Privacy Policy
This Privacy Policy explains how DEWIN Pte. Ltd. collects, uses, and protects information when you interact with our website and services.
Summary: DEWIN is a B2B supply chain services company. We collect business contact information from corporate clients, prospects, and website visitors solely to deliver our services and communicate about your project inquiries. We do not sell personal data. We do not serve consumers or process sensitive personal data.
Who We Are
DEWIN Pte. Ltd. ("DEWIN," "we," "us," or "our") is a supply chain services company incorporated in Singapore. We operate offices in Ho Chi Minh City, Vietnam, and Xi'an, China, and serve corporate clients primarily in the United States and Europe.
DEWIN acts as the data controller for personal data collected through our website (dewintech.com), RFQ forms, email correspondence, and other business communications.
Data We Collect
We collect only the information necessary to evaluate your project requirements, provide quotations, and manage our business relationship. We collect data through the following channels:
Information You Provide Directly
- -- Business contact information: full name, job title, company name, business email address, and phone number submitted via RFQ forms or contact forms.
- -- Project and technical data: engineering drawings, specifications, material requirements, quantities, and delivery timelines submitted as part of an RFQ.
- -- Correspondence: emails, messages, and attachments exchanged during project discussions, quotation reviews, and order management.
- -- Business documents: purchase orders, contracts, invoices, and payment records required for transactional and compliance purposes.
Information Collected Automatically
- -- Log data: IP address, browser type and version, operating system, referring URL, pages visited, and time spent on pages.
- -- Cookie data: session identifiers, analytics preferences, and functional settings. See Section 5 for full details.
- -- Device data: device type, screen resolution, and general geographic region (country/city level only, derived from IP address).
Information From Third-Party Platforms
- -- Alibaba International Station: business contact details and inquiry content submitted through our Alibaba storefront.
- -- LinkedIn: publicly visible professional profile information when you connect with or message our team members.
We do not collect: government ID numbers, financial account credentials, health data, biometric data, or any special category of sensitive personal data as defined under applicable law.
How We Use Your Data
We use personal data only for the purposes for which it was collected or for closely related purposes that you would reasonably expect. Specifically:
| Purpose | Details |
|---|---|
| Responding to RFQs & inquiries | Evaluating your project requirements, preparing quotations, and communicating with your team throughout the sourcing process. |
| Order & contract management | Processing purchase orders, managing production schedules, coordinating logistics, and issuing invoices and documentation (PPAP, COA, etc.). |
| Client relationship management | Maintaining records of past projects, communicating updates on ongoing orders, and providing post-delivery support. |
| Business communications | Sending relevant service updates, capability announcements, or industry information to existing clients and qualified prospects. You may opt out at any time. |
| Legal & compliance | Complying with Singapore PDPA, applicable export regulations, tax obligations, and responding to lawful requests from authorities. |
| Website improvement | Analyzing aggregated, anonymized usage data to understand how visitors interact with our website and improve content and navigation. |
Legal Basis for Processing
DEWIN is headquartered in Singapore and complies with the Personal Data Protection Act 2012 (PDPA). For clients in the European Union or United Kingdom, we also recognize the lawful bases under the GDPR / UK GDPR:
- Contractual necessity: processing required to enter into or perform a contract with you or your company (e.g., processing an RFQ, fulfilling a purchase order).
- Legitimate interests: conducting B2B sales and marketing activities, improving our services, and maintaining business records -- where these interests are not overridden by your data protection rights.
- Legal obligation: complying with applicable laws, tax regulations, and regulatory requirements in Singapore, Vietnam, and China.
- Consent: where required by law (e.g., for certain marketing communications or non-essential cookies), we will obtain your explicit consent and you may withdraw it at any time.
Third-Party Sharing
We do not sell, rent, or trade your personal data. We share data only in the limited circumstances described below, and only to the extent necessary for each purpose.
Our Internal Offices
Project and contact data is shared with our team members in Singapore, Vietnam (Ho Chi Minh City), and China (Xi'an) as needed to manage your project. All offices operate under consistent data handling policies.
Vetted Factory Partners
Technical drawings and specifications are shared with shortlisted factories only after you have approved us to proceed with quoting or sampling. We share the minimum information necessary and require factories to treat drawings as confidential. We strongly recommend signing a mutual NDA before sharing proprietary designs.
Service Providers & Processors
We use third-party service providers for website hosting, email delivery, CRM software, and analytics (e.g., Google Analytics). These providers process data only on our behalf and under contractual data processing agreements. They are not permitted to use your data for their own purposes.
Legal & Regulatory Authorities
We may disclose data to government authorities, regulators, or courts when required by law, court order, or to protect the legal rights and safety of DEWIN, our clients, or third parties.
Business Transfers
In the event of a merger, acquisition, or sale of all or part of DEWIN's business assets, personal data may be transferred to the acquiring entity. We will notify affected individuals prior to any such transfer and ensure continued protection under this policy or a materially equivalent standard.
International Data Transfers
Because DEWIN operates across Singapore, Vietnam, and China, personal data collected from clients in the United States and Europe may be accessed by team members in all three locations. We take the following steps to protect data during cross-border transfers:
- Internal access controls: access to client data is restricted to team members who require it to perform their job functions. We use role-based access and secure communication channels.
- Standard Contractual Clauses (EU/UK clients): where required under GDPR or UK GDPR, we rely on Standard Contractual Clauses approved by the European Commission or the UK ICO to legitimize transfers to our offices in Vietnam and China.
- Singapore PDPA transfer obligations: transfers from Singapore to our overseas offices are governed by our internal data transfer policies in compliance with the PDPA's transfer limitation obligation.
- Encryption in transit: all data transmitted between our offices and with clients uses TLS encryption. Email attachments containing technical drawings or sensitive business data are handled through secure channels.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our general retention periods are:
| Data Type | Retention Period |
|---|---|
| RFQ inquiries (no order placed) | 2 years from last contact |
| Active client records & order data | Duration of business relationship + 7 years |
| Financial & tax documents | 7 years (Singapore statutory requirement) |
| Technical drawings & specifications | Duration of NDA / project life, or as agreed |
| Website analytics data | 26 months (Google Analytics default, anonymized) |
| Marketing communication records | Until opt-out, then deleted within 30 days |
After the applicable retention period expires, personal data is securely deleted or anonymized. Data that has been anonymized and can no longer identify any individual is not subject to this policy.
Security Measures
We implement technical and organizational measures appropriate to the risk level of the data we process. Our security practices include:
While we implement industry-standard security measures, no method of transmission over the internet or electronic storage is 100% secure. In the event of a data breach that poses a risk to your rights, we will notify affected parties and relevant authorities as required by applicable law.
Your Rights
Depending on your location, you may have the following rights regarding your personal data. We will respond to verified requests within 30 days.
Access
Request a copy of the personal data we hold about you and information about how it is processed.
Correction
Request that we correct inaccurate or incomplete personal data we hold about you.
Deletion ("Right to Erasure")
Request deletion of your personal data where we no longer have a legal basis or legitimate need to retain it. Note: we may be required to retain certain data for legal or contractual obligations.
Restriction
Request that we restrict processing of your data in certain circumstances, such as while a correction request is being reviewed.
Portability
Request a machine-readable copy of data you have provided to us, where technically feasible and where processing is based on consent or contract (EU/UK clients).
Objection
Object to processing based on legitimate interests, including direct marketing communications. We will stop processing unless we have compelling grounds to continue.
Withdraw Consent
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
Lodge a Complaint
EU/UK clients may lodge a complaint with their local data protection authority. Singapore-based individuals may contact the Personal Data Protection Commission (PDPC).
To exercise any of these rights, please email us at privacy@dewintech.com with the subject line "Data Rights Request." We may need to verify your identity before processing your request.
Children's Privacy
DEWIN's website and services are directed exclusively at business professionals and corporate entities. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly. If you believe we have collected data from a minor, please contact us at privacy@dewintech.com.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Notify active clients via email if the changes materially affect how we process their data.
- Post a notice on our website homepage for a period of at least 30 days following a significant update.
Your continued use of our website or services after the effective date of any changes constitutes acceptance of the updated policy. We encourage you to review this page periodically.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact our Data Protection contact:
Est. 2011
Regulatory Authority (Singapore): If you are not satisfied with our response to a privacy concern, you may contact the Personal Data Protection Commission (PDPC) of Singapore at www.pdpc.gov.sg. EU/UK residents may contact their local supervisory authority.
This Privacy Policy was last updated on 1 January 2026 and is effective as of that date.
© 2026 DEWIN Pte. Ltd. All rights reserved.