Privacy Policy.
Effective 01 January 2026 · Version 2.4 · Governs personal data processed by Fortified.Solutions
Scope
This Privacy Policy describes how Fortified.Solutions collects, processes, and protects personal data in the course of providing its Services and operating its digital properties. It applies to clients, prospective clients, personnel, and visitors to our systems.
Where Fortified processes personal data on behalf of a Client, it does so as a data processor under the applicable statement of work; the Client remains the data controller.
Data We Collect
We collect only the data necessary to deliver the Services and operate securely: contact and organizational details supplied through our secure intake, engagement telemetry, and audit metadata. We do not collect data beyond the stated purpose.
We do not use third-party advertising trackers. Fonts and assets are self-hosted; no data is shared with content-delivery networks or advertising networks by default.
How We Process It
Personal data is encrypted in transit (TLS 1.3) and at rest (AES-256), segmented by identity under a zero-trust doctrine, and accessible only to personnel with a demonstrated need.
Processing is limited to the purposes disclosed at collection: delivering the Services, meeting legal obligations, and securing our perimeter. We do not sell, rent, or repurpose personal data.
Retention & Deletion
Personal data is retained only for the duration necessary to fulfil its purpose or to meet a legal obligation. On expiry or request, data is returned or cryptographically destroyed within thirty days, evidenced by a certificate of destruction.
Audit metadata required for security and compliance is retained in a tamper-evident ledger for the period mandated by the applicable framework.
Your Rights
Subject to applicable law (including the GDPR), you have the right to access, rectify, port, restrict, or erase your personal data, and to object to certain processing. Requests are honored within the statutory window.
To exercise any right, contact our data protection function through the secure channel below. We may verify identity before actioning a request to protect against unauthorized disclosure.
International Transfers
Fortified operates command nodes across multiple jurisdictions. Where personal data crosses a border, transfers are governed by appropriate safeguards — standard contractual clauses or an equivalent lawful mechanism — and residency is enforced at the infrastructure layer where required.
Sovereign and air-gapped engagements pin data to a specified jurisdiction with no cross-border transfer.
Contact & Updates
Questions, requests, and complaints regarding personal data may be directed to our data protection function. We respond within one operational cycle.
We may update this policy to reflect changes in law or practice. Material changes are versioned and dated; the effective version governs from its stated date.
These terms are governed by the laws of the Canton of Zurich, Switzerland, without regard to conflict-of-law principles. Any dispute arising from an engagement is subject to the exclusive jurisdiction of the courts of Zurich. Where a provision is held unenforceable, the remainder stands in full force.
Questions regarding these terms — legal@fortified.solutions