Legal

Privacy Policy

Website, RFQ and Portal — how we collect, use and protect your data.

Effective date: 31 July 2026 · Version 1.0

1. Who we are

Specialist Components Supply Ltd (“SCS”, “we”, “our”, “us”) is a Zambian private company limited by shares. We operate the website specialistcomponentssupply.com and the associated RFQ and customer portal services. We are the “controller” of your personal data for the purposes described in this policy.

2. What data we collect

  • Contact and identity data: name, job title, company name, email address, phone number, location.
  • RFQ and order data: item descriptions, quantities, specifications, delivery requirements, project context, pricing, quotes, and order history.
  • Account data: login credentials, MFA preferences, customer portal settings.
  • Technical data: IP address, device/browser information, pages visited, timestamps.
  • Payment data: high‑level payment status and transaction references from card/mobile payment providers. We do not store full card numbers or CVV codes.
  • Communications: emails, messages and notes related to your RFQs, quotes, orders and support requests.

3. How we collect data

Directly from you when you submit RFQs, create or use a Portal account, or communicate with us by email or phone. Automatically when you browse the website and Portal (logs and analytics, subject to cookie consent). Indirectly from SCS’s internal systems (Zoho CRM, accounting, RFQ dashboard) and from trusted payment providers when you pay an invoice (non‑sensitive transaction metadata).

4. How we use your data

  • Respond to RFQs and prepare quotes.
  • Manage orders, deliveries and invoicing.
  • Provide and improve the customer portal and RFQ dashboard.
  • Maintain accurate records for tax, accounting and compliance.
  • Communicate with you about RFQs, quotes, orders, and relevant service updates.
  • Measure and improve website and portal performance (where you consent to analytics cookies).
  • Meet legal and regulatory obligations (e.g. accounting records, local‑content reporting).

We rely on one or more of the following legal bases: contractual necessity, legitimate interests, legal obligations, and consent (for cookies/analytics and certain communications).

5. Who we share data with

We share data with trusted service providers (“processors”) to deliver our services, including:

  • Zoho CRM — to store and manage RFQs, leads and customer interactions.
  • QuickBooks (or other accounting system) — to manage accounting records, invoices and payments.
  • Payment gateways: Paystack and PayPal to process card/mobile payments. (Stripe is wired for future use and not currently active for live payments.)
  • Email services: Microsoft 365 (Graph) to send notifications and confirmations.
  • OTP services: Twilio to send SMS one‑time passwords for MFA.
  • Object storage & virus scanning: Emergent object storage and Cloudmersive Virus Scan for attachments uploaded via the RFQ form.
  • Hosting and infrastructure providers: Emergent and its underlying cloud providers, for website, portal and API hosting.

These providers process data under our instructions and are required to protect it appropriately. We may also share data with professional advisers (accountants, lawyers) for legitimate business purposes, and with authorities or courts where required by law. We do not sell your personal data.

6. International transfers

Some service providers (e.g. Zoho, payment gateways, hosting) may store or process data outside Zambia, including in the EU, UK or other regions. Where data is transferred internationally, we seek to ensure it is protected by appropriate safeguards such as data processing agreements with providers and use of providers with recognised data protection standards.

7. Data retention

  • RFQ and order records: typically at least 6 years from the end of the relevant financial year, or longer if required by tax or regulatory rules.
  • Portal account data: while the account is active and for a reasonable period afterwards (e.g. 2 years) to manage relationships and support repeat business.
  • Technical logs: for a shorter period (e.g. 12–24 months) for security and performance analysis.
  • Payment metadata: in line with accounting and tax requirements.

We may retain data longer if necessary for legal, regulatory or dispute‑resolution purposes.

8. Your rights

Subject to applicable law, you may have rights to access, correct, delete, object to or restrict processing of your personal data, and to withdraw consent where processing is based on consent. Contact us using the details in section 12 to exercise these rights. We may need to verify your identity before fulfilling requests.

9. Security

We use secure hosting and encryption where appropriate, limit access to authorised staff and systems, use MFA (SMS OTP) to protect certain accounts, and regularly review systems for vulnerabilities. No system can be completely secure, but we aim to reduce risk to a reasonable level.

10. Cookies and tracking

We use cookies for essential functions (session, authentication, security), functional preferences (device trust for MFA), and analytics (where consented). See our Cookie Notice for full detail and to change your preferences at any time.

11. Changes to this Policy

We may update this Privacy Policy from time to time. Updated versions will be posted on the website and Portal with a revised effective date. Continued use of our services after changes indicates acceptance of the updated Policy.

12. Contact

If you have questions or concerns about how we process your data, please contact:

We use cookies to improve your experience, provide secure access to the portal, and analyse how our services are used. You can choose which cookies we use.  Read our cookie notice.