Personal Data & GDPR
TITLE II – PERSONAL DATA PROTECTION POLICY
Last updated: March 30, 2026
This Personal Data Protection Policy (hereinafter “Data Policy”) describes how Mijay Group BUSINESS LOGISTICS LIMITED collects, processes, stores, and protects the personal data of platform users. It is written in accordance with:
• The Personal Information Protection Act of the PRC (PIPL) – in force since November 1, 2021;
• The Network Security Act of the PRC – 2017;
• The Data Security Act of the PRC – 2021;
• The General Data Protection Regulation (GDPR) of the European Union – Regulation (EU) 2016/679;
• The French Data Protection Act (Loi Informatique et Libertés) – as amended;
• All sector-specific regulations applicable to e-commerce and online payments.
2.1 Data Controller
Data Controller: Mijay Group BUSINESS LOGISTICS LIMITED
Address: Room 2502C, 25/F, 148 Electric Road, North Point, Hong Kong
DPO Email: contact@mijaygroup.com
Data Protection Officer: Smaali Raoua — Privacy Officer
2.2 Data Collected
We collect the following categories of data, depending on the services used:
Data Category Details of Data Collected
Identity Data: Last name, first name, date of birth, nationality, identity document (KYC)
Contact Data: Email address, telephone number, postal address
Business Data: Company name, SIRET/registration number, sector of activity, intra-community VAT number
Connection Data: IP address, session identifiers, access logs Timestamp
Browsing data: Pages visited, clicks, session duration, browser, operating system
Payment data: Card number (tokenized), cardholder, expiry date, IBAN (no raw card data stored)
Order data: Order content, amounts, transaction history, delivery status
Training data: Progress in modules, assessment results, certificates obtained
Communication data: Messages exchanged via internal messaging, support tickets
Geolocation data: User's country (detected via IP, not precise)
Documents provided: Signed contracts, invoices, certificates, customs documents, photos of goods
2.3 Purposes & Legal Basis for Processing
Purpose of Processing Applicable Legal Basis
User Account Creation and Management Performance of the contract (Art. 6.1.b GDPR / Art. 13 PIPL)
Order Processing and Invoicing Performance of the contract
Online Payment Processing Performance of the contract + Legal obligation
Identity Verification (KYC/AML) Legal obligation (Anti-Money Laundering Regulations)
Organization of Transport and Customs Clearance Performance of the contract
Access to Online Training Performance of the contract
Customer Service and Dispute Management Legitimate Interest / Performance of the contract
Sending Transactional Communications Performance of the contract
Sending Marketing Communications / Newsletters Consent (Art. 6.1.a GDPR)
Service Improvement and Statistical Analysis Legitimate Interest (anonymized)
Fraud Prevention and Security Legal obligation + Legitimate interest
Compliance with Accounting and Tax Obligations Obligation Legal
Traceability of payment transactions: Legal obligation (10-year retention period)
2.4 Data Recipients
Your personal data may be shared with the following categories of recipients, strictly to the extent necessary for the performance of the services:
• Payment providers (e.g., Stripe, PayPal, Alipay, WeChat Pay, UnionPay) – for the secure processing of transactions;
• Logistics providers and freight forwarders – for organizing transport and customs formalities;
• Suppliers listed on the platform – for sourcing purposes, limited to the strictly necessary information;
• Hosting and technical service providers – for the operation of the IT infrastructure;
• Email and CRM providers – for managing communications;
• Accountants, auditors, and legal advisors – as required by law;
• Administrative and judicial authorities – upon request or legal obligation;
• Certified training partners – for issuing certificates;
No sale of personal data to third parties for advertising purposes is carried out.
2.5 International Data Transfers
Due to the international nature of our activities, some data may be transferred to third countries (in particular to the European Union for users residing in China, or vice versa). These transfers are governed by:
• Standard contractual clauses (SCCs) approved by the European Commission;
• Approved certification mechanisms or codes of conduct;
• The PIPL requirements for security assessments for cross-border data transfers from China;
• Contractual guarantees equivalent to the level of protection required by applicable law.
The user can obtain information on applicable warranties by contacting: contact@mijaygroup.com
2.6 Data Retention Period
Data Type Retention Period
Active Account Data: Duration of the contractual relationship + 3 years after account closure
Transaction/Order Data: 10 years (accounting and tax obligation)
Payment Data (Tokens): Duration of the business relationship + 13 months (credit card disputes)
KYC/Identity Verification Data: 5 years after end of the relationship (AML/CFT regulations)
Connection and Security Logs: 12 months (legal obligation for network security in China)
Analytical Cookies: Maximum 13 months
Consent Cookies: 6 months
Training/Certification Data: Duration of the subscription + 5 years
Communications (emails, tickets): 3 years from the last interaction
Browsing Data: Maximum 25 months (Google Analytics/equivalent)
2.7 Data Security Data
We implement appropriate technical and organizational measures to ensure the security of your data, including:
• SSL/TLS encryption (minimum TLS 1.2) of all communications between your browser and our servers;
• Encryption at rest of sensitive data (AES-256);
• Tokenization of payment data by PCI DSS Level 1 certified providers;
• Strict control of internal access based on the principle of least privilege;
• Two-factor authentication (2FA) for access to administration interfaces;
• Regular security audits and penetration testing;
• Business continuity and disaster recovery plan (BCP/DRP);
• Regular staff training on IT security best practices;
• Procedure for notifying personal data breaches within the legal timeframes (72 hours GDPR, 24 hours PIPL).
2.8 User Rights
In accordance with the GDPR (for EU residents) and the PIPL (for residents of China), you have the following rights regarding your personal data:
Right Description & Exercise
Right of access (Art. 15 GDPR) Obtain a copy of your processed data and information about its processing
Right to rectification (Art. 16 GDPR) Correct inaccurate or incomplete data
Right to erasure (Art. 17 GDPR) Obtain the deletion of your data in the cases provided for by law
Right to data portability (Art. 20 GDPR) Receive your data in a structured and machine-readable format
Right to object (Art. 21 GDPR) Object to processing based on legitimate interest
Right to restriction of processing (Art. 18 GDPR) Temporarily suspend the processing of your data
Withdrawal of consent At any time for processing based on consent
Right not to be subject to automated decision-making (Art. 22 GDPR) Objecting to decisions made solely on an algorithmic basis
Post-mortem directives (Art. 85 LIL) Instructions regarding the fate of your data after your death
PIPL rights (China residents) Access, rectification, erasure, transfer, revocation according to Art. 44-54 PIPL
To exercise your rights, please send your request to: contact@mijaygroup.com. Proof of identity may be requested. We commit to responding within 30 days (GDPR) or 15 days (PIPL).
If you are dissatisfied, you can contact the CNIL (France/EU) at www.cnil.fr, or the Cyberspace Authority of China (CAC) for residents of China.
2.9 Cookie Policy
Our site uses cookies and similar technologies (pixels, web beacons, local storage). A consent banner is displayed on your first visit for non-strictly necessary cookies.
Cookie Type | Purpose & Duration
Strictly Necessary Cookies: Session, authentication, shopping cart. Duration: session / 24 hours. No consent required.
Preference Cookies: Language, time zone, display preferences. Duration: 12 months. Consent required.
Analytical Cookies: Audience measurement (Google Analytics / Matomo). Anonymized data. Duration: 13 months. Consent required.
Payment Cookies: Payment security and session (PCI DSS certified provider). Duration: session. Necessary.
Security Cookies: Fraud protection, CSRF, bot detection. Duration: session / 24 hours. Necessary.
Third-Party / Social Media Cookies: Sharing buttons (if enabled). Subject to the policies of the relevant third parties. Consent required.
You can manage your cookie preferences at any time via the "Manage cookies" link in the website footer, or through your browser settings. Refusing analytics cookies will not affect your access to the services.