SOURCESQUID®
EN
Start a brief
Legal · privacy

Privacy notice.

This notice explains how Sourcesquid Global Private Limited collects, uses, discloses and protects personal data. It applies to visitors and clients in India, the European Union, the United Kingdom and the United States.

SummaryEffective 28 September 2026
Controller
Sourcesquid Global Private Limited, India
Grievance Officer
Anirudh Raghavan Murali · [email protected]
Frameworks
DPDP Act 2023 · GDPR · UK GDPR · US state law
Analytics
Cookieless, aggregated
Sale of data
None
Advertising
No advertising or tracking cookies

01Scope of this notice

1.1 This notice describes how Sourcesquid Global Private Limited (“SourceSquid”, “we”, “us” or “our”) collects, uses, discloses, retains and protects personal data in connection with the website at sourcesquid.co (the “Website”), the free tools and the free sourcing teardown offered on it, and the sourcing, quality inspection and compliance services we provide (the “Services”).

1.2 It applies to visitors to the Website, to persons who submit a brief, an enquiry or an application, to subscribers to our communications, and to the representatives of our clients, suppliers and partners.

1.3 This notice is intended to satisfy our transparency obligations under the Digital Personal Data Protection Act, 2023 of India (the “DPDP Act”), the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the “GDPR”), the GDPR as retained in the law of the United Kingdom together with the Data Protection Act 2018 (the “UK GDPR”), and applicable privacy laws of the United States. Where a provision of this notice refers to a particular law, it applies only to processing governed by that law.

1.4 Where we process personal data on behalf of a client in the course of an engagement, the written agreement with that client governs that processing and prevails over this notice to the extent of any inconsistency.

02Controller and contact details

2.1 Sourcesquid Global Private Limited, a company incorporated in India, is the data controller and, for the purposes of the DPDP Act, the Data Fiduciary responsible for the personal data described in this notice. We operate from Bengaluru, India, and maintain an office in Ningbo, China.

2.2 Our registered office is in Bengaluru, Karnataka, India. Our corporate identity number (CIN) is U74999KA2019PTC124693.

2.3 In accordance with the DPDP Act, we have designated a Grievance Officer, who is also our contact for all data protection matters: Anirudh Raghavan Murali, Founder and Director, [email protected]. The Grievance Officer shall acknowledge and respond to each grievance within the period prescribed under the DPDP Act and the rules made under it.

2.4 Data subjects in the European Economic Area and the United Kingdom may address any question, request or complaint concerning the processing of their personal data, including a request to exercise their rights under the GDPR or the UK GDPR, directly to us at [email protected]. Such requests are handled in accordance with Section 10.

03Personal data we collect

3.1 We collect the following categories of personal data, principally from you directly:

Briefs and enquiries
Name, company, work email address, WhatsApp or telephone number (optional), product description, volumes, target prices, markets, services of interest, and any drawing, photograph or quotation you attach.
Tool results sent by email
Email address, company (optional), and the inputs and results of the tool you ask us to send. The tools otherwise run in your browser and do not transmit your inputs to us.
Newsletter and early access
Email address, name and company where provided, and your stated preferences, when you subscribe to our monthly brief or to alerts through our early-access list.
Partner applications
Name, company, work email address, website, audience, markets and your description of the proposed collaboration.
Files shared under NDA
Drawings, specifications, supplier information and commercial terms you share in the course of an engagement. These may contain limited personal data, such as names and contact details of your staff or of supplier personnel.
Engagement records
Correspondence, contracts, invoices and payment records; and audit and inspection records, which may include names and job titles of supplier contacts and incidental images of persons in photographs taken at production sites.
Website analytics
Aggregated information on pages viewed, referring website, browser and device type and approximate country, collected through Cloudflare Web Analytics, which as used on the Website does not place cookies on your device.
Technical and security data
IP address, request headers and time of access, processed by our hosting provider to deliver the Website and protect it against abuse.

3.2 We may also receive business contact details from a partner who refers you to us, from your colleagues, or from public business sources such as company websites and trade fair directories.

3.3 We do not request, and ask you not to provide, sensitive personal data or special categories of personal data. Where you provide personal data of another person, you confirm that you are entitled to do so.

04Purposes and lawful bases of processing

4.1 We process personal data only for the purposes set out below. For processing governed by the GDPR or the UK GDPR, the table states the lawful basis under Article 6(1).

PurposeLawful basis (GDPR and UK GDPR)
Responding to briefs and enquiries and preparing the free teardownArt. 6(1)(b), steps taken at your request before entering into a contract; Art. 6(1)(f), legitimate interests, where you act for an organisation
Performing the Services, including supplier search, audits, inspections and compliance workArt. 6(1)(b), performance of a contract; Art. 6(1)(f), legitimate interests, for personnel of clients and suppliers
Sending a tool result you requestArt. 6(1)(b), provision of the service you request
Sending the monthly brief, alerts and early-access invitationsArt. 6(1)(a), consent, which you may withdraw at any time
A single follow-up to a business contact after a teardown or tool requestArt. 6(1)(f), legitimate interests in developing our business, subject to your right to object and to applicable electronic marketing law
Assessing partner applications and administering partner arrangementsArt. 6(1)(b), steps before and performance of a contract; Art. 6(1)(f), legitimate interests
Measuring Website use in aggregate and keeping the Website secureArt. 6(1)(f), legitimate interests in operating a secure and useful website
Accounting, tax, corporate records and responses to lawful requestsArt. 6(1)(c), compliance with a legal obligation
Establishing, exercising or defending legal claimsArt. 6(1)(f), legitimate interests

4.2 Where we rely on legitimate interests, we have assessed that those interests are not overridden by your interests or fundamental rights and freedoms. You may request details of that assessment.

4.3 We do not sell personal data, share it for cross-context behavioural advertising, or use it for targeted advertising or profiling. We do not make decisions producing legal or similarly significant effects based solely on automated processing.

05Processing under the DPDP Act (India)

5.1 For processing governed by the DPDP Act and the rules made under it, to the extent in force, we process digital personal data on one of the following grounds:

  • Consent (Section 6), given by a clear affirmative action, such as submitting a form or subscribing to our communications, for the purpose stated at the point of collection and in this notice; or
  • Certain legitimate uses (Section 7), including where you have voluntarily provided personal data for a specified purpose and have not indicated that you do not consent to its use, and where processing is necessary to comply with law.

5.2 Where processing is based on consent, you may withdraw consent at any time, with the same ease with which it was given, by writing to [email protected] or using the unsubscribe link in any communication. Withdrawal does not affect the lawfulness of processing carried out before it.

5.3 As a Data Principal, you have the right to obtain a summary of the personal data we process and the processing activities undertaken (Section 11); to correction, completion, updating and erasure of your personal data (Section 12); to readily available means of grievance redressal (Section 13); and to nominate another individual to exercise your rights in the event of death or incapacity (Section 14).

5.4 Grievances should first be addressed to our Grievance Officer identified in Section 2.3. If your grievance is not resolved, you may approach the Data Protection Board of India in accordance with the DPDP Act.

5.5 To the extent applicable, we also comply with the Information Technology Act, 2000 and the rules made under it.

06Recipients and processors

6.1 We disclose personal data only to the extent necessary for the purposes described in Section 4, to the following categories of recipient:

  • Service providers acting as processors under written terms, including Zoho (email and customer relationship management) and Cloudflare (Website hosting, content delivery, security, form handling and cookieless analytics).
  • Manufacturers, partner inspectors and accredited laboratories engaged for your project. We share drawings and specifications only with shortlisted manufacturers that have signed a non-disclosure agreement with us, and only to the extent necessary.
  • Referring partners. Where a partner referred you to us, we inform that partner that you have engaged with us and of the general status of the engagement. We do not disclose your files or commercial terms to the partner without your agreement.
  • Professional advisers, such as lawyers, accountants and auditors, bound by duties of confidentiality.
  • Public authorities, courts and regulators, where disclosure is required by law or necessary to establish, exercise or defend legal claims.
  • A successor entity, in connection with a reorganisation, merger or transfer of all or part of our business, subject to equivalent protection.

6.2 All typefaces used on the Website are hosted on our own servers. No third-party font service receives your IP address or any other data when a page loads.

07International transfers

7.1 We are established in India. Personal data is processed in India and, where an engagement concerns manufacturers in China, Vietnam or another supplying country, in that country to the extent necessary for the engagement. Our service providers may process personal data in other countries, including member states of the European Union and the United States.

7.2 Where the GDPR or the UK GDPR requires a transfer mechanism for personal data transferred to a country that is not subject to an adequacy decision, we rely on the standard contractual clauses approved by the European Commission and, for the United Kingdom, the International Data Transfer Addendum, or on another mechanism or derogation permitted by those laws. You may request a copy of the relevant safeguards.

7.3 Transfers of personal data from India are made in accordance with Section 16 of the DPDP Act and are not made to any country or territory to which transfer has been restricted by the Central Government.

08Retention

8.1 We retain personal data only for as long as necessary for the purpose for which it was collected, and then erase it, unless retention is required by law. In particular:

Enquiries, briefs and teardowns
Three years after our last contact with you.
Tool results sent by email
Twelve months after the result is sent.
Newsletter, alerts and early access
Until you unsubscribe or withdraw consent. We then keep only your email address on a suppression list, to honour your choice.
Partner applications
Up to 24 months after the application, or, for appointed partners, for the term of the arrangement and the applicable limitation period.
Files shared under NDA
For the duration of the engagement. Thereafter returned or erased in accordance with the non-disclosure agreement or on your request, save for copies we are required by law to keep.
Non-disclosure agreements, contracts and accounting records
Eight years, as required under Indian law, including for books of account, invoices and related records.
Security logs
For the period set by our hosting provider for the delivery and protection of the Website.

09Security

9.1 We implement reasonable technical and organisational security measures appropriate to the nature of the personal data, including encryption in transit, access restricted to personnel who require it, multi-factor authentication on business accounts, confidentiality obligations on our personnel, and non-disclosure agreements with manufacturers and partner inspectors.

9.2 No method of transmission or storage is entirely secure. In the event of a personal data breach, we will notify the competent authority and affected persons where, and within the period, required by applicable law.

10Your rights and how to exercise them

10.1 European Union and United Kingdom. Subject to the conditions and exceptions of the GDPR and the UK GDPR, you have the right to access your personal data; to rectification; to erasure; to restriction of processing; to data portability; to object to processing based on legitimate interests; to object at any time to direct marketing; and to withdraw consent at any time. You also have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work or place of the alleged infringement; in the United Kingdom, the Information Commissioner’s Office.

10.2 India. Your rights as a Data Principal are set out in Section 5.

10.3 United States. Residents of US states with consumer privacy laws may have the right to know about, access, correct and delete personal data, and to opt out of its sale, sharing for targeted advertising and profiling. We do not engage in those activities. We will not discriminate against you for exercising any right.

10.4 Exercising your rights. To exercise any right, write to [email protected] with the subject “Data protection request”, stating the right you wish to exercise. We may ask for information reasonably necessary to verify your identity, or the authority of an agent acting on your behalf. We respond without undue delay and, for requests under the GDPR or the UK GDPR, within one month of receipt, which may be extended where permitted by law. Requests are handled free of charge unless they are manifestly unfounded or excessive.

11Children

11.1 The Website and the Services are intended for businesses and are not directed at persons under the age of 18. We do not knowingly process personal data of children. If we become aware that we have collected such data, we will erase it.

12Cookies and similar technologies

12.1 The Website does not use advertising or tracking cookies. Our use of strictly necessary storage and cookieless analytics is described in our Cookie notice.

14Changes to this notice

14.1 We may amend this notice from time to time. The amended notice takes effect on publication on the Website, as indicated by the effective date below. Where an amendment materially affects the processing of your personal data, we will inform you by email or by a notice on the Website before it takes effect, and seek your consent where required by law.

15Supplier applications

15.1 This section applies to manufacturers and other suppliers who apply to join the SourceSquid supplier network through the Website, and to the persons who submit an application or a self-audit on their behalf (each, a “Supplier Applicant”). It supplements Sections 3 to 10, which otherwise apply.

15.2 Data collected. We collect the name, role, email address and telephone or WhatsApp number of the contact person; company details, including legal and trading names, registration numbers (such as GSTIN, IEC or unified social credit code), year of establishment, location and website; capability and facility information, including processes, materials, products, capacity, lead times, export markets, certifications, workforce size, equipment and in-house testing; documents uploaded, such as brochures, catalogues, certificates, test reports and photographs of the premises; and the answers and evidence given in the self-audit. Supplier Applicants should not upload images in which individuals can be identified unless those individuals have been informed.

15.3 Purposes. We process this data to assess the Supplier Applicant for inclusion in our private supplier database; to verify the information given, including by an on-site audit where we invite one; to match the Supplier Applicant with enquiries from buyers; and to communicate about the application. Self-audit answers are scored to support the assessment made by our personnel; no decision producing legal or similarly significant effects is taken solely by automated means.

15.4 Lawful basis. We rely on the consent given when the application is submitted (Section 6 of the DPDP Act; Article 6(1)(a) GDPR and UK GDPR), which may be withdrawn at any time in accordance with Section 5.2, and, for the business contact details of company representatives, on our legitimate interests in establishing supplier relationships (Article 6(1)(f) GDPR and UK GDPR).

15.5 Confidentiality and disclosure. The supplier database is not a public directory, and we do not publish any information about a Supplier Applicant. We disclose information about a Supplier Applicant to a buyer only in connection with a specific enquiry matching its capabilities, and only to the extent necessary for that enquiry. Our service providers process the data as processors in accordance with Section 6.1.

15.6 Retention. We retain applications, self-audits and uploaded documents for 24 months from the application or from the Supplier Applicant’s last update, whichever is later, and then erase them, unless the Supplier Applicant becomes an approved supplier, in which case Section 8 applies for the duration of the relationship.

15.7 Rights. Supplier Applicants have the rights described in Sections 5 and 10, including the rights of access, correction and erasure. An application may be withdrawn, and its erasure requested, at any time by writing to [email protected].

15.8 No fee is charged to Supplier Applicants at any stage, and submitting an application creates no obligation for either party.

Chat on WhatsApp+91 98406 98791