1. Introduction and Scope

RhymeVivid takes the privacy and security of personal information seriously. This Privacy Policy explains how we collect, use, store, share, and protect information about individuals who interact with our website, services, and communications. The policy applies to all visitors, clients, prospective clients, partners, and any other natural persons whose data we may process in the course of delivering Computer Systems Design and Related Services.

This document governs the processing of personal data through the website located at www.rhymevivid.lat, any subdomains, related mobile applications, email communications, and all associated services collectively referred to as the Service. By accessing or using the Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with any part of this policy, you should discontinue use of the Service immediately.

We reserve the right to update this Privacy Policy at any time to reflect changes in our practices, legal obligations, or operational requirements. We encourage you to review this page periodically. The date of the most recent revision is indicated at the top of this document. Continued use of the Service after any modification constitutes acceptance of the updated terms.

This policy is designed to comply with applicable data protection laws including but not limited to the Personal Information Protection Law of the Peoples Republic of China (PIPL), the General Data Protection Regulation (GDPR) of the European Union where applicable, the California Consumer Privacy Act (CCPA), and other relevant regional privacy frameworks. Where a conflict exists between this policy and mandatory legal provisions, the legal provisions shall prevail.

2. About the Data Controller

The Service is developed and operated by RhymeVivid, a technology practice specializing in Computer Systems Design and Related Services. The legal entity responsible for data processing and acting as the data controller is Kunming YunJunDuo Trading Co., Ltd., a company duly incorporated and registered under the laws of the Peoples Republic of China.

The registered office and principal place of business of Kunming YunJunDuo Trading Co., Ltd. is located at Attach 1-PL, No. 223 Xiaolong Road, Donghua Street, Panlong District, Kunming, Yunnan 650000, China. All formal correspondence regarding data protection matters, including data subject access requests and privacy inquiries, should be directed to this physical address or to our designated privacy contact email address.

Kunming YunJunDuo Trading Co., Ltd. determines the purposes and means of processing personal data collected through the Service. In this capacity, the company is responsible for ensuring that all personal data is processed lawfully, fairly, and transparently in accordance with the principles set forth in this Privacy Policy and the applicable legal frameworks governing data protection in the jurisdictions where we operate.

3. Information We Collect

We collect several categories of information depending on the nature of your interaction with the Service. The types of personal data we may process include but are not limited to the following categories.

Identity and Contact Data. This includes your full name, email address, telephone number, company name, job title or role, and physical mailing address. We collect this data when you fill out our contact form, subscribe to communications, request a consultation, or otherwise voluntarily provide it to us through the Service. This data allows us to identify you as a distinct individual or business contact and to communicate with you regarding our services.

Technical and Usage Data. When you access the Service, our servers automatically record certain technical information transmitted by your browser or device. This includes your Internet Protocol (IP) address, browser type and version, operating system, device type, screen resolution, referring URL, pages visited, time and date of visits, time spent on each page, clickstream data, and other diagnostic information. This data is essential for maintaining the security, stability, and performance of the Service.

Communication Data. When you send us an email, submit a form, or otherwise communicate with us through any channel, we collect and store the content of that communication, including any attachments you provide. This includes the metadata associated with the communication such as timestamps, subject lines, and delivery status. We retain this data to respond to your inquiries, maintain records of our correspondence, and improve our service quality.

Business Relationship Data. For clients and business partners, we may collect additional information necessary for the performance of our contractual obligations. This includes project specifications, technical requirements, billing and payment information, service level agreements, and records of meetings and deliverables. This category of data is processed strictly within the scope of the professional engagement.

Aggregated and Anonymized Data. We may create aggregated statistical data derived from personal information, which no longer identifies any individual. This anonymized data may be used for analytics, research, service improvement, and business intelligence purposes without restriction, as it falls outside the scope of personal data protection regulations.

4. How We Collect Information

We collect information through multiple channels and methods, each designed to capture data that is relevant and necessary for the specific context of the interaction.

Direct Collection. The primary method of data collection is direct — information you voluntarily provide to us. This occurs when you complete our contact form on the website, send an email to any RhymeVivid email address, call our telephone number, participate in a consultation call or video conference, subscribe to newsletters or updates, register for events, or engage in any other form of direct communication with our team. In each case, you control what information you share, although declining to provide certain data may limit our ability to respond to your inquiry or deliver requested services.

Automated Collection. As you navigate through the Service, we use automated technologies to collect technical and usage data. These technologies include server logs, which record each request made to our web servers, and analytics tools that measure how visitors interact with our pages. Automated collection helps us understand usage patterns, detect security threats, prevent fraud, optimize performance, and improve user experience without requiring active input from you.

Third-Party Sources. In limited circumstances, we may receive information about you from third parties. This includes analytics providers who share aggregated usage reports, publicly available business directories and professional networks, and in rare cases, clients or partners who provide your contact information as part of a project referral or collaboration arrangement. When we receive data from third parties, we verify that the source has obtained appropriate consent for sharing and that the data is relevant to our legitimate business purposes.

5. Purpose and Legal Basis for Processing

We process personal data only when we have a valid legal basis to do so. The specific basis depends on the nature of your relationship with RhymeVivid and the purpose of the processing activity. We identify and document the legal basis before commencing any new data processing operation and regularly review our processing activities to ensure ongoing compliance.

Consent. Where you have given clear and affirmative consent for us to process your personal data for a specific purpose, we rely on that consent as our legal basis. This includes subscribing to marketing communications, agreeing to the use of certain cookies, and providing optional information through our contact form. You have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Contractual Necessity. When you enter into a service agreement with RhymeVivid, we process your personal data as necessary for the performance of that contract. This includes managing project deliverables, processing payments, communicating about project status, and fulfilling our obligations under the terms of the engagement. Without this data processing, we would be unable to provide the contracted services.

Legitimate Interests. We may process personal data based on our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Legitimate interests include improving the Service, analyzing usage trends, ensuring network and information security, preventing fraud, maintaining business records, and responding to inquiries. We conduct a balancing test for each processing activity to ensure our interests are proportionate and justified.

Legal Obligations. In certain circumstances, we are required to process personal data to comply with applicable laws and regulations. This includes tax and accounting obligations, responding to lawful requests from government authorities, maintaining records as required by commercial and corporate law, and cooperating with regulatory investigations.

6. How We Use Your Information

The personal data we collect serves specific, well-defined purposes that align with our mission of delivering professional Computer Systems Design and Related Services. We do not use personal data for purposes that are incompatible with those described in this policy without first notifying you and, where required by law, obtaining your consent.

Service Delivery. We use contact and business relationship data to provide, maintain, and improve the services you have requested. This includes responding to inquiries, preparing proposals, conducting technical assessments, delivering project work, and providing ongoing support and maintenance. This is the core operational purpose for which most personal data is collected.

Communication. We use your contact information to communicate with you about your account, transactions, projects, and any changes to our terms or policies. We may also send you service-related announcements, technical notices, and updates about the Service that are essential to your use or to our ongoing professional relationship.

Marketing and Business Development. With your consent where required by law, we may use your contact information to send you information about new services, case studies, industry insights, events, and other content that we believe may be relevant to your professional interests. You may opt out of marketing communications at any time by using the unsubscribe link included in every message or by contacting us directly.

Analytics and Improvement. Technical and usage data helps us understand how visitors interact with the Service. We analyze navigation patterns, popular content, load times, and error rates to identify areas for enhancement. This data is typically aggregated and anonymized, and it informs our decisions about content development and technical optimizations.

Security and Compliance. We process technical data to monitor for unauthorized access, detect and prevent security incidents, verify user identity, enforce our Terms of Service, and comply with legal obligations. Automated systems analyze log data for patterns that may indicate malicious activity or policy violations.

7. Cookies and Tracking Technologies

The Service uses cookies and similar tracking technologies to enhance functionality, analyze performance, and deliver a consistent user experience. A cookie is a small text file placed on your device by a web server that can later be retrieved by that server. Cookies serve various purposes ranging from essential site functions to analytics and personalization.

Essential Cookies. These cookies are strictly necessary for the operation of the Service. They enable core functionality such as security, network management, and accessibility. The Service cannot function properly without these cookies, and they are set automatically when you access the site. Essential cookies do not require consent under most data protection frameworks, although we disclose their use transparently here.

Analytics Cookies. We use analytics cookies to collect information about how visitors use the Service, including which pages are viewed most frequently, how users navigate through the site, and whether they encounter errors. This data is aggregated and anonymized. The analytics tools we use may set cookies on your device to track your session and distinguish between new and returning visitors.

Managing Cookies. Most web browsers allow you to manage cookie preferences through their settings interface. You can typically configure your browser to block all cookies, accept only first-party cookies, or delete cookies when you close the browser. Please note that blocking essential cookies may impair the functionality of the Service and prevent certain features from operating correctly. For detailed guidance on managing cookies in specific browsers, consult the browser help documentation or visit relevant online resources maintained by browser developers.

Do Not Track Signals. Some browsers offer a Do Not Track (DNT) feature that sends a signal to websites indicating the users tracking preference. At present, there is no universally accepted standard for how websites should respond to DNT signals. As a result, the Service does not currently alter its behavior based on DNT header information.

8. Data Sharing and Disclosure

RhymeVivid does not sell, rent, or trade personal data to third parties for their own marketing purposes. We share personal data only in the limited circumstances described below and always with appropriate safeguards in place to protect the confidentiality and security of the information.

Service Providers. We engage trusted third-party service providers to perform functions and process data on our behalf. These providers include hosting and infrastructure providers, analytics services, email delivery platforms, and professional services firms. Each service provider is contractually bound to process data only in accordance with our instructions, maintain appropriate security measures, and comply with applicable data protection laws. We conduct due diligence on all service providers before engagement and periodically review their compliance.

Business Transfers. In the event of a merger, acquisition, reorganization, sale of assets, or similar corporate transaction, personal data may be transferred as part of the transaction. In such circumstances, we will notify you before your personal data is transferred and becomes subject to a different privacy policy. We will also ensure that the receiving entity agrees to honor the commitments made in this Privacy Policy.

Legal Disclosure. We may disclose personal data when we believe in good faith that disclosure is necessary to comply with applicable law, regulation, legal process, or governmental request; to enforce our Terms of Service and other agreements; to protect the rights, property, or safety of RhymeVivid, our clients, or the public; or to detect, prevent, or otherwise address fraud, security, or technical issues.

With Your Consent. We may share your personal data for purposes not covered by this policy when you have provided explicit consent for such sharing. You retain the right to withdraw that consent at any time.

9. International Data Transfers

RhymeVivid is headquartered in Kunming, Yunnan, China, and our primary data processing activities occur within the Peoples Republic of China. However, as a provider of technology services to clients around the world, and by virtue of using globally distributed cloud infrastructure, certain personal data may be transferred to, stored, or processed in jurisdictions outside of your country of residence. These jurisdictions may have data protection laws that differ from those in your home country.

When we transfer personal data across international borders, we implement appropriate safeguards to ensure that the data receives an adequate level of protection. These safeguards include standard contractual clauses approved by relevant data protection authorities, conducting transfer impact assessments to evaluate the risks associated with cross-border data flows, implementing supplementary technical and organizational measures, and ensuring that any third-party recipients maintain equivalent data protection standards.

For data subjects located in the European Economic Area or the United Kingdom, we ensure that transfers are governed by the European Commissions Standard Contractual Clauses or the UK International Data Transfer Agreement, as applicable. For data subjects in China, we comply with the cross-border data transfer requirements established under the Personal Information Protection Law, including security assessments and standard contracts where required.

By using the Service and providing your personal data, you acknowledge and consent to the transfer, storage, and processing of your information in China and any other country where we or our service providers operate. If you have questions about the specific safeguards applied to a particular transfer, please contact us using the information provided in this policy.

10. Data Retention

We retain personal data only for as long as is necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. The specific retention period depends on the nature of the data and the purpose of its collection. When determining the appropriate retention duration, we consider the amount, nature, and sensitivity of the data; the potential risk of harm from unauthorized use or disclosure; the purposes for which we process the data; whether those purposes can be achieved through other means; and applicable legal requirements.

Contact and Inquiry Data. Information provided through our contact form or general inquiries is retained for a period of twenty-four months from the date of last communication, unless a formal business relationship is established, in which case the data is retained in accordance with our client data policy.

Client Project Data. Data processed in the course of a client engagement is retained for the duration of the engagement plus a period of six years following project completion, consistent with applicable statutes of limitation and commercial record-keeping requirements under Chinese law.

Technical Log Data. Server logs and automated technical data are retained for a rolling period of ninety days, after which they are automatically purged unless required for an ongoing security investigation or legal matter.

Marketing Data. Personal data used for marketing purposes is retained until you withdraw your consent or opt out of receiving marketing communications. An unsubscribe record is maintained indefinitely to ensure compliance with your opt-out preference.

When personal data is no longer required for the purposes described above, we securely delete or anonymize it using industry-standard methods designed to prevent reconstruction or recovery of the original data.

11. Data Security Measures

RhymeVivid implements and maintains administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of personal data under our control. Our security program is built on a defense-in-depth architecture that layers multiple protective controls to create a robust security posture resistant to a broad spectrum of threats.

Technical Controls. We employ encryption in transit using Transport Layer Security (TLS) protocols for all data transmitted between your browser and our servers. Data at rest is encrypted using industry-standard AES-256 encryption. Our infrastructure is protected by network firewalls, intrusion detection and prevention systems, and distributed denial-of-service (DDoS) mitigation. Access to production systems requires multi-factor authentication and is restricted to authorized personnel on a need-to-know basis.

Administrative Controls. All personnel with access to personal data undergo background screening and receive regular training on data protection obligations and security best practices. We maintain detailed access control policies, conduct periodic access reviews, and enforce the principle of least privilege across all systems. Incident response procedures are documented, tested through tabletop exercises, and regularly updated to address emerging threat patterns.

Physical Controls. Our cloud infrastructure is hosted in facilities that maintain SOC 2 Type II certification and implement physical security measures including 24/7 on-site security personnel, biometric access controls, video surveillance, and environmental controls. Physical access to data center floors is restricted to authorized personnel with documented business justification.

Vulnerability Management. We conduct regular vulnerability assessments and penetration tests to identify and remediate security weaknesses. Security patches and updates are applied according to risk-based prioritization schedules. We also maintain a responsible disclosure program for security researchers to report potential vulnerabilities.

Despite these measures, no method of transmission over the Internet or electronic storage is completely secure. While we strive to protect personal data using commercially reasonable means, we cannot guarantee absolute security against all potential threats. In the event of a data breach, we will notify affected individuals and relevant authorities in accordance with applicable legal requirements.

12. Your Rights and Choices

Depending on your jurisdiction, you may have certain rights regarding the personal data we hold about you. RhymeVivid is committed to honoring these rights and will respond to valid requests within the timeframes prescribed by applicable law, typically within thirty calendar days. We may extend this period by up to an additional sixty days for complex or numerous requests, in which case we will notify you of the extension and the reasons for the delay.

Right of Access. You have the right to request confirmation of whether we process your personal data and, if so, to obtain a copy of that data along with information about how and why it is processed. The first copy will be provided free of charge; we may charge a reasonable fee for additional copies to cover administrative costs.

Right to Rectification. If you believe that personal data we hold about you is inaccurate, incomplete, or outdated, you may request that we correct or supplement it. We encourage you to keep your information current and to notify us promptly of any changes.

Right to Erasure. In certain circumstances, you may request the deletion of your personal data. This right applies when the data is no longer necessary for the purpose for which it was collected, when you withdraw consent and there is no other legal basis for processing, when you object to processing and there are no overriding legitimate grounds, or when the data has been processed unlawfully. We may retain certain data where required or permitted by law.

Right to Restrict Processing. You may request that we limit the processing of your personal data in specific situations, such as when you contest the accuracy of the data or object to processing. During the restriction period, we will store the data but not otherwise process it without your consent or for legal claims.

Right to Data Portability. Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it directly to another controller where technically feasible.

Right to Object. You have the right to object to processing based on legitimate interests or for direct marketing purposes. Upon receiving an objection to direct marketing, we will cease such processing immediately. For objections based on legitimate interests, we will evaluate whether our interests override your rights and freedoms.

Right to Withdraw Consent. Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted prior to the withdrawal. To exercise any of these rights, please contact us using the information provided in the Contact Information section below.

13. Childrens Privacy

The Service is designed for and directed at a professional audience — businesses, organizations, and individuals seeking Computer Systems Design and Related Services. The Service is not intended for use by individuals under the age of eighteen years. We do not knowingly collect, solicit, or process personal data from anyone under the age of eighteen, and we do not direct any content or marketing specifically toward children.

If we become aware that a child under the age of eighteen has provided personal data to us without verifiable parental consent, we will take prompt steps to delete that information from our systems. If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us immediately using the contact details provided in this policy so that we can take appropriate action.

We encourage parents and guardians to monitor their childrens online activities and to instruct them never to provide personal information through websites or online services without permission. Our age verification practices are designed to minimize the risk of inadvertently collecting data from minors while respecting the privacy expectations of our legitimate professional audience.

14. Third-Party Links and Services

The Service may contain links to external websites, applications, and online services that are not operated or controlled by RhymeVivid or Kunming YunJunDuo Trading Co., Ltd. These links are provided for your convenience and reference only. We do not endorse, monitor, or exercise any control over the content, privacy practices, or security of third-party websites.

If you follow a link to a third-party website, you will be subject to that websites privacy policy and terms of use. We strongly recommend that you review the privacy policy of every website you visit before providing any personal data. RhymeVivid assumes no responsibility or liability for the data handling practices of third-party operators, including their compliance with data protection laws.

Our Service may also integrate with third-party platforms, APIs, or embedded content that may collect information directly from your browser. Examples include analytics scripts and content delivery networks. These integrations operate subject to the privacy policies of their respective providers. We take reasonable steps to ensure that integrated services align with our privacy standards, but we cannot guarantee the practices of independent third parties.

15. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our data processing practices, the features and functionality of the Service, or the legal and regulatory environment in which we operate. When we make material changes, we will post the revised policy on this page with an updated effective date. For significant changes that affect your rights or the way we handle your personal data, we will provide more prominent notice, which may include an announcement on our website, direct email notification, or both, at our discretion.

We encourage you to review this Privacy Policy regularly to stay informed about our information practices and the choices available to you. The version date displayed at the top of this page indicates when the policy was last revised. Changes take effect immediately upon posting unless a different effective date is specified within the revision notice.

If we make changes that require your consent under applicable law, we will obtain that consent before applying the changes to your personal data. Your continued use of the Service following the posting of any changes constitutes acceptance of those changes, subject to any consent requirements that may apply.

16. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data processing practices, or if you wish to exercise any of the rights described in this document, please contact us through any of the following channels.

Email: reply@rhymevivid.lat

Phone: +1 (850) 546-4395

Postal Address: Attach 1-PL, No. 223 Xiaolong Road, Donghua Street, Panlong District, Kunming, Yunnan 650000, China

Data Controller: Kunming YunJunDuo Trading Co., Ltd.

Developer: RhymeVivid

We will acknowledge receipt of your inquiry within five business days and provide a substantive response within the timeframe required by applicable law, typically thirty calendar days. If your request is particularly complex or if you have submitted multiple requests, we may extend the response period and will notify you of the extension and the reasons for the delay. For requests that we cannot fulfill in whole or in part, we will explain the basis for our decision and inform you of any available appeal or complaint mechanisms.

If you believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or the location of the alleged infringement. We encourage you to contact us first so that we may address your concerns directly before you escalate to a regulatory body.