Data Retention Policy

Global Data Retention Policy — XB2BX.COM
Global Compliance Framework
XB2BX.COM — International B2B Marketplace

Global Data
Retention Policy

Privacy, Security & Data Lifecycle Management Framework for all users, suppliers, buyers, partners, and third parties interacting with the XB2BX platform.

Document Reference XB2BX-DRP-v1.0
Version 1.0 — May 2026
Effective Date Upon Publication
Jurisdiction England & Wales (Global Application)
Review Cycle Annual / As Required
UK GDPR
EU GDPR 2016/679
Data Protection Act 2018
CCPA / CPRA
AML / KYC Regulations
Cross-Border Transfer Standards
eCommerce Directive
FATF Guidelines
§ 01

Introduction

XB2BX.COM ("XB2BX", "the Platform", "we", "our", or "us") is committed to protecting the privacy, confidentiality, integrity, and lawful management of all personal, corporate, transactional, and operational data processed through our global B2B marketplace platform.

This Global Data Retention Policy establishes the principles, standards, retention periods, security measures, and deletion procedures applicable to all information collected, stored, processed, transferred, or archived through XB2BX.COM.

Objectives of This Policy
  • Protect users and corporate clients from data misuse
  • Ensure compliance with international data protection laws
  • Minimise legal, regulatory, and cybersecurity risks
  • Define transparent data handling standards
  • Prevent unauthorised access or unlawful retention
  • Establish responsible data lifecycle management procedures
📋
This policy forms part of the overall XB2BX legal, compliance, cybersecurity, privacy, and operational governance framework and should be read in conjunction with the Terms of Service, Privacy Policy, and Acceptable Use Policy.
§ 02

Scope of This Policy

This policy applies globally to all individuals and entities interacting with the XB2BX platform in any capacity.

Applies To
  • Registered users and account holders
  • Buyers and procurement professionals
  • Suppliers and product vendors
  • Corporate partners and enterprise clients
  • Service providers and contractors
  • Advertisers and marketing partners
  • Affiliates and referral partners
  • Employees, agents, and consultants
  • API integrations and technical partners
  • Website visitors and anonymous users
Applies Across All Systems
  • XB2BX.COM web platform
  • Mobile applications
  • APIs and third-party integrations
  • CRM and customer support systems
  • Cloud infrastructure and storage
  • Payment and compliance systems
  • Marketing and analytics platforms
§ 03

Legal & Regulatory Compliance

XB2BX.COM operates in accordance with applicable international privacy, data protection, and financial compliance regulations. This policy is designed to satisfy the requirements of multiple regulatory frameworks simultaneously.

  • UK GDPR (General Data Protection Regulation — retained)
  • EU GDPR (Regulation 2016/679)
  • Data Protection Act 2018 (United Kingdom)
  • CCPA / CPRA (California Consumer Privacy Act)
  • International AML/KYC compliance obligations
  • Electronic commerce and consumer protection regulations
  • Cross-border data transfer standards (SCCs / adequacy decisions)
  • FATF Recommendations on data in financial crime prevention
⚖️
Stricter Standard Prevails: Where local laws in any applicable jurisdiction require stronger data protections than those set out in this policy, the stricter legal standard shall apply in that jurisdiction without amendment to this document.
§ 04

Types of Data Collected

XB2BX may collect and process information across four principal data categories. All data collection is conducted on the basis of a lawful processing ground under applicable data protection law.

4.1 — Personal Information
  • Full name and contact details
  • Email address and telephone number
  • Business address and registered office
  • Government-issued identification documents
  • User account information and preferences
  • Login credentials (encrypted)
  • IP addresses and device identifiers
4.2 — Corporate & Business Information
  • Company registration documents
  • Tax and VAT information
  • Shareholder and director details
  • Supplier verification documentation
  • Commercial licences and certifications
  • Banking and payment information
4.3 — Transactional Data
  • Orders, invoices, and receipts
  • Payments, refunds, and credits
  • Shipping and logistics information
  • Marketplace communications
  • Supplier and buyer interactions
  • Dispute records and resolutions
4.4 — Technical & Security Information
  • Cookies and analytics data
  • System and access logs
  • Security monitoring records
  • Fraud prevention data
  • Compliance screening records
  • API usage logs
§ 05

Purpose of Data Retention

XB2BX retains information only where necessary for legitimate business, operational, legal, contractual, security, or regulatory purposes. Data is not retained indefinitely without a documented lawful basis.

  • User account management and authentication
  • Marketplace operations and transaction processing
  • Customer and supplier support
  • Fraud prevention and cybersecurity monitoring
  • Compliance with regulatory and legal obligations
  • Legal defence and dispute resolution
  • Financial reporting and auditing
  • Platform improvement and analytics
  • Marketing communications (where consent exists)
  • AML/KYC obligations and sanctions screening
ℹ️
XB2BX applies the principle of data minimisation: we collect only what is necessary for the stated purpose and do not retain data beyond the periods specified in this policy unless a specific legal, regulatory, or security justification applies.
§ 06

Data Retention Periods

The following retention periods apply by default. XB2BX reserves the right to retain information beyond these periods where required for legal claims, regulatory investigations, fraud prevention, court orders, or enforcement of contractual rights.

6.1 — User Account Data
Data CategoryStandard Retention Period
Active User AccountsDuration of Activity
Inactive AccountsUp to 24 months
Deleted AccountsUp to 12 months
6.2 — Corporate & Supplier Verification Records
Data CategoryStandard Retention Period
KYC / AML Verification RecordsUp to 7 years
Corporate Registration DocumentsUp to 7 years
Supplier Compliance RecordsUp to 7 years
6.3 — Financial & Transaction Records
Data CategoryStandard Retention Period
Invoices & Payment RecordsUp to 10 years
Accounting RecordsUp to 10 years
Tax RecordsAs required by law
Transaction LogsUp to 7 years
6.4 — Security & Technical Logs
Data CategoryStandard Retention Period
Security Monitoring Logs12 – 36 months
System Access LogsUp to 24 months
Fraud Investigation RecordsDuration of investigation + legal hold
6.5 — Marketing & Communication Data
Data CategoryStandard Retention Period
Marketing Consent RecordsUntil consent withdrawn
Customer Support RecordsUp to 5 years
Email & Platform CommunicationsUp to 5 years
§ 07

Data Security & Protection Measures

XB2BX implements commercially reasonable administrative, technical, organisational, and cybersecurity safeguards designed to protect all data against unauthorised access, loss, misuse, alteration, disclosure, destruction, or cyberattack.

🔒 Encrypted data transmission (TLS)
🔒 Secure cloud infrastructure
🔒 Role-based access controls
🔒 Multi-factor authentication
🔒 Firewall & intrusion monitoring
🔒 Secure encrypted backups
🔒 Compliance audit procedures
🔒 Restricted data access controls
⚠️
Security Limitation Acknowledgement: Despite these measures, no digital system can guarantee absolute security. Users acknowledge that internet-based communications and cloud storage systems carry inherent cybersecurity risks and are responsible for maintaining the security of their own account credentials and devices.
§ 08

User Rights

Subject to applicable data protection laws, users may exercise the following rights in relation to their personal data held by XB2BX. Requests must be submitted in writing and may be subject to identity verification.

🔍
Right of Access
Request a copy of the personal data we hold about you and information about how it is processed.
✏️
Right to Rectification
Request correction of inaccurate or incomplete personal data without undue delay.
🗑️
Right to Erasure
Request deletion of personal data where retention is no longer legally required.
⏸️
Right to Restriction
Request that we limit processing of your data in certain defined circumstances.
📦
Data Portability
Receive your personal data in a structured, commonly used, machine-readable format.
🚫
Right to Object
Object to processing based on legitimate interests, including direct marketing.
↩️
Withdraw Consent
Withdraw consent at any time where processing is based on consent, without affecting prior processing.
🇺🇸
CCPA Rights
California residents have the right not to sell or share personal information. Contact privacy@xb2bx.com.
How to Submit a Request
  1. Email Submit your request in writing to privacy@xb2bx.com with your full name, registered email address, and description of the right you wish to exercise.
  2. Verification XB2BX reserves the right to verify your identity before processing any rights request. We may request additional documentation.
  3. Response We aim to respond within 30 days of receipt. Complex requests may require up to 90 days with prior notice.
📌
Important: Certain information may not be deleted where retention is required by legal obligation, fraud prevention, financial compliance, contractual enforcement, or ongoing disputes or regulatory investigations.
§ 09

Data Sharing & Third Parties

XB2BX may share information with trusted third parties where necessary for legitimate operational, compliance, or legal purposes. All data processors are engaged under contractual arrangements requiring appropriate confidentiality and security standards.

  • Payment processing providers
  • Logistics and shipping operators
  • Identity and KYC verification services
  • Cloud hosting and infrastructure providers
  • Customer support platform providers
  • Analytics and performance monitoring services
  • Compliance and sanctions screening providers
  • Legal, audit, and regulatory advisers
  • Law enforcement where legally required
🛡️
No Unlawful Sale of Personal Data: XB2BX does not sell personal data in any manner prohibited by applicable privacy laws, including the CCPA/CPRA.
§ 10

Cross-Border Data Transfers

As a global B2B marketplace platform, XB2BX may process or transfer information internationally, including to countries outside the United Kingdom and the European Economic Area (EEA). Users acknowledge and consent that their information may be transferred to and processed in jurisdictions with different data protection frameworks.

Safeguards for International Transfers
  • Standard Contractual Clauses (SCCs) approved by the ICO and European Commission
  • Adequacy decisions where the destination country has been assessed as providing equivalent protection
  • Binding Corporate Rules where applicable
  • Explicit consent where other transfer mechanisms are not available
§ 11

Account Termination & Data Deletion

Users may request account deletion subject to legal, regulatory, security, operational, and contractual requirements. Deletion requests are processed in accordance with the procedures below.

What Happens Following a Deletion Request
  1. Step 1 Public-facing account profile and listing information will be removed from the platform within 30 days of a verified deletion request.
  2. Step 2 Certain records will remain archived in accordance with the retention periods in Section 6, including financial, legal, and compliance records.
  3. Step 3 Backup systems may temporarily retain limited data copies during routine backup cycles; these will be overwritten in accordance with our backup schedule.
  4. Step 4 Legal, financial, and regulatory records are preserved for the mandatory periods regardless of deletion requests.
⚖️
XB2BX reserves the right to retain information necessary to prevent fraud, enforce agreements, resolve disputes, comply with law, and protect platform integrity irrespective of any deletion request.
§ 12

Children's Data

XB2BX is intended exclusively for registered business users and professional participants. The platform is not directed to individuals under the age required by applicable law in their jurisdiction to enter into legally binding commercial agreements.

XB2BX does not knowingly collect, store, or process personal information from children. If we become aware that personal data has been inadvertently collected from a minor, we will take prompt steps to delete such data.

§ 13

Policy Violations & Enforcement

Unauthorised access, misuse, disclosure, extraction, scraping, copying, resale, or abuse of XB2BX data, systems, or user information constitutes a serious violation of this policy and applicable law.

Consequences of Violation
  • Immediate suspension of platform access and account privileges
  • Permanent account termination and blacklisting
  • Civil legal action for damages, injunctive relief, and account of profits
  • Reporting to relevant regulatory and law enforcement authorities
  • Referral to data protection authorities (ICO, EDPB, and equivalents)
  • Financial claims for losses, including consequential and reputational damage

XB2BX reserves all legal rights relating to the protection of its systems, users, intellectual property, and business operations.

§ 14

Disclaimers & Limitation of Liability

XB2BX.COM operates as a global B2B marketplace, technology intermediary, and commercial platform. XB2BX is not a bank, financial institution, regulated investment adviser, escrow provider, or payment processor unless expressly stated otherwise in a specific service agreement.

User Acknowledgements
  • No digital system can guarantee complete cybersecurity protection against all threats
  • Third-party service providers and integrations may introduce independent security risks
  • Users are solely responsible for protecting their own login credentials, devices, and access controls
  • XB2BX does not guarantee uninterrupted availability of the platform or data systems
⚠️
Liability Cap: To the maximum extent permitted by applicable law, XB2BX disclaims all liability for indirect, incidental, consequential, punitive, or speculative damages arising from cyber incidents, third-party breaches, user negligence, internet failures, or external service interruptions.
§ 15

Policy Updates

XB2BX reserves the right to update, amend, or modify this Data Retention Policy at any time to reflect changes in law, regulatory guidance, platform operations, or best practice. Material changes will be communicated to registered users prior to taking effect.

Updated versions will be published at www.xb2bx.com/data-retention-policy with a revised effective date. Continued use of the platform following the publication of any updated version constitutes acceptance of the revised policy.

§ 16

Contact Information

For all data protection enquiries, rights requests, complaints, or questions relating to this policy, please contact our Privacy & Compliance Department using the details below.

Privacy, Compliance & Data Protection
XB2BX.COM — Global B2B Marketplace
Company
XB2BX LTD
Registered Address
71–75 Shelton Street, Covent Garden, London WC2H 9JG, England
Privacy Email
General Enquiries
Policy Matters
Telephone
+44 7413 774377
VAT Registration NumberGB 474 0764 77
ICO Registration ReferenceC1651490
ICO Registered OrganisationXB2BX LTD
🏛️
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk (Reference: C1651490), or with your local data protection supervisory authority if you are based in the EU or another jurisdiction.
live chat xb2bx
Items (0)
No Record Found

Your Shopping Bag Is Empty