请求 URL、来源页。用于安全防护、滥用检测和基本统计。
  • Browser storage: language preference (localStorage), session-state flags (sessionStorage). No personal identifiers stored.浏览器存储:语言偏好(localStorage)、会话状态标记(sessionStorage)。不存储任何个人身份信息。

C. From third partiesC. 来自第三方

  • Referrals and introductions: when an existing client or counterparty introduces you to us.引荐和推荐:当既有客户或交易对手将您介绍给我们时。
  • Public sources: for KYC and counterparty due diligence (sanctions lists, regulatory filings, news media).公开来源:用于 KYC 与交易对手尽调(制裁名单、监管申报、新闻媒体)。

3. How we use your data3. 我们如何使用您的数据

  • Respond to inquiries and discuss prospective engagements.回应咨询并讨论潜在合作。
  • Conduct KYC and anti-money-laundering checks before formal engagement.在正式合作前进行 KYC 与反洗钱核查。
  • Deliver advisory services, structure transactions, and report progress.提供顾问服务、搭建交易架构、报告进展。
  • Maintain records of communications and transactions for legal, tax, and regulatory purposes.出于法律、税务和监管目的保留通信与交易记录。
  • Send substantive insights, market commentary, or service announcements (only with your consent — see your right to withdraw, §8).发送实质性洞察、市场评论或服务公告(仅在您同意的情况下——参见第 8 条撤回权)。
  • Detect and prevent fraud, abuse, and unauthorised access to our systems.检测并防止欺诈、滥用和未授权访问。

We do not sell, rent, or trade your personal data. We do not use your data for behavioural advertising. 我们不会出售、出租或交易您的个人数据。我们不将您的数据用于行为定向广告。

4. Legal basis for processing4. 处理的法律依据

Depending on the jurisdiction that applies to you:依据适用于您的法域:

  • Singapore PDPA: consent (deemed or actual), business contact information, or specific PDPA exceptions (e.g., legitimate interest, legal obligation).新加坡 PDPA:同意(推定或实际)、商务联系信息例外,或 PDPA 特定例外(如合法利益、法律义务)。
  • EU GDPR: consent (Art. 6(1)(a)), contract performance (b), legal obligation (c), legitimate interest (f), as applicable.欧盟 GDPR:视情况依据同意(第 6(1)(a) 条)、合同履行(b)、法律义务(c)、合法利益(f)。
  • China PIPL: separate consent for cross-border transfer where required, contractual necessity, or statutory obligation.中国《个人信息保护法》:必要时取得跨境传输的单独同意、合同必要性、或法定义务。

5. Sharing & disclosure5. 共享与披露

We share data only with parties who help deliver our services or fulfil legal obligations:我们仅与以下协助服务或履行法律义务的方共享数据:

  • Professional advisors: external lawyers, auditors, tax advisors, corporate secretaries — bound by professional confidentiality.专业顾问:外部律师、审计师、税务顾问、公司秘书——均受职业保密义务约束。
  • Banking and compliance partners: for client onboarding, KYC verification, and AML monitoring.银行与合规伙伴:用于客户开户、KYC 验证、反洗钱监控。
  • Service providers: hosting (cloud infrastructure), email (transactional and newsletter), web fonts (Google Fonts), CDN libraries (jsdelivr).服务提供商:托管(云基础设施)、邮件(事务性与订阅)、网页字体(Google Fonts)、CDN 库(jsdelivr)。
  • Authorities: regulators, courts, or law enforcement when required by law in Singapore, the EU, China, the United States, Brazil, or Malaysia.监管机构:新加坡、欧盟、中国、美国、巴西或马来西亚法律要求时,向监管机构、法院或执法机关披露。

All third parties are contractually bound to use your data only for the specific service provided.所有第三方在合同上均受限于仅为约定服务使用您的数据。

6. Cross-border transfers6. 跨境传输

Our work is inherently cross-border. Personal data may be transferred to and processed in jurisdictions including Singapore (primary), Hong Kong, Mainland China, the United States, Brazil, Malaysia, and the European Union. For each transfer we apply at least one of: 我们的业务本身就是跨境的。个人数据可能被传输至并在以下法域处理:新加坡(主要)、香港、中国大陆、美国、巴西、马来西亚、欧盟。对于每次传输,我们至少采用以下一项保障:

  • Singapore PDPA — Transfer Limitation Obligation, with comparable protection in the destination jurisdiction;新加坡 PDPA 第 26 条传输限制义务,确保目的地法域具备同等保护水平;
  • EU GDPR — Standard Contractual Clauses (SCCs), adequacy decisions, or other Article 46 safeguards;欧盟 GDPR 标准合同条款(SCC)、充分性决议或第 46 条其他保障措施;
  • China PIPL — separate consent, government security assessment, or PIPL Standard Contract.中国 PIPL 单独同意、网信办安全评估或 PIPL 标准合同。

7. Retention7. 保留期

We retain personal data only as long as necessary for the purpose collected, plus statutory retention periods. As a guideline: 我们仅在收集目的所需期间内保留个人数据,并加上法定保留期。一般为:

  • Inquiry data without engagement: 24 months from last contact.未促成合作的咨询数据:自最后联系起 24 个月。
  • Engaged client records: 7 years after engagement ends (financial-industry standard).已开展业务的客户记录:合作结束后 7 年(金融行业标准)。
  • Transaction records: 7 years for tax and audit purposes (Singapore Companies Act, IRAS requirements).交易记录:用于税务与审计目的,保留 7 年(新加坡《公司法》、IRAS 要求)。
  • Server logs: 90 days for security analysis, then deleted or aggregated.服务器日志:用于安全分析的 90 天,之后删除或聚合处理。

8. Your rights8. 您的权利

Subject to applicable law, you have the right to:在适用法律范围内,您有权:

  • Access the personal data we hold about you.查询我们持有的关于您的个人数据。
  • Correct inaccurate or incomplete data.更正不准确或不完整的数据。
  • Erase your data (subject to retention requirements above).删除您的数据(受上述保留要求限制)。
  • Restrict certain types of processing.限制特定类型的处理活动。
  • Object to processing based on legitimate interest.反对基于合法利益的处理。
  • Data portability — receive your data in a machine-readable format.数据可携——以机器可读格式获取您的数据。
  • Withdraw consent at any time (does not affect lawfulness of prior processing).随时撤回同意(不影响撤回前处理的合法性)。
  • Lodge a complaint with a supervisory authority (Singapore PDPC, your local EU DPA, China CAC).向监管机构投诉(新加坡 PDPC、您所在的欧盟 DPA、中国网信办)。

To exercise any of these rights, email sales@guojuninternational.com.sg or guojuninternational@gmail.com. We will respond within 30 days (Singapore PDPA / GDPR standard). 行使上述任一权利,请邮件至 sales@guojuninternational.com.sgguojuninternational@gmail.com。我们将在 30 天内回复(PDPA / GDPR 标准)。

9. Security9. 安全措施

We apply commercially reasonable technical and organisational measures to protect personal data, including: encrypted communications (TLS), access controls, audit logging, security review of third-party processors, and incident response procedures. No system is perfectly secure; in the event of a personal data breach affecting your rights, we will notify you and the relevant supervisory authority within 72 hours of becoming aware (where required). 我们采用合理的技术与组织措施保护个人数据,包括:加密通信(TLS)、访问控制、审计日志、第三方处理者安全审查、事件响应流程。没有系统是绝对安全的;如发生影响您权利的个人数据泄露事件,我们将在意识到事件后 72 小时内(在法律要求的情况下)通知您及相关监管机构。

10. Cookies & tracking10. Cookie 与追踪

This site uses minimal browser storage (no cross-site tracking cookies). See our Cookie Policy for details on what is stored, why, and how to opt out. 本站使用极少量的浏览器存储(不使用跨站追踪 Cookie)。详细的存储内容、用途与退出方式请参阅 Cookie 政策

11. Changes & updates11. 政策变更

We may update this policy as our practices, applicable law, or services evolve. The "Last updated" date at the top will reflect any change. Material changes will be notified to active clients and subscribers by email. 我们可能因实践、适用法律或服务变化而更新本政策。顶部"最近更新"日期将反映任何变更。重大变更将通过邮件通知活跃客户与订阅者。

12. Contact our DPO12. 联系我们的数据保护官

For privacy questions, requests, or complaints: 隐私相关问题、请求或投诉:

This policy is provided in English and Chinese. In case of any inconsistency, the English version prevails for legal interpretation. 本政策提供中英文版本。如出现不一致,以英文版作为法律解释依据。

See also: Terms of Service · Cookie Policy 另见:服务条款 · Cookie 政策