Privacy Policy
Last updated: April 21, 2026
1. Introduction
CIYuan Performance Marketing Agency Ltd ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, process, and safeguard your information when you visit our website (ciyuan.co.uk), use our services, or interact with us.
As a data controller under the UK GDPR and Data Protection Act 2018, we are responsible for ensuring that your personal data is processed lawfully and transparently. This policy applies to all personal data we collect from you, whether through our website, email communications, or direct interactions.
By using our services or providing us with your information, you consent to the collection and use of information in accordance with this policy.
2. Information We Collect
Personal Information You Provide
We collect information you directly provide to us, including:
- Contact Information: Name, email address, phone number, business address
- Business Information: Company name, job title, industry, company size, website URL
- Communication Data: Messages, inquiries, feedback, and correspondence with us
- Marketing Preferences: Your preferences for receiving marketing communications and newsletters
- Service-Related Data: Details about your marketing goals, campaigns, and performance metrics we help you track
Automatically Collected Information
When you visit our website or use our services, we automatically collect certain technical information:
- Device Information: IP address, browser type and version, operating system, device identifiers
- Usage Data: Pages visited, time spent on pages, click-through rates, referral sources
- Location Data: General location based on IP address (not precise GPS data)
- Cookies and Tracking: Information collected through cookies, web beacons, and similar technologies
- Analytics Data: Anonymous usage statistics collected through Google Analytics and similar services to understand website performance and user behavior
Third-Party Data Collection
We use third-party services that may collect anonymous data about your visit to our website:
- Google Analytics: Collects anonymous data about website usage, including pages visited, time on site, and referral sources. This data helps us improve our website and services. Google Analytics uses cookies and may collect IP addresses (anonymized).
- Google Ads and Advertising Platforms: May collect data for advertising purposes, including conversion tracking and audience building. Data is used to show relevant ads and measure campaign effectiveness.
- Social Media Platforms: LinkedIn, Twitter, and other platforms may collect data when you interact with our social media content or use sharing features.
All third-party data collection is conducted in accordance with their respective privacy policies and applicable data protection laws. You can opt out of many third-party tracking features through your browser settings or privacy tools.
Information from Third Parties
We may receive information about you from third-party sources, including:
- Business directories and professional networking platforms
- Advertising platforms and analytics providers
- Publicly available sources for business verification
3. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR:
- Consent: When you explicitly agree to our processing (e.g., subscribing to newsletters)
- Contract: To perform our contractual obligations and provide services to you
- Legitimate Interest: For business purposes like improving our services and communicating with you
- Legal Obligation: To comply with applicable laws and regulations
4. How We Use Your Information
We use the collected information for the following purposes:
- Service Delivery: Providing performance marketing services, campaign management, and consulting
- Communication: Responding to inquiries, sending service updates, and providing customer support
- Marketing: Sending promotional materials, newsletters, and information about our services (with consent)
- Analytics: Analyzing website usage, campaign performance, and user behavior to improve our services
- Personalization: Tailoring our communications and recommendations based on your interests
- Compliance: Meeting legal obligations, preventing fraud, and ensuring platform security
- Business Operations: Managing our business relationships, conducting research, and improving our processes
5. Information Sharing and Disclosure
We do not sell your personal information to third parties. However, we may share your information in the following circumstances:
- Service Providers: With trusted third-party vendors who help us operate our business (e.g., hosting providers, email services, analytics tools)
- Advertising Partners: With advertising platforms for campaign delivery and performance tracking
- Professional Advisors: With legal, financial, or technical advisors when necessary
- Business Transfers: In connection with mergers, acquisitions, or sale of assets
- Legal Requirements: When required by law, court order, or to protect our rights and safety
- Consent: With your explicit consent for specific purposes
All third parties are contractually obligated to protect your data and use it only for the purposes specified by us.
6. International Data Transfers
As a UK-based company, your data is primarily stored within the European Economic Area (EEA). However, some of our service providers may be located outside the EEA. In such cases, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions by the UK government
- Your explicit consent where required
7. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy:
- Customer Data: For the duration of our business relationship and up to 7 years after for tax and legal purposes
- Marketing Data: Until you unsubscribe or withdraw consent
- Website Analytics: Typically 26 months for analytical purposes
- Legal Obligations: As required by applicable laws
You can request deletion of your data at any time, subject to legal retention requirements.
8. Data Security
We implement comprehensive security measures to protect your personal data:
- Encryption: Data transmission and storage using industry-standard encryption protocols
- Access Controls: Restricted access to personal data on a need-to-know basis
- Regular Audits: Periodic security assessments and vulnerability testing
- Employee Training: Staff training on data protection and privacy best practices
- Incident Response: Procedures for responding to data breaches and notifying affected individuals
While we strive to protect your data, no method of transmission over the internet is 100% secure.
9. Your Rights
Under GDPR and UK data protection laws, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data (subject to legal exceptions)
- Restriction: Limit how we process your data in certain circumstances
- Data Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests or direct marketing
- Withdraw Consent: Withdraw consent for processing based on consent
- Automated Decision-Making: Not be subject to automated decision-making with significant effects
To exercise these rights, please contact us using the details below.
10. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience, analyze usage, and provide personalized content. Our Cookie Policy provides detailed information about:
- Types of cookies we use (essential, analytics, marketing)
- Purpose of each cookie category
- How to manage your cookie preferences
- Third-party cookies from advertising and analytics partners
You can control cookies through your browser settings or our cookie consent banner.
11. Third-Party Links
Our website may contain links to third-party websites, social media platforms, or external services. We are not responsible for the privacy practices or content of these external sites. We encourage you to review their privacy policies before providing any personal information.
12. Children's Privacy
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such information, we will delete it immediately.
13. Marketing Communications
With your consent, we may send you marketing communications about our services, industry insights, and promotional offers. You can opt out at any time by:
- Clicking the unsubscribe link in our emails
- Contacting us directly
- Updating your preferences in your account settings
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by:
- Email notification (if you have provided an email address)
- Prominent notice on our website
- Updating the "Last updated" date at the top of this policy
Continued use of our services after changes constitutes acceptance of the updated policy.