Privacy Policy

Last Updated: May 21, 2026

Regulatory Compliance

GDT Group operations strictly comply with global data protection standards, including the European Union GDPR, California CCPA, and regional PDPA mandates across Southeast Asia.

Scope: Global Operations
Data Controller: GDT Group Inc.
DPO Email: dpo@gdt.team

1. Introduction and Scope

GDT Group Inc. and its global subsidiaries (collectively, "GDT", "we", "us", or "our") respect your privacy and are committed to protecting your personal data. This Privacy Policy describes how we collect, use, process, disclose, and safeguard your information when you visit our website, utilize our enterprise Shopify solutions, engage with our performance marketing engines, or interact with our DTC consumer brand portfolio (including Fulico, Tokoyo, and Puri).

2. Information We Collect

We collect information that identifies, relates to, describes, or could reasonably be linked with you. This information falls into two core categories:

A. Information You Provide Voluntarily

This includes personal coordinates provided via contact forms, corporate consultation requests, or transaction portals—such as name, corporate email address, phone number, company profile, target markets, and financial billing credentials.

B. Information Collected Automatically

When interacting with our digital ecosystems, we automatically harvest behavioral logs via cookies and tracking tags. This encompasses IP addresses, browser specifications, operating system architectures, localized time zones, referring URLs, and granular clickstream engagement behaviors metrics.

3. How We Use Your Information

GDT utilizes your processed datasets strictly under lawful baselines for predefined commercial purposes:

  • To provision, maintain, optimize, and customize our full-funnel digital infrastructure and multi-channel marketing solutions.
  • To process secure commercial transactions, verify cross-border payment compliance, and orchestrate logistics distribution metrics.
  • To feed our advanced server-side Conversions API (CAPI) infrastructure to scale ad delivery efficiencies while maintaining maximum data anonymity.
  • To monitor system diagnostic integrity, prevent malicious cyber threats, and audit multi-regional statutory legal compliances.

4. Data Sharing and Cross-Border Transfers

GDT does not rent or sell your analytical datasets to third-party brokers. We share structural information only with trusted enterprise service vendors (such as secure cloud hosting infrastructures, authenticated transaction gateways, and authorized logistics carriers) acting under strict data processing agreements.

Because GDT acts as an integrated global matrix with regional operation hubs spanning Bangkok, Taipei, Jakarta, and Tokyo, your datasets may be securely transferred and accessed across cross-border perimeters. We enforce legally binding Standard Contractual Clauses (SCCs) to guarantee equivalent tiers of cryptographic protection globally.

5. Advanced Data Security

We implement advanced, military-grade administrative, logic, and physical security architecture barriers to neutralize data breaches, leaks, unauthorized access, or structural alterations. Data pipelines are encrypted using industry-standard Transport Layer Security (TLS/SSL) mechanisms during transmission, and standard AES-256 protocols at rest.

6. Your Statutory Legal Rights

Depending on your localized multi-regional jurisdiction (such as GDPR for EU residents, CCPA for California citizens, or PDPA mandates), you hold powerful statutory privacy privileges:

  • The Right to Access: Request digital copies of your archived personal datasets.
  • The Right to Rectification: Demand immediate corrections of corrupted or inaccurate datasets.
  • The Right to Erasure ("Right to be Forgotten"): Request total permanent deletion of personal tracking traces.
  • The Right to Object/Restrict Processing: Opt-out or limit specific behavioral marketing algorithms.

To execute any standard legal mandates, please immediately issue an official request to our Data Protection Officer at dpo@gdt.team

7. Policy Modifications

GDT Group reserves the executive authority to modify this constitutional Privacy Policy blueprint at any moment to mirror technological innovations or legal amendments. Any updates will be broadcasted transparently via this URL architecture with a renewed "Last Updated" timestamp designation.