Privacy Policy
1. Information we collect
This website only collects personal information when you actively submit the "Contact Us" form. The following fields may be collected:
| Category | Fields | Required |
|---|---|---|
| Identity & contact | Name, business email | Required |
| Affiliation | Company name | Required |
| Region | Region (Asia-Pacific / Europe / North America / South America / Middle East & Africa) | Required |
| Inquiry | Inquiry type (partnership / sales / technical / media / careers / other), free-text details | Type required, details optional |
| Technical | Submission timestamp, IP address, referer page, User-Agent | Automatically logged for security audit and abuse prevention |
Beyond the above, this website does not deploy advertising cookies, fingerprinting scripts or third-party analytics that track your browsing behavior. The only client-side storage is a single LocalStorage entry recording the timestamp of your last form submission, used purely for client-side rate limiting; it never leaves your browser.
2. How we use the information
- To respond to your inquiry through the appropriate business unit (sales, marketing, technical support, etc.);
- To detect and prevent abuse (form spam, injection attempts) and apply protective measures;
- For internal business reporting and lead management;
- To comply with applicable laws or legitimate requests from regulatory authorities.
We do not use your personal information for any other purpose, and we do not sell or unlawfully share it with any third party.
3. Storage and cross-border transfer
Form data is stored on the following infrastructure:
- Static site: hosted on Vercel (global edge network);
- Form backend and database: Supabase (built on AWS, primary region ap-southeast-1 / Singapore);
- Bot mitigation: Cloudflare Turnstile.
This means form submissions may be transferred and stored across borders at the providers' data centers above. We require these providers to implement reasonable data-protection and security measures (TLS in transit, encryption at rest, access control). If you are located in mainland China and are concerned about cross-border storage, please contact us via the email below to request domestic-only storage or deletion.
4. Security measures
- Encrypted transport: site-wide HTTPS with HSTS preload; TLS 1.2+ end-to-end for form submission;
- Server-side validation: every submission passes Cloudflare Turnstile bot challenge and a strict server-side Edge Function that enforces field-length / format / whitelist rules, strips HTML tags, and blocks dangerous regex patterns;
- Access control: Row-Level Security (RLS) is enabled; only authorized accounts can read contact-form data;
- Rate limiting: max 5 submissions per IP per minute and 3 per email per day;
- Security headers: 8 security headers (CSP / HSTS / X-Frame-Options / X-Content-Type-Options / Permissions-Policy / Referrer-Policy / COOP / X-XSS-Protection) are configured;
- SRI: all self-hosted JavaScript is delivered with Subresource Integrity hashes;
- Periodic audits: this website has been audited multiple times by the IT department and remediated accordingly.
5. Retention
Form data is retained for 24 months by default for follow-up communication and customer relationship management, after which it is purged on a quarterly basis. You may request earlier deletion at any time.
6. Your rights
Subject to applicable laws (including the PRC Personal Information Protection Law and, where applicable, GDPR), you have the right to:
- Access and obtain a copy of the information you submitted;
- Correct inaccurate or incomplete information;
- Request deletion or withdraw your consent;
- Be informed about how we process your personal information.
To exercise any of the rights above, please contact us via:
- Email: info@realman-robot.com
- Hotline: +86-400-898-2018
- Office: Haidian District, Beijing, China
We will respond within 15 business days.
7. Children
This website is intended for business users and does not knowingly target or collect information from minors. If you are a minor, please use this website under the supervision of a guardian and avoid submitting personal information.
8. Changes to this policy
We may update this policy in response to legal, business, or technical changes. Material changes will be announced in a prominent place on the website. The latest version is always indicated by the "Last updated" date at the top of this page.
9. Contact us
For any question, comment or complaint regarding this Privacy Policy, please contact:
- Data Protection contact: info@realman-robot.com
- Hotline: +86-400-898-2018