Privacy Policy and Cookie Policy
The protection of your privacy is one of our main objectives. This information is provided in compliance with Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") to users of the website www.lisnsgroup.com (the "Website").
Last update: 11 September 2026
1. Who we are
The data controller is Shanghai Lichen Furniture Co., Ltd. ("LISNS", "we", the "Controller"), with registered office at No.158, Jinhuan Road, Jinshanwei Town, Jinshan District, Shanghai City, China.
You can contact us on matters relating to the protection of personal data by writing to [email protected].
2. Which personal data we process
2.1 Navigation data
The computer systems and software procedures used to operate this Website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This category of data includes: IP addresses or domain names of the computers used by users connecting to the Website, URI (Uniform Resource Identifier) addresses of the requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.), and other parameters relating to the user's operating system and online environment.
This information is not collected in order to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified.
These data are used for the sole purpose of checking the correct functioning of the Website, ensuring the security of the Website and its systems, and identifying anomalies and/or abuse (see Section 3.2). The data could be used to ascertain responsibility in the event of hypothetical computer crimes against the Website or third parties. The data on web contacts are not stored for more than 14 days. Security audit logs generated by our website security plugin are retained for no more than 3 months.
2.2 Data you provide voluntarily
The optional, explicit and voluntary sending of e-mails to the addresses indicated on this Website, or the submission of our contact form, involves the subsequent acquisition of the personal data you provide: your name, e-mail address and the content of your message. Our contact form is protected against automated abuse by Cloudflare Turnstile.
2.3 Cookies
In some cases, personal data is collected by using different technologies, including cookies. Cookies are small text files sent to the user's browser when the website is accessed, which identify the device but not the user. We use only cookies strictly necessary for the safe and efficient functioning of the Website — see the Cookie Policy in Section 12.
3. Purposes and legal bases of processing
3.1 Responding to your requests
Your personal data is processed to follow up on requests made by you through the Website, such as requests for information through the contact form.
The legal basis for this processing is to deal with a request made by you (Art. 6(1)(b) GDPR — steps at the request of the data subject prior to entering into a contract). Your consent is not required.
Your personal data is processed for the time strictly required to handle your request and, in any case, will not be stored for more than 6 months, unless a business relationship is established, in which case the data will be kept for the time required to perform the contract and to fulfil legal obligations.
3.2 Security of the Website and its systems
Your navigation data is processed as strictly necessary to ensure network and information security, including:
- preventing unauthorised access to the Website and its underlying systems;
- mitigating denial-of-service attacks;
- detecting and preventing abuse, fraud and automated attacks;
- rate-limiting and other technical measures necessary to maintain the availability and integrity of the Website.
This processing is based on our legitimate interest (Art. 6(1)(f) GDPR, as clarified by Recital 49 of the GDPR) in maintaining the security and proper functioning of this Website. The processing is limited to what is necessary and proportionate for these security purposes and is not used for profiling, marketing or any other purpose.
3.3 Compliance with legal obligations
Where applicable, personal data may be processed for the fulfilment of obligations provided for by law, regulations or orders of competent authorities. The legal basis is Art. 6(1)(c) GDPR.
4. Nature of the provision of data and consequences of refusal
The provision of your personal data through the contact form is optional. However, failure to provide the data marked as mandatory with an asterisk (*) will make it impossible for us to handle your request.
5. Methods of processing
Personal data is processed with the aid of computerised and telematic means, in any case by means of appropriate technical and organisational measures to ensure security and confidentiality, in compliance with Article 32 of the GDPR.
6. Recipients of personal data
Personal data may be known and used by our employees and staff, acting as persons authorised to process personal data, solely for the purposes described above.
Furthermore, personal data may be disclosed to third parties belonging to the following categories:
- providers of hosting and cloud infrastructure services (our Website is hosted on servers located in Frankfurt, Germany, operated by Tencent Cloud);
- providers of IT security services, content delivery and bot protection (Cloudflare, Inc., including its Turnstile service);
- professional consultants and authorities, where required by law.
The parties belonging to the above categories act, in some cases, as independent data controllers and, in other cases, as data processors specifically appointed by the Controller under Article 28 GDPR. You may request a list of the data processors at any time by contacting us at the address in Section 1.
Your personal data is not sold, and is not disclosed to the public.
7. Transfers of personal data
Hosting and primary processing take place within the European Union. Where Cloudflare processes data at locations outside the European Economic Area, such transfers are based on the Standard Contractual Clauses approved by the European Commission (Commission Implementing Decision (EU) 2021/914).
8. Automated decision-making
There is no automated decision-making process producing legal or similarly significant effects concerning you, and your data is not subject to profiling. The automated security filtering described in Section 3.2 operates solely for the protection of the Website and does not constitute a decision producing legal effects.
9. Your rights
In relation to the processing described above, you may exercise the following rights under Articles 15 to 21 of the GDPR:
- right of access (Art. 15) — obtain confirmation as to whether your personal data is being processed and access to it, together with information on purposes, categories of data, recipients, retention periods and your other rights;
- right of rectification (Art. 16) — obtain rectification of inaccurate personal data or completion of incomplete data;
- right to erasure / "right to be forgotten" (Art. 17) — obtain erasure of your personal data, subject to legal retention obligations;
- right to restriction of processing (Art. 18);
- right to data portability (Art. 20) — receive the data you provided to us in a structured, commonly used and machine-readable format;
- right to object (Art. 21) — object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (including the security-related processing in Section 3.2), unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims;
- right to withdraw consent — where processing is based on consent, withdraw it at any time with future effect (no consent-based processing currently takes place on this Website);
- right to lodge a complaint — lodge a complaint with the supervisory authority of your habitual residence, place of work or place of the alleged infringement.
To exercise any of these rights, contact us at [email protected]. We will respond within one month. We may ask you to verify your identity before acting on a request. The exercise of your rights is free of charge.
10. Security measures
Pursuant to Article 32 of the GDPR, we adopt appropriate technical and organisational security measures, including: TLS encryption for all data in transit; a web application firewall and rate-limiting to prevent unauthorised access and denial-of-service attacks; access controls restricting server and database access to authorised personnel; security monitoring and logging to detect and respond to attacks and abuse; and regular security updates to the Website software and server systems.
11. Use of the Website by minors
The Website is a business-to-business site intended for use by persons of legal age. We do not knowingly collect personal data from minors.
12. Cookie Policy
The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission. This Website uses only strictly necessary cookies — no analytics, advertising, profiling or other non-essential cookies are used, and no third-party tracking services are present.
| Name | Provider | Purpose | Maximum storage duration | Type |
|---|---|---|---|---|
| lisns_cc | lisnsgroup.com | Security: distinguishes between humans and bots and verifies that requests come from a real browser | 1 day | HTTP Cookie |
| lisns_cookie_ok | lisnsgroup.com | Stores your choice in our cookie notice | 1 year | HTML Local Storage |
| __cf_bm | Cloudflare | Distinguishes between humans and bots (set by our CDN and security provider) | 30 minutes | HTTP Cookie |
| cf.turnstile.u | Cloudflare | Bot protection for the contact form | Persistent | HTML Local Storage |
You can delete or block cookies through your browser settings at any time; however, blocking strictly necessary cookies may prevent the Website from functioning correctly. No cookie-based consent management is required because no non-essential cookies are used.
13. Changes and updates to this policy
We may modify or update this policy, in whole or in part, in consideration of changes in laws, regulations or our processing activities. Changes will be published on this Website and the "Last update" date at the top of this page will be revised accordingly. We recommend that you regularly consult this page. This policy is governed by Regulation (EU) 2016/679 (GDPR) and applicable EU data protection law.
®