Legal
Privacy Policy
How ADIT International collects, uses, shares and protects information when you use the ADIT Connect industrial sourcing platform — written around what the platform actually does.
Last updated: 20 August 2026
Draft — pending legal review
This document has been drafted specifically for the ADIT Connect platform and its current functionality. It is not yet legal advice and is not a final instrument. It must be reviewed, amended and approved by qualified UAE legal counsel before commercial launch. Sections marked [for counsel] require a decision from your lawyers.
1.Who we are and what this policy covers
ADIT International (“ADIT”, “we”) operates the ADIT Connect platform. This policy covers information we handle through the platform, its emails and its supporting services. ADIT Connect is a business-to-business platform: most of the information we hold is company information, but it necessarily includes personal data about the individuals who act for those companies.
Privacy questions and requests should be sent to projects@aditintl.com.
2.Information we collect
Account and contact information — name, job title, company name, business email address, phone or WhatsApp number, and the role assigned to your account (buyer, supplier, team member or administrator).
Company and verification information — company registration and trade licence details, tax or VAT registration number, country and address, brands, product categories and markets served, and the verification documents you or your colleagues upload.
Buyer and supplier profile information — the profile you build on the platform, including saved products, saved searches, preferences and team membership.
Transactional content — RFQs and their specifications, quantities, delivery locations, dates, Incoterms and certificate requirements; quotations, prices, lead times, landed-cost inputs and commercial conditions; awards, order and shipment tracking information; and messages exchanged between buyers and suppliers on the platform.
Uploaded files and documents — drawings, bills of quantity, datasheets, test and material certificates, price lists, product data spreadsheets, shipping documents and any other file you attach.
Technical, device and security information — IP address, browser and device information, and security events such as failed sign-in attempts and rate-limit triggers.
Login and activity records — sign-in times, session records and an audit log of significant actions taken in the platform (for example verifying a company, approving product data, changing a subscription or awarding an enquiry).
Support enquiries — the name, email, company, phone, topic, subject and message you submit through the Get help form, together with any account attribution.
Subscription and billing information — your plan, subscription status, renewal date, payment and refund history, tax-invoice data and the identifiers returned to us by our payment provider. See clause 5 regarding card details.
3.Why we use it
- Account management — creating, authenticating and administering accounts, roles and team access.
- RFQ matching — identifying and notifying the suppliers whose categories, brands and markets match an enquiry.
- Providing quotations — delivering enquiries to suppliers and returning their quotations, comparisons and landed-cost estimates to the buyer.
- Platform operation — running the specification database, search, equivalence data, orders, messaging, exports and invoices.
- Customer support — answering Get help requests and other enquiries, and investigating problems you report.
- Security — protecting accounts, detecting and blocking unauthorised access, brute-force attempts and abuse.
- Fraud prevention — checking company and document authenticity, detecting counterfeit or misattributed certificates and abusive behaviour.
- Subscription administration — checkout, activation, renewal, cancellation, refunds, disputes and tax invoicing.
- Email notifications — transactional notices such as account confirmations, matching enquiries, quotations received, award outcomes, closing-date reminders, order updates, messages and subscription receipts.
- Legal and compliance — meeting accounting, tax, record-keeping, sanctions and other legal obligations, and establishing or defending legal claims.
We rely on the performance of our contract with you, our legitimate business interests in operating and securing a B2B platform, your consent where we ask for it, and our legal obligations. We do not sell personal data, and we do not use your commercial data to broker deals behind your back.
4.How information is shared inside the platform
The platform is designed so that commercially sensitive information is visible only to the parties who need it:
- When a buyer submits an RFQ, the enquiry and its attachments are shared with the suppliers matched to it, together with the buyer's company identity and the contact details necessary to quote.
- When a supplier quotes, the quotation, its documents and the supplier's identity are shared with that buyer only.
- A supplier does not see competing suppliers' prices or quotation contents.
- Enterprise team members see the enquiries and quotations of their own company according to their assigned role.
- Authorised ADIT staff may access data for platform operation, verification, support, fraud prevention and dispute handling.
5.Third-party service providers
We use a small number of providers to run the platform:
- Stripe — payment processing for supplier subscriptions, including checkout, renewals, refunds and disputes.
- Resend (via the Emergent integration layer) — delivery of transactional and notification emails.
- Emergent — application hosting and platform infrastructure.
- MongoDB database hosting and object/file storage used to hold platform records and the files you upload.
- Other necessary providers such as error logging and, where applicable, currency, freight or duty reference data.
Card details are processed by Stripe, not by us. ADIT Connect does not receive or store your complete card number, expiry date or security code. We hold only subscription status, transaction identifiers, amounts and the invoice data required for accounting.
We may also disclose information where required by law, to a regulator or court, to protect our rights or the safety of users, or to a professional adviser, auditor or acquirer under appropriate confidentiality obligations.
6.Data security
We apply measures appropriate to a B2B sourcing platform: encrypted transport (HTTPS), passwords stored only as salted one-way hashes, http-only session cookies, role-based access control enforced on the server, rate limiting and lockout on authentication, signature verification on payment webhooks, an audit log of sensitive actions, and access to production data restricted to authorised personnel.
No system is completely secure. You are responsible for keeping your credentials confidential, for not sharing accounts, and for telling us promptly at projects@aditintl.com if you believe an account has been compromised.
7.Data retention
We keep information for as long as your account is active and afterwards only as long as necessary. In outline: account and company records are kept while the account exists and for a reasonable period after closure; RFQ, quotation, award and order records are retained as commercial records, including for dispute and audit purposes; invoices, payment and tax records are retained for the period required by applicable accounting and tax law; security and audit logs are retained for a limited period appropriate to their purpose; and support enquiries are retained while the matter is open and for a reasonable period afterwards.
[for counsel] Exact retention periods should be fixed against UAE accounting, tax and commercial record-keeping requirements before commercial launch.
8.Cookies and technical data
The platform uses cookies and equivalent local storage that are necessary for it to function: an http-only session cookie and refresh token to keep you signed in, and technical values needed for security and to remember interface preferences. We do not use advertising cookies and do not sell browsing data. We may use limited, aggregated analytics to understand which platform features are used. Blocking essential cookies will prevent sign-in from working.
9.Cross-border processing
ADIT operates from the United Arab Emirates and serves the wider GCC and international markets. Our service providers — including hosting, database, email and payment providers — may process data in other countries. Where information is transferred outside its country of origin, we seek to ensure an appropriate level of protection through the provider's contractual commitments and security measures.
Note that a cross-border transfer is inherent to the service itself: if you submit an enquiry to a supplier in another country, your enquiry details will be sent to that supplier in that country.
10.Your rights and how to exercise them
Subject to applicable law, you may ask us to: confirm what information we hold about you and provide a copy; correct inaccurate or incomplete information; delete information where we no longer have a lawful basis to keep it; restrict or object to certain processing; provide your data in a portable format; and withdraw a consent you previously gave.
You may also opt out of non-essential emails. Transactional notices that are part of the service — such as an award outcome, a payment receipt or a security alert — cannot be switched off while the account remains active.
Send account or data requests to projects@aditintl.com. We may need to verify your identity and your authority to act for the company. We aim to respond within 30 days.
Some rights are limited: we may not be able to delete records we must retain for legal, tax or audit reasons, or commercial records of a completed transaction that a counterparty is also entitled to hold. Where a company is our customer, that company — not ADIT — normally controls the working data its employees create on the platform.
11.Children and eligibility
The platform is for business use by commercial entities and is not directed at individuals under 18. We do not knowingly collect information from children.
12.Changes to this policy
We may update this policy as the platform develops. The “last updated” date above will change, and we will notify you of material changes by email or by notice in the platform.
13.Contact
For any privacy question, access request or complaint, contact projects@aditintl.com or use the Get help page. This policy has been drafted with UAE and general international personal-data protection principles in mind and must receive final review by qualified UAE legal counsel before commercial launch, including confirmation of the applicable data-protection regime, the identity of the data controller entity, retention periods and any registration or notification duties.
Also in Legal & Support
