Data Protection & GDPR Notice
1. Scope
This Notice supplements our Privacy Policy and sets out our commitments under the EU General Data Protection Regulation (GDPR), the UK GDPR & Data Protection Act 2018, India's Digital Personal Data Protection Act 2023 (DPDPA), and equivalent laws worldwide. Where any of these regulations impose a stricter standard than our Privacy Policy, the stricter standard applies.
2. Roles
For personal data collected through fortunesourcings.com, RFQs, sourcing engagements, and our client / vendor portals, Fortune Imports and Exports (India) acts as the data controller. Where we process personal data on behalf of a client (for example, personal data embedded in a client-supplied BOQ), we act as the client's processor subject to a written data-processing addendum.
3. Legal bases (Article 6 GDPR)
We rely on the following lawful bases: (a) contract — to service RFQs, quotations and sourcing engagements; (b) consent — for marketing communications, non-essential cookies and gated-content downloads; (c) legitimate interest — for security, fraud prevention, aggregated analytics; (d) legal obligation — for tax records, export documentation and sanctions screening.
4. Data subject rights
Subject to applicable law you have the right to: access, rectify, erase, restrict, or port your personal data; object to processing; withdraw consent at any time; and lodge a complaint with your local supervisory authority. Requests can be sent to privacy@fortunesourcings.com and are answered within 30 days, extendable by 60 days for complex requests with notice.
5. International transfers
We may transfer personal data outside the EEA / UK to India (our head office) and China (our on-ground operating team). Such transfers are made subject to the Standard Contractual Clauses adopted by the European Commission (or the UK IDTA where applicable), and, where required, supplementary technical and organisational measures including encryption at rest and in transit, access-controlled endpoints and audit logging.
6. Retention
RFQ and project records are kept for up to seven years to satisfy Indian export-documentation and tax requirements. Marketing data is retained until consent is withdrawn. Cookie preferences are retained for 13 months. Session logs are retained for 12 months for security purposes.
7. Security
We maintain a documented information-security programme aligned with ISO 27001 principles: role-based access, session auditing, 2FA on the Fortune OS portal, TLS 1.2+ on every endpoint, encrypted database at rest, regular vulnerability scanning, and a documented incident-response plan (breach notification within 72 hours where required by law).
8. Data Protection Officer
Our Data Protection Officer can be reached at privacy@fortunesourcings.com. For EU representative requests, please write to the same address and we will designate a representative under Article 27 GDPR upon request.
