Privacy Policy
Last updated: June 21, 2026
1. Introduction
Beijixin ("we," "us," or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website beijixin.org or use our services.
This policy is issued in accordance with the UK General Data Protection Regulation (UK GDPR), the UK Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). It sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us.
For the purposes of the UK GDPR, we are the data controller. Our registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
2. Information We Collect
Personal Data You Provide
We may collect and process the following categories of personal data about you:
- Identity Data: Name, username, or similar identifier.
- Contact Data: Email address, phone number, and postal address.
- Transaction Data: Details about payments to and from you, and other details of services you have purchased from us.
- Financial Data: Payment card details, bank account information (processed securely by our payment processor Stripe — we do not store full card details).
- Profile Data: Your username and password, preferences, feedback, and survey responses.
- Marketing and Communications Data: Your preferences in receiving marketing from us and your communication preferences.
Automatically Collected Data
When you access our website, we may automatically collect:
- Technical Data: Internet Protocol (IP) address, browser type and version, time zone setting, browser plug-in types, operating system, and device information.
- Usage Data: Information about how you use our website, including pages visited, time spent, clickstream data, and navigation paths.
- Cookie Data: Data collected through cookies and similar tracking technologies (see Section 9).
3. Legal Basis for Processing
Under the UK GDPR, we rely on the following lawful bases for processing your personal data:
- Contractual Necessity: Processing necessary to perform a contract with you or to take steps at your request before entering into a contract (Article 6(1)(b)).
- Legitimate Interests: Processing necessary for our legitimate interests, provided these are not overridden by your rights and interests (Article 6(1)(f)).
- Legal Obligation: Processing necessary for compliance with a legal obligation to which we are subject (Article 6(1)(c)).
- Consent: Processing based on your explicit consent, which you may withdraw at any time (Article 6(1)(a)).
4. How We Use Your Information
We use your personal data for the following purposes:
- To register you as a new customer and provide our services to you.
- To process and deliver your orders, including managing payments, fees, and charges.
- To manage our relationship with you, including notifying you about changes to our terms or privacy policy.
- To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, and security).
- To deliver relevant website content and measure the effectiveness of our communications.
- To use data analytics to improve our website, services, marketing, and customer experiences.
- To make suggestions and recommendations about goods or services that may interest you, where you have consented to receive such communications.
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your personal data with the following categories of recipients:
- Service Providers: Third-party vendors who perform services on our behalf, including:
- Stripe, Inc. for payment processing (see Stripe's Privacy Policy at stripe.com/gb/privacy)
- Cloud hosting and infrastructure providers
- Email delivery and communication services
- Analytics and data processing services
- Professional Advisers: Including lawyers, bankers, auditors, and insurers where reasonably necessary.
- Legal and Regulatory Authorities:When required by applicable law, court order, or governmental regulation, including HM Revenue & Customs and the Information Commissioner's Office (ICO).
- Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your data may be transferred as part of that transaction.
6. Payment Processing
We use Stripe, Inc. as our primary payment processor. We also support payments via Alipay, WeChat Pay, and other payment methods available through Stripe. When you make a payment, your payment card information is collected and processed directly by Stripe in accordance with the Payment Card Industry Data Security Standard (PCI DSS). We do not store or have access to your full payment card details.
Stripe's processing of your personal data is governed by their own Privacy Policy and Stripe Services Agreement, both available at stripe.com/gb/privacy. Stripe is certified to PCI DSS Level 1, the highest level of certification.
7. Data Security
We have implemented appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include:
- Encryption of data in transit using TLS 1.3 and data at rest using AES-256 encryption.
- Regular security assessments and vulnerability scanning.
- Access controls limiting personal data to authorised personnel on a need-to-know basis.
- Multi-factor authentication for administrative access.
- Procedures for dealing with data breaches, including notification to the ICO within 72 hours where required.
While we take all reasonable steps to protect your personal data, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee the absolute security of your data.
8. International Data Transfers
Your personal data may be transferred to and processed in countries outside the United Kingdom and the European Economic Area (EEA). Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by implementing at least one of the following safeguards:
- Transferring to countries deemed to provide an adequate level of protection by the UK government (adequacy regulations).
- Using the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs).
- Where these are not available, relying on derogations for specific situations as set out in the UK GDPR.
9. Cookies
Our website uses cookies and similar technologies to distinguish you from other users. This helps us provide you with a good experience and allows us to improve our site. In accordance with PECR, we request your consent before placing non-essential cookies on your device.
We use the following categories of cookies:
- Strictly Necessary Cookies: Essential for the operation of our website. These do not require consent under PECR.
- Analytical/Performance Cookies: Allow us to recognise and count visitors and understand how they navigate our site.
- Functionality Cookies: Used to recognise you when you return and to personalise content.
- Targeting Cookies: Record your visit, pages visited, and links followed to make advertising more relevant to you.
You can manage your cookie preferences through your browser settings. Most browsers allow you to refuse or accept cookies, delete existing cookies, or set notification preferences. Please note that disabling cookies may affect the functionality of our website.
10. Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and applicable legal requirements.
By law, we must keep basic information about our customers (including contact, identity, financial, and transaction data) for six years after they cease being customers for tax purposes, in accordance with UK tax law.
11. Your Legal Rights
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of Access: Request access to your personal data (commonly known as a "data subject access request").
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data in certain circumstances ("right to be forgotten").
- Right to Restrict Processing: Request restriction of processing in certain circumstances.
- Right to Data Portability: Request transfer of your data to another party in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing of your personal data for direct marketing purposes, or where we rely on legitimate interests.
- Rights in Automated Decision-Making: Not to be subject to decisions based solely on automated processing, including profiling, which produce legal effects.
To exercise any of these rights, please contact us at m18274357873@163.com. We will respond to your request within one month (which may be extended by two months for complex or numerous requests). There is no fee to exercise these rights unless your request is manifestly unfounded or excessive.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues, at ico.org.uk. We would, however, appreciate the chance to deal with your concerns before you approach the ICO.
12. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child under 18 has provided us with personal data, we will take steps to delete such information promptly. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically. If changes are material, we may provide additional notice, such as by email.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us:
Beijixin
71-75 Shelton Street
Covent Garden, London, WC2H 9JQ
United Kingdom
Email: m18274357873@163.com
Phone: +86 18274357873
Contact Person: Jiahao Deng