Legal Document

GDPR Notice

General Data Protection Regulation Notice

Last updated: 8 May 2025 · Applies to: EU / European Economic Area (EEA) users

This notice is provided specifically for users in the European Union (EU) and European Economic Area (EEA), in accordance with the transparency requirements under Articles 13 and 14 of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679). This notice should be read alongside our Privacy Policy.

01 Scope

This GDPR Notice applies to all users located in EU Member States or the European Economic Area (Iceland, Liechtenstein, Norway). GDPR applies to Xuanyin in the following circumstances:

If you are not located in the EU/EEA, your data processing is still governed by our Privacy Policy, but GDPR-specific rights provisions may not apply.

  • Offering services to EU/EEA data subjects (whether or not for payment)
  • Processing personal data of EU/EEA data subjects
  • Monitoring the behavior of EU/EEA data subjects (e.g., using analytics tools to track Platform usage)

02 Data Controller

Under Article 4(7) of the GDPR, Xuanyin is the data controller for the processing of personal data on this Platform, responsible for determining the purposes and means of processing.

  • Controller name

    玄隐 · Xuanyin

  • Platform address

    xuanyin.org

  • GDPR contact email

    privacy@xuanyin.org

  • GDPR reference

    Art. 4(7), Art. 13, Art. 14

03 Lawful Basis for Processing (GDPR Art. 6)

Under GDPR Article 6, all processing of personal data requires a lawful basis. We rely on the following bases for different processing activities:

We do not rely on GDPR Art. 6(1)(b) (contract performance) or Art. 6(1)(e) (public task) to process user data, as these bases do not apply to Xuanyin's current business context.

  • Art. 6(1)(a) Consent

    Email subscription: You explicitly provide your email and submit the subscription form, constituting explicit consent under GDPR Art. 6(1)(a). You can withdraw consent at any time by unsubscribing via email. Withdrawal does not affect the lawfulness of prior processing (GDPR Art. 7(3)).

  • Art. 6(1)(f) Legitimate interests

    Contact responses & visit statistics: Our legitimate interests are: (1) responding to contact initiated by users — communication both parties reasonably expect, with minimal impact on users; (2) understanding anonymous aggregate page visits to improve content quality, using data with no personal identifiers. We have conducted a balancing test and concluded the processing has minimal impact on users' privacy interests.

04 Data Subject Rights (GDPR Art. 15–22)

As an EU/EEA user, you have the following specific rights under the GDPR:

  • Art. 15 Right of access

    Obtain a copy of personal data we process about you, along with processing purposes, data categories, and recipients.

  • Art. 16 Right to rectification

    Request correction of inaccurate or incomplete personal data without undue delay.

  • Art. 17 Right to erasure

    Request deletion of your data when it is no longer necessary, you withdraw consent, or you object under Art. 21.

  • Art. 18 Right to restrict processing

    Request restriction of processing when accuracy is contested or processing is unlawful but you prefer restriction over deletion.

  • Art. 20 Right to data portability

    Receive data you provided to us in a structured, machine-readable format (applies when processing is consent-based and automated).

  • Art. 21 Right to object

    Object to processing based on legitimate interests (Art. 6(1)(f)). We will cease processing unless we can demonstrate compelling legitimate grounds.

  • Art. 7(3) Withdraw consent

    Withdraw consent at any time without affecting the lawfulness of prior processing. To withdraw newsletter subscription consent: use the unsubscribe link or email privacy@xuanyin.org.

  • Art. 22 No automated decisions

    Not be subject to decisions based solely on automated processing (including profiling) that produce significant legal effects. Xuanyin does not conduct any automated decision-making.

05 How to Exercise Your Rights

To exercise any of your rights under the GDPR, follow this process:

  • Step 1: Submit Request

    Send an email to privacy@xuanyin.org with subject line “Data Subject Rights Request”. Please include: the type of right you wish to exercise; your email address (so we can verify your identity); and the specific data your request relates to (if known).

  • Step 2: Identity Verification

    We may ask for additional information to verify your identity and prevent unauthorized access. We will request only the minimum information proportionate to the request.

  • Step 3: Processing & Response

    We will respond within 30 days of receiving a valid request (the timeframe set by GDPR Art. 12). Complex requests may be extended to 60 days, but we will notify you of the extension and reason within 30 days. Exercising rights is free of charge, unless requests are manifestly unfounded or repetitive (in which case we may charge a reasonable fee or refuse).

06 Cross-Border Data Transfers (GDPR Art. 44–49)

In some circumstances, we may transfer your data to countries outside the European Economic Area (EEA), for example where our email delivery service providers are based in the United States. In such cases, we ensure appropriate safeguards required by GDPR Chapter V:

If you wish to learn about the specific safeguards we use for cross-border data transfers, or to obtain a copy of the SCCs, please contact privacy@xuanyin.org.

  • Adequacy decisions

    Where the European Commission has made an adequacy decision for the destination country (e.g., UK, Japan), no additional safeguards are required (GDPR Art. 45).

  • Standard Contractual Clauses

    For countries without adequacy decisions such as the US, we use Standard Contractual Clauses (SCCs, 2021 edition) approved by the European Commission in data processing agreements with third-party processors (GDPR Art. 46(2)(c)).

  • Transfer Impact Assessment

    Where applicable, we conduct Transfer Impact Assessments (TIA) to ensure the legal framework of the destination country does not undermine the level of protection provided by SCCs.

07 Data Protection Officer (DPO)

Under GDPR Article 37, Xuanyin does not currently meet the threshold requiring mandatory appointment of a Data Protection Officer (not a public authority, does not conduct large-scale systematic monitoring, does not process special categories of data at large scale).

For data protection matters, please contact our privacy contact: privacy@xuanyin.org. We take all GDPR-related inquiries seriously and will respond within statutory timeframes.

08 Right to Lodge a Complaint (GDPR Art. 77)

Under GDPR Article 77, if you believe our processing of your personal data violates the GDPR, you have the right to lodge a complaint with the relevant supervisory authority (data protection authority).

You may generally lodge a complaint with the data protection supervisory authority in your EU Member State. Below are the supervisory authorities for some major Member States:

Before lodging a complaint with a supervisory authority, we encourage you to contact us first (privacy@xuanyin.org) to give us the opportunity to address the issue.

  • Germany

    BfDI (Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit) — bfdi.bund.de

  • France

    CNIL (Commission Nationale de l'Informatique et des Libertés) — cnil.fr

  • Netherlands

    AP (Autoriteit Persoonsgegevens) — autoriteitpersoonsgegevens.nl

  • Ireland

    DPC (Data Protection Commission) — dataprotection.ie

  • Other Member States

    Visit the European Data Protection Board website to find the supervisory authority for your country: edpb.europa.eu

09 Automated Decision-Making & Profiling

Xuanyin does not engage in automated decision-making within the meaning of GDPR Article 22 (including profiling that produces legal effects or similarly significant effects on you).

We do not use algorithms to evaluate, rank, or automatically make decisions affecting your rights based on your personal data. All content recommendations (such as “related content” sections) are editorially curated rather than algorithmic.

10 Children's Data Protection (GDPR Art. 8)

Under GDPR Article 8, when processing consent for information society services for children under 16, parental or guardian consent is required.

The Xuanyin Platform is intended for users aged 16 and above. We do not knowingly serve or collect data from persons under 16. If we discover a user under 16 has registered, we will immediately delete the relevant data.

11 Updates to This Notice

We will periodically review this GDPR Notice to ensure it remains consistent with our data processing practices and applicable law. For material changes, we will notify users in the same manner as described in our Privacy Policy.

The latest version of this Notice is always available at xuanyin.org/gdpr.html, with the last update date noted at the top of the page.

12 Contact Us

For any questions about this GDPR Notice or our data processing practices, or to exercise your GDPR rights, please contact us:

  • GDPR / Privacy matters

    privacy@xuanyin.org

  • General contact

    hello@xuanyin.org

  • Statutory response deadline

    Within 30 days (GDPR Art. 12)

Version: 8 May 2025