Security & Cyber Protection

Security & Cyber Protection Policy — XB2BX.COM
XB
XB2BX.COM
Global B2B Marketplace
Official Policy Document
XB2BX LTD — Compliance & Legal Framework
Security &
Cyber Protection
Policy
Comprehensive framework governing data privacy, cybersecurity, user rights, and platform protection across the XB2BX global marketplace.
180+ Countries Covered
GDPR EU Compliant
ISO 27001 Aligned
24/7 Security Monitoring
Issued by: XB2BX LTD — Legal & Compliance Division
Jurisdiction: England & Wales — Global Application
Document ID: XB2BX-SEC-POL-2025-001
Version 2.0
Effective: January 1, 2025
Next Review: January 1, 2026

XB2BX.COM is a global Business-to-Business (B2B) digital marketplace operated by XB2BX LTD, registered in England & Wales, connecting buyers, suppliers, manufacturers, exporters, and service providers across more than 180 countries. This Security & Cyber Protection Policy ("the Policy") constitutes a legally binding framework governing the collection, processing, storage, and protection of all data on the platform.

This document is designed to protect the rights of individual users, business entities, and XB2BX LTD itself. It reflects our commitment to international standards including the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA), and ISO/IEC 27001 security principles. By accessing or using the XB2BX platform, all users unconditionally agree to be bound by the provisions set out herein.

Table of Contents
Definitions & Scope

The following definitions apply throughout this Policy and all related XB2BX LTD documentation:

"Platform"
The XB2BX.COM website, mobile applications, APIs, and all associated digital services operated by XB2BX LTD.
"User"
Any individual, business representative, company, or automated system that accesses, registers with, or interacts with the Platform in any capacity.
"Personal Data"
Any information relating to an identified or identifiable natural person, including but not limited to: name, email address, IP address, device identifiers, transaction records, and behavioural data.
"Business Data"
Corporate registration details, trade documents, product listings, pricing information, and any commercially sensitive data submitted by registered companies.
"Controller"
XB2BX LTD, which determines the purposes and means of processing personal data.
"Processor"
Any third party that processes personal data on behalf of XB2BX LTD under a formal Data Processing Agreement.
"Data Breach"
Any confirmed or suspected unauthorised access, disclosure, alteration, loss, or destruction of personal or business data.
"DPO"
Data Protection Officer — the designated officer responsible for overseeing compliance with this Policy and applicable data protection laws.
Scope: This Policy applies universally to all users, employees, contractors, and third-party service providers operating within or in connection with the XB2BX platform, regardless of geographic location. International users are advised that additional local regulations may apply concurrently.
Governance & Accountability
πŸ› Organisational Responsibility

XB2BX LTD maintains a dedicated Security & Compliance function with clear executive accountability. Ultimate responsibility for data protection and cybersecurity rests with the Board of Directors, supported by the following roles:

Role Responsibility Accountable For
Board of Directors Strategic oversight & ultimate liability Policy approval, resource allocation
Data Protection Officer (DPO) GDPR & international compliance oversight Regulatory reporting, DSARs, impact assessments
Chief Information Security Officer (CISO) Technical security architecture Threat management, incident response, audits
Legal & Compliance Team Policy enforcement & legal risk Contract review, regulatory liaison
Platform Operations Day-to-day security implementation Monitoring, patch management, access control

Policy Review & Updates

This Policy is reviewed annually or upon any significant change to our operations, technology, or applicable legislation. Users will be notified of material changes via:

  • Email notification to all registered account holders
  • Prominent banner notice on the XB2BX.COM homepage for a minimum of 30 days
  • In-platform notification upon next login
  • Version history published in the Policy Archive section of the website

Continued use of the Platform following notification of changes constitutes acceptance of the updated Policy.

Data Collection & Legal Basis
πŸ“‹ What Data We Collect

Account & Identity Data

  • Full name and business title
  • Company name and registration number
  • Email address and telephone number
  • Physical and registered business address
  • VAT / Tax identification numbers
  • Government-issued identity verification documents (KYB/KYC)

Transaction & Commercial Data

  • Purchase and sales transaction records
  • Product enquiries and RFQ submissions
  • Payment method metadata (no raw card data stored)
  • Trade credit and financing applications
  • Shipping and logistics documentation
  • Dispute and complaint records

Technical & Device Data

  • IP address and geolocation (country/city level)
  • Browser type, version, and operating system
  • Device identifiers and session tokens
  • Access timestamps and page interaction logs
  • API call logs and integration activity

Communications Data

  • Platform messaging between buyers and sellers
  • Support ticket and live chat transcripts
  • Email correspondence with XB2BX teams
  • Review and rating content submitted by users
  • Survey and feedback responses

Legal Basis for Processing

Processing Activity Legal Basis (GDPR Art.) Notes
Account registration & contract fulfilment Article 6(1)(b) — Contract Necessary to provide services
Legal compliance & KYB verification Article 6(1)(c) — Legal obligation AML, sanctions screening
Marketing communications Article 6(1)(a) — Consent Opt-in; withdrawable at any time
Fraud prevention & platform security Article 6(1)(f) — Legitimate interest LIA conducted and documented
Analytics & platform improvement Article 6(1)(f) — Legitimate interest Anonymised where possible
Special category data (where applicable) Article 9(2)(a) — Explicit consent Collected only when strictly necessary
Data Minimisation Commitment: XB2BX LTD collects only the minimum data necessary to fulfil the stated purpose. We do not sell, rent, or trade personal data to third parties for their own marketing purposes under any circumstances.
Purpose of Data Use
🎯 How We Use Your Data

XB2BX LTD uses collected data exclusively for the following defined and documented purposes:

Core Platform Operations

  • Creating, managing, and authenticating user accounts
  • Facilitating trade introductions between buyers, suppliers, and manufacturers
  • Processing RFQs, orders, and commercial enquiries
  • Providing customer support and dispute resolution services
  • Delivering contracted services including verification badges and premium listings

Trust, Safety & Compliance

  • Know Your Business (KYB) and identity verification
  • Anti-Money Laundering (AML) and sanctions screening against international watchlists
  • Fraud detection, abuse prevention, and account integrity monitoring
  • Enforcement of platform Terms & Conditions and this Policy
  • Compliance with court orders, regulatory investigations, and law enforcement requests (where legally required)

Platform Development & Analytics

  • Aggregated, anonymised analytics to improve platform performance and user experience
  • A/B testing and feature development (using pseudonymised data sets)
  • Market intelligence reports for the global trade community (no individual-level data)

What We Will Never Do

  • Sell, lease, or otherwise transfer personal data to third parties for their commercial benefit
  • Use personal data to make fully automated decisions with significant legal effect without human review
  • Share business-sensitive trade data between competing users without explicit consent
  • Process data for purposes materially different from those stated without fresh consent or a valid legal basis
  • Retain data beyond the periods specified in Section 13 of this Policy
Cybersecurity Controls
ISO 27001 Aligned TLS 1.3 Encrypted AES-256 at Rest SOC 2 Type II PCI DSS Compliant OWASP Top 10 Protected
πŸ”’ Technical Security Measures

Encryption Standards

  • Data in Transit: All communications between users and the platform are encrypted using TLS 1.3 (minimum TLS 1.2). HTTP connections are automatically redirected to HTTPS.
  • Data at Rest: All stored data is encrypted using AES-256 encryption. Database encryption keys are managed via a Hardware Security Module (HSM) with strict access controls.
  • End-to-End Messaging: Private trade communications between platform members use end-to-end encryption protocols ensuring XB2BX LTD staff cannot access message contents except under legally compelled circumstances.
  • Backups: All backup data is encrypted at the same standard as live data, stored in geographically separate locations with restricted access.

Access Control & Authentication

  • Multi-Factor Authentication (MFA) is available and strongly recommended for all accounts; mandatory for verified business accounts and API access
  • Role-Based Access Control (RBAC) governs all internal staff access to production systems and user data
  • Privileged Access Management (PAM) with just-in-time provisioning for administrative access
  • All internal access to personal data is logged, monitored, and subject to quarterly access reviews
  • Automated session timeout and suspicious login detection with real-time user notification
  • Password policies enforcing minimum 12-character complexity; bcrypt hashing for stored credentials

Infrastructure & Network Security

  • Cloud infrastructure hosted on enterprise-grade providers with Tier IV data centre certifications
  • Web Application Firewall (WAF) protecting against OWASP Top 10 vulnerabilities
  • DDoS mitigation at network and application layers with automatic traffic scrubbing
  • Intrusion Detection and Prevention Systems (IDS/IPS) with 24/7 Security Operations Centre (SOC) monitoring
  • Network segmentation separating production, staging, and development environments
  • Regular automated vulnerability scanning and quarterly third-party penetration testing
  • Software Composition Analysis (SCA) for all open-source dependencies

Application Security

  • Secure Software Development Lifecycle (SSDLC) with security review gates at each stage
  • Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) integrated into CI/CD pipelines
  • Content Security Policy (CSP) headers protecting against cross-site scripting (XSS) attacks
  • SQL injection prevention through parameterised queries and ORM usage
  • CSRF token protection on all state-changing operations
  • Bug Bounty programme enabling responsible disclosure by security researchers

Operational Security

  • All XB2BX staff complete mandatory security awareness training upon onboarding and annually thereafter
  • Background screening conducted on all staff with access to production systems or personal data
  • Supplier and contractor security assessments before granting any system access
  • Formal change management process with security sign-off for all infrastructure modifications
  • Disaster Recovery (DR) and Business Continuity Plans (BCP) tested bi-annually with documented RTO/RPO targets
User Rights & Data Subject Requests
βš–οΈ Your Legal Rights

XB2BX LTD fully recognises and upholds all rights afforded to data subjects under the GDPR, UK DPA 2018, CCPA, and equivalent legislation in other jurisdictions. You may exercise any of the following rights at no cost:

Right Description Response Time
Right of Access (SAR) Receive a copy of all personal data XB2BX holds about you, with information on how it is used. 30 days
Right to Rectification Require correction of inaccurate or incomplete personal data without undue delay. 14 days
Right to Erasure Request deletion of your personal data where there is no legitimate legal basis for retention. 30 days
Right to Restrict Processing Limit processing while accuracy or the legal basis for processing is disputed. 72 hours (acknowledgment)
Right to Data Portability Receive your data in a structured, machine-readable format (JSON or CSV) for transfer to another service. 30 days
Right to Object Object to processing based on legitimate interests, including profiling and direct marketing. 14 days
Rights re: Automated Decisions Request human review of any automated decision with significant legal or commercial impact. 30 days
Right to Withdraw Consent Withdraw any previously given consent for processing at any time without penalty. Immediate effect

How to Submit a Request

Submit a Data Subject Access Request (DSAR) through any of the following channels:

  • Online: Via the Privacy Dashboard in your account settings (authenticated users)
  • Email: privacy@xb2bx.com — include full name, account email, and nature of request
  • Post: Data Protection Officer, XB2BX LTD, [Registered Address], England
Identity Verification: To protect your privacy, we may require you to verify your identity before processing a DSAR. We will acknowledge receipt within 5 business days. If a request is complex or requires an extension, we will notify you within the initial 30-day period and explain the reason.
Complaints: If you believe your rights have not been respected, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or the relevant supervisory authority in your jurisdiction. We encourage you to contact us first to resolve concerns directly.
Third-Party & Cross-Border Data Transfers
🌐 Third-Party Processors

XB2BX LTD engages third-party service providers strictly as data processors, bound by Data Processing Agreements (DPAs) that enforce equivalent or higher data protection standards. Categories of processors include:

Category Purpose Data Shared
Cloud Infrastructure Providers Hosting, storage, compute All platform data (encrypted)
Payment Processing Partners Secure transaction handling Transaction metadata (not raw card data)
Identity Verification (KYB/KYC) Business and user verification Identity documents, registration data
Email & Communication Services Transactional and marketing emails Email address, name, preferences
Analytics Providers Platform usage analytics Anonymised behavioural data
Fraud Prevention & AML Risk screening and sanctions checks Identity data, transaction patterns
Customer Support Platform Helpdesk and ticket management Account info, support interactions
Legal & Regulatory Advisors Compliance and legal obligations Disclosed only as legally required

International Data Transfers

As a global marketplace serving 180+ countries, data may be transferred to and processed in countries outside the United Kingdom and European Economic Area (EEA). All such transfers are safeguarded by one or more of the following mechanisms:

  • UK Adequacy Regulations: Transfers to countries deemed adequate by the UK Secretary of State
  • Standard Contractual Clauses (SCCs): EU Commission-approved SCCs incorporated into all DPAs with non-adequate country processors
  • UK International Data Transfer Agreements (IDTAs): For transfers from the UK under the Data Protection Act 2018
  • Binding Corporate Rules (BCRs): Where applicable within group structures
  • Adequacy Decisions: Where the destination country has received an adequacy decision
User Rights on Transfer: You may request details of the specific transfer mechanisms applied to your data by contacting our DPO at privacy@xb2bx.com. A full list of current third-party processors is available upon request.
Incident & Breach Response
🚨 Security Incident Response Protocol

XB2BX LTD maintains a formally documented Incident Response Plan (IRP) aligned with NIST SP 800-61 and tested through bi-annual tabletop exercises. The following timeline governs our response to any confirmed data breach:

HOUR 0–4: DETECTION & CONTAINMENT
Automated monitoring systems or reported incidents trigger immediate CISO notification. Incident Response Team convened. Affected systems isolated to prevent further compromise. Evidence preservation initiated.
HOUR 4–24: ASSESSMENT & ESCALATION
Forensic investigation to determine scope, nature, and categories of data affected. Senior management and legal team engaged. Decision on regulatory notification requirement. User accounts at risk secured.
HOUR 24–72: REGULATORY NOTIFICATION
If the breach poses a risk to the rights and freedoms of individuals, notification filed with the ICO (and other applicable supervisory authorities) within 72 hours of awareness, as required by GDPR Article 33.
DAY 3–7: USER NOTIFICATION
Where a breach is likely to result in high risk to affected individuals, direct notification issued to impacted users without undue delay (GDPR Article 34), including: nature of breach, data affected, likely consequences, and protective measures taken.
DAY 7–30: REMEDIATION & REVIEW
Root cause analysis completed. Technical and procedural fixes implemented. Post-incident review with documented lessons learned. Breach recorded in the platform's internal breach register. Regulatory follow-up completed.
User Reporting: If you suspect unauthorised access to your account or believe your XB2BX data has been compromised, contact our Security Team immediately at security@xb2bx.com or via the in-platform emergency reporting button. Do not attempt to investigate a suspected breach yourself.
Regulatory Compliance Framework
πŸ“œ Applicable Laws & Standards
Regulation / Standard Jurisdiction XB2BX Commitment
GDPR (EU) 2016/679 European Union Full compliance for all EU data subjects
UK Data Protection Act 2018 United Kingdom Primary governing legislation
CCPA / CPRA California, USA Opt-out rights, disclosure obligations
PIPEDA Canada Consent and accountability principles
PDPA Thailand / Singapore Local representative designations
LGPD Brazil Lawful basis and data subject rights
ISO/IEC 27001:2022 International ISMS framework adoption
PCI DSS v4.0 International Payment data security compliance
Network & Information Systems (NIS) Regulations UK Incident reporting obligations
FATF AML Recommendations International KYB, sanctions screening, transaction monitoring
XB2BX LTD conducts Data Protection Impact Assessments (DPIAs) for all new high-risk processing activities before implementation. Our DPO maintains an Article 30 Records of Processing Activities (RoPA) register, reviewed quarterly.
Acceptable Use Policy
πŸ“ Platform Usage Standards

All users of XB2BX.COM agree to comply with this Acceptable Use Policy as a binding condition of platform access. Violations may result in immediate account suspension, permanent ban, civil legal proceedings, and/or referral to law enforcement authorities.

Permitted Use

  • Legitimate B2B trade enquiries, negotiations, and commercial transactions
  • Accurate representation of your company, products, capabilities, and credentials
  • Responding truthfully to buyer enquiries and providing accurate product specifications
  • Using the platform's messaging and RFQ tools for genuine commercial communication
  • Accessing your own account data and exercising your data subject rights

Strictly Prohibited Activities

  • Fraudulent Misrepresentation: Creating false or misleading listings, fake company profiles, or impersonating other businesses
  • Sanctions Violations: Trading with sanctioned individuals, entities, or countries in violation of UK, EU, US OFAC, or UN sanctions regimes
  • Cybersecurity Attacks: Attempting to hack, scrape, reverse-engineer, introduce malware, conduct DDoS attacks, or otherwise interfere with platform infrastructure
  • Unauthorised Data Harvesting: Using automated bots, scrapers, or crawlers to extract user data, contact information, or commercial intelligence from the platform
  • Money Laundering & Fraud: Using the platform to facilitate financial crime, trade-based money laundering, or payment fraud
  • Counterfeit & Prohibited Goods: Listing, promoting, or trading in counterfeit, stolen, or legally prohibited products
  • Spam & Unsolicited Contact: Bulk unsolicited messaging, phishing attempts, or using platform data to contact users outside the platform
  • Intellectual Property Infringement: Uploading content that infringes the IP rights of third parties, including copyrighted images, trademarks, or trade secrets
  • Account Sharing & Multi-Accounting: Sharing login credentials, operating multiple accounts for the same entity, or creating accounts on behalf of sanctioned parties

Enforcement & Consequences

Violation Severity Platform Response Additional Actions
Minor (first offence) Warning notice and mandatory policy review Activity log review
Moderate Temporary account suspension (7–90 days) Content removal, listing suspension
Serious Permanent account termination Forfeiture of fees; civil claim reserved
Criminal / Regulatory Immediate ban and data preservation Mandatory law enforcement referral
Intellectual Property Protection
IP Rights & Platform Content

XB2BX Platform IP

All intellectual property rights in the XB2BX platform, including but not limited to: software code, interface design, algorithms, trade marks, logos, database structures, and compiled data analytics products, are the exclusive property of XB2BX LTD. No licence is granted to any user to reproduce, distribute, or create derivative works without express written permission.

User-Submitted Content

  • Users retain ownership of all original content they upload (product images, descriptions, company profiles)
  • By uploading content, users grant XB2BX LTD a non-exclusive, worldwide, royalty-free licence to display, distribute, and use that content solely for platform operation and promotion
  • Users warrant that all uploaded content does not infringe the IP rights of any third party
  • XB2BX LTD will remove infringing content promptly upon receipt of a valid takedown notice under the applicable jurisdiction's safe harbour provisions

IP Infringement Reporting

To report IP infringement on the platform, submit a formal notice to legal@xb2bx.com including: your contact details, identification of the infringing content and its URL, identification of the original work, a statement of good faith belief, and a declaration of accuracy. We will acknowledge valid notices within 5 business days.

Trade Secrets & Confidential Information

XB2BX LTD will not disclose trade secrets, confidential pricing, supplier lists, or proprietary technical specifications shared by users in the course of trade to any competing party. Our staff are bound by strict confidentiality agreements, and all such data is marked and handled under our Information Classification Policy.

Limitation of Liability
⚠️ Legal Liability Framework
Important Legal Notice: This section constitutes a material term of the agreement between XB2BX LTD and all platform users. Users are advised to read this section carefully before using the platform.

Platform's Liability

XB2BX LTD's aggregate liability to any user arising from or in connection with use of the Platform shall not exceed the greater of: (a) the total fees paid by that user to XB2BX LTD in the 12 months preceding the event giving rise to the claim; or (b) £500 GBP.

XB2BX LTD shall not be liable for:

  • Indirect, special, consequential, or punitive damages of any kind
  • Loss of revenue, profit, business, or contracts arising from use of the platform
  • Acts, omissions, or fraudulent conduct of other platform users
  • Service interruptions resulting from force majeure events, including cyberattacks beyond reasonable control
  • Accuracy of information submitted by third-party users in their listings or profiles
  • Trade disputes, delivery failures, or quality issues between buyers and sellers

User Indemnification

Users agree to indemnify, defend, and hold harmless XB2BX LTD, its directors, officers, employees, and agents from and against any claims, liabilities, damages, and costs (including legal fees) arising from: (a) user's breach of this Policy or the platform Terms & Conditions; (b) user's violation of any applicable law or third-party rights; (c) content submitted by the user to the platform; or (d) user's fraudulent or wilfully harmful conduct.

Exclusions

Nothing in this Policy limits XB2BX LTD's liability for: death or personal injury caused by our negligence; fraud or fraudulent misrepresentation; or any other liability that cannot be excluded or limited under applicable law.

Data Retention & Deletion
πŸ—‚ Retention Schedule
Data Category Retention Period Legal Basis for Retention
Active account data Duration of account + 2 years post-closure Contract; Legitimate interest
Transaction & financial records 7 years from transaction date Legal obligation (Companies Act, HMRC)
KYB/KYC identity documents 5 years post-relationship end Legal obligation (AML Regulations)
Communications & messaging logs 3 years from creation Legitimate interest (dispute resolution)
Security & access logs 12 months rolling Legitimate interest (security)
Marketing consent records Until consent withdrawn + 3 years Legal obligation (ePrivacy)
Anonymised analytics data Indefinite (no personal data) N/A — not personal data
Legal hold data Duration of legal proceedings Legal obligation
Secure Deletion: Upon expiry of retention periods, personal data is securely deleted using NIST 800-88 compliant methods. Where deletion is not immediately possible (e.g. backup media), data is suppressed from active processing until its scheduled secure deletion window.
Cookies & Tracking Technologies
πŸͺ Cookie Policy
Cookie Category Purpose Consent Required? Retention
Strictly Necessary Session management, authentication, security No (essential) Session / 1 year
Functional Language preferences, UI personalisation Yes 1 year
Analytics Usage statistics, performance monitoring Yes 2 years
Marketing Remarketing, cross-platform tracking Yes (explicit) 90 days

Users can manage their cookie preferences at any time via the Cookie Preference Centre accessible in the platform footer. Withdrawing consent for non-essential cookies will not affect platform functionality. We do not use fingerprinting or persistent tracking technologies that bypass standard browser controls.

Minors & Vulnerable Users
πŸ›‘ Child Protection & Vulnerable User Policy

XB2BX.COM is a professional B2B marketplace platform intended exclusively for business use by individuals aged 18 years or older acting in a commercial capacity on behalf of registered business entities.

  • We do not knowingly collect, process, or store personal data of individuals under 18 years of age
  • Age verification is conducted as part of the account registration and KYC/KYB process
  • If we become aware that an account has been created by or on behalf of a minor, we will immediately suspend the account and securely delete all associated personal data
  • Parents or guardians who believe a minor has registered on the platform should contact privacy@xb2bx.com for immediate remediation
  • We apply additional care in our communications and security processes for users who have self-identified as operating in high-risk jurisdictions or industries
Contact, Complaints & Regulatory Bodies
Data Protection Officer
DPO Office
XB2BX LTD
England & Wales
privacy@xb2bx.com
Response: 5 business days
Security Team
CISO & Security Operations
Incident reporting
Vulnerability disclosure
security@xb2bx.com
24/7 monitoring
Legal & Compliance
Legal Team
IP notices, legal requests
Regulatory correspondence
legal@xb2bx.com
Response: 10 business days
General Enquiries
Platform Support
Account & policy questions
support@xb2bx.com
www.xb2bx.com
Live chat available
πŸ› Supervisory Authorities

If you are not satisfied with our response to a privacy complaint, you have the right to escalate to the relevant data protection supervisory authority:

Authority Jurisdiction Website
Information Commissioner's Office (ICO) United Kingdom ico.org.uk
Data Protection Commission (DPC) Ireland / EU Lead dataprotection.ie
CNIL France cnil.fr
Federal Trade Commission (FTC) United States ftc.gov
ANPD Brazil gov.br/anpd
PDPC Singapore pdpc.gov.sg

Governing Law & Effective Date

This Policy is governed by and construed in accordance with the laws of England and Wales. Any disputes arising under this Policy shall be subject to the exclusive jurisdiction of the English courts, without prejudice to any mandatory rights of users under applicable local legislation.

This Policy is effective as of 1 January 2025 and supersedes all previous versions. The current version number is 2.0. Document ID: XB2BX-SEC-POL-2025-001.

By using the XB2BX.COM platform, you confirm that you have read, understood, and agree to be bound by this Security & Cyber Protection Policy in its entirety.

live chat xb2bx
Items (0)
No Record Found

Your Shopping Bag Is Empty