Privacy Policy
How FabSetu collects, uses, shares, protects and retains personal data.
Privacy Policy
Last updated
1. Scope and roles
This policy applies when you visit FabSetu, create an account, join an organisation, use a product, communicate, transact or request support. Third-party sites and services have their own notices.
FabSetu determines processing for platform accounts, security, support and operations. Your organisation may separately control uploaded product data, while buyers and sellers may independently process data received during transactions.
2. Data we collect
We process account and contact details; organisation, membership, permission and entitlement data; business identity and verification status; public profiles and listings; and information submitted to product workflows.
Workflow data may include RFQs, BOMs, bids, NDAs, orders, invoices, payment status, shipping, messages, support, contacts, job applications and files. We also process device, browser, IP, session, security, audit and usage-event information.
3. Purposes and legal grounds
We use data to create and secure accounts; verify access; provide entitled products; operate discovery, sourcing, transactions and communications; process payments; support users; prevent abuse; keep audits; and comply with law.
Depending on applicable law, processing relies on consent, requested pre-contract steps or contract performance, legal duties, protection of systems and users, or another permitted use. Optional data may be withheld, but required data may be necessary for a feature or order.
4. Public and private information
Approved public Marketplace pages may show organisation descriptions, roles, regions, categories, websites, published products, RFQ summaries and review summaries, which search engines may index.
Membership records, identity numbers, internal contacts, private certification files, protected BOMs, bids, NDAs, attachments and confidential sourcing materials stay in authorised workflows and are not public Marketplace profile data.
5. Sharing and international processing
We share data with authorised organisation members, invited or transacting organisations, and contracted hosting, authentication, storage, communication, security, payment and support providers as needed. We may also disclose it to advisers, a corporate successor or authorities when lawfully required.
Providers or transaction participants may process data in other countries. Where required, we use appropriate contractual, organisational or legal safeguards and follow transfer restrictions.
6. Retention and security
We retain data while needed for the account, organisation or workflow and afterward for audit, security, tax, disputes, fraud prevention and legal requirements. Data is deleted, anonymised or restricted when no longer needed.
FabSetu uses organisation isolation, server-side authorisation, provider encryption, access controls and audit safeguards. No system is perfectly secure; promptly report suspected account compromise.
7. Your rights
Subject to law, you may request access to a summary, correction, completion, erasure, consent withdrawal and grievance redressal, and may nominate another person where law provides. Other jurisdictions may grant objection, restriction or portability rights.
Submit requests through FabSetu support and identify the account and organisation. We may verify identity and authority, protect others, retain legally required records and explain any limit on a request.
8. Children, changes and contact
FabSetu is intended for business users and not directed to children. Do not submit a child's data unless a supported product and all required permissions and safeguards allow it.
Material updates will show a new effective date and be communicated where required. Submit privacy questions through FabSetu support and escalate unresolved matters under the Grievance Redressal Policy.