← Back to the checker

Privacy Policy

Last updated 24 September 2026

FindSuppliersIndia helps buyers find out whether a product can be sourced from India. This policy explains what information we collect when you use the site, why we collect it, who we share it with, and the choices you have. It is written to meet the EU and UK General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act).

Who we are

FindSuppliersIndia is operated by [COMPANY LEGAL NAME], [REGISTERED ADDRESS] ("we", "us"). We are the data controller (a "Data Fiduciary" under the DPDP Act) for the personal data described here. You can reach us about privacy at [[email protected]].

What we collect

Information you give us

When you request a report, we collect:

We don't ask for your name, phone number, company details or payment information, and you don't need an account. Please don't include personal information about yourself or anyone else in the product or requirements fields.

Information collected automatically

How we use it

PurposeData usedLegal basis (GDPR)
Draft your RFQ and prepare your feasibility report Product description, requirements, volume, destination country Taking steps at your request (Art. 6(1)(b))
Email you the report and any follow-up about that request Email address, report reference Taking steps at your request (Art. 6(1)(b))
Pre-fill your importing country IP address Legitimate interests: a faster form (Art. 6(1)(f))
Prevent spam, abuse and automated submissions IP address, bot-protection signals Legitimate interests: security (Art. 6(1)(f))
Check report quality and improve our product coverage Product descriptions and requirements Legitimate interests: service quality (Art. 6(1)(f))

Under the DPDP Act, we process your data for the purpose you gave it to us (getting your report), and you can withdraw consent at any time as described below.

We don't sell your personal data. We don't use it for advertising. We don't add you to a marketing list.

AI and human review

We use AI services to draft your RFQ from the product name and to match your product to a customs (HS) classification. Only the product description is sent to these services. Your email address is not. Reports are built from public trade, tariff and compliance datasets. Before any report email is sent, a member of our team reviews it. Reports are estimates, not supplier quotations, and no decision with legal or similarly significant effect is made about you automatically.

Who we share it with

We share personal data only with service providers that process it on our behalf and under our instructions:

ProviderWhat they doData involved
CloudflareNetwork security, bot protection (Turnstile) and country lookupIP address, browser and device signals, request data
ResendSending emailsEmail address, report contents
OpenRouter and the AI model provider it routes toDrafting RFQ textProduct description
TypeSafeProduct classificationProduct description
[DATABASE PROVIDER]Database hostingAll request data above
[HOSTING PROVIDER]Website and server hostingServer logs
Google FontsServing the site's typefacesIP address, browser details

We do not share your email address or requirements with manufacturers or suppliers. We may also disclose data if the law requires it, or to protect our rights, users or the public.

International transfers

Some of these providers process data outside your country, including in the United States and India. Where GDPR applies, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses to protect these transfers. [CONFIRM WITH EACH PROVIDER'S DATA PROCESSING AGREEMENT]

How long we keep it

We delete your data sooner if you ask us to (see below).

Your rights

Depending on where you live, you have the right to:

To use any of these rights, email [[email protected]] from the address you used and include your report reference if you have it. We'll respond within 30 days.

You can also complain to a regulator. In the EU, that's your local data protection authority. In the UK, it's the Information Commissioner's Office. In India, it's the Data Protection Board of India. We'd appreciate the chance to resolve your concern first.

Cookies

We don't use cookies for analytics or advertising, and we don't run tracking scripts. Cloudflare Turnstile may use strictly necessary technologies to tell people and bots apart. Those are needed to accept your request, so they don't require consent.

Children

This service is for businesses. It isn't directed at anyone under 18, and we don't knowingly collect data from children. If you think a child has given us personal data, contact us and we'll delete it.

Security

We protect your data with encryption in transit, access controls that limit it to staff who need it, and providers with recognised security practices. No system is completely secure. If a breach affects your personal data, we'll notify you and the relevant authorities as the law requires.

Changes to this policy

If we change this policy, we'll update the date at the top. For significant changes, we'll give notice on this page before they take effect.

Contact and grievance officer

For privacy questions, requests or complaints, including as our Grievance Officer under Indian law, contact:
[NAME / ROLE]
[COMPANY LEGAL NAME], [REGISTERED ADDRESS]
[[email protected]]