Privacy Policy
Effective Date: August 5, 2026 | Last Updated: August 5, 2026
This Privacy Policy describes how Zhijiang Nuhong Trading Co., Ltd., operating under the brand name Rage Wave (developed by Rage Wave), collects, uses, stores, discloses, and protects information obtained from visitors to our website at www.ragewave.buzz and from users and clients of our integrated technology services. By accessing or using our website and services, you acknowledge that you have read and understood the practices described in this policy and agree to the collection and use of your information in accordance with these terms.
Rage Wave provides computer integrated systems design, digital commerce platform development, and technical consulting services to a global clientele. Because the nature of our work involves handling diverse categories of information — from basic contact details to sophisticated system configuration data — we have designed this privacy policy to be transparent, thorough, and aligned with internationally recognized data protection principles. We encourage you to read this policy in full so that you understand both the scope of our data practices and the measures we take to safeguard your privacy.
1. Information We Collect
We gather multiple categories of information to deliver, maintain, and improve our computer integrated systems design services. The information we collect depends on the nature of your interaction with Rage Wave — whether you are a casual website visitor, an inquiring prospective client, or an established customer engaged in an active systems integration project. Each category of data is collected with a defined purpose and is retained only for as long as that purpose remains relevant.
- Contact Information — When you reach out via email to feedback@ragewave.buzz or through any contact form on our site, we collect your name, email address, phone number, company name, job title, and any other details you choose to share in your message.
- Technical Data — Automatically collected information includes your IP address, browser type and version, operating system, device identifiers, screen resolution, referring URLs, pages viewed, time spent on pages, clickstream data, and geographic region derived from your IP address. This data is collected through standard server logs and analytics tools operating on our infrastructure.
- Service Usage Information — If you engage us for system design or integration projects, we may collect project specifications, API keys, system access credentials, infrastructure topology data, network diagrams, performance metrics, configuration files, and deployment logs necessary to deliver our services effectively.
- Communication Records — Copies of email correspondence, support tickets, project briefs, meeting notes, recorded call summaries where you have been notified, and technical documentation exchanged during the course of our professional engagement are retained to maintain continuity and improve service delivery.
- Billing and Transaction Information — For clients who engage our paid services, we collect invoicing details, payment method identifiers, transaction histories, and related financial records necessary to process payments and comply with tax and accounting obligations.
The collection of this information is grounded in our legitimate business interest to operate a functional website and to deliver high-quality systems integration services. Where required by law, we obtain your explicit consent before collecting certain categories of data. You are never obligated to provide any information beyond what is strictly necessary for your chosen interaction with Rage Wave.
2. How We Use Collected Information
The information we collect serves specific, legitimate business purposes directly connected to the delivery and improvement of our technology services. Every category of data is processed with a clearly defined objective, and we do not repurpose information for uses that are incompatible with the original purpose of collection without first notifying you and, where required, obtaining your consent.
- Service Delivery — To design, develop, deploy, monitor, and maintain integrated computer systems and digital commerce platforms tailored to your technical and business requirements. This includes the provisioning of development environments, staging infrastructure, and production systems.
- Communication — To respond to inquiries with relevant and timely information, provide project status updates and milestone reports, deliver technical support through our designated support channels, and send administrative notifications about our services, including maintenance windows and feature updates.
- Website Improvement — To analyze traffic patterns and visitor behavior, monitor page load performance and uptime, identify and resolve technical issues affecting site availability, and iteratively enhance the user experience of our digital presence based on observed usage data.
- Security and Fraud Prevention — To detect, investigate, and prevent unauthorized access attempts, malicious activities, denial-of-service attacks, data breaches, credential stuffing, and other security incidents affecting our systems or your data. This includes real-time monitoring and forensic analysis of security events.
- Legal Compliance — To meet obligations under applicable national and international laws, regulations, binding court orders, and legitimate law enforcement requests, including maintaining records required by tax authorities, corporate governance frameworks, and industry-specific regulatory mandates.
- Business Development — To understand market trends, evaluate the performance and adoption of our service offerings, identify opportunities for new technology capabilities, and make informed strategic decisions about the direction of our systems integration practice.
We do not use your personal information to make automated decisions that produce legal effects or similarly significant consequences for you. Any analysis we perform is directed at improving our service quality and business operations, and you retain full access to the underlying information we hold about you, as described in the rights section of this policy.
3. Cookies and Tracking Technologies
Rage Wave uses cookies and similar tracking technologies on our website to ensure proper functionality, analyze visitor behavior, and enhance the browsing experience. A cookie is a small text file placed on your device by your web browser at the direction of the website you are visiting. Cookies enable our systems to recognize your browser and remember certain information across sessions and pages.
We deploy the following categories of cookies on ragewave.buzz. Essential cookies are strictly necessary for the website to operate and cannot be disabled in our systems; they support core functions such as page navigation, secure area access, and session management. Analytics cookies help us understand how visitors interact with the site by collecting aggregate, anonymized data about pages visited, time on site, and referral sources. Preference cookies allow the website to remember choices you make, such as language selection or display preferences, and provide enhanced, more personal features. You may manage cookie preferences through your browser settings at any time, including blocking or deleting cookies. Please note that restricting certain types of cookies may impact your experience of the site and the services we are able to offer through it.
4. Legal Basis for Processing
Where required by applicable data protection laws — including the General Data Protection Regulation (GDPR) for individuals located in the European Economic Area and the United Kingdom — we rely on the following legal grounds for processing your personal information. We maintain records of our processing activities in accordance with Article 30 of the GDPR, and we regularly review our legal bases to ensure they remain valid and appropriate for each processing operation we conduct.
- Contractual Necessity — Processing is required to perform a contract with you or to take pre-contractual steps at your request, such as preparing a systems design proposal, executing a service agreement, or delivering ongoing project work under an active statement of work.
- Legitimate Interests — We process data to pursue our legitimate business interests in providing, improving, and securing our technology services, provided those interests are not overridden by your rights and freedoms. We conduct a legitimate interest assessment before relying on this basis to ensure our interests are balanced and justified.
- Consent — Where we rely on your consent for specific processing activities, such as sending marketing communications about our services, you may withdraw that consent at any time by contacting us. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
- Legal Obligation — Processing necessary to comply with applicable laws, regulations, binding court orders, and lawful requests from public authorities with jurisdiction over Zhijiang Nuhong Trading Co., Ltd. or our operations.
If you have questions about the specific legal basis applicable to a given processing activity, or if you wish to receive a copy of a legitimate interest assessment we have conducted, please contact us using the details provided in the contact section of this policy.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties for their own marketing purposes. We consider your data to be a professional trust, and we treat it accordingly. We may share information in the following limited and carefully scoped circumstances, each governed by binding contractual obligations and, where applicable, independent due diligence assessments of the recipient.
- Service Providers and Partners — We engage trusted third-party vendors for cloud hosting, content delivery, analytics, email delivery, payment processing, and cybersecurity monitoring. These providers are contractually bound to process data only on our documented instructions and to uphold confidentiality and security standards at least as protective as those set forth in this policy. We conduct vendor security assessments before onboarding any service provider with access to personal data.
- Corporate Transfers — In the event of a merger, acquisition, reorganization, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and a prominent notice on our website before your data becomes subject to a materially different privacy policy as a result of a corporate transaction.
- Legal and Safety Requirements — We may disclose information when we believe in good faith that disclosure is necessary to comply with a legal obligation, protect our rights or property, prevent fraud or illegal activity, or protect the safety of any person against an imminent threat of serious harm.
- With Your Consent — We may share your information for any other purpose with your explicit, informed permission obtained in advance of the disclosure.
We require all third parties with whom we share personal data to respect the security and confidentiality of that data and to treat it in accordance with applicable law. We do not permit our service providers to use your personal data for their own purposes and only permit them to process it for specified purposes in accordance with our instructions.
6. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. The specific retention period for each category of data is determined by the nature of the information, the purpose for which it was collected, and our legal and operational requirements.
The criteria we use to determine appropriate retention periods include the duration of our business relationship with you and the time needed to complete any ongoing projects or technical support obligations that remain outstanding, whether there is a legal or regulatory obligation to which we are subject — such as tax record-keeping requirements, mandatory data preservation orders, or administrative regulations applicable to companies registered under Chinese law — and whether retention is advisable in light of our legal position regarding applicable statutes of limitations, pending or anticipated litigation, or ongoing regulatory investigations. When personal information is no longer required for the purpose for which it was collected and no legal obligation mandates its preservation, we securely delete or irreversibly anonymize it using industry-standard data sanitization methods, including cryptographic erasure and secure media destruction where appropriate.
7. Data Minimization and Accuracy
Rage Wave is committed to the principle of data minimization. We collect only the personal information that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Before initiating any new data collection activity, our engineering and compliance teams evaluate whether the intended collection is proportionate to the stated purpose and whether the same objective could be achieved with less intrusive means.
We also take reasonable steps to ensure that the personal information we hold is accurate and, where necessary, kept up to date. You have the ability to review and request corrections to your information at any time through the rights described in this policy. If you become aware that any information we hold about you is incomplete or inaccurate, we encourage you to contact us promptly so that we can correct our records. Maintaining accurate data is not only a regulatory expectation but also a practical necessity for the effective delivery of our systems integration services, where outdated configuration details or stale contact information can materially impact project outcomes.
8. Data Security
Protecting your information is a core operational priority at Rage Wave. We implement a comprehensive and continuously evolving set of administrative, technical, and physical safeguards designed to protect your data against unauthorized access, alteration, disclosure, or destruction. Our security architecture is built on a defense-in-depth model that applies multiple overlapping layers of protection, ensuring that the failure of any single control does not result in a meaningful reduction of overall security posture.
- Encryption of data in transit using TLS 1.3 with strong cipher suites, and encryption of sensitive data at rest using AES-256 standards with keys managed through a hardware security module or equivalent key management service.
- Access controls based on the principle of least privilege, with role-based access policies, multi-factor authentication required for all administrative access to production systems, and quarterly access reviews to revoke unnecessary permissions.
- Regular vulnerability assessments, penetration testing conducted by independent third-party security evaluators, and code-level security reviews integrated into our software development lifecycle.
- Continuous network monitoring with intrusion detection systems, automated threat response workflows, and security information and event management (SIEM) infrastructure operating 24 hours a day, 7 days a week.
- Mandatory employee training programs on data protection regulations, secure coding practices, social engineering awareness, and incident response procedures, with refresher training conducted at least annually.
- Redundant backup systems with geographically distributed storage, daily incremental backups, weekly full backups, and regular restoration testing to ensure data durability and availability in the event of a system failure or disaster.
While we strive to protect your information using commercially reasonable and industry-standard measures, no method of electronic transmission or storage is 100 percent secure. We cannot guarantee absolute security, but we are committed to promptly notifying you and relevant supervisory authorities in the event of a personal data breach that poses a risk to your rights and freedoms, in accordance with applicable legal requirements and within the notification deadlines prescribed by law.
9. Your Rights and Choices
Depending on your jurisdiction, you may have specific rights regarding the personal information we hold about you. We will honor all valid, verifiable requests to exercise these rights in accordance with applicable law, and we will not discriminate against you for exercising any of the rights described below.
- Right of Access — You may request a copy of the personal information we hold about you, along with details about the categories of data processed, the purposes of processing, the categories of recipients to whom data has been disclosed, and the expected retention period.
- Right of Rectification — You may ask us to correct inaccurate or incomplete personal information we maintain about you. We will respond to such requests without undue delay and will communicate any corrections to recipients to whom the data was disclosed, where feasible.
- Right of Erasure — In certain circumstances, you may request deletion of your personal information from our systems. This right is not absolute and may be limited by competing legal obligations, such as tax record-keeping requirements or the defense of legal claims.
- Right to Restrict Processing — You may request that we limit the processing of your personal information under specific conditions, such as when you contest the accuracy of the data or object to the processing.
- Right to Data Portability — You may request a copy of your data in a structured, commonly used, and machine-readable format, and you may ask us to transmit that data directly to another data controller where technically feasible.
- Right to Object — You may object to processing of your personal information based on legitimate interests or for direct marketing purposes at any time. Upon receiving an objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
- Right to Withdraw Consent — Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, please contact us at feedback@ragewave.buzz. We will respond to your request within the timeframe required by applicable law — typically 30 calendar days for GDPR requests, with the possibility of a 60-day extension for complex or numerous requests after notifying you. We may ask you to provide reasonable verification of your identity before taking action on your request to prevent unauthorized disclosures. If you are unsatisfied with our response, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction.
10. California and Other U.S. State Privacy Rights
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, or any other U.S. state with a comprehensive consumer privacy law, you may have additional rights under those laws. This section describes the rights available to you under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and similar state privacy frameworks, to the extent that Rage Wave is subject to those laws.
Under the CCPA, California residents have the right to know what personal information we collect, use, disclose, and sell — though we do not sell personal information as that term is broadly defined. You have the right to request deletion of your personal information, subject to certain exceptions. You have the right to correct inaccurate personal information. You have the right to non-discrimination for exercising your CCPA rights, meaning we will not deny you services, charge different prices, or provide a different quality of service because you exercised a privacy right. To submit a verifiable consumer request under the CCPA or an equivalent state law, please email us at feedback@ragewave.buzz. We will verify your identity before processing the request and will respond within the timeframe prescribed by the applicable statute.
11. International Data Transfers
As a company based in China with a globally distributed client base and infrastructure spanning multiple jurisdictions, your personal information may be transferred to, stored in, and processed in countries outside your country of residence. These recipient countries may have data protection laws that differ in scope and substance from those in your jurisdiction. When we transfer personal data across international borders, we do so in compliance with applicable data protection laws and through the implementation of appropriate safeguards designed to ensure a level of protection consistent with the standards described in this policy.
The safeguards we rely on for international data transfers include standard contractual clauses (also known as model clauses) approved by relevant data protection authorities, such as the European Commission Standard Contractual Clauses for transfers from the EEA and the UK International Data Transfer Addendum. We also conduct documented transfer impact assessments to evaluate the legal and regulatory environment in the destination country, considering factors such as government access requests, judicial oversight, and the availability of individual remedies. In addition, we apply technical measures including transport layer encryption, data-at-rest encryption, and granular access controls that apply regardless of the geographic location of our systems or those of our service providers. If you would like more information about the specific transfer mechanisms applicable to your data, please contact us.
12. Automated Decision Making and Profiling
Rage Wave does not engage in fully automated decision making, including profiling, that produces legal effects concerning you or similarly significantly affects you. Our systems do not use personal information to automatically evaluate, analyze, or predict aspects concerning your performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements in a manner that would have a material impact on your rights or opportunities.
To the extent that we use any automated processes in our service delivery or website operations — such as automated security monitoring, traffic anomaly detection, or performance analytics — these processes are overseen by human review and do not result in decisions that have a legal or similarly significant effect on individuals. If we introduce any automated decision making processes in the future that could have such effects, we will update this policy, provide you with meaningful information about the logic involved, and obtain any required consents before applying those processes to your data.
13. Children and Privacy
Our website and services are directed at businesses and professional users and are not designed, targeted, or intended for individuals under the age of 16. We do not knowingly collect, use, solicit, or disclose personal information from children. We have designed our onboarding and contact processes to minimize the likelihood that personal data relating to children is inadvertently collected through our digital channels.
If we become aware that we have collected personal data from a child under the age of 16 without verifiable consent from a parent or legal guardian, we will take immediate and conclusive steps to delete that information from all active systems, backups processed within a reasonable timeframe, and any third-party service environments where it may reside. If you believe that a child has provided us with personal information through our website or services, please contact us at feedback@ragewave.buzz with the relevant details. We will investigate and, where applicable, confirm deletion of the data in question. We also encourage parents and guardians to observe and guide their children in online activities and to instruct them never to provide personal information through websites without permission.
14. Third-Party Links and Services
Our website may, from time to time, contain links to third-party websites, plugins, and applications. These links are provided for informational or reference purposes, and clicking on them or enabling those connections may allow the relevant third parties to collect or share data about you independently of Rage Wave. We do not control these third-party websites, applications, or services and are not responsible for their privacy practices, content, or security.
When you leave our website through an external link or interact with an embedded third-party service, we encourage you to read the privacy policy and terms of service of every website you visit and every application you use before providing any personal information. The inclusion of a link on our website does not imply endorsement of the linked site or service by Rage Wave or Zhijiang Nuhong Trading Co., Ltd., and this privacy policy applies solely to information collected through our own digital properties and direct business operations.
15. Do Not Track Signals
Certain web browsers offer a Do Not Track (DNT) setting that transmits a signal to websites requesting that they refrain from tracking the browsing activity of the user. At present, there is no universally adopted industry or legal standard for how websites should interpret or respond to DNT signals. Accordingly, Rage Wave does not currently alter its data collection and usage practices in response to DNT browser signals.
We continue to monitor developments in the legal and technical landscape surrounding DNT technology and browser-based tracking preference signals, including the Global Privacy Control (GPC) mechanism. If a widely recognized standard emerges that is supported by regulatory guidance or industry consensus, we will evaluate its applicability to our operations and update this policy and our practices accordingly. In the meantime, you may exercise control over tracking through the cookie management options described earlier in this policy and through the privacy settings available in your browser.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, technology infrastructure, legal obligations, service offerings, or for other operational and strategic reasons. When we make changes, we will revise the effective date and the last updated date at the top of this document so that you can immediately see when the policy was last modified.
For material changes — defined as modifications that expand the scope of data collection, alter the purposes for which data is used, introduce new categories of data recipients, or otherwise affect your rights in a significant way — we will provide additional notice through one or more of the following channels: a prominent banner or notice on our website homepage, a direct email notification to the address associated with your account or inquiry, or a notification within the service dashboard if you are an active client. We encourage you to review this policy periodically to stay informed about how we are protecting your information. Your continued use of our website and services after any changes become effective constitutes your acceptance of the revised policy, unless applicable law requires us to obtain your explicit consent to the changes.
17. Dispute Resolution and Governing Law
This Privacy Policy and any disputes arising out of or relating to it shall be governed by and construed in accordance with the laws of China, without giving effect to any conflict of law principles that would result in the application of the laws of another jurisdiction. Any claim, dispute, or controversy arising out of or relating to this policy or the data practices described herein shall be resolved through good faith negotiation between the parties.
If a resolution cannot be reached through negotiation within 60 days, either party may submit the dispute to binding arbitration administered by the China International Economic and Trade Arbitration Commission (CIETAC) in accordance with its then-current arbitration rules. The arbitration shall take place in Yichang, Hubei, conducted in English, and the decision of the arbitrator shall be final and binding. Nothing in this section limits your right to bring a complaint before a data protection supervisory authority in your jurisdiction or to seek injunctive or other equitable relief from a court of competent jurisdiction where such rights cannot be waived under applicable law.
18. Contact Information
If you have questions, concerns, requests, or feedback regarding this Privacy Policy, our data protection practices, or your interactions with Rage Wave, please do not hesitate to contact us using any of the channels listed below. We are committed to transparency in our privacy practices and will address your inquiry promptly, thoroughly, and with the respect your privacy deserves. We aim to acknowledge all privacy-related communications within five business days of receipt.
Data Controller: Zhijiang Nuhong Trading Co., Ltd. (Rage Wave)
Address: Renhe Yuan Village Group 3 No. 136, Gujiadian Town, Yichang — 443200, Hubei, China
Email: feedback@ragewave.buzz
Phone: +16518946982
Website: www.ragewave.buzz
For residents of the European Economic Area and the United Kingdom, you also have the right to lodge a complaint with the data protection supervisory authority in your country of residence. We would, however, appreciate the opportunity to address your concerns directly before you approach a regulatory body and encourage you to contact us in the first instance.