Plain English.
Real rights.
No surprises.
Your data belongs to you. We collect only what we need to run the platform, we never sell it, and every right you hold — access, correction, erasure, portability — works in practice, not just on paper. This page is the plain-English summary; the Privacy Policy in our document library is the binding contract. Both say the same thing.
- We don't sell your data. We don't share it for cross-context behavioural advertising.
- We collect what's necessary to run the Platform — account, billing metadata (no full card numbers), RFQ content, supplier verification documents, usage and device data.
- We share data only with Subprocessors listed at /trust/compliance, on documented data-protection terms.
- You can export, correct, or delete your data at any time — see "Your rights" below.
With verbs, not nouns.
See exactly what we hold about you.
Fix anything that is wrong.
Delete your account and data (subject to legal retention).
Limit what we do with your data.
Get your data in a machine-readable format.
Lodge a complaint with us, or escalate to a regulator.
We respond within 30 days (or shorter, where the law requires) and may need to verify your identity first.
Mapped end-to-end.
| What | Why | Legal basis |
|---|---|---|
| Account info, organisation profile | Run your account | Contract |
| Billing metadata (Stripe holds full card numbers) | Process subscriptions, tax, invoices | Contract; legal obligation |
| RFQ content, supplier profiles, verification documents | Match buyers and suppliers; verify suppliers | Contract; legitimate interests |
| Usage & device data | Operate, secure, and improve the Platform | Legitimate interests |
| Transactional email metadata | Send receipts, renewal reminders, payment failures | Contract |
| Marketing email | Optional product updates | Consent (opt-in), withdrawable any time |
Acknowledged in your jurisdiction.
- · GDPR & UK GDPR compliant.
- · Legal bases documented per category.
- · Article 27 representative / DPO published at /legal/dpo when appointed.
- · Lodge complaints with your local DPA or the UK ICO.
- · No sale or share of personal information.
- · No cross-context behavioural advertising.
- · Global Privacy Control (GPC) honoured.
- · Right to know · delete · correct · opt-out · limit use · non-discrimination.
- · Privacy Act 2020 + Information Privacy Principles.
- · Complaints lodgeable with the Office of the NZ Privacy Commissioner (privacy.org.nz).
- · Notifiable breaches reported via NotifyUs as soon as practicable.
- · Privacy Act 1988 + Australian Privacy Principles.
- · Complaints lodgeable with OAIC (oaic.gov.au).
- · Eligible data breaches under APP 11A cooperated with OAIC and affected individuals.
We summarise here; the documents below are the binding versions. Each one opens directly from the Trust Centre document library.
