Responsibility and contact
The company is responsible for its handling of website enquiries and related records. Its company registration number is 1000634930.
Privacy contact: [email protected].
Postal address: Shop No. 2F-60, Sihanoukville Special Economic Zone, Preah Sihanouk Province, Cambodia.
This contact route is the company’s general mailbox. It is not a separate data-protection officer service.
Information covered
The notice covers website visits, form submissions, email correspondence, documentation requests, accessibility and privacy requests, and safety, quality, authenticity or conduct reports.
It does not describe unrelated websites or every possible employment, contractual, clinical or regulated activity. Information collected for another activity may require a separate notice.
Information supplied in an enquiry
The form requests a name, email address, selected subject and message. Organisation is optional. It also requires an acknowledgement of this notice.
Email correspondence can include sender details, message headers, the message, attachments and subsequent replies. A report may include product identifiers, batch details, event dates, a description of a concern and contact details for follow-up.
Provide only what is necessary. Do not include passwords, payment information, complete identity documents or confidential technical files in an initial enquiry.
Safety reports can involve health information. Avoid full patient names, complete medical records and other direct identifiers unless they are necessary and an appropriate exchange has been arranged. Do not delay medical assistance to prepare a report.
Website delivery and request records
Cloudflare sits in front of the website and terminates the encrypted connection. For every request it processes the visitor’s IP address, approximate location including country, device and browser information, the requested URL and its headers, connection and security details, and a unique request identifier.
The web server is a Microsoft Azure virtual machine in the Germany West Central region, in Germany.
The web server records the date and time, requested page, response status and size, the IP address received directly and forwarded by Cloudflare, the country determined by Cloudflare, browser identification information, request headers and the Cloudflare request identifier.
These records support delivery, troubleshooting and protection against misuse. A website-services contractor operates the web server, enquiry form and sending account on the company’s behalf. The contractor has access to the server access log, form audit log, rate-limit counters, failed-delivery copies on the server and weekly encrypted server backup. Avoid placing sensitive information in a URL.
Form checks and delivery
The form uses checks designed to distinguish legitimate submissions from automated or abusive traffic. These include validation, a hidden anti-abuse field, rate limiting and Cloudflare Turnstile.
Turnstile loads on the contact form page. Cloudflare processes browser and device signals for the check. The server receives a verification token and checks it with Cloudflare.
The form’s audit record contains the time, language, subject key, outcome code and a keyed hash of the IP address. It does not record the name, email address, organisation or message. A keyed hash is a pseudonymous identifier, not a guarantee of anonymity. Rate-limit counters use this identifier and are kept for one hour.
A processed enquiry is sent by email, through a sending account operated by the website-services contractor on the company’s behalf, to [email protected], hosted by Zoho Mail. A copy of the relayed message may remain in that sending account and is subject to the company’s enquiry-email rule: deletion no later than 30 days after the enquiry is closed, unless a legal obligation requires longer retention.
If email delivery fails after processing, a restricted copy of the enquiry is saved on the web server and deleted after 30 days. A failure message therefore does not necessarily mean that no information was stored.
Purposes and recipients
Information is used to receive and answer correspondence, identify its subject, consider requests or reports, maintain the relevant correspondence record, protect the website and meet applicable legal requirements.
Company staff with access to [email protected] can read enquiries. All published enquiry subjects reach the same mailbox.
Service providers supporting the process include:
- Cloudflare, for website delivery, traffic protection, transit and Turnstile;
- Microsoft Azure, for hosting the server and records held there;
- the website-services contractor, for operating the server, the enquiry form and the sending account that relays form-generated email;
- the email service supporting that sending account, for processing the relayed message and any retained sending-account copy;
- Zoho Mail, for the receiving mailbox.
Information may also need to be disclosed to professional advisers, a competent authority or another necessary recipient where the law permits or requires it. Any disclosure must be limited to its purpose.
The website has no customer account, newsletter, marketing list, payment or ordering function. It uses no analytics or advertising scripts.
Retention
The company’s retention rule for enquiry emails and attachments is deletion no later than 30 days after the enquiry is closed, unless a legal obligation requires longer retention.
Server access-log entries are deleted no later than 31 days after they are written. A weekly encrypted server backup, including those logs, is kept for up to five weeks.
Failed-delivery copies on the web server are deleted after 30 days. Rate-limit counters are kept for one hour.
Other enquiry and security records must be limited to the purpose for which they are held and any applicable legal requirement.
The periods above describe the identified company records. Provider-held records are also subject to the relevant provider’s processing and retention arrangements. Cloudflare does not publish one fixed period for all request data; its retention depends on purpose and applicable legal requirements.
A legal requirement to preserve particular information can affect deletion. Questions about the handling or retention of a specific record can be sent to the privacy contact.
Browser storage and external links
The current website configuration sets no cookies. One localStorage entry, galvanta_site_notice_v2, records the value dismissed when Continue is selected in the entry notice. It has no automatic expiry, remains in that browser and is not sent to the server.
The Facebook link loads no Facebook content until selected. Visiting Facebook then involves that service’s own processing.
See Cookies and similar technologies for details and browser controls.
International processing and applicable law
The web server is hosted in Germany; service providers may also process information outside Cambodia. The use of these providers does not establish that a particular international-transfer mechanism applies to every message.
The EU or UK GDPR can apply in circumstances involving an establishment, relevant offers of goods or services, or monitoring of people’s behaviour in the relevant territory. Access from abroad alone does not determine applicability. Other countries apply their own scope and threshold rules.
Where a law applies, its requirements concerning lawful processing, sensitive information, transfers, notices and individual rights remain applicable. The legal basis for processing and any additional condition required for health information must be assessed separately from the form acknowledgement.
Mandatory duties and rights under applicable law are unaffected by this notice.
Requests, security and changes
Use Privacy rights and requests to ask about access, correction, deletion or another applicable right. You may also contact a competent supervisory or public authority directly where the law provides that route.
The website uses encrypted connections and access restrictions, but internet communications and storage cannot be guaranteed completely secure.
The site is intended for corporate and institutional enquiries, not the collection of information from children. If information about a child is necessary to a safety concern, an appropriate adult or professional should minimise identifying details.
This notice may change with the website or its processing. The stated date identifies the version. Provider information is available in the Cloudflare privacy policy, Zoho privacy policy and Microsoft privacy statement.
