CKTC 中肯商贸城

PRIVACY · PUBLIC APPLICATIONS

How information in public cooperation applications is used and protected

This notice applies to warehouse rental applications opened from public enterprise spaces. It explains what applicants provide, why the platform processes it, who can see it, and how drafts, tokens and submitted applications are retained.

Effective version · 29 August 2026

  1. 01 · DATA

    Information handled by the application flow

    An application includes a verified contact email, applicant enterprise, contact, optional phone, country or region, requested area, planned date, expected duration, goods type, required services and optional notes. The system also handles the application number, source enterprise space, warehouse and workflow status.

    • Email codes remain valid for 10 minutes with at most 5 attempts
    • Codes and recovery tokens are not written to business logs
    • Application data is stored on the server
  2. 02 · PURPOSE

    Information is used only to handle the current request

    The platform uses this information to verify the applicant's email, preserve an unfinished draft, prevent duplicate submission, connect the requirement to the correct warehouse, and support evaluation and follow-up by the platform and corresponding provider.

    • Verify the source of a public application
    • Resume and submit the same draft
    • Support contact and handling by the corresponding parties
  3. 03 · ACCESS

    Who can see an application

    A submitted application is available only to authorized platform personnel and authorized personnel of the enterprise providing the selected warehouse. It is never displayed in the public enterprise space or shared with unrelated enterprises.

    • Platform personnel act within their responsibilities
    • The corresponding provider sees only relevant applications
    • Public visitors and unrelated enterprises cannot view it
  4. 04 · SECURITY

    The browser stores only a random recovery token

    The browser does not place the application body in local storage. It keeps only a random recovery token valid for no more than 7 days. The server stores only its hash, rotates it after every save, and invalidates it after submission.

    • Recovery credentials remain separate from application content
    • Tokens are hashed and continuously rotated
    • Expired, invalid or mismatched credentials fail closed
  5. 05 · RETENTION

    Drafts and applications follow defined retention periods

    Unsubmitted drafts are automatically removed after 7 days. Submitted applications are retained for 24 months by default; contact information is anonymized 24 months after an application is closed. Any legally required change must be governed and recorded separately.

    • Unsubmitted draft: 7 days
    • Submitted application: 24 months
    • Closed for 24 months: contact details anonymized
  6. 06 · CHOICES

    You can stop before submission and contact the platform afterwards

    Before submission, you may stop and clear the recovery information from your browser. After submission, use a verified site contact or return to the corresponding enterprise space to ask about handling, correct contact details or make a reasonable data request.

    • No formal cooperation request is created until submission
    • Clearing local recovery information does not immediately delete an unexpired server draft
    • Provide the application number when asking about a specific request