Privacy Policy

We protect your data because that is who we are, not because the law says so.

Last updated: March 18, 2026

Only what we need to serve you well.

We believe in keeping things simple. We collect exactly three types of information — no more, no less — because that is all we need to give you a great experience.

Account Data

Your name, email, company name, and job title. We need these to set up your account and make sure we can reach you when it matters. Think of it as your digital business card with us.

Business Data

Employee records, payroll, compliance docs, financials — everything you put into Fortress. This is your data, full stop. We store it safely and serve it back to you whenever you need it. We never peek at it for our own purposes.

Usage Data

Which features you use most, which pages you visit. This helps us understand what is working well and what we can improve — so your experience keeps getting better. This data stays on our servers and is never shared with anyone.

What we do NOT collect:

Personal browsing history, social media profiles, third-party behavioral data, or anything unrelated to running your Fortress account. We are a business tool, not an advertising company. Your attention is not our product — your success is.

We take your security personally.

Your business data deserves the same protection that banks and government agencies use. We built Fortress with that standard from day one — not as an afterthought, but as the foundation everything else sits on.

Data Protection Architecture

Sensitive fields (bank details, identity documents) are masked in all user-facing views. Full encryption at rest is deployed in production environments. Development instances use database-level access controls.

Encrypted Connections

All production deployments use TLS-encrypted connections between your browser and our servers. Security headers enforce HTTPS-only access. No data travels in plaintext.

Audit Trail on All Changes

Every data modification is logged — who did it, when, which record, from which IP address and device. Your accountant changes a number at 2 AM? Logged. Permanently. Undeletable.

Role-Based Access Control (RBAC)

Your salesman cannot see your supplier prices. Your receptionist cannot see payroll. Every user sees only what their role permits. Enforced at the system level — not by honor system.

Data Backup & Recovery

Production environments include automated backup schedules with retention policies. Recovery procedures are tested regularly. Your data is protected against loss.

UAE Data Protection Aligned

Built with UAE Federal Decree-Law No. 45 of 2021 (PDPL) principles in mind. Tenant data isolation, sensitive field masking, role-based access controls, and immutable audit trails form the foundation. Full PDPL compliance tooling is on our roadmap.

Client-Hosted Option

Want your data on servers you physically control? We support on-premise deployment. Your data never has to leave your building if you prefer it that way.

Your data stays yours. Always.

Let us be completely clear about this: your data is not a product, a bargaining chip, or a revenue stream for us. We make money by building software you love — not by selling your information to anyone, ever.

Tenant Isolation

Every client account is completely isolated from every other. Your data is invisible to other tenants — enforced at the database engine level, not just application logic. No cross-contamination, no "anonymized aggregation" tricks. Your fortress is yours alone.

When We Must Share

Only in these limited circumstances:

  • Legal requirement: When UAE law or a court order compels disclosure. We comply with the law — we do not volunteer information.
  • Service providers: Hosting and infrastructure partners who are bound by strict data protection agreements. They process data on our behalf — they cannot use it for their own purposes.
  • Business transfer: If FortressCEO LLC is acquired, your data rights transfer with the agreement. You will be notified before any change.

The bottom line:

We make money by building great software, not by selling your information. Our business model requires your trust. Violating it would be commercial suicide.

We want to get this right for you.

We want to make sure your experience with us is exactly right. If anything about your data needs attention, we are here to help. No forms to fill out, no hoops to jump through — just reach out and we will take care of it.

1

Want to see what we have? Just ask.

We will prepare a complete copy of all personal data we hold about you, in a clean, readable format. No delays, no runaround. You deserve to know exactly what is on file.

2

Something not accurate? Tell us.

Help us serve you better — if anything in your data is outdated or incorrect, let us know and we will fix it within 48 hours. Accurate data means a better experience for everyone.

3

Want your data deleted? We understand.

We will process your request within 30 days. All your data is permanently removed from our systems. The only exception is financial records we are legally required to retain under UAE law — and we will tell you exactly what those are.

4

Want to take your data elsewhere? No problem.

We will export everything in standard formats (CSV, Excel, JSON) — anytime, no fees, no waiting period. No hostage-taking. Your data is yours, and it goes where you go.

5

Changed your mind about something? No hard feelings.

Withdraw consent to data processing at any time. We will respect your decision immediately, no questions asked. Your comfort with how we handle your data matters more to us than anything else.

Contact us at support@fortress.ceo — we genuinely want to get this right.

And in the unlikely event of a data breach, we notify affected users and the relevant authority within 72 hours. No cover-ups, no delays, no excuses. That is our promise.

Just the essentials. Nothing sneaky.

We use cookies for one reason: to make your experience smoother. That means keeping you logged in and remembering your preferences. That is genuinely the full list.

What we use

  • Session cookies: Keep you logged in while you use the platform.
  • Preference cookies: Remember your language, theme, and display settings.

What we do NOT use

  • No advertising cookies
  • No third-party tracking cookies
  • No social media tracking pixels
  • No cross-site tracking of any kind

We do not track where you go after you leave Fortress. That is your business, not ours. We are here to help you run your company — not follow you around the internet.

Questions? We are happy to help.

Email us at support@fortress.ceo

FortressCEO LLC — fortress.ceo

Important Legal Notice: This Privacy Policy is provided for informational purposes and forms part of the agreement between you and FortressCEO LLC. The Client is solely responsible for the accuracy, completeness, and legality of all data entered into the platform. FortressCEO LLC processes personal data solely to deliver the services described herein and does not sell, rent, or trade personal data to third parties. All system-generated reports and compliance indicators are decision-support tools — they do not constitute legal, financial, tax, or professional advice. Clients should independently verify all compliance matters and regulatory obligations with qualified professionals licensed in their jurisdiction. By using the Fortress.CEO platform, the Client acknowledges and accepts all terms outlined in this Privacy Policy and the accompanying Terms of Service. This policy is governed by the laws of the United Arab Emirates, with exclusive jurisdiction in the courts of Sharjah, UAE.

Third-Party Trademark Notices

Tally and TallyPrime are registered trademarks of Tally Solutions Pvt. Ltd. Fortress.CEO is an independent product and is not affiliated with, endorsed by, or in any way officially connected with Tally Solutions Pvt. Ltd. SAP and SAP Business One are registered trademarks of SAP SE. QuickBooks is a registered trademark of Intuit Inc. Zoho is a registered trademark of Zoho Corporation Pvt. Ltd. Odoo is a trademark of Odoo S.A. All other product names, trademarks, and registered trademarks mentioned on this platform are the property of their respective owners. References to compatibility with third-party software describe data import and migration capability only and do not imply partnership, certification, or endorsement by those companies. Fortress.CEO makes no representations regarding the accuracy, completeness, or fitness for purpose of data migrated from third-party systems. Data migration results may vary based on the source system version, data volume, and configuration. Clients are advised to verify all migrated data before switching production operations to Fortress.CEO.