This Privacy Policy explains how Fujian New Yifa Group Co., Ltd. ("NewYiFa Group", "we", "us", or "our") collects, uses, discloses, and protects your personal data when you visit https://fjnewyifa.com (the "Site") or interact with our sales, OEM/ODM, and customer-support services. It is written to meet the standards of the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA").
We respect your privacy and are committed to protecting your personal data. This policy tells you what to expect when we collect personal data about you, the legal bases we rely on, and the rights you have. If you have any questions, please contact our Data Protection team using the details in Section 13.
This policy applies to information we collect: (a) on the Site; (b) in email, text, and other electronic messages between you and us; (c) through quote-request, contact, and newsletter forms; and (d) when you engage our sales or OEM/ODM services. It does not apply to data collected by any third party whose sites or services may link to or be accessible from the Site.
For the purposes of the GDPR and UK GDPR, the data controller is:
Fujian New Yifa Group Co., Ltd. (trading as "NewYiFa Group" / "New Yifa Group"), established 1994, a manufacturer of baby diapers, adult diapers, pull-up pants, wet wipes, underpads, and feminine care products.
Yifa Industry and Trade Park, Hanjiang District, Putian City, Fujian Province, China 351100.
EU/UK Representative. Under Article 27 GDPR, we have appointed an EU/UK representative to act as a point of contact for data-protection authorities and data subjects in the European Economic Area and the United Kingdom. You may contact our representative, and our Data Protection Officer, at the addresses in Section 13.
We collect several categories of personal data. "Personal data" means any information relating to an identified or identifiable natural person.
We do not collect special categories of personal data (such as health, biometric, or religious data) through the Site, except where you voluntarily include such information in a free-text message.
We use your personal data only where we have a lawful basis to do so. The table below sets out our purposes and the corresponding legal bases under the GDPR.
| Purpose | Examples | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Respond to inquiries & provide quotes | Reply to contact/RFQ forms; prepare OEM/ODM quotations | Contract (Art. 6(1)(b)) & legitimate interests (Art. 6(1)(f)) |
| Perform contracts & orders | Production, shipping, invoicing, after-sales support | Contract (Art. 6(1)(b)) & legal obligation (Art. 6(1)(c)) |
| Improve the Site & services | Analytics, performance, UX research | Legitimate interests (Art. 6(1)(f)) |
| Marketing communications | Newsletters, product updates, trade-show invites | Consent (Art. 6(1)(a)) |
| Security, fraud & legal compliance | Login security, abuse prevention, record-keeping | Legal obligation (Art. 6(1)(c)) & legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have balanced our interests against your rights and freedoms and concluded that processing is proportionate. You may object at any time (see Section 9).
Where we rely on consent (e.g. newsletters, non-essential cookies), you may withdraw it at any time without affecting prior lawful processing. We will never make consent a condition of purchasing our products where it is not strictly necessary.
We use cookies, web beacons, and similar technologies to operate the Site, remember preferences, measure performance, and support live chat. Cookies are small text files placed on your device. We classify them as follows:
| Category | Purpose | Can be disabled? |
|---|---|---|
| Strictly necessary Always on | Site security, load balancing, session management, cookie-consent record | No — required for the Site to function |
| Functional Optional | Language, region, and UI preferences; live chat (Tawk.to) | Yes |
| Analytics Optional | Google Analytics 4 (GA4) — aggregated usage statistics | Yes |
| Advertising / remarketing Optional | Google Ads, Meta Pixel — measure ad effectiveness | Yes |
When you first visit the Site, our cookie banner asks for your consent to non-essential cookies. You can change or withdraw your choice at any time via the "Cookie Settings" link in the footer, or by adjusting your browser settings. Because we do not currently respond to "Do Not Track" (DNT) browser signals uniformly, please use the consent controls provided.
Third-party providers (Google, Meta, Tawk.to) may process data as independent controllers; their processing is governed by their own privacy policies.
We do not sell your personal data for money. We share personal data only with the categories of recipients below, under appropriate contracts:
Where a recipient is located outside your jurisdiction, transfers are protected as described in Section 7.
NewYiFa Group is based in China. Your personal data may be transferred to, and processed in, China and other countries whose data-protection laws may differ from those in your home country. For transfers of personal data from the EEA or the UK to China (or other third countries), we rely on:
You may request a copy of the relevant safeguards by contacting us (see Section 13). For transfers to US-based providers (e.g. Google, Meta), we rely on their certified participation in the EU–US Data Privacy Framework where applicable, or on SCCs.
We keep personal data only for as long as necessary for the purposes set out in this policy, or as required by law:
If you are in the EEA or the UK, you have the following rights. We will respond within one month (extendable by two further months for complex requests).
To exercise any of these rights, contact us at privacy@newyifagroup.com. We may need to verify your identity. You also have the right to complain to a supervisory authority — for the UK, the Information Commissioner's Office (ICO) at ico.org.uk; for the EEA, your local Data Protection Authority.
If you are a California resident, you have the following rights regarding your personal information, subject to verification:
| Right | What it means |
|---|---|
| Right to know / access | Request the categories and specific pieces of personal information we collect, use, and disclose. |
| Right to delete | Request deletion of personal information we collected from you, with certain exceptions. |
| Right to correct | Request correction of inaccurate personal information. |
| Right to opt out of sale/share | Direct us not to "sell" or "share" (including cross-context behavioral advertising) your personal information. |
| Right to limit use of sensitive PI | Limit our use and disclosure of sensitive personal information to permitted purposes. |
| Right to non-discrimination | We will not discriminate against you for exercising your CCPA rights. |
Categories of personal information collected (past 12 months): identifiers (name, email, phone, IP); commercial information (inquiry/order records); internet activity (usage, cookies); professional/employment information; and inferences for marketing. We disclose these to service providers and, for analytics/advertising, to advertising partners (a "share" under CPRA).
We do not "sell" personal information for monetary consideration. However, the use of advertising cookies may constitute a "share" of personal information for cross-context behavioral advertising. You can exercise your opt-out right below.
Do Not Sell or Share My Personal Information: To opt out of the "sale" or "sharing" of your personal information, submit a request to privacy@newyifagroup.com or use the Global Privacy Control (GPC) signal supported by your browser. We honor GPC signals as a valid opt-out.
You may submit a request through an authorized agent with proof of authorization. We will not discriminate against you for exercising these rights.
The Site is a business-to-business site intended for professional buyers and is not directed to children under the age of 16 (or under 13 in the United States). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
We implement appropriate technical and organisational measures to protect your personal data, including: HTTPS/TLS encryption in transit; encryption at rest for stored credentials; role-based access controls; network firewalls; regular security assessments; and staff confidentiality obligations. No method of transmission over the internet is 100% secure, but we work to protect your data and will notify affected users and authorities where the law requires us to report a personal-data breach.
We may update this policy from time to time. Material changes will be posted on this page with a revised "Last updated" date, and, where required, we will notify you by email or through the Site. We encourage you to review this policy periodically.
For any question about this policy or to exercise your privacy rights (GDPR, UK GDPR, or CCPA/CPRA), please contact: