Última actualización: 1 de agosto de 2026
Introducción y Alcance
Wuxi Yirox Auto Parts Co., Ltd. (“Yirox,” “nosotros,” “nos” o “nuestro”) opera la marca Yirox y el sitio web ubicado en yiroxautoparts.com. Somos un fabricante de productos automotrices y de vehículos de nueva energía y proveedor de soluciones, suministrando accesorios automotrices y servicios relacionados de abastecimiento, OEM, ODM, cotización y exportación a clientes comerciales en todo el mundo.
Wuxi Yirox Auto Parts Co., Ltd. es la entidad legal responsable de determinar los fines y medios del procesamiento de los datos personales descritos en esta Política de Privacidad y actúa como el Controlador de Datos, salvo que se indique lo contrario.
Esta Política de Privacidad (“Política”) explica cómo recopilamos, utilizamos, divulgamos, retenemos, transferimos y protegemos los datos personales en relación con:
- Visitas a nuestro sitio web y cualquier plataforma digital asociada;
- Consultas, solicitudes de cotización y comunicaciones previas a la venta;
- Transacciones B2B, incluidos pedidos estándar de SKU, programas de desarrollo OEM/ODM y pedidos de prueba con MOQ bajo;
- Gestión continua de relaciones con clientes, soporte postventa y manejo de garantías;
- Cumplimiento de las obligaciones aplicables de control de exportaciones, comercio y regulaciones.
Esta Política se aplica a todas las personas cuyos datos personales procesamos en el curso de estas actividades, incluidos contactos comerciales en empresas clientes, distribuidores, mayoristas, socios OEM/ODM, proveedores y visitantes del sitio web. No se aplica a nuestros empleados ni solicitantes de empleo, cuyos datos se rigen por políticas internas separadas.
Estamos comprometidos a procesar datos personales de acuerdo con el Reglamento General de Protección de Datos de la UE (GDPR), el Reglamento General de Protección de Datos del Reino Unido (UK GDPR), la Ley de Privacidad del Consumidor de California y la Ley de Derechos de Privacidad de California (CCPA/CPRA), la Ley de Protección de Información Personal de la República Popular China (PIPL) y todas las demás leyes de protección de datos aplicables.
Definiciones
Las siguientes definiciones se aplican en toda esta Política:
| Término | Definición |
|---|---|
| Datos Personales | Cualquier información relacionada con una persona natural identificada o identificable (“sujeto de datos”). Esto incluye información de contacto comercial como nombre, correo electrónico laboral o número de teléfono, incluso cuando se proporciona en capacidad profesional. |
| Controlador de Datos | Wuxi Yirox Auto Parts Co., Ltd., la entidad legal que determina los fines y medios del procesamiento de los Datos Personales cubiertos por esta Política de Privacidad. |
| Encargado de Datos | Una persona natural o legal, autoridad pública, agencia u otro organismo que procesa Datos Personales en nombre del Controlador de Datos bajo un acuerdo escrito. |
| Procesamiento | Cualquier operación realizada sobre Datos Personales, incluida la recopilación, registro, almacenamiento, uso, divulgación, transferencia o eliminación. |
| Consentimiento | Una indicación libremente dada, específica, informada e inequívoca de los deseos del sujeto de datos, que significa acuerdo con el procesamiento de sus datos personales para un propósito declarado. |
| Galletas. | Pequeños archivos de texto colocados en un dispositivo por un sitio web, utilizados para almacenar información de navegación y preferencias. |
| Datos de Uso | Datos recopilados automáticamente de la infraestructura del sitio web, incluidas direcciones IP, tipos de navegador, páginas visitadas y tiempo pasado en las páginas. |
| OEM/ODM | Programas de Fabricante de Equipo Original / Fabricante de Diseño Original, bajo los cuales Yirox desarrolla o fabrica productos según las especificaciones o requisitos de marca del cliente. |
Categorías de Datos Personales que Recopilamos
Recopilamos datos personales solo en la medida necesaria para los fines legítimos descritos en esta Política. Las categorías de datos personales que podemos recopilar incluyen:
1 Datos de Contacto Comercial e Identificación
Recopilamos nombres, títulos de trabajo, nombres de empresas, correos electrónicos laborales, números de teléfono y direcciones postales comerciales de personas que nos contactan, envían consultas, se registran en nuestro portal B2B o establecen relaciones comerciales con nosotros. Esta información es proporcionada directamente por la persona o por su empleador en el curso de establecer una relación comercial.
2 Datos de Transacción y Comerciales
En el curso del procesamiento de pedidos y la gestión de relaciones comerciales, recopilamos y procesamos detalles de pedidos (incluidas categorías de productos, especificaciones de SKU, cantidades y precios), requisitos de proyectos OEM/ODM (incluidos dibujos, muestras, datos de ajuste de vehículos, rangos de precios objetivo y especificaciones de marca privada), historial de compras, información de pago, direcciones de facturación y números de identificación fiscal requeridos para facturación y documentación de exportación.
3 Datos Técnicos y de Uso
Cuando visita nuestro sitio web, recopilamos automáticamente información técnica, incluida la dirección de Protocolo de Internet (IP) de su dispositivo, tipo y versión de navegador, sistema operativo, identificadores de dispositivo, las páginas de nuestro sitio web que visita, la hora y fecha de su visita y el tiempo pasado en esas páginas. Estos datos se recopilan a través de registros de servidor y cookies.
4 Datos de Comunicación
Retenemos registros de comunicaciones intercambiadas con nosotros, incluido el contenido de formularios de consulta, correspondencia por correo electrónico, notas de reuniones y registros de interacciones en ferias comerciales o exposiciones. Estos datos se utilizan para gestionar nuestras relaciones comerciales y proporcionar un servicio consistente.
5 Datos de Cumplimiento y Debida Diligencia
Para cumplir con nuestras obligaciones bajo las regulaciones de comercio internacional y control de exportaciones, podemos recopilar y procesar información requerida para la verificación de sanciones, incluidos nombres, nombres de empresas y país de domicilio de nuestros socios comerciales. También podemos obtener información de referencia crediticia de agencias de terceros para evaluar el riesgo comercial.
6 Datos Obtenidos de Fuentes de Terceros
Podemos complementar los datos personales que usted proporciona con información obtenida legalmente de fuentes de acceso público (como registros comerciales y directorios comerciales) o de terceros (como agencias de referencia crediticia, organizadores de ferias comerciales o socios de referencia).
Fines y Bases Legales para el Procesamiento
Procesamos datos personales solo cuando tenemos una base legal para hacerlo. La tabla a continuación establece los fines principales para los cuales procesamos datos personales y la base legal correspondiente bajo el GDPR.
| Propósito | Base Legal (Art. 6 del RGPD) |
|---|---|
| Procesamiento de pedidos, gestión de acuerdos OEM/ODM y cumplimiento de obligaciones contractuales | Necesidad Contractual (Art. 6(1)(b)) |
| Respuesta a consultas previas a la venta y provisión de cotizaciones | Legitimate Interests (Art. 6(1)(f)) |
| Managing B2B customer relationships and after-sales support | Contractual Necessity / Legitimate Interests |
| Warranty handling and product safety monitoring | Contractual Necessity / Legal Obligation |
| Issuing invoices and maintaining accounting records | Legal Obligation (Art. 6(1)(c)) |
| Complying with export control, customs, and tax regulations | Legal Obligation (Art. 6(1)(c)) |
| Conducting sanctions screening and trade compliance due diligence | Legal Obligation (Art. 6(1)(c)) |
| Facilitating product recalls or safety notifications | Legal Obligation / Legitimate Interests |
| Sending marketing communications to existing customers | Legitimate Interests (Art. 6(1)(f)) |
| Sending marketing communications to new contacts | Consent (Art. 6(1)(a)) |
| Analyzing website performance and improving user experience | Legitimate Interests (Art. 6(1)(f)) |
| Ensuring IT security and preventing fraud | Legitimate Interests (Art. 6(1)(f)) |
| Conducting credit risk assessments | Legitimate Interests (Art. 6(1)(f)) |
| Publishing case studies or client references naming individuals | Consent (Art. 6(1)(a)) |
Where we rely on legitimate interests as our legal basis, we have conducted a balancing test to ensure that our interests are not overridden by your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests at any time (see Section 13).
5. Export Control and Trade Compliance
As an export-oriented manufacturer serving global markets, Yirox is subject to international trade regulations, including export control laws and sanctions regimes administered by the European Union, the United States (OFAC), the United Nations, and other relevant authorities. In order to comply with these obligations, we screen our business partners against applicable sanctions lists before entering into commercial relationships. This screening may involve processing personal data such as names, company names, countries of domicile, and, where a potential match is identified, additional identifying information to conduct further due diligence.
This processing is carried out on the basis of our legal obligation under applicable export control and sanctions regulations. Records of sanctions screening are retained for up to ten (10) years to demonstrate compliance with our regulatory obligations.
6. Product Safety and Recall Obligations
Yirox manufactures and supplies products subject to safety standards and certification requirements, including CE, RoHS, EMC, FCC, UKCA, TUV, DOT, E-mark, ECE, ETL, CSA, Energy Star, ISO 9001, IATF 16949, MPA, and EN12413. In the event of a product safety issue or recall, we may be required to process the personal data of our business customers (including contact names, email addresses, and order records) to identify affected products, notify relevant parties, and coordinate corrective actions. This processing is carried out on the basis of our legal obligation under applicable product safety regulations and our legitimate interest in protecting the safety of end users.
7. OEM/ODM Confidentiality
In the course of OEM/ODM development programs, customers may share with us confidential technical information, including product drawings, samples, specifications, and private-label requirements. While this information primarily constitutes confidential business information rather than personal data, we treat it with the same level of care and protection. We enter into Non-Disclosure Agreements (NDAs) with OEM/ODM customers as appropriate, and we restrict access to project-specific information to personnel directly involved in the relevant program.
8. Disclosure of Personal Data to Third Parties
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share personal data with the following categories of recipients, strictly for the purposes described in this Policy:
Service Providers and Data Processors. We engage third-party service providers to support our operations, including cloud hosting providers, payment processors, logistics and freight forwarding companies, CRM and ERP system providers, email marketing platforms, and IT security vendors. These providers act as Data Processors and are bound by written data processing agreements that require them to process personal data only on our instructions and to implement appropriate security measures.
Manufacturing and Sourcing Partners. Where a customer requires special sourcing support or where we engage sub-contractors for specific manufacturing processes, we may share limited technical specifications and project requirements with trusted partners. We ensure that confidential OEM/ODM data is protected through appropriate contractual arrangements.
Certification and Testing Bodies. We may share product specifications and related documentation with certification and testing bodies (such as TUV, SGS, Bureau Veritas, and similar organizations) to obtain or maintain product certifications. This process does not typically involve the sharing of personal data.
Legal, Regulatory, and Governmental Authorities. We may disclose personal data to customs authorities, tax authorities, sanctions screening service providers, and other governmental or regulatory bodies to the extent required by applicable law or to protect the legal rights, property, or safety of Yirox, our customers, or others.
Professional Advisors. We may share personal data with our legal counsel, auditors, and other professional advisors where necessary for the provision of their services, subject to appropriate confidentiality obligations.
9. International Data Transfers
Yirox operates internationally and may transfer personal data across national borders in the course of our business. When we transfer personal data from the European Economic Area (EEA), the United Kingdom, or other jurisdictions with data transfer restrictions to countries that do not provide an equivalent level of data protection, we implement appropriate safeguards to ensure that your data remains protected. These safeguards may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA;
- International Data Transfer Agreements (IDTAs) approved by the UK Information Commissioner’s Office for transfers from the UK;
- Compliance with the Personal Information Protection Law (PIPL) of the People’s Republic of China for transfers of data out of China, including the conclusion of standard contracts issued by the Cyberspace Administration of China where required.
You may request a copy of the transfer mechanisms we use by contacting us at the details provided in Section 17.
10. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or alteration. Our security measures include, but are not limited to:
- Encryption of data in transit using Transport Layer Security (TLS/SSL) protocols;
- Role-based access controls and the principle of least privilege for internal systems;
- Multi-factor authentication (MFA) for access to systems containing personal data;
- Regular security assessments and vulnerability management;
- Physical security controls at our manufacturing and office facilities;
- Staff training on data protection and information security obligations.
Our commitment to quality management under ISO 9001 and IATF 16949 extends to our information security practices, reflecting a culture of traceability, accountability, and continuous improvement. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals, in accordance with applicable law.
11. Data Retention
We retain personal data only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable law. The following table sets out our standard retention periods for different categories of data:
| Data Category | Retention Period | Basis |
|---|---|---|
| Inquiry and pre-sales lead data | Up to 24 months from last contact | Business development and relationship management |
| Active customer and contract data | Duration of relationship + up to 10 years | Contractual and legal obligations |
| Invoice, payment, and accounting records | Up to 10 years | Tax and accounting compliance |
| Export documentation and customs records | Up to 7 years | Customs and trade compliance |
| Sanctions screening records | Up to 10 years | Regulatory compliance demonstration |
| Product liability and warranty records | Up to 10 years | Statutory liability periods and safety monitoring |
| OEM/ODM project documentation | Duration of program + up to 7 years | Contractual and legal obligations |
| Website technical logs | Up to 12 months | IT security and system integrity |
| Marketing consent records | Until consent is withdrawn + 3 years | Documentation of lawful basis |
Upon expiry of the applicable retention period, personal data is securely deleted or anonymized, unless it is required for the establishment, exercise, or defense of legal claims.
12. Cookie Policy
Our website uses cookies and similar tracking technologies to ensure the proper functioning of the site, analyze website traffic, and support our marketing activities.
12.1 Types of Cookies We Use
Strictly Necessary Cookies are essential for the website to function and cannot be switched off. They are typically set in response to actions you take, such as setting your privacy preferences, logging in, or filling in forms.
Performance and Analytics Cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. All information these cookies collect is aggregated and therefore anonymous.
Functional Cookies enable the website to provide enhanced functionality and personalization, such as remembering your language preferences or region.
Targeting and Advertising Cookies may be set through our site by our advertising partners to build a profile of your interests and show you relevant advertisements on other sites. They do not store directly personal information but are based on uniquely identifying your browser and internet device.
12.2 Cookie Details
| Cookie Name | Provider | Propósito | Duration | Categoría |
|---|---|---|---|---|
_ga | Google Analytics | Distinguishes users for analytics | 2 years | Analytics |
_gid | Google Analytics | Distinguishes users for analytics | 24 hours | Analytics |
_gat | Google Analytics | Throttles request rate | 1 minute | Analytics |
cookieconsent_status | Yirox | Stores your cookie consent preferences | 1 año | Strictly Necessary |
PHPSESSID | Yirox | Maintains your session state | Session | Strictly Necessary |
12.3 Managing Your Cookie Preferences
You can manage your cookie preferences at any time by accessing our cookie consent banner or by adjusting your browser settings to refuse all or some cookies. Please note that disabling certain cookies may affect the functionality of our website. You may also opt out of analytics tracking by installing the Google Analytics Opt-out Browser Add-on.
13. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data. We will respond to all valid requests within the timeframes required by applicable law (generally 30 days under the GDPR, extendable to 90 days in complex cases).
13.1 Rights Under the GDPR (EEA and UK Residents)
Right of Access (Art. 15 GDPR). You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that data along with supplementary information about how it is processed.
Right to Rectification (Art. 16 GDPR). You have the right to request that we correct inaccurate or incomplete personal data about you without undue delay.
Right to Erasure (Art. 17 GDPR). You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you withdraw consent (and no other legal basis applies), or where the data has been unlawfully processed. This right is subject to exceptions, including where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defense of legal claims.
Right to Restriction of Processing (Art. 18 GDPR). You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while the accuracy of the data is contested or while an objection to processing is being considered.
Right to Data Portability (Art. 20 GDPR). Where processing is based on your consent or on a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
Right to Object (Art. 21 GDPR). You have the right to object at any time to the processing of your personal data where that processing is based on legitimate interests, including profiling. You also have an absolute right to object to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing.
Right to Withdraw Consent (Art. 7(3) GDPR). Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Right to Lodge a Complaint (Art. 77 GDPR). You have the right to lodge a complaint with the competent data protection supervisory authority in your country of residence, place of work, or place of the alleged infringement.
13.2 Rights Under the CCPA/CPRA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Right to Know. You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business or commercial purpose for collecting it, and the categories of third parties with whom we share it.
Right to Delete. You have the right to request that we delete personal information we have collected from you, subject to certain exceptions.
Right to Correct. You have the right to request that we correct inaccurate personal information we maintain about you.
Right to Opt-Out of Sale or Sharing. We do not sell personal information. We do not share personal information for cross-context behavioral advertising purposes.
Right to Non-Discrimination. We will not discriminate against you for exercising any of your CCPA rights.
To submit a request under the CCPA, please contact us at the details provided in Section 17 with the subject line “California Privacy Rights Request.”
14. Children’s Privacy
Our website and services are designed for B2B commercial interactions and are not directed at children under the age of 16 (or 18 in certain jurisdictions). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child without appropriate parental consent, we will take prompt steps to delete such information from our records.
15. Third-Party Links
Our website may contain links to third-party websites, including those of our logistics partners, certification bodies, or industry associations. This Policy does not apply to those third-party websites, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party websites you visit.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, our services, or applicable legal requirements. When we make material changes, we will update the “Last Updated” date at the top of this Policy and, where appropriate, notify you by email or by a prominent notice on our website. We encourage you to review this Policy periodically to stay informed about how we protect your information.
17. Contact Us and Exercising Your Rights
If you have any questions, concerns, or requests regarding this Privacy Policy, our processing of personal data, or the exercise of your privacy rights, please contact:
Wuxi Yirox Auto Parts Co., Ltd.
Attn: Privacy / Data Protection
Dirección registrada: No. 2008 Taihu East Avenue, Distrito Xinwu, Wuxi, Jiangsu 214000, China
Correo electrónico: info@yiroxautoparts.com
Phone: +86 150 6180 6669
Please include sufficient information for us to identify your request and, where necessary, verify your identity. We may request additional information where reasonably required to protect personal data from unauthorized disclosure.
We will acknowledge and respond to valid privacy requests within the timeframes required by applicable law. Where legally permitted, we may extend the response period for complex or multiple requests and will inform you of any applicable extension.
If you are not satisfied with our response, you may have the right to lodge a complaint with the competent data protection or supervisory authority in your jurisdiction.
Annex A — Jurisdiction-Specific Disclosures
A.1 EEA and UK Residents
For the purposes of the GDPR and UK GDPR, Wuxi Yirox Auto Parts Co., Ltd. acts as the Data Controller for the personal data described in this Privacy Policy. The legal bases for our processing activities are set out in Section 4. You have the right to lodge a complaint with the supervisory authority in your country of residence. A list of EEA supervisory authorities is available on the European Data Protection Board website. The UK supervisory authority is the Information Commissioner’s Office (ICO).
A.2 California Residents (CCPA/CPRA)
In the preceding twelve (12) months, Wuxi Yirox Auto Parts Co., Ltd. has collected the following categories of personal information as defined by the CCPA: identifiers (such as name, email address, and IP address), commercial information (such as records of products purchased or inquired about), and internet or other electronic network activity information (such as browsing history on our website). We have not sold or shared personal information for cross-context behavioral advertising purposes. For the full list of your rights and how to exercise them, please refer to Section 13.2.
A.3 Personal Information Protection Law (PIPL) — China
For personal data processed by Wuxi Yirox Auto Parts Co., Ltd. in connection with individuals located in the People’s Republic of China, we process personal information in accordance with applicable requirements of the Personal Information Protection Law of the People’s Republic of China. We implement the measures required by the PIPL, including the conclusion of standard contracts issued by the Cyberspace Administration of China where applicable. You may exercise your rights under the PIPL by contacting us at the details provided in Section 17.
