Privacy

1. Who we are & scope

This Privacy Policy explains how Groxx Gears Industrial Pte. Ltd. (UEN [•]), a company incorporated in Singapore with its registered office at [10 Anson Road #22‑02, International Plaza, Singapore 079903] (“Groxx“, “we“, “us“) collects, uses, discloses and protects personal data in connection with the website at [groxxgears.com] and our related sales, quotation, account and support activities (together, the “Services“).

This Policy forms part of our Terms & Conditions (see clause 13) and applies to site visitors, account holders, individuals named as business contacts by our B2B customers, and consumers who buy from us directly.

Where local law (e.g. Singapore’s PDPA, the EU/UK GDPR, Australia’s Privacy Act) gives you additional or different rights, that law prevails over anything in this Policy to the contrary — see the market‑specific Annex B.


2. Personal data we collect

  • Account & order data — name, job title, company name, business/delivery address, email, phone number, order and quotation history, distributor/trade application details.
  • Payment data — billing details and the last four digits/type of a payment method. Full card numbers are processed directly by our payment provider(s) ([card processor(s), e.g. Stripe]); we do not store full card numbers on our own systems.
  • Communications — enquiries, quotation requests, support tickets, contact‑form submissions, and related correspondence.
  • Marketing preferences — newsletter subscription status and consent records.
  • Account credentials — username and a hashed/encrypted password.
  • Technical & usage data — IP address, device/browser type, pages viewed, referral source, and similar data collected via cookies and analytics (see clause 5).
  • We collect this data directly from you (forms, account registration, orders, correspondence), automatically as you use the Site, and occasionally from third parties such as credit‑reference or business‑registry checks for trade account approval.


3. How we use personal data

We use personal data to:

  • process quotations and orders, manage your Account, and provide customer/technical support;
  • verify identity, prevent fraud, and carry out export‑control/sanctions screening where required for cross‑border shipments;
  • send transactional communications (order confirmations, invoices, shipping updates);
  • send marketing communications about products, promotions or new content, where you have consented or, where permitted by law, on the basis of our legitimate interest — you can opt out at any time (see clause 9);
  • maintain, secure and improve the Site and our Services, including analytics;
  • comply with legal, tax, customs and product‑safety recordkeeping obligations; and
  • assess and manage distributor/trade account applications.


4. Legal bases for processing (EU/EEA/UK)

Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases: performance of a contract with you; our legitimate interests (e.g. fraud prevention, site security, direct marketing to existing business customers); your consent (e.g. marketing emails, non‑essential cookies); and compliance with a legal obligation (e.g. tax and customs records).


5. Cookies & similar technologies

5.1 We use essential cookies (required for the Site and checkout to function), analytics cookies (to understand how the Site is used), and, where you consent, marketing/tracking cookies.

5.2 Where required by local law (notably for EU/EEA and UK visitors), we ask for your consent to non‑essential cookies via a cookie banner and let you change your preferences at any time via [cookie settings link].

5.3 See our [Cookie Policy] at [/cookies/] for the full list of cookies, their purpose, and retention period.


6. How we share personal data

We share personal data with:

  • Service providers who process data on our behalf, including payment processors, couriers/freight forwarders, IT hosting and email/marketing platforms, and accounting or bookkeeping providers — under contracts that require them to protect your data;
  • Professional advisers, such as auditors, insurers and lawyers, where necessary;
  • Distributors, agents or logistics partners where necessary to fulfil your order;
  • Regulators, customs authorities and government bodies, where required by law (including export‑control and product‑safety reporting); and
  • A buyer or successor, if we are involved in a merger, acquisition, or sale of assets, subject to appropriate safeguards.

We do not sell personal data.


7. International transfers

7.1 As a Singapore‑based company serving multiple markets, personal data may be transferred to, stored, and processed in Singapore and in the countries where our service providers operate (see [list of processor locations]).

7.2 For personal data originating in the EU/EEA or UK, we transfer it internationally only where an adequacy decision applies or where appropriate safeguards are in place, such as the European Commission’s Standard Contractual Clauses (or the UK equivalent), copies of which are available on request.


8. Data retention

We keep personal data only as long as necessary for the purposes described in this Policy, including to meet legal, accounting, tax and product‑liability recordkeeping requirements (typically [7] years for transaction records from our jurisdictions, unless a longer period is required by law), after which it is securely deleted or anonymised.


9. Your rights

Subject to the law of your country (see Annex B for market‑specific detail), you may have the right to: request access to the personal data we hold about you; ask us to correct inaccurate data; ask us to delete or restrict processing of your data; object to processing (including direct marketing) at any time; request a portable copy of data you provided to us; and withdraw consent where processing is based on consent, without affecting processing carried out before withdrawal.

To exercise any of these rights, contact us at [privacy@groxxgears.com]. We may need to verify your identity before actioning a request, and we will respond within the time limit required by applicable law.


10. Security

We use reasonable technical and organisational measures (such as access controls, encryption in transit, and staff confidentiality obligations) to protect personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.


11. Children’s privacy

Our Services are intended for business use and adult consumers; we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will take steps to delete it.


12. Third‑party links

The Site may link to third‑party websites (e.g. carrier tracking, payment providers). We are not responsible for the privacy practices of those third parties; please review their own policies.


13. Changes to this Policy

We may update this Policy from time to time; the version in force is the one published at /privacy/. Material changes will be dated and, where required by law, notified to you directly.


14. Contact us

[Groxx Gears Industrial Pte. Ltd.] · [privacy@groxxgears.com] · [10 Anson Road #22‑02, International Plaza, Singapore 079903] · [phone]

If you are not satisfied with our response, you may also have the right to lodge a complaint with your local data protection authority — see Annex B for the relevant authority in your market.




Annex B — Market‑specific rights & disclosures

These summarise non‑excludable local rules to flag for your lawyer. They are not a complete statement of the law and must be verified per country.


B1. Singapore

  • The Personal Data Protection Act 2012 (PDPA) applies. You may request access to and correction of your personal data, and withdraw consent to marketing at any time (including via the Do Not Call Registry for telemarketing).
  • We will notify affected individuals and the Personal Data Protection Commission (PDPC) of a data breach where required under the PDPA’s mandatory breach‑notification rules.
  • Our appointed Data Protection Officer can be reached at [dpo@groxxgears.com].


B2. Other SEA markets (Malaysia, Indonesia, Thailand, Vietnam, Philippines, …)

  • Data‑protection regimes differ by country (e.g. Malaysia’s PDPA 2010, Indonesia’s PDP Law, Thailand’s PDPA, the Philippines’ Data Privacy Act 2012). Do not assume the Singapore text suffices — confirm local consent, registration/notification and cross‑border transfer requirements before relying on this Policy for those markets.


B3. Australia

  • The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to personal data we collect from individuals in Australia. You may request access to and correction of your data, and may complain to us in the first instance and then, if unresolved, to the Office of the Australian Information Commissioner (OAIC).


B4. France / EU

  • The GDPR applies to personal data of individuals in the EU/EEA. You have the rights listed in clause 9 above, plus the right to lodge a complaint with your local supervisory authority (in France, the CNIL).
  • [If Groxx has no establishment in the EU: appoint an EU representative under Art. 27 GDPR and insert their contact details here.]
  • [Confirm whether a Data Protection Officer is required under Art. 37 GDPR given the scale/nature of processing, and insert DPO contact details if so.]
  • Language: consumer‑facing privacy information should be available in French.