Fortizan is a software engineering practice operating from Sri Lanka. This policy covers this website and our engineering engagements.
It does not cover Sqoura, the product we operate. Sqoura has its own privacy policy and its own data controller relationship with the organisations that use it; see sqoura.com.
What we collect
If you visit this website
Nothing that identifies you. This site sets no cookies, runs no analytics, and embeds no third-party trackers. Our hosting provider keeps standard server logs (IP address, time, requested path, user agent) which exist to serve the page and detect abuse, and which we do not use to build a profile of you.
Every asset on this page — including the web fonts — is served from this domain. Your
browser contacts no third party to render it. The fonts used to come from Google
Fonts, which meant a request to fonts.gstatic.com that showed Google your
IP address; they are now hosted here, and that request is gone.
The one exception is the contact form, which carries a Cloudflare Turnstile check to
stop automated submissions. That page loads a script from
challenges.cloudflare.com and the check sees your IP address and enough
about your browser to tell a person from a script. It sets no tracking cookie and is
not used to identify you or to build a profile. Cloudflare already serves this whole
site, and is listed as a processor below. No other page loads it.
If you contact us
Whatever you put in the form or the email: your name, your email address, your organisation if you give it, and the description of your problem. We keep it so we can reply to you and so we have a record of what was discussed. If a conversation does not lead to work, we delete the correspondence on request.
If you become a client
Contact and billing details for the people we work with, and — necessarily — access to parts of your systems. That can include source code, database contents, infrastructure credentials and API keys.
We treat all of it as yours. Credentials are held in encrypted storage, access is limited to the engineers on your engagement, and access is revoked when the engagement ends. We do not copy client data onto personal machines, and we do not use it to train anything.
What we do not do
- We do not sell personal information, and never have.
- We do not share it with advertisers or data brokers.
- We do not run behavioural advertising or retargeting.
- We do not use client data or client code as material for marketing without written permission.
Who else processes data on our behalf
This section covers this website and our own internal operations. Systems we build and run for clients sit on whatever infrastructure that engagement specifies, and its providers are named in its own agreement. The providers below are the ones that can, in the course of doing their job, hold information relating to you:
- Oracle Cloud Infrastructure — compute for the production systems we operate.
- Cloudflare — hosting, content delivery, DNS, object storage, and the anti-automation check on the contact form.
- Amazon Web Services — transactional email, via Amazon SES.
- GitHub — source hosting for our open-source packages, and for engagement work not held in a client's own repository.
- Google Workspace — email and documents.
A provider is listed here before it starts handling anything, not after. If that list changes, this page changes with it.
How long we keep things
- Enquiries that go nowhere: twelve months, then deleted.
- Client correspondence and project records: for the duration of the engagement and seven years afterwards, which is what tax and contract law require of us.
- Credentials and system access: revoked and destroyed at the end of the engagement.
- Server logs: rotated on our provider's standard schedule.
Security
Data is encrypted in transit and at rest. Administrative access requires multi-factor authentication. Access to any given system is limited to the people working on it.
We will not claim a specific certification we do not hold. If your procurement process needs one, ask us directly and we will tell you what we have and what we do not.
Your rights
You can ask us what we hold about you, ask for it corrected, or ask for it deleted where we are not legally required to keep it. Write to info@fortizan.com and we will respond within thirty days.
Changes
If this policy changes substantively, the date at the top of this page changes with it. We do not quietly revise it.