Table of Contents
- Introduction and Scope
- Information We Collect
- How We Collect Your Information
- How We Use Your Information
- Legal Basis for Processing
- Data Sharing and Disclosure
- Data Storage and Security
- Cookies and Tracking Technologies
- Third-Party Services and Links
- Children and Privacy
- International Data Transfers
- Data Retention Policy
- Your Data Protection Rights
- Changes to This Privacy Policy
- Contact Information
1. Introduction and Scope
This Privacy Policy describes how BravePass, a computer systems design and related services brand developed and operated by JiuJiang YongHanGuan Trading Co., Ltd., collects, uses, stores, and protects personal information obtained from visitors to the website located at https://www.bravepass.hair and from individuals and organizations who engage our professional technology services. By accessing our website or using our services, you acknowledge that you have read and understood the practices described in this document.
JiuJiang YongHanGuan Trading Co., Ltd. is a company duly registered and operating under the laws of the People’s Republic of China, with its registered office at Room 401-48, 4/F, Development Company Building, No. 168 Changhong Avenue, Lianxi District, Jiujiang, Jiangxi Province, 332000, China. Throughout this policy, references to we, us, our, the Company, or BravePass refer to JiuJiang YongHanGuan Trading Co., Ltd. acting through its BravePass service brand. References to you or your refer to the individual or entity visiting our website or using our services.
We take the protection of personal data seriously. This policy is designed to comply with applicable data protection laws and regulations, including but not limited to the Personal Information Protection Law of the People’s Republic of China, the General Data Protection Regulation of the European Union where applicable, and other relevant privacy frameworks in jurisdictions where we operate or where our clients are located.
This policy applies to all information collected through our website, via email communications, through service engagement agreements, during technical consulting sessions, and through any other interaction where personal data may be collected by BravePass. If you do not agree with any provision of this policy, you should discontinue use of our website and services immediately.
2. Information We Collect
We collect several categories of information to provide and improve our computer systems design and related services. The types of information we collect depend on your interaction with our website and services, and may include the following categories.
Contact Information: When you reach out through our website contact form, send us an email at reach@bravepass.hair, call our office at +1 (740) 895-9338, or engage us for a project, we may collect your full name, email address, phone number, company name, job title, and physical or mailing address. This information is necessary for us to respond to your inquiries and to manage client relationships effectively.
Technical and Usage Data: When you visit our website, our servers automatically record certain technical information transmitted by your browser or device. This may include your Internet Protocol address, browser type and version, operating system, referring URL, pages visited, time and date of your visit, time spent on each page, and other diagnostic data. This information helps us understand how our website is used and identify performance issues.
Service Engagement Data: When you engage BravePass for professional services, we may collect information about your existing technical infrastructure, system architecture, software configurations, performance metrics, security posture, and other technical data necessary for us to perform our consulting, design, and engineering work. This data is collected solely for the purpose of delivering the contracted services.
Communication Records: We may retain records of correspondence including emails, messages sent through our contact form, phone call summaries, meeting notes, and project documentation. These records help us maintain continuity in client relationships and provide accurate service delivery.
We do not intentionally collect sensitive personal data such as government identification numbers, financial account credentials, health information, biometric data, or information about criminal convictions unless such collection is specifically required and agreed upon as part of a security audit or compliance engagement.
3. How We Collect Your Information
We collect information through a variety of methods, all of which are designed to be transparent and consistent with the purpose for which the information is provided.
Direct Collection: The majority of personal information we collect is provided directly by you. This occurs when you fill out the contact form on our website, send us an email, call our office, subscribe to any newsletter or updates we may offer, participate in a consultation call or technical assessment, or sign a service agreement with us. We collect only the information that is reasonably necessary for the purpose at hand.
Automated Collection: As you navigate our website, certain information is collected automatically through standard web server logs and through the use of cookies and similar technologies. This automated collection helps us maintain website security, analyze traffic patterns, and improve the user experience. The specific technologies we use for automated data collection are described in detail in Section 8 of this policy.
Third-Party Sources: On rare occasions, we may receive information about you from third-party sources such as publicly available business directories, professional networking platforms, or referrals from existing clients. Any information obtained from such sources is handled with the same care as information you provide directly.
Service Delivery Discovery: During the course of providing our computer systems design and consulting services, we may discover or be given access to technical data and system information that is necessary for the performance of our engagement. This is not personal information per se, but may be associated with your organization and is treated with confidentiality under our service agreements.
4. How We Use Your Information
BravePass uses the information we collect for specific, limited purposes that are directly related to providing and improving our services. We do not use your information for purposes that are incompatible with those described in this policy without first providing notice and, where required, obtaining your consent.
Service Provision and Client Management: We use contact information and service engagement data to respond to inquiries, prepare proposals and quotations, deliver contracted computer systems design, cloud infrastructure, security hardening, performance engineering, data pipeline design, and DevOps integration services, manage ongoing client relationships, process invoices and payments, and provide technical support and maintenance.
Website Operation and Improvement: Technical and usage data is used to monitor and analyze website traffic and usage patterns, diagnose and resolve technical issues with our website, protect against fraudulent, malicious, or unauthorized activity, and improve the content, functionality, and user experience of our website.
Communication: We use your contact information to respond to your inquiries and requests, send service-related notifications and updates including confirmations, invoices, and technical alerts, and communicate changes to our policies, terms, or service offerings. We do not send unsolicited marketing communications. If we ever offer a newsletter or promotional updates in the future, participation will be strictly opt-in with a clear unsubscribe mechanism in every communication.
Legal and Compliance Obligations: We may use and retain information as necessary to comply with applicable laws, regulations, legal processes, or governmental requests, enforce our terms of service and other agreements, and protect the rights, property, and safety of BravePass, JiuJiang YongHanGuan Trading Co., Ltd., our clients, and the public.
5. Legal Basis for Processing
The legal basis on which we process personal information depends on the nature of the data, the context in which it was collected, and the applicable data protection laws of your jurisdiction. We process personal information only when we have a valid legal ground to do so.
Contractual Necessity: Much of the information we collect and process is necessary for the performance of a contract with you or to take steps at your request prior to entering into a contract. This includes responding to service inquiries, preparing proposals, and delivering the computer systems design and related services that you have engaged us to provide.
Legitimate Interests: We process certain information based on our legitimate business interests, provided that those interests are not overridden by your data protection rights. Our legitimate interests include improving our website and services, ensuring the security and integrity of our systems, understanding how visitors interact with our website, and managing our client relationships efficiently.
Legal Obligation: In some cases, we may be required to process personal information to comply with a legal obligation, such as retaining records for tax or accounting purposes, responding to valid legal requests from authorities, or complying with applicable data protection and privacy regulations.
Consent: Where required by applicable law, we will obtain your explicit consent before processing your personal information for specific purposes. You have the right to withdraw your consent at any time by contacting us using the information provided in Section 15 of this policy. Withdrawal of consent does not affect the lawfulness of processing that occurred prior to the withdrawal.
6. Data Sharing and Disclosure
BravePass does not sell, rent, or trade your personal information to third parties for their marketing purposes. We share your information only in the limited circumstances described below and always with appropriate safeguards in place.
Service Providers and Subcontractors: We may engage trusted third-party companies and individuals to perform functions on our behalf, such as website hosting, email delivery, data storage, analytics, payment processing, and legal or accounting services. These service providers are given access only to the information that is reasonably necessary to perform their specific functions and are contractually obligated to process such information solely in accordance with our instructions and applicable data protection laws.
Legal and Regulatory Disclosures: We may disclose your information if we believe in good faith that such disclosure is necessary to comply with a legal obligation, respond to a valid legal request from a competent authority, protect and defend the rights or property of BravePass or JiuJiang YongHanGuan Trading Co., Ltd., prevent or investigate possible wrongdoing in connection with our services, or protect the personal safety of users of our services or the public.
Business Transfers: If JiuJiang YongHanGuan Trading Co., Ltd. or the BravePass service brand is involved in a merger, acquisition, reorganization, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. You will be notified via email or a prominent notice on our website of any change in ownership or use of your personal information.
With Your Consent: We may share your information for any other purpose with your explicit consent or at your direction.
We require all third parties with whom we share personal information to respect the security of your data and to treat it in accordance with applicable law. We do not permit our service providers to use your personal data for their own purposes.
7. Data Storage and Security
We take the security of your personal information seriously and implement appropriate technical and organizational measures designed to protect your data against unauthorized access, alteration, disclosure, or destruction. However, no method of electronic storage or transmission over the internet is completely secure, and we cannot guarantee absolute security.
Technical Measures: We employ industry-standard security practices including encryption of data in transit using Transport Layer Security protocols, firewalls and intrusion detection systems, regular vulnerability assessments and penetration testing of our infrastructure, access controls that limit data access to authorized personnel on a need-to-know basis, and secure authentication mechanisms for all systems that store or process personal information.
Organizational Measures: Our personnel who have access to personal information are bound by confidentiality obligations and receive training on data protection practices. We maintain internal policies and procedures governing the handling of personal data, incident response protocols, and regular reviews of our security posture.
Data Breach Response: In the event of a data breach that affects your personal information, we will notify you and the relevant supervisory authorities without undue delay, in accordance with the timeframes and procedures required by applicable data protection laws. Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures we have taken or propose to take to address the breach.
Data Location: Personal information collected by BravePass is primarily stored and processed on servers and infrastructure located in the People’s Republic of China and, where necessary for service delivery, in other jurisdictions as described in Section 11 of this policy.
8. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and understand where our visitors come from. This section explains what these technologies are, why we use them, and your choices regarding their use.
What Are Cookies: Cookies are small text files that are placed on your computer or mobile device when you visit a website. They are widely used to make websites work more efficiently and to provide information to the website owners. Cookies may be session cookies, which are deleted when you close your browser, or persistent cookies, which remain on your device for a set period or until you manually delete them.
Types of Cookies We Use: We use essential cookies that are necessary for the proper functioning of our website, including maintaining secure sessions and remembering your cookie preferences. We may also use analytics cookies to collect information about how visitors use our website, such as which pages are visited most often and whether visitors encounter error messages. These cookies do not collect information that directly identifies you; the data is aggregated and anonymized. We do not use advertising cookies or third-party tracking cookies for behavioral advertising purposes.
Your Cookie Choices: Most web browsers allow you to control cookies through their settings. You can configure your browser to accept all cookies, reject all cookies, or notify you when a cookie is being set. Each browser is different, so please consult the help menu of your browser to learn how to modify your cookie preferences. Please note that if you choose to disable cookies, certain features of our website may not function properly.
Server Logs: In addition to cookies, our web servers automatically record information in server logs when you access our website. These logs include your IP address, browser type, referring page, and timestamp of your request. This information is used for security monitoring, troubleshooting, and aggregate traffic analysis and is not used to identify individual visitors.
9. Third-Party Services and Links
Our website may contain links to third-party websites, plugins, or services that are not owned or controlled by BravePass or JiuJiang YongHanGuan Trading Co., Ltd. This section explains our relationship with such third parties and your responsibilities when interacting with them.
Third-Party Links: If you click on a link to a third-party website, you will be directed to that third party’s site. We strongly advise you to review the privacy policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites or services. The inclusion of a link on our website does not imply endorsement of the linked site or its operators.
Embedded Content: Our website does not currently embed content such as videos, maps, or social media feeds from third-party services that would result in those services placing cookies or collecting data about our visitors. Should this change in the future, we will update this policy and provide appropriate notice.
Analytics Services: We may use self-hosted or privacy-respecting analytics solutions to understand website usage patterns. Any analytics solution we deploy will be configured to respect user privacy and will not be used to track individuals across multiple websites or build behavioral advertising profiles. We do not use services that collect personal information for advertising or marketing purposes unrelated to our own service delivery.
Payment Processing: If and when we accept payments through our website, payment transactions will be processed by a reputable third-party payment processor. We will not store or have access to your full credit card or bank account details. The payment processor will handle your financial information in accordance with its own privacy policy and applicable Payment Card Industry Data Security Standards.
10. Children and Privacy
Our website and services are not directed to, and we do not knowingly collect personal information from, children under the age of 16. We take the protection of children and their privacy seriously and have established the following policies in this regard.
No Collection from Children: BravePass provides professional computer systems design and related services to businesses and organizations. Our website and services are intended for use by adults in a professional or business capacity. We do not design our website, content, or services to appeal to or target children, and we do not knowingly solicit or collect personal information from anyone under the age of 16.
Parental Responsibility: If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately using the information provided in Section 15 of this policy. Upon verification, we will take prompt steps to remove such information from our records and terminate any associated accounts or subscriptions.
Age Verification: We do not currently implement age verification mechanisms on our website because the nature of our services does not typically attract or involve minors. If we become aware that we have inadvertently collected personal information from a child under the age of 16 without verified parental consent, we will delete that information as quickly as reasonably possible.
11. International Data Transfers
BravePass operates primarily from the People’s Republic of China, but our clients may be located in various jurisdictions around the world. This section describes how we handle the transfer of personal information across international borders.
Primary Processing Location: Personal information we collect is primarily processed and stored at our facilities and on our servers located in China. Our operations are based at Room 401-48, 4/F, Development Company Building, No. 168 Changhong Avenue, Lianxi District, Jiujiang, Jiangxi Province, 332000, China, and our primary technical infrastructure is hosted within Chinese data centers. By submitting your personal information to us, you acknowledge and agree to this transfer, storage, and processing.
Cross-Border Safeguards: When we transfer personal information from the European Economic Area, the United Kingdom, or other jurisdictions with data transfer restrictions to countries that may not have been deemed to provide an adequate level of data protection, we implement appropriate safeguards in accordance with applicable legal requirements. These safeguards may include standard contractual clauses approved by relevant regulatory authorities, explicit consent from the data subject, or other lawful transfer mechanisms recognized by applicable data protection laws.
Access from Other Jurisdictions: If you are accessing our website or services from a jurisdiction outside China, please be aware that your information may be transferred to, stored, and processed in China or other countries where our service providers operate. The data protection laws of these jurisdictions may differ from those of your home jurisdiction. By using our website or services, you consent to the transfer of your information to these jurisdictions.
12. Data Retention Policy
We retain personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our retention periods are determined based on the nature of the data, the purposes of processing, and our legal obligations.
Retention Criteria: The criteria we use to determine appropriate retention periods include the duration of our relationship with you and the period during which we provide services to you, whether there is a legal obligation to which we are subject that requires retention for a minimum period, whether retention is advisable in light of our legal position regarding statutes of limitations, litigation, or regulatory investigations, and any relevant industry standards or guidance on data retention.
Specific Retention Periods: Contact and communication records are generally retained for the duration of our client relationship and for a period of three years following the conclusion of that relationship, unless a longer retention period is required for legal or regulatory purposes. Technical and usage data collected through website visits is retained in identifiable form for a maximum of 26 months, after which it is anonymized or deleted. Service engagement data is retained for the duration of the engagement and for a period of five years thereafter to support any warranty obligations, regulatory compliance, and potential dispute resolution.
Data Deletion: When personal information is no longer required for the purposes described in this policy or for legal compliance, we will securely delete or anonymize it. Deletion may involve erasure from active databases, secure overwriting of storage media, or the irreversible anonymization of data such that it can no longer be associated with an identified or identifiable individual.
13. Your Data Protection Rights
Depending on your jurisdiction, you may have certain rights regarding the personal information we hold about you. We respect these rights and have established procedures to help you exercise them. This section summarizes the rights that may be available to you under applicable data protection laws.
Right of Access: You have the right to request a copy of the personal information we hold about you, together with information about how we process it. We will provide this information in a commonly used electronic format unless you request otherwise.
Right to Rectification: If you believe that any personal information we hold about you is inaccurate or incomplete, you have the right to request that we correct or supplement it. We encourage you to keep us informed of any changes to your contact details or other personal information.
Right to Erasure: In certain circumstances, you have the right to request that we delete the personal information we hold about you. This right is not absolute and may be subject to exceptions, such as where we need to retain information to comply with a legal obligation or to establish, exercise, or defend legal claims.
Right to Restrict Processing: You have the right to request that we restrict the processing of your personal information in certain situations, such as where you contest the accuracy of the data or object to our processing. Where processing is restricted, we may continue to store your data but will only process it with your consent or for specific legal purposes.
Right to Data Portability: Where processing is based on your consent or a contract and is carried out by automated means, you have the right to receive your personal information in a structured, commonly used, and machine-readable format, and to have it transmitted directly to another data controller where technically feasible.
Right to Object: You have the right to object to our processing of your personal information where we rely on legitimate interests as the legal basis. You also have an absolute right to object to the processing of your data for direct marketing purposes, though as stated elsewhere in this policy, we do not currently engage in direct marketing.
Exercising Your Rights: To exercise any of the rights described above, please contact us using the details provided in Section 15. We will respond to your request within the timeframes required by applicable law, typically within 30 days. We may need to verify your identity before processing your request. There is generally no fee for exercising these rights, though we may charge a reasonable fee if your request is manifestly unfounded, excessive, or repetitive.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal obligations, or service offerings. We encourage you to review this policy periodically to stay informed about how we protect your personal information.
Notification of Changes: When we make material changes to this policy, we will post a prominent notice on our website at https://www.bravepass.hair and update the Last updated date at the top of this page. If the changes are significant, we may also notify you by email if we have your contact information on file. Changes to this policy are effective immediately upon posting unless a later effective date is specified.
Your Continued Use: Your continued use of our website or services after any modification to this Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the revised policy, you should discontinue use of our website and services and contact us to discuss the handling of your existing personal information.
Version History: We maintain an internal record of all versions of this Privacy Policy. Previous versions are available upon request by contacting us using the information provided in Section 15. The version date at the top of this page indicates when the current version became effective.
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please do not hesitate to contact us. We welcome your inquiries and are committed to addressing them promptly and transparently.
Data Controller: The data controller responsible for your personal information is JiuJiang YongHanGuan Trading Co., Ltd., operating through its BravePass service brand. You can reach us through any of the following channels:
Email: reach@bravepass.hair — For privacy-related inquiries, please include Privacy Inquiry in the subject line to ensure your message is routed appropriately.
Phone: +1 (740) 895-9338 — Available during standard business hours, China Standard Time.
Postal Address:
JiuJiang YongHanGuan Trading Co., Ltd.
Attn: Data Protection
Room 401-48, 4/F, Development Company Building
No. 168 Changhong Avenue, Lianxi District
Jiujiang, Jiangxi Province, 332000
People’s Republic of China
Supervisory Authority: If you believe that we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with the data protection supervisory authority in your jurisdiction. We encourage you to contact us first so that we can attempt to resolve your concern directly.
Response Commitment: We acknowledge all privacy-related inquiries within two business days and aim to provide a substantive response within 14 calendar days. Complex requests that require additional investigation may take longer, and we will keep you informed of our progress throughout the process.
This Privacy Policy was last reviewed and updated on August 3, 2026. It is effective immediately and supersedes all prior versions.