Privacy & personal data
A clear data boundary for commercial inquiries.
This notice explains how Supply Turk handles information submitted through the export quotation form, related B2B communication, optional website analytics and the separate newsletter preference form. An RFQ never subscribes you to marketing; newsletter email starts only after a separate choice and email confirmation.
Effective date: 30 August 2026
24 months
Inquiry data after the last substantive activity
24 months
Private RFQ attachments after the last substantive activity
3 hours
Uploads abandoned before a form is submitted
7 days
Unconfirmed newsletter requests
Session / 180 days
Local analytics attribution, depending on your choice
1. Controller and contact
Supply Turk is responsible for the personal data submitted through this website's RFQ channel. Privacy, access, correction or deletion requests can be sent to contact@supplyturk.com.
2. Data we handle
- Company and business-contact details: company name, contact name, work email, phone, country and city.
- Inquiry content: product or machinery category, technical and commercial requirements, destination, quantities and requested delivery period.
- Files you choose to attach, such as specifications, drawings, product briefs or packing information.
- Limited security and attribution data: site language, source path, campaign parameters and a one-way protected request identifier derived from network information for abuse prevention.
- Newsletter data, only when submitted separately: email address, Industrial / Food / Both preference, language, consent version and confirmation or withdrawal timestamps.
- Optional analytics data, only for allowlisted events: page type, language, vertical, query-free target path, controlled CTA/content/tool/video/campaign/derivative/partner/field/error identifiers, source class, progress/completeness/time/value/error buckets, boolean recoverability, Web Vital name/value/rating/navigation type and a random anonymous session identifier.
- Analytics does not include RFQ or newsletter field values, names, email addresses, phone numbers, company details, free text, filenames, signed file URLs, raw referrer URLs or search-query strings.
3. Why we use it
Depending on the applicable law, processing is based on steps requested before a contract, legitimate interests in operating a secure B2B inquiry process, legal obligations, or consent where the law specifically requires it.
- To review and respond to the quotation request, clarify requirements and take requested steps before a possible B2B contract.
- To coordinate only the relevant details with suitable producers, suppliers, logistics or professional-service providers when necessary for the inquiry.
- To protect the form and systems against spam, duplicate submissions, malicious files and misuse.
- To keep limited records for commercial follow-up, dispute handling and compliance where a legitimate business or legal need applies.
- To send the selected editorial brief after double confirmation and to record, apply and evidence subscription preferences or withdrawal.
- When you allow optional analytics, to understand which public pages, resources, tools, videos and quotation steps are useful and where the experience needs improvement.
5. Retention and deletion
Updating an active inquiry's recorded last-activity date renews its retention deadline. This prevents younger active inquiries from being removed while allowing inactive lead data to expire.
- Inquiry records and contact data are kept for up to 24 months after the last substantive commercial activity, then deleted unless a documented legal, contractual or dispute-related hold applies.
- Private attachments are automatically released from the inquiry and permanently deleted after 24 months from the last substantive activity.
- A file uploaded but never attached to a submitted inquiry is treated as abandoned and is deleted after at least 3 hours.
- An unconfirmed newsletter request expires after 24 hours and its pending record is deleted after 7 days.
- A withdrawn newsletter record and its consent evidence are retained for up to 36 months for suppression, complaint handling and consent accountability, then deleted unless law requires longer retention.
- Analytics lineage in session storage lasts for the browser-tab session. With analytics consent, the same controlled attribution lineage may be kept in local storage for no more than 180 days since the last visit and is then purged and reset; at most 12 touchpoints and 12 controlled content identifiers are retained. The analytics consent choice remains until you change it.
- A documented retention hold must state its reason and review date and is reviewed at least every 6 months. When the hold ends, the normal expiry rules resume.
6. Security
RFQ attachments are stored in a private bucket. Public file URLs are not used; internal access should use short-lived signed links. File type, size and upload-session checks are applied, but you should still avoid sending unnecessary personal, financial, identity or special-category data.
7. Your choices and rights
Depending on the law that applies to you, you may request access, correction, deletion, restriction, portability or objection, and may complain to the competent data-protection authority. Where processing relies on consent, you may withdraw it for future processing. We may need to verify your identity and may retain limited information when a legal exception applies.
Send a request to contact@supplyturk.com and identify the company, contact email and inquiry concerned. We will respond under the applicable legal timeframe.
8. Optional analytics and local storage
Analytics starts as off: Google Tag Manager is not loaded while the choice is unknown or declined. You can use the fixed Analytics settings control to allow or decline it. Session-only attribution may classify a visit as direct, search, AI assistant, social, email, paid, partner or referral without keeping the raw referrer or URL query. Cross-session attribution is written to local storage only after consent and expires after at most 180 days.
If you withdraw a previous analytics choice, the site sends a denied consent update, removes persisted attribution and reloads without loading Google Tag Manager. Future allowlisted events are not put on the external analytics data layer while consent is declined. Any Google Analytics retention setting and deletion process must also be configured in the connected property before production measurement is enabled.
10. Changes to this notice
Material changes will be published on this page with a revised effective date. The notice that applies when an inquiry is submitted remains available through the dated repository or deployment record.