Privacy policy

What SpecSourcing collects, why, how long it is kept, and the rights you have over your data under GDPR and PIPL.

This policy is written in plain language. It covers the public site and the intake form. The CMS backend (used only by our editors) is covered in the cookie note below.

Privacy policy

Who is responsible

The data controller is SpecSourcing. For any privacy question, write to [email protected]. If you are in the EU and unsatisfied with our response, you may also lodge a complaint with your local supervisory authority.

What we collect

When you submit the intake form we receive the fields you fill in: your name, company, email, country, the equipment or specification you describe, and any message you add. We also record the submitter IP address (for abuse control) and the time of submission. We do not ask for, and you should not send, national ID numbers, bank credentials, or payment-card data through the form.

Why we collect it

To reply to your enquiry, to scope and deliver the advisory work you request, and to meet our legal and export-control obligations. We do not build advertising profiles and we do not sell or share your data with third parties for marketing.

Legal basis

Where GDPR applies: we process enquiry data on the basis of taking steps at your request before a contract (Art. 6(1)(b)) and our legitimate interest in responding to and securing legitimate business enquiries (Art. 6(1)(f)). Where PIPL applies to individuals in mainland China, we rely on your consent for enquiry handling and on necessity for providing the requested service.

How long we keep it

Intake submissions are retained for 36 months from the last contact, then deleted or anonymised. If an engagement proceeds, the related correspondence is kept for the duration of the engagement plus the statutory limitation period. Marketing emails, where you have subscribed, are kept until you unsubscribe.

Your rights

You may request access to, correction of, deletion of, or a portable copy of your data, and you may object to or restrict processing. To exercise any of these, email [email protected]. We respond within 30 days. You may withdraw consent at any time without affecting prior lawful processing.

Cross-border transfer

Enquiry data submitted from outside China may be accessed by our team for the purpose of responding to you. Where GDPR applies and data is transferred out of the EEA, we put in place Standard Contractual Clauses (SCCs) and a Data Processing Agreement (DPA) with any processor involved.

Sub-processors

We use a small number of processors strictly necessary to run the site and deliver replies: the static-site host, the form-handler that writes submissions to our own storage, and our email provider. None are permitted to use your data for their own purposes.

Cookies

The public marketing site sets no tracking or advertising cookies and uses no third-party analytics. The CMS backend (a restricted path used only by our editors, sets a session cookie required to keep an editor logged in. You can use the entire public site without any cookie.

Security contact

To report a vulnerability, use the security contact published at /.well-known/security.txt. Please do not include confidential client data in a vulnerability report.

Last updated: 2026-07-26.

Independent · No kickbacks · Files that audit

Not sure which engagement fits your risk stage?

Submit one supplier and get a free go / hold / walk read, no commitment, no sales call.

Written quote within 24 hours