Scope and contact
This policy describes the collection, processing and use of personal information by 沃達永續資源整合有限公司 (Taiwan business registration number 93658640, the Company) on vosurein.com. It applies to browsing, service inquiries and related communication.
For personal information matters, contact agesmyth@gmail.com, 0932-606-514, or write to No. 53, Lane 69, Xingxiang Street, Wuri District, Taichung City, Taiwan.
Information collected and purposes
The inquiry form requires a contact name, email, service selection and needs summary. Company or organisation, phone, operating region and timing are optional. Information is used to answer questions, assess needs, prepare quotations, discuss cooperation, arrange communication and, where applicable, perform contracts and provide customer service. With a lawful basis and only as necessary, relevant correspondence, transaction and handling records may also be retained and used for legal obligations, specific disputes, exercising or defending legal rights, and website and information security. These purposes do not authorise unrelated uses.
The policy is available before submission and you are asked to confirm the data-use notice. General inquiries are processed on informed consent. Contract discussions and performance are handled within applicable law and necessity. An inquiry does not enrol you in marketing. Inquiry information is not sold or supplied as a third party's marketing list.
Do not provide identity documents, medical information, passwords, system keys, complete customer lists or unrelated sensitive information in an initial inquiry. Before supplying someone else's contact information, establish an appropriate basis, inform them and provide only necessary information. The Company still assesses and fulfils any legally required notice when information is obtained from someone other than the individual concerned.
Technical and anti-abuse information
Hosting services process technical records such as IP addresses, request times, URLs and connection details to deliver pages, maintain service and handle incidents. The website does not intentionally write inquiry bodies, verification tokens or keys to application logs.
At the inquiry confirmation stage, Cloudflare Turnstile loads to distinguish people from automated abuse. It processes signals including IP address, browser and TLS connection characteristics, site identifiers and origin. Cloudflare also uses verification signals to improve detection under its policy. The website sends the token for verification, not the inquiry body. See the Turnstile privacy policy.
To limit repeated submissions, the website uses keyed hashes of email identifiers and short-lived counters. These identifiers are not fully anonymous. The rate-limit database does not hold names, plain-text email addresses or inquiry bodies.
Use, recipients and processing locations
Information is used through website storage and processing, email, phone, post and necessary business documents according to the inquiry or cooperation needs. Access is restricted to authorised personnel with a business need, within the necessary scope and subject to confidentiality obligations.
The website uses Vercel for hosting, Cloudflare Turnstile for verification, Upstash Redis for temporary rate limits and article feedback, Supabase for inquiry storage, Resend for sending mail, and Google Gmail for receiving and retaining correspondence. After verification and rate limiting, contact and inquiry information is saved in Supabase with a submission identifier, consent record, processing status and necessary internal handling notes for authorised staff to respond and follow up. Resend then sends a notification to agesmyth@gmail.com. A failed notification does not delete a saved inquiry. Each provider processes information needed for its function; this does not mean every provider receives the complete form.
The Company processes business information in Taiwan. Cloud services may process information in the United States, Japan and locations of providers and supporting services. The Supabase customer database is configured in Tokyo, Japan; this does not confine every technical record, support operation or backup to Japan. Upstash is configured in Virginia, United States. Resend's Tokyo sending region controls routing, not storage: its published information states that customer data such as email content and sending logs is stored in the United States. See Vercel, Supabase, Upstash, Resend and Google.
The Company may replace providers with equivalent functions for operational, security or service-quality reasons and update recipients, locations and other required notices. Where separate notice or consent is legally required, the necessary steps will be taken first. Changing providers does not expand information uses or remove legal obligations.
Apart from the services described, appropriate consent, lawful disclosure to competent authorities or another lawful basis, the Company does not disclose inquiry information at will. Disclosure to appointed professionals for legal claims or disputes is limited to a lawful and necessary scope with appropriate confidentiality measures.
Article feedback
You may choose whether an article was helpful without providing a name or email. The browser stores a random identifier and your choice so the same browser can remember and change feedback. Reading does not depend on using this feature.
On submission, the identifier is converted to a keyed hash and stored in Upstash Redis with the article path and choice to improve content, adjust counts and prevent repeated actions. Such identifiers are not fully anonymous. Feedback does not send email or add you to marketing lists. Ordinary connections may still generate hosting technical records.
Retention and deletion
To deter automated voting, the server also converts the connection IP address (a network segment for IPv6) into a keyed hash and stores only temporary rate-limit counters in Upstash Redis, not the original IP. Visitors sharing a network exit may share a limit. These hashes are not fully anonymous.
Feedback and aggregates are retained for content improvement and reviewed quarterly. Related data is cleared when an article is permanently removed or analysis is no longer needed. Individual feedback rate counters expire after one hour; source counters after one hour and 24 hours respectively; site-wide counters after 24 hours. This does not mean voting records are deleted at the same time.
Clearing website storage removes the browser feedback identifier and choices, but does not automatically delete submitted server records. To request action on submitted feedback, contact us with the article and necessary identifying information. We first determine what information can be identified. After changing devices, clearing storage or losing the original identifier, linking a record to you may be impossible. Unrelated identity documents should not be required.
Retention depends on the information, purpose, relationship and applicable law and is reviewed regularly. General inquiry information is deleted or irreversibly anonymised when the response and necessary follow-up are complete and no ongoing discussion or other lawful retention basis remains. Cooperation records are retained for contract performance, necessary after-sales service and legally required periods.
Where law, a specific dispute, or exercising or defending a claim requires continued retention, only relevant information with a lawful basis is kept and its use and access are restricted. When the dispute, obligation or other basis ends, information is deleted, processing or use ceases, or irreversible anonymisation is applied as required by law. A general possibility of future cooperation does not justify indefinite retention.
These principles apply to Supabase inquiry and internal handling records and Gmail correspondence. The database and mailbox must be handled separately; deletion by one or by the sending service does not automatically delete the other.
Email rate-limit counters expire ten minutes after their counting window begins; site-wide counters after 24 hours. The Resend Free plan currently lists 30-day email and log retention, with a separate seven-day backup cycle. These provider periods differ from the Company's email retention principles. Other technical records and backups follow service settings, provider rules and necessary security or legal needs. Immediate removal of all backups is not promised.
Your rights
Using the contact details above, you may request inquiry or access to your information, a copy, supplementation, correction, cessation of collection, processing or use, and deletion. The Company does not require advance waiver of statutory rights.
Provide a reply contact, the right you wish to exercise and enough information to locate the records, such as the original inquiry email, approximate contact date or article URL. Identity checks may be necessary and proportionate to the request's risk; an agent may be asked to establish authority. Unrelated identity information is not required, nor is an identity-document copy a universal condition. If more information is needed, the Company explains what is missing and follows the law rather than arbitrarily extending statutory periods.
For requests legally concerning inquiry, access or copies, a decision is made within 15 days, extendable by no more than 15 days where necessary with written reasons. For requests legally concerning correction, cessation of processing or use, or deletion, a decision is made within 30 days, extendable by no more than 30 days where necessary with written reasons. Any lawful retention or exception will be explained with the scope of action. Decision deadlines do not mean every provider backup can be deleted that day.
Necessary costs for inquiry, access or copies may be charged under Article 14 of Taiwan's Personal Data Protection Act, with advance explanation of items, calculation and delivery. This does not extend to correction, cessation of use, deletion or other rights requests.
Withdrawal of consent-based permission is handled under applicable law. It does not affect lawful processing before withdrawal or exclude necessary processing on another lawful basis. If a particular service cannot continue, the impact will be explained without limiting your other statutory rights.
Whether information is required
You may omit optional fields or use phone or email instead of the form. Without necessary contact information, needs, data-use confirmation or security verification, the form cannot be submitted or the Company may be unable to reply. Omitting optional information does not disqualify a general inquiry, although further details may be needed for an assessment.
Cookies, local storage and sharing links
Article feedback uses localStorage to save a random identifier and choice when you use the feature, so feedback can be remembered and changed. No automatic expiry is currently set. You may clear site storage and the browser may also clear it. Previous feedback identification may then be unrecoverable, but reading remains available and server records are not automatically deleted.
Google Analytics, advertising pixels, Vercel Web Analytics and Speed Insights are not currently enabled. Verification and hosting may still process necessary technical signals; this is not a claim of no third-party processing. If non-essential tracking is introduced, notices and necessary choices will be updated for the actual function and applicable requirements.
Social sharing uses external links. Once followed, the platform's policy applies to its processing.
Security and policy changes
The Company applies access and security measures proportionate to the information and risks. If an information security incident is discovered, it will limit the impact, investigate the cause and fulfil notifications or other obligations under the law applicable at that time. This policy may change with services, processing or law, with the latest revision date shown here. Where rights are materially affected or separate notice or consent is legally required, appropriate steps are taken rather than relying only on publication. Revisions do not retroactively authorise unlawful processing, and simply browsing does not constitute consent to all new purposes.