Defence Armament OÜ, registry code 17555647, registered in the Republic of Estonia, European Union, trading as Defence.us

1.1 Overview

Defence.US (“Website”, “Platform”, “We”, “Us”, “Our”) is a defence procurement facilitation platform operated by
Vorn Initiative Ltd. (“Company”, “Vorn”). This Privacy Policy explains how we collect, use, disclose,
and protect your personal information when you visit our Website, submit procurement enquiries, or use our Services.

1.2 Commitment to Privacy

We are committed to protecting the confidentiality and security of information entrusted to us, particularly given the
sensitive nature of defence procurement activities. We handle all personal and procurement-related information in
accordance with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018
  • Applicable international data protection laws
  • Our contractual and legal obligations regarding defence procurement

1.3 Scope

This Privacy Policy applies to:

  • All users of our Website
  • Individuals and organisations submitting procurement enquiries
  • Government and institutional buyers engaging with our Services
  • Vendors, manufacturers, and partners in our network
  • Any person whose information we process in connection with defence procurement facilitation

1.4 Acceptance

By using our Website or Services, you acknowledge that you have read, understood, and agree to the practices described
in this Privacy Policy. If you do not agree, please do not use our Website or Services.

2. INFORMATION WE COLLECT

2.1 Information You Provide Directly

We collect information that you voluntarily provide when:

2.1.1 Procurement Enquiries

When you submit a procurement enquiry through our Website, forms, or email, we collect:

  • Personal identification: Name, rank, title, position
  • Organisational information: Organisation name, ministry, department, agency
  • Contact details: Official email address, phone number, postal address
  • Procurement details: Product or system of interest, quantity, timeline, budget range
  • End-user information: End-user certification details, delivery location
  • Supporting documentation: End User Certificates (EUC), import licences, authorisation letters

2.1.2 Account Registration (if applicable)

  • Username and password
  • Professional credentials and certifications
  • Organisation verification documents

2.1.3 Communications

  • Email correspondence with our team
  • Telephone call records (with consent)
  • Chat or messaging communications

2.1.4 Vendor / Partner Onboarding

  • Company registration documents
  • Export licence information
  • Banking and payment information
  • Compliance and certification records

2.2 Information Collected Automatically

When you visit our Website, we automatically collect:

Data Type Description
Log Data IP address, browser type, operating system, referring pages, timestamps
Usage Data Pages visited, time spent, clicks, scrolls, search queries
Device Information Device type, screen resolution, language settings
Location Data Approximate geolocation (city/country level) based on IP address

2.3 Cookies and Similar Technologies

We use cookies and similar tracking technologies to:

  • Enhance Website functionality and performance
  • Remember your preferences and settings
  • Analyse Website traffic and usage patterns
  • Detect and prevent security threats

Types of Cookies We Use:

Cookie Type Purpose Duration
Essential Cookies Website operation, security, authentication Session
Preference Cookies Remember user settings and language 12 months
Analytics Cookies Google Analytics to understand usage patterns 24 months
Security Cookies CSRF protection, rate limiting Session

Your Choices: You can control cookies through your browser settings. However, disabling essential
cookies may affect Website functionality.

2.4 Information from Third Parties

We may receive information about you from:

  • Government agencies (with appropriate authorisation)
  • Manufacturers and vendors (in connection with procurement facilitation)
  • Verification services (for compliance and due diligence)
  • Publicly available sources (for sanctions screening and export compliance)

3. HOW WE USE YOUR INFORMATION

3.1 Primary Purposes

We use your information to:

Purpose Legal Basis
Process procurement enquiries Contractual necessity, legitimate interest
Facilitate introductions to manufacturers Contractual necessity
Conduct export compliance screening Legal obligation
Verify end-user status and authority Legal obligation
Communicate about procurement status Contractual necessity
Provide customer and technical support Legitimate interest
Improve our Website and Services Legitimate interest
Detect and prevent fraud or misuse Legal obligation

3.2 Export Compliance and Sanctions Screening

Critical Use: We use your information to screen against:

  • UN Security Council sanctions lists
  • US OFAC Specially Designated Nationals (SDN) List
  • UK HM Treasury sanctions lists
  • EU consolidated sanctions lists
  • Entity List, Denied Persons List, Unverified List
  • National debarment and export denial lists

This screening is mandatory and a legal requirement for defence procurement
facilitation.

3.3 Secondary Purposes

We may also use your information for:

  • Analytics and performance monitoring (aggregated, anonymised)
  • Security investigations and threat detection
  • Legal compliance and regulatory reporting
  • Enforcement of our Terms & Conditions

3.4 Aggregated Data

We may aggregate and anonymise data for statistical analysis, market research, and business intelligence. Aggregated
data does not identify you personally and is not subject to this Privacy Policy.

4. LEGAL BASES FOR PROCESSING (UK GDPR)

We process your personal data under the following legal bases:

Legal Basis Application
Contractual Necessity Processing procurement enquiries, facilitating introductions, and providing our Services
Legal Obligation Export compliance screening, sanctions checks, record-keeping, reporting to authorities
Legitimate Interests Website improvement, security monitoring, fraud prevention, business development
Consent Marketing communications, optional cookies, certain data processing (where required)
Vital Interests Emergency situations (rarely applicable)

5. INFORMATION SHARING AND DISCLOSURE

5.1 When We Share Information

We share your information only in the following circumstances:

5.1.1 Procurement Facilitation

We share procurement enquiries with:

  • Verified OEM manufacturers (to match your requirement)
  • Prime contractors (for specific system enquiries)
  • Government export agencies (for G2G facilitation)

Limitation: We share only the information necessary for procurement matching. We do not share your
information with unverified parties.

5.1.2 Compliance and Legal Obligations

We disclose information when required to:

  • Government export control authorities (for licence applications)
  • Law enforcement agencies (pursuant to valid legal process)
  • Regulatory bodies (for compliance audits)
  • Courts or tribunals (in response to court orders)

5.1.3 Service Providers

We engage third-party service providers for:

  • Website hosting and cloud services
  • Email and communication platforms
  • Analytics and performance monitoring
  • Security monitoring and threat detection

All service providers are bound by data processing agreements and may only process information as instructed.

5.1.4 Corporate Transactions

In the event of a merger, acquisition, restructuring, or sale of assets, your information may be transferred to the
successor entity. We will notify you of any such transfer.

5.2 When We Do NOT Share

We do NOT sell, rent, or trade your personal information to third parties for marketing or
advertising purposes. We do NOT share your procurement information with competitors or unauthorised
parties.

5.3 International Data Transfers

Given the global nature of defence procurement, your information may be transferred to and processed in countries
outside the United Kingdom, including:

Region Countries
Europe France, Germany, Italy, Norway, Turkey, Belgium, Switzerland
Asia China, South Korea, Malaysia, India, Singapore, UAE
North America United States, Canada
Other Australia, South Africa

Safeguards: For transfers outside the UK, we implement appropriate safeguards, including:

  • UK GDPR adequacy decisions (where applicable)
  • Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner’s Office
    (ICO)
  • Vendor data processing agreements with export compliance provisions

6. DATA SECURITY

6.1 Security Measures

We implement industry-standard security measures to protect your information:
Technical Safeguards:

  • Encryption: TLS 1.3 for data in transit; AES-256 for data at rest
  • Access controls: Role-based access, least privilege principle
  • Authentication: Multi-factor authentication for administrative access
  • Network security: Firewalls, intrusion detection, DDoS protection
  • Secure development: Regular security testing and code reviews

Organisational Safeguards:

  • Staff training: Regular data protection and security awareness
  • Access restrictions: Need-to-know basis for sensitive procurement data
  • Incident response: Formal breach notification and response procedures
  • Third-party audits: Independent security assessments

6.2 Retention of End User Certificates (EUC)

Due to export compliance requirements, End User Certificates and related procurement documentation are
retained for a minimum of ten (10) years
after the completion of any transaction, or as otherwise
required by applicable export control laws.

6.3 Security Limitations

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your
information, we cannot guarantee absolute security. You transmit information to us at your own risk.

6.4 Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify:

  • You directly (where we have your contact information)
  • The UK Information Commissioner’s Office (ICO) within 72 hours, where required

7. DATA RETENTION

7.1 Retention Periods

We retain your personal information for as long as necessary to fulfil the purposes outlined in this Privacy Policy,
unless a longer retention period is required or permitted by law.

Data Category Retention Period
Procurement enquiries 7 years after last activity
End User Certificates (EUC) Minimum 10 years (export compliance requirement)
Export licence documentation 10 years after licence expiry
Communication records 5 years
Website usage data 24 months (aggregated)
Sanctions screening records 7 years
Vendor/partner due diligence Duration of relationship + 7 years

7.2 Criteria for Retention

We consider:

  • The nature and sensitivity of the information
  • The purpose for which we collected it
  • Legal and regulatory retention requirements
  • Export control and compliance obligations
  • Potential need for dispute resolution or litigation

7.3 Deletion Requests

You may request deletion of your information as described in Section 9 (Your Rights). However, we may retain
information required for legal compliance, including export control records.

8. YOUR RIGHTS

8.1 UK GDPR Rights

Under the UK GDPR, you have the following rights:

Right Description
Right to Access Obtain confirmation of whether we process your data and request a copy
Right to Rectification Correct inaccurate or incomplete personal data
Right to Erasure Request deletion of your data (“right to be forgotten”)
Right to Restrict Processing Limit how we use your data in certain circumstances
Right to Data Portability Receive your data in a structured, machine-readable format
Right to Object Object to processing based on legitimate interests or direct marketing
Right to Withdraw Consent Withdraw consent where processing is based on consent
Right to Lodge a Complaint Complain to the UK Information Commissioner’s Office (ICO)

8.2 Exercising Your Rights

To exercise any of these rights, please contact us at:
Email: [email protected]
Postal Address: Defence.US — Data Protection Officer, Vorn Initiative Ltd.
Verification: We may require you to verify your identity before processing your request. This may
include providing official identification or answering questions about your interactions with us.

8.3 Response Time

We will respond to your request within one (1) month of verification. Complex requests may require
an additional two (2) months, and we will notify you of any extension.

8.4 Limitations

Your rights are not absolute. We may refuse requests where:

  • Compliance would violate export control or other legal obligations
  • The request is manifestly unfounded or excessive
  • The information is subject to legal privilege or professional secrecy
  • Disclosure would compromise national security or defence interests

8.5 Right to Complain to ICO

If you believe we have violated your data protection rights, you have the right to lodge a complaint with the
UK Information Commissioner’s Office (ICO) :
Website: https://ico.org.uk
Telephone: 0303 123 1113
Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

9. CHILDREN’S PRIVACY

Our Website and Services are not intended for individuals under 18 years of age. We do not
knowingly collect personal information from children. If you believe a child has provided us with personal
information, please contact us immediately, and we will take steps to delete such information.

10. THIRD-PARTY LINKS

Our Website may contain links to third-party websites, including manufacturer websites, government portals, and
industry resources. We are not responsible for the privacy practices or content of such third-party sites. We
encourage you to read the privacy policies of any website you visit.

11. CHANGES TO THIS PRIVACY POLICY

We reserve the right to modify this Privacy Policy at any time. If we make material changes, we will notify you by:

  • Posting the revised policy on our Website
  • Updating the “Last Updated” date at the top of this policy
  • Providing such other notice as we deem appropriate

Your continued use of our Website or Services following the posting of changes constitutes your acceptance
of such changes.

12. CONTACT INFORMATION

12.1 General Enquiries

Email: [email protected]

12.2 Privacy Enquiries

Email: [email protected]

12.3 Data Protection Officer (DPO)

Email: [email protected]

12.4 Compliance and Export Control

Email: [email protected]

12.5 Postal Address

Defence.US — Privacy Office
Vorn Initiative Ltd.

12.6 Response Times

We aim to respond to all privacy-related enquiries within five (5) business days and to formal data
subject requests within one (1) month as described in Section 8.3.

APPENDIX A: SUMMARY OF YOUR RIGHTS

Right What It Means How to Exercise
Access Get a copy of your data Email [email protected]
Rectification Correct inaccurate data Email [email protected]
Erasure Request deletion Email [email protected]
Restrict processing Limit how we use your data Email [email protected]
Data portability Receive data in machine-readable format Email [email protected]
Object Object to processing based on legitimate interests Email [email protected]
Withdraw consent Withdraw any consent given Email [email protected]
Complain to ICO Lodge complaint with UK regulator https://ico.org.uk

APPENDIX B: COOKIE TABLE

Cookie Name Type Purpose Duration
session_id Essential User session management Session
csrf_token Essential Security (CSRF protection) Session
user_preferences Preference Stores language and display settings 12 months
_ga Analytics Google Analytics — user identification 24 months
_gid Analytics Google Analytics — user session 24 hours
security_ratelimit Security Rate limiting protection 1 hour

BY USING DEFENCE.US, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THE PRACTICES DESCRIBED IN
THIS PRIVACY POLICY.