Core

Privacy Policy

Last updated: November 2026 · Version 3.0 · Governing law: Republic of Cyprus

Global B2B Group ("we", "us", "our") is the controller of the personal data you submit through this Platform. This Privacy Policy explains what personal data we collect, why, on what legal basis, with whom we share it, how long we keep it and what rights you have. It applies together with the Cookie Policy, the GDPR Compliance & Data Subject Rights notice and the Data & Cyber Security Policy.

1. What personal data we collect

  • Identity data — name, job title, company, country.
  • Contact data — business email, phone / WhatsApp.
  • Project data — RFQ content, project brief, industry, budget range, timeline, attachments you choose to upload.
  • Investor data (where applicable) — entity type, ticket size, notes to the board.
  • Account data — credentials (hashed), preferences, saved projects, activity logs.
  • Technical data — IP address, device, browser, referrer, UTM parameters, pages viewed.
  • Compliance data — screening results (e.g. sanctions/PEP hits) where we perform such checks in our own interest or as required by law.

2. How we collect it

Directly from you (forms, RFQ builder, calculators, chat, email, WhatsApp, phone), from cookies and analytics (see the Cookie Policy), and from public or third-party sources used for enrichment and compliance screening.

3. Purposes and legal bases

  • Respond to your inquiry, evaluate your project and route your request to the right partner — legitimate interest and/or consent.
  • Operate, secure and improve the Platform — legitimate interest.
  • Perform compliance screening (identity, sanctions, AML/CTF, fraud) — legal obligation and/or legitimate interest.
  • Send transactional confirmations — contract and/or legitimate interest.
  • Send occasional market / venture updates — consent, which you can withdraw at any time.
  • Comply with legal, regulatory and enforcement requests — legal obligation.

4. Regional bases

  • EU / UK — GDPR / UK GDPR Art. 6(1)(a) consent, 6(1)(b) contract, 6(1)(c) legal obligation, 6(1)(f) legitimate interest.
  • China — PIPL: explicit consent for handling and cross-border transfer.
  • Japan — APPI: consent for handling and cross-border transfer.
  • Korea — PIPA: consent.
  • Singapore / Hong Kong — PDPA / PDPO: consent and reasonable-purpose.
  • USA — CCPA / CPRA: we do not "sell" or "share" personal information for cross-context behavioural advertising.

5. Sub-processors

We use a limited number of vetted sub-processors, currently including: Supabase (database and authentication, EU region), Resend (transactional email), Cloudflare (hosting, CDN, security), analytics and AI providers used for research, translation and assistance. Full list on request from support@globalb2bgroup.com. Cross-border transfers rely on Standard Contractual Clauses, Adequacy Decisions or equivalent safeguards.

6. Sharing personal data

We share personal data only where necessary: (i) with the sub-processors above; (ii) with the specific supplier, financier or partner you asked us to route your request to; (iii) with professional advisors, auditors and insurers; (iv) with authorities where required by law; (v) in connection with a merger, acquisition or corporate reorganisation. We do not sell personal data.

7. Retention

Inquiry and RFQ data: up to 24 months from last contact unless a longer period is required by law or an active engagement is in place. Account data: for the life of the account plus the applicable limitation period. Compliance records: as required by AML/CTF, sanctions and tax law. Server logs: typically 30–90 days.

8. International transfers

Personal data may be processed outside the EEA/UK. Where this happens, we rely on Standard Contractual Clauses, Adequacy Decisions or equivalent lawful transfer mechanisms.

9. Your rights

Subject to applicable law you may request access, rectification, erasure, restriction, portability, objection to processing, and withdrawal of consent. See the full GDPR Compliance & Data Subject Rights notice. To exercise a right, email support@globalb2bgroup.com. EU/UK data subjects also have the right to lodge a complaint with a supervisory authority.

10. Security

We apply technical and organisational measures appropriate to the risk, including TLS in transit, encryption at rest for stored data, least-privilege access, secret rotation, monitoring and vendor review. See the Data & Cyber Security Policy and the Responsible Disclosure Policy. No system is completely secure and we cannot guarantee absolute security.

11. Children

The Platform is a business-to-business service and is not directed at children. We do not knowingly collect personal data from anyone under 18.

12. Changes

We may update this Privacy Policy from time to time. The version and "Last updated" date at the top reflect the latest revision.

13. Contact

Data controller: Global B2B Group. Privacy / DPO enquiries: support@globalb2bgroup.com.

Questions about this document? Email support@globalb2bgroup.com or support@globalb2bgroup.com. Also see the Legal Center.

Home