Legal
Privacy Notice
Fortiv Solutions Pvt Ltd
How Fortiv Solutions collects, uses, shares and protects personal data — for visitors to this site, for enquirers, and for personal data processed on behalf of enterprise clients.
TODO: legal copy required
This page is a structural scaffold. The headings below are the sections a notice must cover to satisfy the Digital Personal Data Protection Act 2023 and, for EU-resident data subjects, the GDPR. The operative text has not been written and must be drafted or approved by counsel before this page is treated as a published notice.
Until then, direct any data-protection request to info@fortivsolutions.in, which is monitored by a person.
- 01
Who we are and how to reach us
Placeholder — brief for counsel
Registered entity name, CIN, registered office address, and the contact point for data-protection queries. DPDP s.5 requires a named Data Protection Officer or equivalent contact; GDPR Art.13(1)(a)-(b) requires controller identity and, where one is appointed, DPO details.
- 02
What personal data we collect
Placeholder — brief for counsel
Enumerate every collection point that actually exists on the site: the /contact enquiry form, the footer briefing subscription, the /assessment questionnaire, the /free-roadmap and /roadmap tools, and the Cal.com booking embed on /book-consultation. State the fields each one captures. Do not describe collection the site does not perform.
- 03
Why we process it, and on what lawful basis
Placeholder — brief for counsel
Purpose-by-purpose mapping. GDPR Art.6 requires a lawful basis per purpose — legitimate interest for responding to a business enquiry is defensible; marketing email requires consent. DPDP is consent-led with a narrower set of legitimate uses, so the consent record for each purpose needs to be described.
- 04
Third parties and processors
Placeholder — brief for counsel
Every service that receives personal data, named. This needs an actual audit rather than a guess — the enquiry and subscription forms post to an external endpoint, /book-consultation embeds Cal.com, and hosting, analytics and email delivery each involve a processor. Each needs its role, location and the transfer mechanism if it sits outside India or the EEA.
- 05
International transfers
Placeholder — brief for counsel
The site advertises service in IN, US, AE, GB and SG. For EU-resident data subjects, name the GDPR Chapter V mechanism relied on — Standard Contractual Clauses, adequacy decision, or otherwise — and where the SCCs sit.
- 06
How long we keep it
Placeholder — brief for counsel
A retention period or a criterion for determining one, per data category. Required by GDPR Art.13(2)(a) and by DPDP's erasure obligation, which requires deletion once the purpose is served and consent is withdrawn.
- 07
Your rights
Placeholder — brief for counsel
DPDP s.11-14: access, correction, erasure, grievance redressal, and nomination. GDPR Art.15-22: access, rectification, erasure, restriction, portability, objection, and rights around automated decision-making. State the mechanism and the response time for each, plus the supervisory authority a complaint can go to.
- 08
Withdrawing consent
Placeholder — brief for counsel
DPDP s.6(4)-(6) requires withdrawal to be as easy as giving consent, and requires the consequences of withdrawal to be stated. Describe the actual mechanism, including unsubscribe for the briefing list.
- 09
Cookies and similar technologies
Placeholder — brief for counsel
Audit what the site actually sets before writing this. It uses next/font (self-hosted, no Google request at runtime) and no analytics script is present in the repo at time of writing — so this section may be genuinely short. Verify against the deployed site, including anything added by hosting, before finalising.
- 10
Security of processing
Placeholder — brief for counsel
Summarise controls and cross-reference /security rather than restating it. Include the breach-notification commitment: DPDP requires notification to the Data Protection Board and to affected principals; GDPR Art.33 sets a 72-hour supervisory-authority deadline.
- 11
Children's data
Placeholder — brief for counsel
DPDP s.9 sets a verifiable-parental-consent requirement for under-18s and prohibits tracking and targeted advertising directed at children. State the position — for a B2B enterprise site the honest answer is likely that the service is not directed at children and such data is not knowingly collected.
- 12
Changes to this notice
Placeholder — brief for counsel
How changes are communicated and from when they take effect. Add a 'last updated' date to the page when copy lands.
Fortiv Solutions Pvt Ltd is a private limited company registered in India. Security architecture and governance controls are documented separately on the security and governance page — that page describes how systems are built, and is not a substitute for this notice.

