Compliance Center
Last updated · 2026-09-22
The standard of legality
Whether continuous collection of public data is lawful does not depend on the act of collection itself, but on three things: the public nature of the data, the nature of the means, and the legitimacy of the use. Our entire system was built to those boundaries — everything on this page describes what the system actually does.
Data sourcing principles
- Public data only. Nothing behind a login, a paywall, or a CAPTCHA ever enters the collection scope.
- robots.txt respected. Search engines serve as query entries only; every content site is governed by its own robots.txt.
- A restrained technical posture. Requests to the same domain are spaced 1.2–2.8 seconds at random — we place no burden on any target system.
- No circumvention, ever. No CAPTCHA solving, no identity spoofing, no confrontation with anti-bot mechanisms. A refusal signal means we stop.
- A complete evidence chain. Every record carries its source URL and an excerpt of the original page text, re-verifiable at any time.
- Personal data boundaries honored. The system processes publicly listed business contact information only; inadvertently collected non-essential personal data is deleted or anonymized promptly, per Article 24 of China's Network Data Security Management Regulation.
- Opt-out takes effect immediately. Every email carries a one-click unsubscribe; unsubscribers are never contacted again, with the disposition fully logged.
- No data of unknown origin. We never buy, trade, or use lists that cannot be traced to their source.
Jurisdictional framework
| Jurisdiction | Key laws & cases | Our practice |
|---|---|---|
| China | Cybersecurity Law Art. 27; Data Security Law; PIPL; Network Data Security Management Regulation (in force 2025) Arts. 18 & 24; Anti-Unfair Competition Law. robots.txt is self-regulatory, but breach can evidence fault or unfair competition. | Public pages only; robots honored per site; per-domain rate limiting; a full evidence trail; non-essential personal data deleted or anonymized. |
| United States | CFAA: hiQ Labs v. LinkedIn (9th Cir. 2022) — scraping publicly accessible pages is not unauthorized access; Van Buren v. United States (SCOTUS 2021) narrowed its scope; Facebook v. Power Ventures — circumventing technical blocks after a stop notice is unlawful. Feist: facts are not copyrightable. Commercial email is governed by CAN-SPAM. | No login wall or technical barrier is ever bypassed; publicly listed business contact information only; every email carries a physical address, a working unsubscribe, and truthful sender and subject information. |
| European Union | GDPR: public visibility does not exempt processing; B2B role addresses typically rely on legitimate interest (Art. 6(1)(f)) with a documented assessment. The ePrivacy Directive governs electronic communications; the Database Directive (96/9/EC) restricts substantial extraction. | EU outreach prioritizes business role addresses, with an option to skip free personal mailboxes; no whole-database reproduction or redistribution; a data subject rights channel is provided. |
| United Kingdom | UK GDPR and PECR: B2B role addresses permitted under legitimate interest; personal and generic (info@) addresses require consent. | Same posture as the EU; opt-out honored immediately. |
| Canada | CASL: consent required in principle; a conspicuously published business address relevant to the recipient's role is an exception. PIPEDA governs personal information. | Outreach only to published role addresses; unsubscribe in every email; the suppression list is append-only. |
| Japan | APPI; the Act on Regulation of Electronic Solicitation requires commercial email to be identified as an advertisement with the sender disclosed. | Messages to .jp domains are automatically prefixed with 【広告】, with sender identification in the header. |
| Australia | Spam Act 2003: a published business address constitutes inferred consent; unsubscribe must be honored within five business days. | Opt-out takes effect immediately — ahead of the statutory window. |
Outreach principles
- One-to-one communication. Every message is written for a specific customer; unsolicited identical mass mailings are unlawful in most jurisdictions.
- Three essentials in every email: a physical address (CAN-SPAM), a one-click unsubscribe (RFC 8058), and truthful sender and subject information.
- One recipient, one email; a daily cap applies and widens gradually with domain reputation.
- Opt-out is permanent. The suppression list is checked before every send; no pipeline can bypass it.
- Free personal mailboxes can be skipped entirely, avoiding the higher-risk category of personal-address marketing in the EU.
- .jp domains are auto-labeled as advertisements in the subject line.
Your rights
Every email footer carries an unsubscribe link that takes effect immediately. To inquire, correct or delete data relating to you, write to ir@craneecho.com — we will verify and act within 15 business days. Under PIPL and, where applicable, GDPR, you have the right to access, correct or delete such data.
This page is a general summary based on public legal texts, regulatory guidance and court decisions, provided for reference only. It does not constitute legal advice. Applicability varies by case and jurisdiction; consult a qualified lawyer for specific matters. Cases cited are public judicial records whose precedential force is limited to their respective courts.