Fortune Sourcings
Legal · Fortune Sourcings

Data Protection & GDPR Notice

Fortune Imports and Exports (India) · Last updated 1 February 2026

1. Scope

This Notice supplements our Privacy Policy and sets out our commitments under the EU General Data Protection Regulation (GDPR), the UK GDPR & Data Protection Act 2018, India's Digital Personal Data Protection Act 2023 (DPDPA), and equivalent laws worldwide. Where any of these regulations impose a stricter standard than our Privacy Policy, the stricter standard applies.

2. Roles

For personal data collected through fortunesourcings.com, RFQs, sourcing engagements, and our client / vendor portals, Fortune Imports and Exports (India) acts as the data controller. Where we process personal data on behalf of a client (for example, personal data embedded in a client-supplied BOQ), we act as the client's processor subject to a written data-processing addendum.

3. Legal bases (Article 6 GDPR)

We rely on the following lawful bases: (a) contract — to service RFQs, quotations and sourcing engagements; (b) consent — for marketing communications, non-essential cookies and gated-content downloads; (c) legitimate interest — for security, fraud prevention, aggregated analytics; (d) legal obligation — for tax records, export documentation and sanctions screening.

4. Data subject rights

Subject to applicable law you have the right to: access, rectify, erase, restrict, or port your personal data; object to processing; withdraw consent at any time; and lodge a complaint with your local supervisory authority. Requests can be sent to privacy@fortunesourcings.com and are answered within 30 days, extendable by 60 days for complex requests with notice.

5. International transfers

We may transfer personal data outside the EEA / UK to India (our head office) and China (our on-ground operating team). Such transfers are made subject to the Standard Contractual Clauses adopted by the European Commission (or the UK IDTA where applicable), and, where required, supplementary technical and organisational measures including encryption at rest and in transit, access-controlled endpoints and audit logging.

6. Retention

RFQ and project records are kept for up to seven years to satisfy Indian export-documentation and tax requirements. Marketing data is retained until consent is withdrawn. Cookie preferences are retained for 13 months. Session logs are retained for 12 months for security purposes.

7. Security

We maintain a documented information-security programme aligned with ISO 27001 principles: role-based access, session auditing, 2FA on the Fortune OS portal, TLS 1.2+ on every endpoint, encrypted database at rest, regular vulnerability scanning, and a documented incident-response plan (breach notification within 72 hours where required by law).

8. Data Protection Officer

Our Data Protection Officer can be reached at privacy@fortunesourcings.com. For EU representative requests, please write to the same address and we will designate a representative under Article 27 GDPR upon request.

Cookies & Privacy

We respect your privacy.

Fortune Sourcings uses essential cookies to run the site. With your consent, we also use analytics and marketing cookies to understand how the site is used and to make our communications more relevant. You can change your preferences at any time. Read our privacy policy and cookie policy.