← Trust Centre/ Privacy

Plain English.
Real rights.
No surprises.

Your data belongs to you. We collect only what we need to run the platform, we never sell it, and every right you hold — access, correction, erasure, portability — works in practice, not just on paper. This page is the plain-English summary; the Privacy Policy in our document library is the binding contract. Both say the same thing.

/ 01 — The 30-second summary
  • We don't sell your data. We don't share it for cross-context behavioural advertising.
  • We collect what's necessary to run the Platform — account, billing metadata (no full card numbers), RFQ content, supplier verification documents, usage and device data.
  • We share data only with Subprocessors listed at /trust/compliance, on documented data-protection terms.
  • You can export, correct, or delete your data at any time — see "Your rights" below.
/ 03 — What we collect, why, on what basis

Mapped end-to-end.

WhatWhyLegal basis
Account info, organisation profileRun your accountContract
Billing metadata (Stripe holds full card numbers)Process subscriptions, tax, invoicesContract; legal obligation
RFQ content, supplier profiles, verification documentsMatch buyers and suppliers; verify suppliersContract; legitimate interests
Usage & device dataOperate, secure, and improve the PlatformLegitimate interests
Transactional email metadataSend receipts, renewal reminders, payment failuresContract
Marketing emailOptional product updatesConsent (opt-in), withdrawable any time
/ 04 — Region-specific disclosures

Acknowledged in your jurisdiction.

EU / UK / EEA / Switzerland
  • · GDPR & UK GDPR compliant.
  • · Legal bases documented per category.
  • · Article 27 representative / DPO published at /legal/dpo when appointed.
  • · Lodge complaints with your local DPA or the UK ICO.
United States (CA · CO · VA · CT · UT · TX & others)
  • · No sale or share of personal information.
  • · No cross-context behavioural advertising.
  • · Global Privacy Control (GPC) honoured.
  • · Right to know · delete · correct · opt-out · limit use · non-discrimination.
New Zealand
  • · Privacy Act 2020 + Information Privacy Principles.
  • · Complaints lodgeable with the Office of the NZ Privacy Commissioner (privacy.org.nz).
  • · Notifiable breaches reported via NotifyUs as soon as practicable.
Australia
  • · Privacy Act 1988 + Australian Privacy Principles.
  • · Complaints lodgeable with OAIC (oaic.gov.au).
  • · Eligible data breaches under APP 11A cooperated with OAIC and affected individuals.
/ 05 — Binding documents

We summarise here; the documents below are the binding versions. Each one opens directly from the Trust Centre document library.

Privacy questions: privacy@giwahs.com
See also: Security · Compliance