metadata & Control

XB2BX — Content Metadata Control Framework v3.0
Metadata Control Framework — v3.0 ACTIVE
Content Metadata Control System

Global Marketplace Metadata
Governance Framework

A unified technical and legal architecture governing classification, provenance, lifecycle, moderation, and compliance metadata across all XB2BX platform content objects.

Jurisdiction
England & Wales + EU
Standard
UK GDPR / ISO 23081
Version
3.0 — 2025
Scope
All B2B Content Objects
Company No.
15190772
Section 00 — Governance

Document Control & Metadata

⚠ Confidential This document constitutes proprietary operational infrastructure. Distribution without written authorisation from XB2BX Ltd. Legal Infrastructure Directorate is strictly prohibited under applicable intellectual property and trade secrets law.
Control AttributeValue
Document TitleXB2BX Content Metadata Control Framework
Framework IdentifierXB2BX-CMC-3.0
Governing EntityXB2BX Ltd., Registered in England & Wales — Company No. 15190772
VAT RegistrationGB474076477
Primary Domainxb2bx.com
Version3.0 (Production)
Effective Date1 January 2025
Review FrequencyAnnual, or upon material legislative change
Regulatory BaseUK GDPR, EU GDPR 2016/679, ISO 23081 (Records Metadata), ISO 15836 (Dublin Core), UK Trade Controls, OFAC, UN Security Council Sanctions
Contactcompliance@xb2bx.com
Approved ByXB2BX Legal Infrastructure Directorate
Amendment Register
VersionDateChange SummaryAuthor
1.0Jan 2023Initial framework creationLegal Directorate
2.0Jun 2024AI-content clauses added; sanctions expansionLegal + Compliance
3.0Jan 2025ISO 23081 alignment; cross-border data transfer update; full lifecycle rulesLegal + Ops
Section 01 — Governance

Framework Overview & Purpose

β—ˆ Scope Statement This framework applies to every content object published, submitted, stored, transmitted, or generated within the XB2BX platform ecosystem — including product listings, trade documents, images, certificates, user profiles, and AI-generated content.
1.1 Purpose & Rationale

XB2BX operates a global B2B algorithmic marketplace in which the accuracy, classification, ownership, and status of every content object directly impacts regulatory compliance, counterparty trust, search integrity, and legal liability. Metadata controls are the technical and governance mechanism by which these properties are captured, maintained, verified, and enforced throughout the content lifecycle.

This framework establishes the authoritative rules for what metadata must be attached to each class of content, how that metadata must be validated, who is responsible for maintaining it, and what happens when it is incomplete, inaccurate, or fraudulently supplied.

1.2 Governing Principles
  • Accuracy: Every metadata field must truthfully represent the actual state of the content object at the time of submission and must be updated immediately upon any material change.
  • Completeness: Mandatory metadata fields must be populated before any content object is permitted to enter an active, visible, or tradeable state within the platform.
  • Traceability: The full chain of custody — from original submission through every modification, moderation action, or status change — must be immutably recorded in the platform audit log.
  • Non-repudiation: All metadata submissions are cryptographically timestamped and attributed to the authenticated user account that performed the action. Denial of authorship is not a valid defence.
  • Proportionality: Metadata requirements are calibrated to the risk profile of the content category. Higher-risk content (dual-use goods, regulated materials, financial instruments) carries expanded mandatory fields.
  • Data Minimisation: Metadata collected shall not exceed what is necessary for the stated governance and operational purpose, consistent with UK GDPR Article 5(1)(c).
1.3 Content Object Classes
ACore
Product Listings
All tradeable goods, raw materials, and wholesale inventory offers published to the marketplace catalogue.
BCore
Trade Documents
Certificates of origin, quality reports, inspection records, bills of lading, customs declarations.
CStandard
Media Assets
Product images, facility photographs, video files, technical diagrams, and branding assets.
DStandard
Company Profiles
Entity registration data, UBO filings, certifications, accreditations, and capacity statements.
EConditional
AI-Generated Content
Any content object partially or fully produced, classified, or modified by automated AI or ML systems.
FConditional
User Communications
Negotiation messages, offer amendments, and dispute correspondences stored in the platform.
Section 02 — Core Metadata

Universal Metadata Schema

Every content object published to the XB2BX platform, regardless of category, must carry the following Universal Base Metadata. These fields are non-negotiable and are enforced at the platform API layer prior to any content entering an indexable or tradeable state.

2.1 Universal Base Fields
// Universal Base Object — required on ALL content types { "object_id": "UUID v4 — platform-generated, immutable", "object_type": "enum[listing|document|media|profile|ai_content|communication]", "schema_version": "3.0", // Ownership & Attribution "owner_entity_id": "verified corporate entity UUID — mandatory", "submitter_user_id": "authenticated user UUID — mandatory", "submitter_ip_hash": "SHA-256 of originating IP — auto-captured", // Timestamps (ISO 8601 UTC) "created_at": "datetime — platform-stamped on creation", "updated_at": "datetime — updated on every mutation", "published_at": "datetime | null — set when status → active", "expires_at": "datetime | null — mandatory for time-limited content", // Lifecycle Status "status": "enum[draft|pending_review|active|suspended|archived|deleted]", "visibility": "enum[public|restricted|private|confidential]", "moderation_status": "enum[unreviewed|approved|flagged|rejected|under_appeal]", // Provenance "origin_method": "enum[user_submission|api_import|ai_generated|system_migration]", "content_hash": "SHA-256 of canonical content at last verified state", // Legal & Compliance Flags "sanctions_screened": "boolean — mandatory before active state", "trade_control_flag": "boolean — set by dual-use screening engine", "gdpr_lawful_basis": "enum[contract|legal_obligation|legitimate_interests] | null", // Jurisdiction & Locale "jurisdiction": "ISO 3166-1 alpha-2 country of submitting entity", "content_language": "BCP 47 language tag" }
β„Ή API Enforcement The XB2BX platform API will return HTTP 422 (Unprocessable Entity) and reject any content submission that does not satisfy mandatory universal base fields. Partial submissions are not queued — they are discarded and logged with the submitting entity's account.
2.2 Field Classification
ClassObligationEnforcement PointResponsible Party
MandatoryMust be present and valid before publicationAPI validation layerSubmitting entity
Auto-CapturedPlatform-generated; entity cannot overridePlatform infrastructureXB2BX systems
RecommendedStrongly advised; omission may restrict visibilityQuality scoring engineSubmitting entity
ConditionalMandatory only when triggered by content category or flagCategorical validatorSubmitting entity
Section 03 — Core Metadata

Product Listing Metadata Requirements

⚠ Ghost Listing Prohibition Publishing any listing without verified physical inventory ownership or confirmed supply chain access constitutes a "Ghost Listing" under XB2BX Acceptable Use Policy and applicable fraud statutes. All quantity claims are subject to automated verification workflows.
3.1 Required Listing Fields
FieldTypeObligationValidation Rule
product_titleString (5–200 chars)MandatoryNo placeholder text; trade name or specification required
hs_codeString (6–10 digits)MandatoryValid Harmonised System tariff code; validated against WTO schedule
origin_countryISO 3166-1 alpha-2MandatoryCountry of manufacture, not country of seller
quantity_availableDecimal + unitMandatoryMust be supported by storage certificate or supply agreement
unit_of_measureEnum (UN/CEFACT)MandatoryStandard UN unit code (KGM, MTR, LTR, etc.)
minimum_order_qtyDecimalMandatoryMust be ≤ quantity_available
incotermsEnum (ICC 2020)MandatoryMust match agreed delivery scope
quality_standardStringRecommendedISO, ASTM, EN, or equivalent reference
storage_certificate_idDocument UUIDConditionalRequired if quantity > threshold tier or commodity is regulated
dual_use_flagBooleanAuto-CapturedSet by dual-use screening engine against EU Regulation 2021/821
embargo_check_statusEnumAuto-CapturedCleared | Flagged | Blocked — updated at every listing mutation
3.2 Quantity Verification Tiers
T1Auto
Below Threshold
Standard metadata verification only. Algorithmic cross-check against historical supply data.
T2Document
Mid-Volume
Storage certificate or supplier framework agreement required within 72 hours of listing activation.
T3Manual
High-Volume / Regulated
Manual verification by XB2BX Compliance team. Listing suspended until clearance granted. SLA: 5 business days.
Section 04 — Core Metadata

Trade Document Metadata Requirements

Trade documents — including but not limited to certificates of analysis, phytosanitary certificates, bills of lading, inspection reports, customs declarations, and letters of credit — carry elevated metadata obligations given their role as legal instruments in international commerce.

4.1 Document Classification Matrix
Document TypeMetadata ClassExpiry TrackingThird-Party Verification
Certificate of OriginLegal InstrumentRequiredIssuing authority cross-check
Certificate of Analysis / QualityTechnical RecordRequired (batch validity)Accredited lab reference required
Bill of LadingTitle DocumentN/ACarrier reference validation
Phytosanitary / Health CertificateRegulatory PermitRequired (strict)Issuing authority validation
Customs Entry / Export DeclarationRegulatory FilingN/ACustoms reference cross-check
Insurance CertificateFinancial InstrumentRequiredUnderwriter reference required
Inspection / Survey ReportTechnical RecordRequiredAccredited body reference required
4.2 Mandatory Document Metadata Fields
  • document_type: Enumerated classification from the Document Classification Matrix above.
  • issuing_authority: Full legal name and country of the organisation that issued the document. Must not be the submitting entity itself for third-party verification classes.
  • issue_date: ISO 8601 date. Cannot be a future date. Documents dated more than 12 months prior require compliance review before activation.
  • expiry_date: Required for all certificate types. Platform will auto-suspend any listing linked to an expired document at 00:00 UTC on expiry date.
  • document_reference_number: Unique identifier assigned by the issuing authority. Must be unique per issuing authority within the platform database.
  • linked_listing_ids: Array of listing UUIDs this document supports. A document cannot be unlinked from a listing that has active trades referencing it.
  • content_hash: SHA-256 of the document file at the point of upload. Any subsequent file replacement resets moderation status to unreviewed.
  • falsification_risk_flag: Auto-set by document forensic engine. Flagged documents are quarantined pending manual review.
Section 05 — Core Metadata

Media & Image Metadata Controls

β„Ή Stock Image Prohibition Generic stock photography purporting to represent specific products, facilities, or inventory is classified as a Metadata Accuracy Violation. All product images must be verifiable as the actual goods being offered.
5.1 Required Media Metadata
FieldObligationPurpose
capture_dateMandatoryEstablishes temporal relationship to listed inventory
capture_locationRecommendedGeo-tagged coordinates for facility/warehouse imagery
copyright_ownerMandatoryLegal owner of image rights; must be submitting entity or licensed party
license_typeMandatoryEnum: proprietary | cc_by | cc_by_nc | third_party_licensed
ai_generation_flagMandatoryBoolean — must be true if any AI tool was used in generation or enhancement
exif_strippedAuto-CapturedPlatform strips EXIF on storage; original EXIF archived separately
content_moderation_scoreAuto-CapturedAutomated NSFW and trademark violation scoring
perceptual_hashAuto-CapturedpHash for duplicate detection and provenance tracking
watermark_appliedAuto-CapturedXB2BX watermark applied on serving; original archived
5.2 Image Authenticity Verification

The platform operates an automated image authenticity pipeline. Uploaded images are cross-checked against a proprietary database of known stock photography libraries, reverse image search APIs, and AI-generation fingerprint detection models. Images triggering authenticity flags are held in moderation pending manual review. Entities with more than three authenticity violations in a rolling 12-month period will have their media upload privileges suspended.

Section 06 — Compliance & Control

Provenance & Chain of Custody

Provenance metadata establishes the verified origin and unbroken chain of custody for any content object or physical good represented on the platform. This is particularly critical for regulated commodities, goods subject to sanctions screening, and products with geographic indication protections.

6.1 Content Lifecycle Flow
Step 1
Submission
Step 2
Schema Validation
Step 3
Sanctions Screen
Step 4
Moderation
Step 5
Active
Step 6
Archived / Expired
6.2 Provenance Metadata Fields
  • supply_chain_tier: Enumerated position in supply chain (manufacturer | processor | distributor | trader | broker). Self-declared but subject to verification.
  • manufacturer_entity_id: XB2BX registered entity UUID of the actual manufacturer, where known. Required for goods claiming country-of-origin preferential tariff treatment.
  • batch_lot_number: Production batch or lot identifier assigned by the manufacturing entity. Must correspond to attached quality documentation.
  • production_date_range: ISO 8601 date range specifying manufacturing or harvest period. Cannot post-date the submission date.
  • custody_transfer_log: Append-only array of custody events. Each event records entity ID, timestamp, action type, and optional document reference.
  • geographic_indication: Applicable GI or PDO/PGI designation where legally protected (e.g., EU GI Register reference). Claiming a protected designation requires supporting documentation.
  • conflict_mineral_declaration: Required for goods containing tin, tantalum, tungsten, or gold (3TG). Must reference a compliant OECD Due Diligence smelter audit or equivalent.
Section 07 — Compliance & Control

Content Moderation & Classification Controls

7.1 Moderation Status Definitions
StatusDefinitionPlatform BehaviourResolution Path
UnreviewedNewly submitted; not yet assessedNot publicly visible; indexed for internal queueAutomatic — queue processing
ApprovedPassed all automated and manual checksFully visible and tradeableN/A
FlaggedAutomated risk signal triggeredHidden from public; entity notifiedEntity response required within 5 business days
SuspendedActive enforcement actionRemoved from all views; trades blockedFormal compliance review; appeal available
RejectedFails platform standardsPermanently removed; metadata retained for auditAppeal within 14 calendar days
Under AppealRejection or suspension contestedStatus frozen; no changes permittedOutcome within 10 business days
7.2 Automated Moderation Triggers
  • Prohibited Category Keyword Match: Content matching terms on the XB2BX Prohibited Goods Register is automatically rejected and referred to the Compliance team.
  • Document Forensic Anomaly: AI-based analysis detecting signs of digital alteration in uploaded certificates or documents triggers Flagged status.
  • Quantity Anomaly: Declared quantities exceeding statistical norms for the submitting entity's verified supply capacity trigger a Flagged status and T3 verification requirement.
  • Price Anomaly: Prices deviating more than a defined percentage from market reference data trigger a Flagged status pending review.
  • Duplicate Content Hash: A content hash matching an existing Rejected or Suspended object triggers automatic rejection of the new submission.
  • Sanctions Hit: Any positive match in sanctions screening immediately moves content to Suspended status with concurrent Compliance team notification.
Section 08 — Compliance & Control

Sanctions & Trade Control Screening

⚠ Legal Obligation XB2BX operates under a mandatory trade compliance programme. Engaging in or facilitating any transaction, listing, or data interaction that breaches applicable sanctions regimes — including UK, EU, US OFAC, and UN Security Council measures — is a strict liability criminal offence. No commercial justification constitutes a defence.
8.1 Screening Regime Coverage
RegimeAuthorityInstrumentScreening Frequency
UK Consolidated Sanctions ListOFSI / FCOThe Sanctions and Anti-Money Laundering Act 2018Real-time + Daily refresh
EU Consolidated Sanctions ListEuropean CommissionEU Council Regulation frameworksReal-time + Daily refresh
OFAC SDN & Consolidated ListUS TreasuryIEEPA, TWEAReal-time + Daily refresh
UN Security Council SanctionsUN SCSCUN Charter Article 41Daily refresh
UK Export Control ListECJU / DITExport Control Order 2008Per-listing + Weekly refresh
EU Dual-Use RegulationEuropean CommissionRegulation EU 2021/821Per-listing submission
8.2 Sanctions Metadata Fields
  • sanctions_screen_timestamp: UTC datetime of most recent screening run. Must be within 24 hours for any active listing.
  • sanctions_screen_result: Enum: clear | hit_pending_review | confirmed_hit | false_positive_cleared
  • screening_engine_version: Reference to the sanctions list version used. Critical for audit trail defence in case of regulatory enquiry.
  • export_control_classification: Applicable Export Control Classification Number (ECCN) or UK Schedule reference. Mandatory for technology, software, and dual-use goods.
  • end_user_declaration_required: Boolean — set to true automatically for items on the Military End-Use list or where the HS code falls within dual-use categories.
Section 09 — Compliance & Control

Intellectual Property & Licensing Controls

All content objects submitted to the XB2BX platform carry implicit or explicit intellectual property claims. This section governs how IP ownership, licensing status, and third-party rights are recorded, validated, and enforced in platform metadata.

9.1 IP Metadata Requirements
  • ip_ownership_declared: Boolean confirmation that the submitting entity either owns the IP in the submitted content or holds a valid licence to submit and display it on the platform.
  • trademark_references: Array of registered trademark identifiers (TMкласс, class, jurisdiction) that the listing invokes. Unregistered claims must be marked as such.
  • patent_references: Applicable patent numbers for goods where patented technology is a claimed attribute. Expired or ungranted patents must be flagged.
  • third_party_brand_flag: Boolean — set automatically if listing content contains brand names not registered to the submitting entity. Triggers brand verification workflow.
  • content_license: For media and document assets, the applicable licence type must be declared (proprietary, Creative Commons variant, royalty-free commercial, etc.).
  • takedown_history: Immutable record of any prior IP takedown notices associated with the content object or submitting entity. Accessible to Compliance team only.
β„Ή DMCA & UK Copyright Act Alignment XB2BX processes valid IP takedown notices in accordance with the Digital Economy Act 2010 and equivalent EU Directive 2019/790 obligations. Receipt of a valid takedown notice triggers immediate content suspension and notification to the submitting entity. Counter-notices must be submitted through the formal dispute resolution workflow (Section 16).
Section 10 — Operations

Content Lifecycle Management

10.1 Status Transition Rules

Content object status transitions are governed by strict rules. Not all transitions are permitted, and certain transitions are irreversible. The table below defines the authorised state machine.

From StatusTo StatusTriggerReversible?
DraftPending ReviewSubmitting entity submits for publicationYes — can revert to Draft
Pending ReviewActiveModeration approval grantedYes — via suspension
Pending ReviewRejectedModeration rejection issuedOnly via appeal
ActiveSuspendedCompliance action or flag reviewYes — upon resolution
ActiveArchivedExpiry date reached or entity requestNo — archived state is permanent
SuspendedActiveCompliance clearance grantedYes
SuspendedDeletedConfirmed serious violationNo — deletion is irreversible
ArchivedDeletedRetention period expiryNo
10.2 Automatic Lifecycle Events
  • Certificate Expiry: Any content object linked to a document whose expiry_date has passed is automatically moved to Suspended at 00:00 UTC on the expiry date.
  • Quantity Depletion: When a listing's available quantity reaches zero through confirmed trades, it is automatically moved to Archived.
  • Entity Deactivation: All Active content belonging to an entity whose account is suspended or deactivated is moved to Suspended. Content belonging to a terminated entity is Archived after 30 days.
  • Sanctions Re-Screen: All Active listings are re-screened against updated sanctions lists within 4 hours of list publication. Any new positive matches trigger immediate Suspension.
Section 11 — Operations

AI-Generated Content Controls

⚠ Disclosure Obligation Any content object — including product descriptions, technical specifications, translated text, images, or documents — that was generated, classified, or materially modified by an AI or ML system must be disclosed as such via the ai_generation_flag and associated metadata fields. Non-disclosure is treated as a Metadata Accuracy Violation.
11.1 AI Content Metadata Fields
  • ai_generation_flag: Boolean — must be set to true for any content produced or substantially modified by an AI system. Platform may auto-detect and override if detection signals fire.
  • ai_model_reference: Name and version of the AI model(s) used (e.g., GPT-4o, Claude 3.5, Stable Diffusion XL). Required if ai_generation_flag is true.
  • human_review_completed: Boolean — AI-generated content must be reviewed and approved by a verified human user before publication. Automated submission pipelines cannot bypass this requirement.
  • ai_accuracy_attestation: The human reviewer must attest that AI-generated factual claims (quantities, specifications, certifications) have been independently verified against primary sources.
  • generation_prompt_hash: SHA-256 of the prompt or instruction set used to generate the content, for internal audit purposes. Not publicly exposed.
11.2 Restrictions on AI-Generated Content
  • No AI-Generated Legal Instruments: Certificates of origin, inspection reports, bills of lading, and other legal trade documents must be issued by an accredited human or institutional authority. AI-generated versions will be automatically rejected.
  • No Synthetic Product Imagery: Product images must represent the actual goods being offered. AI-generated or digitally rendered product images that do not accurately represent the actual goods are prohibited.
  • AI Classification Assistance: Where the platform's AI classification engine suggests HS codes, quality standards, or category tags, these constitute recommendations only. The submitting entity bears sole responsibility for the accuracy of all submitted metadata.
Section 12 — Operations

Audit Log Requirements

The XB2BX platform maintains an immutable, tamper-evident audit log for every action that creates, modifies, or changes the status of a content object or its associated metadata. This log is the authoritative record for compliance investigations, regulatory enquiries, dispute resolution, and forensic analysis.

12.1 Audit Event Schema
{ "event_id": "UUID v4 — immutable", "event_type": "enum[create|update|status_change|moderation_action|access|delete|appeal]", "event_timestamp": "ISO 8601 UTC — microsecond precision", // Actor "actor_type": "enum[user|system|compliance_admin|api_integration]", "actor_id": "UUID of acting entity (user or system process)", "actor_ip_hash": "SHA-256 — captured for human actors", // Object "object_id": "UUID of affected content object", "object_type": "content object class", // Change Delta "fields_changed": "array of field names modified", "previous_values": "object — field: previous_value pairs (encrypted at rest)", "new_values": "object — field: new_value pairs (encrypted at rest)", // Integrity "log_hash": "SHA-256 chained hash linking to previous audit event", "signature": "HMAC-SHA256 signed by platform audit key" }
12.2 Audit Log Access & Protection
  • Immutability: Audit records cannot be modified or deleted by any user, including platform administrators. Append-only storage with cryptographic chaining ensures integrity.
  • Retention: Audit logs are retained for a minimum of 7 years from the date of the logged event, consistent with UK company records requirements and HMRC guidelines.
  • Access Controls: Full audit log access is restricted to XB2BX Compliance Officers and authorised legal representatives. Entities may request their own audit trail via the Subject Access Request process (GDPR Article 15).
  • Regulatory Disclosure: XB2BX will disclose audit log records to UK regulatory authorities (HMRC, FCA, NCA, OFSI) and law enforcement pursuant to valid legal process without further notice to the affected entity where disclosure would compromise an investigation.
Section 13 — Operations

Retention, Archival & Disposal

13.1 Retention Schedule
Content CategoryActive PeriodArchive RetentionDisposal Method
Product Listings (completed trade)Duration of trade cycle7 years post-completionCryptographic deletion
Product Listings (no trade completed)Until expiry or withdrawal3 years post-archivalCryptographic deletion
Trade DocumentsDuration of associated listing7 years from last associated tradeCryptographic deletion
Media AssetsDuration of linked listing3 years post-archivalSecure deletion
Audit LogsPermanent (append-only)Minimum 7 yearsNot disposed without court order
Moderation RecordsPermanentMinimum 7 yearsNot disposed without court order
Sanctions Screening RecordsPermanentMinimum 10 yearsNot disposed
User Personal DataAccount lifetimePer GDPR erasure rightsGDPR-compliant erasure
βœ“ GDPR Right to Erasure Notwithstanding the retention schedule above, individual natural persons may exercise their right to erasure under UK GDPR Article 17. However, erasure rights do not apply where retention is required by law (e.g., AML obligations, audit trail integrity, or active legal proceedings). Entities will be notified of applicable exemptions within 30 days of erasure request submission.
Section 14 — Operations

Cross-Border Data Transfer Controls

As a global B2B marketplace, XB2BX processes metadata submitted by and relating to entities in jurisdictions across the world. Cross-border data flows involving personal data or commercially sensitive metadata are governed by the following framework.

14.1 Transfer Mechanism Matrix
Destination JurisdictionLegal MechanismApplicable Standard
EU / EEA Member StatesUK Adequacy Regulations 2021UK GDPR Article 45
United StatesInternational Data Transfer Agreement (IDTA)UK GDPR Article 46(2)(d)
Other Adequate CountriesUK Adequacy Regulations (as amended)UK GDPR Article 45
Non-Adequate Third CountriesIDTA + Transfer Impact Assessment (TIA)UK GDPR Article 46
Sanctioned JurisdictionsTransfer prohibitedOFSI / FCO guidance
14.2 Localisation Requirements
  • Russian Federation, People's Republic of China: Data relating to transactions involving entities in these jurisdictions is subject to additional screening and may be subject to data localisation requirements under applicable local law. XB2BX complies with applicable UK and EU trade restrictions affecting these jurisdictions.
  • FATF High-Risk Jurisdictions: Enhanced due diligence metadata is required for all listings submitted by entities registered in jurisdictions on the FATF High-Risk and Other Monitored Jurisdictions list.
  • Platform Primary Storage: All platform metadata is stored on infrastructure located within the United Kingdom and European Economic Area.
Section 15 — Enforcement

Violations, Liability & Penalties

⚠ Platform Liability XB2BX Ltd. operates as a technology marketplace and is not a party to transactions between users. However, XB2BX reserves all rights to take immediate enforcement action against any entity whose metadata submissions violate this framework, applicable law, or platform standards — without liability to the offending entity for consequential commercial losses.
15.1 Violation Classification
ClassDescriptionExamplesConsequence
MinorTechnical non-compliance; no fraud or regulatory breachMissing recommended fields; late expiry updateWarning + 30-day rectification window
ModerateMaterial inaccuracy without evidence of intent to deceiveOverstated quantity; outdated certificateListing suspension; mandatory review
SeriousIntentional misrepresentation or document falsificationForged certificate; ghost listing; false origin claimAccount suspension; legal referral; civil claim
CriticalSanctions violation; fraud; criminal activityPositive sanctions hit; trade finance fraudImmediate termination; mandatory regulatory disclosure; criminal referral
15.2 Indemnity & Liability Allocation

Each submitting entity agrees, as a condition of platform access, to fully indemnify and hold harmless XB2BX Ltd., its directors, officers, employees, and contracted agents against any and all losses, claims, penalties, regulatory fines, legal costs, and third-party damages arising from:

  • Inaccurate, incomplete, falsified, or fraudulent metadata submitted by the entity or its authorised users.
  • Failure to update metadata to reflect material changes in the status, availability, or characteristics of listed goods or documents.
  • Breach of applicable sanctions, trade control, or anti-money laundering obligations in connection with platform activity.
  • Infringement of third-party intellectual property rights through content submitted to the platform.
  • Non-compliance with applicable data protection law in the collection and submission of personal data embedded in metadata fields.
Section 16 — Enforcement

Disputes, Appeals & Resolution

16.1 Appeal Process
Day 0
Notice Issued
Day 1–14
Appeal Submitted
Day 15–17
Acknowledgement
Day 17–27
Review
Day 27
Decision
16.2 Appeal Eligibility
  • Rejection Decisions: Must be submitted within 14 calendar days of notification. Appeals submitted after this window will not be accepted without exceptional circumstances.
  • Suspension Decisions: Must be submitted within 10 business days. The suspension remains in effect during the appeal process unless XB2BX issues a provisional lifting order.
  • Account Termination: Must be submitted within 21 calendar days. Legal representation is strongly recommended for termination appeals given their binding nature.
16.3 Required Appeal Content
  • Full legal entity name, registration number, and XB2BX account identifier.
  • Specific grounds of appeal with reference to the violation classification and the factual basis for dispute.
  • Supporting evidence — original documents, corrected metadata, third-party verification, or other relevant materials.
  • Declaration signed by an authorised signatory of the entity attesting to the truth and completeness of the information provided.
16.4 Governing Law & Jurisdiction

This framework and all disputes arising from it are governed by the laws of England and Wales. The parties irrevocably submit to the exclusive jurisdiction of the courts of England and Wales in respect of any dispute, claim, or proceedings arising out of or in connection with this framework or its subject matter. This does not limit XB2BX's right to seek injunctive relief in any jurisdiction where an entity holds assets or conducts operations.

β—ˆ Contact For all compliance, metadata, and appeals correspondence: compliance@xb2bx.com — For legal notices and regulatory communications: legal@xb2bx.com — For data protection enquiries: policy@xb2bx.com
live chat xb2bx
Items (0)
No Record Found

Your Shopping Bag Is Empty