Privacy
Privacy Notice
How SPANORIX F.Z.C. handles information when people visit the website or contact the business.
Who is responsible for your information
SPANORIX F.Z.C. is responsible for the website and business-enquiry processing described in this notice.
- Company
- SPANORIX F.Z.C.
- Commercial operating location
- Dubai, United Arab Emirates
- Privacy contact
- contact@spanorix.com
- EU representative
- No EU representative under GDPR Article 27 is identified in this notice.
Information we handle
- Website use: Vercel may process request and security information such as IP address, browser details, requested page, timestamp and response status to deliver and protect the website.
- Direct contact: if you email, call or use WhatsApp, we handle the contact, company and enquiry information you choose to send.
- Online buyer enquiries: when the buyer form is active, it may collect identity and work-contact details, company and buyer context, application, quantity, destination, timing, technical and document requirements, preferred contact method and your message.
- Supplier introductions: only when separately activated, the supplier form may collect business, contact, factory-location, product-capability and message information.
- Security: active forms use a submission reference, request metadata and Cloudflare Turnstile signals to validate the request and reduce misuse.
- Optional LinkedIn advertising measurement: only after Marketing permission, LinkedIn may receive tagged-visit information such as the page URL and referrer, timestamp, IP address, and device or browser information.
The website provides no file upload and sends form submissions to no application database, spreadsheet or CRM. LinkedIn enhanced matching is not enabled and buyer-form fields are not sent to LinkedIn.
Why we use information
- Optional advertising measurement
- With Marketing permission, to understand visits from LinkedIn advertising and measure campaign effectiveness. The intended basis is consent under GDPR Article 6(1)(a), where applicable. Permission can be withdrawn through Privacy choices.
- Responding to business enquiries
- To understand a buyer requirement or supplier introduction, reply, and take requested steps before a possible business relationship. Depending on the circumstances, this may rely on legitimate interests or steps requested before a contract under GDPR Article 6(1)(f) or 6(1)(b).
- Business correspondence
- To maintain relevant communications, assess options and document decisions, normally under legitimate interests.
- Security and misuse prevention
- To validate requests, prevent spam or fraud and protect the website, normally under legitimate interests.
- Legal obligations
- To meet an applicable accounting, tax, customs, regulatory or other legal duty where one applies.
We do not use the enquiry pathways for marketing, profiling or automated decision-making. “I have read the Privacy Notice” records that the notice was presented; it is not consent to unrelated processing.
Who may receive information
- Vercel hosts and delivers the website and its form functions.
- Zoho Mail provides the published SPANORIX business mailbox.
- WhatsApp/Meta processes communications when you voluntarily use WhatsApp.
- Cloudflare Turnstile processes anti-bot signals only on a form page whose corresponding form mode is active.
- Resend transmits the internal notification and your acknowledgement only for an authorised live form submission.
- LinkedIn provides optional advertising measurement after Marketing permission. LinkedIn may process tagged-visit data and set identifiers under its own terms and account settings.
- Authorised professional advisers, service providers or authorities may receive information where necessary and permitted by law.
Some providers may process information outside the European Economic Area. Applicable contracts, locations, safeguards and transfer mechanisms must be reviewed for the configured services. LinkedIn states that Insight Tag data is stored on servers in the United States; its current transfer information and safeguards require review. Using an external contact link also subjects the communication to that provider’s privacy terms.
How long we keep information
- Enquiries that do not progress should be deleted 12 months after the last meaningful contact.
- Active commercial discussions may be kept for the discussion and up to 12 months after closure unless a dispute or legal duty requires longer.
- Transaction records are kept for the period required by applicable accounting, tax, customs, contractual or other law.
- SPANORIX application logs must not contain names, contact details, messages, requirements or Turnstile tokens. Provider-side retention is governed by the applicable service settings and terms.
Your privacy rights
Where the GDPR applies, you may have rights of access, correction, deletion, restriction, objection and data portability, and the right to complain to a competent supervisory authority. The rights available depend on the processing and applicable law.
Send a privacy request to contact@spanorix.com. Please provide enough information to identify the relevant correspondence without sending unnecessary sensitive data.
Marketing permission can be changed or withdrawn at any time through.
Last updated: 10 September 2026.
Continue exploring
