1.personal data

personal data refer to the information that can identify an individual when used alone or in combination with other information. such data may be submitted to us by your side when you use our website, products or services, and when you interact with us, or we obtain it by recording how you interact with our website, products or services, for example, through such technologies as cookies. the data we collect depends on the website you visit or the products and services you use and may include personal data of name, address, email address, phone number, etc. we collect personal data for the purpose of contacting you in order to provide appropriate services or send important notices, etc.

2.privacy policy

shanghai rass blood products co., ltd. and its subsidiaries worldwide (hereinafter referred to as "[shanghai rass] [tonrol biopharmaceutical] [haikang biopharmaceutical] [zhengzhou rass]", "we" or "ours") are aware of the importance of personal data to our customers and users. for this reason, shanghai rass blood products co., ltd. takes the protection of customers' and users' personal data very seriously and has taken a series of measures to ensure that the relevant business complies with the applicable personal data protection requirements (e.g. gdpr).

2.1 in order to ensure effective implementation of personal data protection requirements,shanghai rass blood products co., ltd. has appointed a data protection officer (dpo).

2.2 shanghai rass blood products co., ltd. has adopted industry-recognized personal data protection methods and practices. in business scenarios where the gdpr applies, shanghai rass blood products co., ltd. uses the data protection impact assessment (dpia) methodology to assess and mitigate personal data security risks in products and services.

2.2.1 shanghai rass blood products co., ltd. requires that personal data involved in products and services be fully assessed and that items involving personal data be subject to a dpia;

2.2.2 items involving personal data shall establish a data inventory and data flow diagram;

2.2.3 projects involving personal data shall identify potential risks in data processing (including the processes of collection, use, storage, sharing, deletion, etc.) and take appropriate measures (including administrative, physical and technical measures) according to the risk level.

2.2.4 after the execution of dpia, the corresponding output report shall be accompanied and approved by dpo.

2.3. shanghai rass blood products co., ltd. implements technical measures including intrusion detection, access control, encryption, data leakage prevention, anti-spam, endpoint security protection, vulnerability scanning, etc., and tests the effectiveness of personal data protection measures through penetration test.

2.4. shanghai rass blood products co., ltd. has established a personal data leakage emergency response mechanism. in the event of a personal data leakage, shanghai rass will immediately initiate the emergency response process in an effort to reduce the potential loss caused by the personal data leakage and ensure that the affected personnel are duly notified.

2.5. shanghai rass blood products co., ltd. has established an ongoing employee training mechanism on privacy policy to ensure that each employee involved in gdpr accurately understands the legal principles of data protection based on his or her specific job responsibilities and strictly enforces the company’s applicable systems and processes.

2.6. to ensure compliance, shanghai rass blood products co., ltd. has implemented the necessary technical and process audits for personal data protection.

personal data protection is not only a legal requirement, but also a corporate social responsibility. shanghai rass will continue to optimize its products and services to ensure security and privacy and to reduce the risk of personal data protection for customers and users.

3.policy update

shanghai rass reserves the right to update or modify this policy from time to time. if changes are made to this policy, we will post the latest version of this policy here. in case of material changes made to our privacy policy, we may also send you notice thereof through various channels, such as posting a notice on our website or giving you a separate notice.