Última actualización: 1 de agosto de 2026

Introducción y Alcance

Wuxi Yirox Auto Parts Co., Ltd. (“Yirox,” “nosotros,” “nos” o “nuestro”) opera la marca Yirox y el sitio web ubicado en yiroxautoparts.com. Somos un fabricante de productos automotrices y de vehículos de nueva energía y proveedor de soluciones, suministrando accesorios automotrices y servicios relacionados de abastecimiento, OEM, ODM, cotización y exportación a clientes comerciales en todo el mundo.

Wuxi Yirox Auto Parts Co., Ltd. es la entidad legal responsable de determinar los fines y medios del procesamiento de los datos personales descritos en esta Política de Privacidad y actúa como el Controlador de Datos, salvo que se indique lo contrario.

Esta Política de Privacidad (“Política”) explica cómo recopilamos, utilizamos, divulgamos, retenemos, transferimos y protegemos los datos personales en relación con:

Esta Política se aplica a todas las personas cuyos datos personales procesamos en el curso de estas actividades, incluidos contactos comerciales en empresas clientes, distribuidores, mayoristas, socios OEM/ODM, proveedores y visitantes del sitio web. No se aplica a nuestros empleados ni solicitantes de empleo, cuyos datos se rigen por políticas internas separadas.

Estamos comprometidos a procesar datos personales de acuerdo con el Reglamento General de Protección de Datos de la UE (GDPR), el Reglamento General de Protección de Datos del Reino Unido (UK GDPR), la Ley de Privacidad del Consumidor de California y la Ley de Derechos de Privacidad de California (CCPA/CPRA), la Ley de Protección de Información Personal de la República Popular China (PIPL) y todas las demás leyes de protección de datos aplicables.


Definiciones

Las siguientes definiciones se aplican en toda esta Política:

TérminoDefinición
Datos PersonalesCualquier información relacionada con una persona natural identificada o identificable (“sujeto de datos”). Esto incluye información de contacto comercial como nombre, correo electrónico laboral o número de teléfono, incluso cuando se proporciona en capacidad profesional.
Controlador de DatosWuxi Yirox Auto Parts Co., Ltd., la entidad legal que determina los fines y medios del procesamiento de los Datos Personales cubiertos por esta Política de Privacidad.
Encargado de DatosUna persona natural o legal, autoridad pública, agencia u otro organismo que procesa Datos Personales en nombre del Controlador de Datos bajo un acuerdo escrito.
ProcesamientoCualquier operación realizada sobre Datos Personales, incluida la recopilación, registro, almacenamiento, uso, divulgación, transferencia o eliminación.
ConsentimientoUna indicación libremente dada, específica, informada e inequívoca de los deseos del sujeto de datos, que significa acuerdo con el procesamiento de sus datos personales para un propósito declarado.
Galletas.Pequeños archivos de texto colocados en un dispositivo por un sitio web, utilizados para almacenar información de navegación y preferencias.
Datos de UsoDatos recopilados automáticamente de la infraestructura del sitio web, incluidas direcciones IP, tipos de navegador, páginas visitadas y tiempo pasado en las páginas.
OEM/ODMProgramas de Fabricante de Equipo Original / Fabricante de Diseño Original, bajo los cuales Yirox desarrolla o fabrica productos según las especificaciones o requisitos de marca del cliente.

Categorías de Datos Personales que Recopilamos

Recopilamos datos personales solo en la medida necesaria para los fines legítimos descritos en esta Política. Las categorías de datos personales que podemos recopilar incluyen:

1 Datos de Contacto Comercial e Identificación

Recopilamos nombres, títulos de trabajo, nombres de empresas, correos electrónicos laborales, números de teléfono y direcciones postales comerciales de personas que nos contactan, envían consultas, se registran en nuestro portal B2B o establecen relaciones comerciales con nosotros. Esta información es proporcionada directamente por la persona o por su empleador en el curso de establecer una relación comercial.

2 Datos de Transacción y Comerciales

En el curso del procesamiento de pedidos y la gestión de relaciones comerciales, recopilamos y procesamos detalles de pedidos (incluidas categorías de productos, especificaciones de SKU, cantidades y precios), requisitos de proyectos OEM/ODM (incluidos dibujos, muestras, datos de ajuste de vehículos, rangos de precios objetivo y especificaciones de marca privada), historial de compras, información de pago, direcciones de facturación y números de identificación fiscal requeridos para facturación y documentación de exportación.

3 Datos Técnicos y de Uso

Cuando visita nuestro sitio web, recopilamos automáticamente información técnica, incluida la dirección de Protocolo de Internet (IP) de su dispositivo, tipo y versión de navegador, sistema operativo, identificadores de dispositivo, las páginas de nuestro sitio web que visita, la hora y fecha de su visita y el tiempo pasado en esas páginas. Estos datos se recopilan a través de registros de servidor y cookies.

4 Datos de Comunicación

Retenemos registros de comunicaciones intercambiadas con nosotros, incluido el contenido de formularios de consulta, correspondencia por correo electrónico, notas de reuniones y registros de interacciones en ferias comerciales o exposiciones. Estos datos se utilizan para gestionar nuestras relaciones comerciales y proporcionar un servicio consistente.

5 Datos de Cumplimiento y Debida Diligencia

Para cumplir con nuestras obligaciones bajo las regulaciones de comercio internacional y control de exportaciones, podemos recopilar y procesar información requerida para la verificación de sanciones, incluidos nombres, nombres de empresas y país de domicilio de nuestros socios comerciales. También podemos obtener información de referencia crediticia de agencias de terceros para evaluar el riesgo comercial.

6 Datos Obtenidos de Fuentes de Terceros

Podemos complementar los datos personales que usted proporciona con información obtenida legalmente de fuentes de acceso público (como registros comerciales y directorios comerciales) o de terceros (como agencias de referencia crediticia, organizadores de ferias comerciales o socios de referencia).


Fines y Bases Legales para el Procesamiento

Procesamos datos personales solo cuando tenemos una base legal para hacerlo. La tabla a continuación establece los fines principales para los cuales procesamos datos personales y la base legal correspondiente bajo el GDPR.

PropósitoBase Legal (Art. 6 del RGPD)
Procesamiento de pedidos, gestión de acuerdos OEM/ODM y cumplimiento de obligaciones contractualesNecesidad Contractual (Art. 6(1)(b))
Respuesta a consultas previas a la venta y provisión de cotizacionesLegitimate Interests (Art. 6(1)(f))
Managing B2B customer relationships and after-sales supportContractual Necessity / Legitimate Interests
Warranty handling and product safety monitoringContractual Necessity / Legal Obligation
Issuing invoices and maintaining accounting recordsLegal Obligation (Art. 6(1)(c))
Complying with export control, customs, and tax regulationsLegal Obligation (Art. 6(1)(c))
Conducting sanctions screening and trade compliance due diligenceLegal Obligation (Art. 6(1)(c))
Facilitating product recalls or safety notificationsLegal Obligation / Legitimate Interests
Sending marketing communications to existing customersLegitimate Interests (Art. 6(1)(f))
Sending marketing communications to new contactsConsent (Art. 6(1)(a))
Analyzing website performance and improving user experienceLegitimate Interests (Art. 6(1)(f))
Ensuring IT security and preventing fraudLegitimate Interests (Art. 6(1)(f))
Conducting credit risk assessmentsLegitimate Interests (Art. 6(1)(f))
Publishing case studies or client references naming individualsConsent (Art. 6(1)(a))

Where we rely on legitimate interests as our legal basis, we have conducted a balancing test to ensure that our interests are not overridden by your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests at any time (see Section 13).


5. Export Control and Trade Compliance

As an export-oriented manufacturer serving global markets, Yirox is subject to international trade regulations, including export control laws and sanctions regimes administered by the European Union, the United States (OFAC), the United Nations, and other relevant authorities. In order to comply with these obligations, we screen our business partners against applicable sanctions lists before entering into commercial relationships. This screening may involve processing personal data such as names, company names, countries of domicile, and, where a potential match is identified, additional identifying information to conduct further due diligence.

This processing is carried out on the basis of our legal obligation under applicable export control and sanctions regulations. Records of sanctions screening are retained for up to ten (10) years to demonstrate compliance with our regulatory obligations.


6. Product Safety and Recall Obligations

Yirox manufactures and supplies products subject to safety standards and certification requirements, including CE, RoHS, EMC, FCC, UKCA, TUV, DOT, E-mark, ECE, ETL, CSA, Energy Star, ISO 9001, IATF 16949, MPA, and EN12413. In the event of a product safety issue or recall, we may be required to process the personal data of our business customers (including contact names, email addresses, and order records) to identify affected products, notify relevant parties, and coordinate corrective actions. This processing is carried out on the basis of our legal obligation under applicable product safety regulations and our legitimate interest in protecting the safety of end users.


7. OEM/ODM Confidentiality

In the course of OEM/ODM development programs, customers may share with us confidential technical information, including product drawings, samples, specifications, and private-label requirements. While this information primarily constitutes confidential business information rather than personal data, we treat it with the same level of care and protection. We enter into Non-Disclosure Agreements (NDAs) with OEM/ODM customers as appropriate, and we restrict access to project-specific information to personnel directly involved in the relevant program.


8. Disclosure of Personal Data to Third Parties

We do not sell, rent, or trade your personal data to third parties for their own marketing purposes. We may share personal data with the following categories of recipients, strictly for the purposes described in this Policy:

Service Providers and Data Processors. We engage third-party service providers to support our operations, including cloud hosting providers, payment processors, logistics and freight forwarding companies, CRM and ERP system providers, email marketing platforms, and IT security vendors. These providers act as Data Processors and are bound by written data processing agreements that require them to process personal data only on our instructions and to implement appropriate security measures.

Manufacturing and Sourcing Partners. Where a customer requires special sourcing support or where we engage sub-contractors for specific manufacturing processes, we may share limited technical specifications and project requirements with trusted partners. We ensure that confidential OEM/ODM data is protected through appropriate contractual arrangements.

Certification and Testing Bodies. We may share product specifications and related documentation with certification and testing bodies (such as TUV, SGS, Bureau Veritas, and similar organizations) to obtain or maintain product certifications. This process does not typically involve the sharing of personal data.

Legal, Regulatory, and Governmental Authorities. We may disclose personal data to customs authorities, tax authorities, sanctions screening service providers, and other governmental or regulatory bodies to the extent required by applicable law or to protect the legal rights, property, or safety of Yirox, our customers, or others.

Professional Advisors. We may share personal data with our legal counsel, auditors, and other professional advisors where necessary for the provision of their services, subject to appropriate confidentiality obligations.


9. International Data Transfers

Yirox operates internationally and may transfer personal data across national borders in the course of our business. When we transfer personal data from the European Economic Area (EEA), the United Kingdom, or other jurisdictions with data transfer restrictions to countries that do not provide an equivalent level of data protection, we implement appropriate safeguards to ensure that your data remains protected. These safeguards may include:

You may request a copy of the transfer mechanisms we use by contacting us at the details provided in Section 17.


10. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, or alteration. Our security measures include, but are not limited to:

Our commitment to quality management under ISO 9001 and IATF 16949 extends to our information security practices, reflecting a culture of traceability, accountability, and continuous improvement. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals, in accordance with applicable law.


11. Data Retention

We retain personal data only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable law. The following table sets out our standard retention periods for different categories of data:

Data CategoryRetention PeriodBasis
Inquiry and pre-sales lead dataUp to 24 months from last contactBusiness development and relationship management
Active customer and contract dataDuration of relationship + up to 10 yearsContractual and legal obligations
Invoice, payment, and accounting recordsUp to 10 yearsTax and accounting compliance
Export documentation and customs recordsUp to 7 yearsCustoms and trade compliance
Sanctions screening recordsUp to 10 yearsRegulatory compliance demonstration
Product liability and warranty recordsUp to 10 yearsStatutory liability periods and safety monitoring
OEM/ODM project documentationDuration of program + up to 7 yearsContractual and legal obligations
Website technical logsUp to 12 monthsIT security and system integrity
Marketing consent recordsUntil consent is withdrawn + 3 yearsDocumentation of lawful basis

Upon expiry of the applicable retention period, personal data is securely deleted or anonymized, unless it is required for the establishment, exercise, or defense of legal claims.


12. Cookie Policy

Our website uses cookies and similar tracking technologies to ensure the proper functioning of the site, analyze website traffic, and support our marketing activities.

12.1 Types of Cookies We Use

Strictly Necessary Cookies are essential for the website to function and cannot be switched off. They are typically set in response to actions you take, such as setting your privacy preferences, logging in, or filling in forms.

Performance and Analytics Cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. All information these cookies collect is aggregated and therefore anonymous.

Functional Cookies enable the website to provide enhanced functionality and personalization, such as remembering your language preferences or region.

Targeting and Advertising Cookies may be set through our site by our advertising partners to build a profile of your interests and show you relevant advertisements on other sites. They do not store directly personal information but are based on uniquely identifying your browser and internet device.

12.2 Cookie Details

Cookie NameProviderPropósitoDurationCategoría
_gaGoogle AnalyticsDistinguishes users for analytics2 yearsAnalytics
_gidGoogle AnalyticsDistinguishes users for analytics24 hoursAnalytics
_gatGoogle AnalyticsThrottles request rate1 minuteAnalytics
cookieconsent_statusYiroxStores your cookie consent preferences1 añoStrictly Necessary
PHPSESSIDYiroxMaintains your session stateSessionStrictly Necessary

12.3 Managing Your Cookie Preferences

You can manage your cookie preferences at any time by accessing our cookie consent banner or by adjusting your browser settings to refuse all or some cookies. Please note that disabling certain cookies may affect the functionality of our website. You may also opt out of analytics tracking by installing the Google Analytics Opt-out Browser Add-on.


13. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data. We will respond to all valid requests within the timeframes required by applicable law (generally 30 days under the GDPR, extendable to 90 days in complex cases).

13.1 Rights Under the GDPR (EEA and UK Residents)

Right of Access (Art. 15 GDPR). You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that data along with supplementary information about how it is processed.

Right to Rectification (Art. 16 GDPR). You have the right to request that we correct inaccurate or incomplete personal data about you without undue delay.

Right to Erasure (Art. 17 GDPR). You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you withdraw consent (and no other legal basis applies), or where the data has been unlawfully processed. This right is subject to exceptions, including where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defense of legal claims.

Right to Restriction of Processing (Art. 18 GDPR). You have the right to request that we restrict the processing of your personal data in certain circumstances, such as while the accuracy of the data is contested or while an objection to processing is being considered.

Right to Data Portability (Art. 20 GDPR). Where processing is based on your consent or on a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.

Right to Object (Art. 21 GDPR). You have the right to object at any time to the processing of your personal data where that processing is based on legitimate interests, including profiling. You also have an absolute right to object to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing.

Right to Withdraw Consent (Art. 7(3) GDPR). Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Right to Lodge a Complaint (Art. 77 GDPR). You have the right to lodge a complaint with the competent data protection supervisory authority in your country of residence, place of work, or place of the alleged infringement.

13.2 Rights Under the CCPA/CPRA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Right to Know. You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business or commercial purpose for collecting it, and the categories of third parties with whom we share it.

Right to Delete. You have the right to request that we delete personal information we have collected from you, subject to certain exceptions.

Right to Correct. You have the right to request that we correct inaccurate personal information we maintain about you.

Right to Opt-Out of Sale or Sharing. We do not sell personal information. We do not share personal information for cross-context behavioral advertising purposes.

Right to Non-Discrimination. We will not discriminate against you for exercising any of your CCPA rights.

To submit a request under the CCPA, please contact us at the details provided in Section 17 with the subject line “California Privacy Rights Request.”


14. Children’s Privacy

Our website and services are designed for B2B commercial interactions and are not directed at children under the age of 16 (or 18 in certain jurisdictions). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child without appropriate parental consent, we will take prompt steps to delete such information from our records.


15. Third-Party Links

Our website may contain links to third-party websites, including those of our logistics partners, certification bodies, or industry associations. This Policy does not apply to those third-party websites, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party websites you visit.


16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, our services, or applicable legal requirements. When we make material changes, we will update the “Last Updated” date at the top of this Policy and, where appropriate, notify you by email or by a prominent notice on our website. We encourage you to review this Policy periodically to stay informed about how we protect your information.


17. Contact Us and Exercising Your Rights

If you have any questions, concerns, or requests regarding this Privacy Policy, our processing of personal data, or the exercise of your privacy rights, please contact:

Wuxi Yirox Auto Parts Co., Ltd.
Attn: Privacy / Data Protection
Dirección registrada: No. 2008 Taihu East Avenue, Distrito Xinwu, Wuxi, Jiangsu 214000, China
Correo electrónico: info@yiroxautoparts.com
Phone: +86 150 6180 6669

Please include sufficient information for us to identify your request and, where necessary, verify your identity. We may request additional information where reasonably required to protect personal data from unauthorized disclosure.

We will acknowledge and respond to valid privacy requests within the timeframes required by applicable law. Where legally permitted, we may extend the response period for complex or multiple requests and will inform you of any applicable extension.

If you are not satisfied with our response, you may have the right to lodge a complaint with the competent data protection or supervisory authority in your jurisdiction.


Annex A — Jurisdiction-Specific Disclosures

A.1 EEA and UK Residents

For the purposes of the GDPR and UK GDPR, Wuxi Yirox Auto Parts Co., Ltd. acts as the Data Controller for the personal data described in this Privacy Policy. The legal bases for our processing activities are set out in Section 4. You have the right to lodge a complaint with the supervisory authority in your country of residence. A list of EEA supervisory authorities is available on the European Data Protection Board website. The UK supervisory authority is the Information Commissioner’s Office (ICO).

A.2 California Residents (CCPA/CPRA)

In the preceding twelve (12) months, Wuxi Yirox Auto Parts Co., Ltd. has collected the following categories of personal information as defined by the CCPA: identifiers (such as name, email address, and IP address), commercial information (such as records of products purchased or inquired about), and internet or other electronic network activity information (such as browsing history on our website). We have not sold or shared personal information for cross-context behavioral advertising purposes. For the full list of your rights and how to exercise them, please refer to Section 13.2.

A.3 Personal Information Protection Law (PIPL) — China

For personal data processed by Wuxi Yirox Auto Parts Co., Ltd. in connection with individuals located in the People’s Republic of China, we process personal information in accordance with applicable requirements of the Personal Information Protection Law of the People’s Republic of China. We implement the measures required by the PIPL, including the conclusion of standard contracts issued by the Cyberspace Administration of China where applicable. You may exercise your rights under the PIPL by contacting us at the details provided in Section 17.