Privacy notice
On this page
At a glance
We process account and contact information to manage requests, check product information, and prepare and deliver safety data sheets. Original formulations and uploaded materials are not used as public samples.
We manage the preparation, storage and backup of original formulations, attachments and completed documents ourselves. Cloudflare is used for website access, and necessary notices are sent through Zoho China email services; messages may include the recipient address, verification codes and company or product names related to a request. Confidentiality of the original formulation is distinct from ingredient information that an SDS must disclose.
Use https://msds-master.com/en/privacy-request to exercise your personal-data rights, or contact [email protected]. Retention periods, applicable exceptions and request procedures are explained below.
1. Who is responsible for the service
MSDS Master is provided by Shenzhen Wanzera Information Technology Co., Ltd. This notice covers personal information processed when you visit the website, create an account, submit service materials, contact us and receive documents. It also explains how we protect formulations and business materials.
Contact address: No. 2008-2 Xingye Road, Xixiang Subdistrict, Bao'an District, Shenzhen, Guangdong, China. Privacy enquiries: [email protected] or https://msds-master.com/en/privacy-request. Service enquiries: [email protected]. Applicable registration details appear at the top of this page and on our contact page.
For account, security and business records, we take the responsibilities required of us under applicable rules. Where third-party personal information submitted by a customer is processed on that customer’s behalf, the parties’ roles, instructions and necessary agreement depend on the actual processing, rather than a blanket classification in this notice.
2. Information we process and why
The following inventory describes the information actually needed for the service. Not providing a required field may prevent account creation or completion of the relevant request; optional information does not affect unrelated functions. Identity documents, full payment-card details and unrelated personal information are not general conditions of opening an account.
| Category | Details |
|---|---|
| Account and contact information | Name or preferred name, sign-in email, password-verification data, interface language and account status, supplied by the user and used for registration, authentication, security and service contact. |
| Applicant and document parties | Company details and optional logos for organisation profiles, necessary names and contacts for individual profiles, and required supplier/importer contacts, supplied with authority for service checks and accurate document identification. |
| Product information and uploads | Product name, use, capacity, ingredients, concentrations, supplier SDSs, test information and necessary contacts in attachments, supplied by the applicant for preparation and review. |
| Requests and documents | Request number, region/country/language, information versions, service correspondence, delivered PDFs and actual delivery/download records, generated to fulfil, correct and trace the service. |
| Credits and payments | Credit allocation, reservation, use and release, plans and payment/refund summaries actually generated, for accounting and payment enquiries. |
| Technical and security records | Sessions, request times, browser/device technical information and necessary security events actually recorded, for service operation and abuse investigation. |
| Enquiries and safety verification | Reply email, enquiry question, optional contact details and relevant product category, destination or plan, for pre-service communication, email verification, reply notices and abuse prevention. An enquiry does not automatically create an SDS request or use credits. |
| Privacy rights requests | Reply email, request type, optional name and brief details, acknowledgement and handling status, used to receive, verify, handle and respond to privacy rights requests and retain necessary evidence. |
The inventory describes actual processing; it does not require every user to provide every category. A billing page does not create a payment record when payment functionality is unavailable.
For an enquiry, we process the reply email, question, optional contact details and relevant product category, destination or plan. Email verification confirms access to the enquiry. General enquiries do not automatically create SDS requests or use credits. Notifications use the disclosed email service and do not attach original formulations, customer files or complete conversation text. Cloudflare Turnstile and server-side rate limits help prevent automated abuse.
For privacy rights requests, we process the reply email, request type, optional name and brief details, acknowledgement and handling status to record, verify and respond to the request and retain necessary evidence. The form uses Cloudflare Turnstile and server-side rate limits; notification emails do not include the submitted details or identity documents.
3. Sources and grounds for processing
Information mainly comes from forms you complete, files you upload, service correspondence, and account and security records generated by the service. Applicants may also provide contact information for suppliers, importers or customers on behalf of their business.
When providing another person’s information, limit it to the business contact details necessary for the request, ensure that you are authorised to provide it, and give any required information to that person. You may share this notice with them; that does not replace any notification duties that we must perform ourselves. Receiving a buyer’s email address does not add that person to a marketing list.
We rely on the grounds applicable to each processing activity, which may include necessary performance of a contract, legal obligations or valid consent. The grounds are identified with the purposes in the inventory above. A legitimate-interests ground is used only where the relevant law recognises it and its conditions are met; a ground available in one jurisdiction is not assumed to apply everywhere. Consent-based processing may be withdrawn as explained below.
Core account and request processing is based on performing the agreed service. Other purposes are assessed against their actual grounds separately.
4. Formulations, attachments and company branding
We use original formulations, supplier SDSs, test materials, company logos and business information ourselves for information checks, preparation, human review, delivery, necessary corrections and agreed record-keeping. Access is limited to our authorised personnel with a work-related need for the relevant information.
We do not display these original materials publicly, sell original formulations or provide them to other customers. Customer formulations, documents and logos are not used for promotional case studies without separate express permission.
A delivered SDS may need to contain ingredients, hazard information and responsible-party contact details required by the applicable rules. Confidentiality does not authorise omission of required disclosures. Access to the original formulation is distinct from access to the delivered document. Customers should manage their own business recipients when forwarding a completed SDS.
Automated checks identify missing information, formatting issues and inconsistent states; preparation and formal delivery remain human-controlled. We manage business storage, archiving and backup of customer materials ourselves. Website access and upload traffic use Cloudflare, and necessary notices use Zoho China email services; notification messages do not attach original formulations or SDS files.
5. Self-managed information and required disclosures
We manage formulation preparation, business storage, archiving and backups ourselves. We do not sell original formulations or provide customer materials to other customers. Website access and traffic pass through Cloudflare. Necessary account verification, security, request and delivery notices are sent through Zoho China SMTP. Related messages may contain a name, recipient address, code or reset link, request number, company or product name and status; complete formulations and attachments are not sent by email. These external channels do not prepare formulations or host the original materials.
We deliver the agreed SDS files to you. When you provide a completed file to prospective customers, buyers, importers or other business recipients, you should manage its recipients and use. Distribution of a completed file does not grant recipients access to the original materials you submitted to this platform.
Where the law requires disclosure to a competent authority, we check the basis and limit the information to what is necessary. Such legal obligations do not provide general permission to outsource routine preparation or custody of customer materials.
If external services or their processing scope change in the future, we will update the relevant information and meet applicable notice, authorisation and other requirements before the change. Acceptance of these terms does not authorise unspecified future external processing.
6. Processing locations and international transfers
The main processing locations for the service are: Shenzhen, China. This includes self-managed website records, preparation devices and backups. Cross-border access, document delivery and other applicable international activities are addressed below; self-managed custody does not itself mean that every data activity takes place within one country.
Authorised staff process information through this service; any cross-border arrangement is reviewed for the request.
Where processing constitutes an international transfer under applicable law, we meet the relevant information, safeguard and, where required, separate-consent conditions before the transfer. Accepting service terms, choosing an SDS destination, using an English interface or manually uploading information does not by itself satisfy those conditions.
7. Retention and end-of-retention handling
Retention is determined by the category, service purpose and applicable law. When information expires or is no longer needed, we delete it, anonymise it or restrict retention where legally permitted. The need for traceable contract records does not justify keeping every contact detail or temporary file indefinitely.
| Category | Details |
|---|---|
| Unsubmitted drafts | Unsubmitted drafts are retained for 180 days after their last edit, then scheduled for deletion. Attachments still used by another request are not deleted with the draft. |
| Account and contact information | Necessary information is retained while the account service is provided. Valid closure or deletion requests are handled under this notice. Legal records and necessary technical archives follow their separate rules. |
| Formal technical archive | Each delivered PDF and the necessary supporting information and preparation record are retained under the archive arrangement for 10 years from that delivery; unnecessary personal contact data is minimised separately. |
| Ordinary backups | Isolated backups are overwritten on the implemented rolling cycle of no more than 90 days, except specifically justified records under a valid legal hold. |
| Payment and tax records | Necessary payment and order records are retained according to the applicable tax, accounting and transaction-record requirements. The verified record schedule specifies the period or determining criteria. Authorised staff periodically review the applicable retention requirements for this category. |
| Security records | Necessary security records are retained for service protection and applicable cybersecurity duties, with the period or criteria stated in the verified schedule. Authorised staff periodically review the applicable retention requirements for this category. |
| Terms and rights-request records | We retain the minimum records needed to demonstrate notices, agreements and handling of requests, using applicable record duties, claim periods and necessity reviews to determine retention. Authorised staff periodically review the applicable retention requirements for this category. |
For unfinished requests, legally required records or a specifically justified legal hold, we retain only what is necessary and restrict unrelated use. We review the record when the justification ends; the possibility of a future dispute is not a basis for unlimited retention of everything.
After deletion from the live system, isolated backups are overwritten on the actual published cycle. They are not used for ordinary business, and effective deletion or restriction decisions are reapplied after restoration. Closing an account does not automatically erase an SDS lawfully received by another party or records that must be retained by law.
The platform’s archive service does not replace the customer’s own supply-chain record obligations. Customers should keep usable copies of documents they need to retain.
Unverified guest enquiries are normally retained for seven days. Verified enquiries not linked to a formal request are normally retained for 180 days after the last exchange. Necessary correspondence linked to a formal request follows the record-keeping arrangements applicable to that request. Verification credentials and anti-abuse counters are cleared according to their short-term purposes, subject to applicable retention requirements.
9. Your rights and how to contact us
You can edit information supported by the account interface, or use https://msds-master.com/en/privacy-request or [email protected] to request access, a copy, correction, completion, deletion, restriction, applicable portability, account closure or withdrawal of consent-based processing. A contact person without an account may also request action concerning their own information.
Describe the requested action and provide only the information needed to identify the relevant records. Do not include identity-document copies, passwords, verification codes or full formulations in the initial request. We verify identity only when reasonably necessary and avoid excessive collection. Personal-information rights do not automatically entitle someone to another business’s confidential formulations or another person’s information.
We respond promptly. Our ordinary internal handling target is 30 calendar days; a shorter applicable legal deadline takes priority. If a complex request needs an extension or cannot be met, we explain the reasons and available remedies within the required period, rather than restarting the clock by requiring a new submission.
We ordinarily do not charge for rights requests. A reasonable fee or refusal is used only where applicable law allows it and its conditions are met. Withdrawing consent does not affect prior lawful processing. Withdrawal concerning information genuinely necessary for a service may affect that service; we explain the specific consequences. You may also complain to the competent supervisory authority or pursue other available legal remedies.
10. Children and unrelated sensitive information
The service is not directed at children and does not request health, identity or financial-account information unrelated to aerosol SDS preparation. If irrelevant information is uploaded by mistake, contact [email protected] so that we can restrict processing and arrange appropriate handling.
Where information is legally classified as sensitive personal information, including it in an attachment does not bypass applicable necessity, information and authorisation requirements.
11. Marketing, automated decisions and changes of purpose
Service messages concern verification, request handling, additional information and delivery; they are not a marketing subscription. Creating an account does not automatically opt you into marketing. Any future optional marketing requires a separate choice and a convenient way to stop it.
The service does not make solely automated decisions producing legal or similarly significant effects on individuals. Format checks, credit calculations and status indicators do not mean that human review has been completed. Material changes of purpose or processing are explained in advance as required, and any necessary new permission is obtained.
12. Updates to this notice
This notice takes effect on 2026-10-01. The website shows the current text; older text remains in internal records and is available after sign-in to customers with a corresponding legal record. Material changes are explained through appropriate account notices or contact channels; reading an update is not consent to every new use.
This notice does not retroactively change agreed service prices or refund conditions. Where renewed consent is required for a processing activity, we obtain it separately.
13. Additional information for applicable EEA and other regimes
Additional information is provided here according to the actual processing and the territorial scope of applicable law. Selecting an “EU SDS” for a product does not by itself determine which privacy laws apply to the account. Conversely, being outside the EU does not automatically exclude obligations that may apply.
When applicable, the following EEA supplement and verified entity or representative information form part of this notice. Absence of a displayed optional module does not contractually exclude rights that apply by law.
EEA supplement: lawful grounds and contacts
Where the GDPR applies to this processing, we use the following verified grounds for the specific purposes:
| Category | Details |
|---|---|
| Service performance | Processing the information needed for accounts, requests and delivery. |
Necessary account and service processing may rely on contract where you personally are a party to it. A person acting for a company is not automatically a personal party to that company’s contract. Where legitimate interests are used for business contact, proportionate security or corrections, we assess necessity and the individual’s rights. Legally required records rely on applicable obligations; optional uses rely on withdrawable consent where appropriate.
Where an EEA representative or data protection officer is legally required and has been designated, their details are shown in the corresponding contact block. We do not invent contacts where no such designation exists.
EEA supplement: rights and response time
Where the relevant conditions are met, you have rights of access, rectification, erasure, restriction, objection and data portability. You may object to processing based on legitimate interests as provided by law, and to any direct marketing at any time. Consent-based processing can be withdrawn. You may complain to the relevant authority in your habitual residence, place of work or the location of an alleged infringement.
We handle requests without undue delay and ordinarily respond within one month of receipt. Where the conditions for complex or numerous requests are met, this may be extended by up to two further months, with reasons given within the first month. An internal “30-day” target does not replace the one-month statutory period or provide an automatic extension.
EEA supplement: indirectly obtained data and transfers
Where an applicant business or its authorised representative provides your necessary business contact information, we provide the required information about its source, categories and purposes. Indirect-collection notices are given within the applicable time or at first contact/disclosure where required, unless a lawful exception applies and its basis is recorded.
For personal-data transfers outside the EEA, we use an applicable adequacy decision or other valid safeguard appropriate to the actual transfer. Receiving locations, mechanisms and how to obtain information about the safeguards are set out in “Processing locations and international transfers”. An agreement or mechanism that has not been implemented is not described as effective.