What information we collect, why we collect it, and how it is used.
Last Updated: 12-Dec-2025
Your privacy is important to us, and this Privacy Policy is meant to help you understand what information we collect, why we collect it, and how it is used.
This policy is intended to comply with GDPR, CCPA, and any other relevant jurisdictional laws (e.g., LGPD, PIPEDA).
Note: GlobalFinex B2B may act as either a Data Controller (determines the purposes and means of processing) or a Data Processor (processes data only on the Customer's instructions). The role is determined on a per-service basis.
This Privacy Policy applies to all visitors and users ("you") of GlobalFinex B2B ("we," "our," "us").
If you are a business that has contracted with us, this policy governs the processing of personal data you provide to us or to us via your employees, agents, or authorized third-party partners ("end-users").
By using our Services, you give specific, informed consent for each purpose listed in the Consent & Preference Management table below.
If you do not agree with any part of this policy, you may refuse to use our Services and may withdraw consent at any time (see "Your Rights").
GlobalFinex B2B provides a number of Services to help connect businesses and streamline their processes. These Services include, but are not limited to:
| Term | Definition | GDPR reference | Quick Example |
|---|---|---|---|
| Personal Data | Any information that can identify an individual either directly or indirectly (e.g., name, email, unique identifier). | GDPR Article 4(1) | Email address, phone number |
| Sensitive Personal Data | Personal data likely to cause harm or discrimination if mishandled; also known as "special categories." | GDPR Article 4(13)(14)(15) | Race, religion, health data, biometric data |
| Data Controller | The entity that determines the purpose and means of processing personal data. | GDPR Article 4(7) | GlobalFinex B2B |
| Data Processor | The entity that processes personal data on behalf of the data controller. | GDPR Article 4(8) | Payment-gateway provider |
| Data Subject | The natural person whose personal data is being processed. | GDPR Article 4(1) | Buyer or supplier contact |
| Third-Party Service Provider | External entity receiving personal data for specific services (hosting, analytics, etc.). | GDPR Article 4(10) | Cloud host, email-marketing platform |
| Processing | Any operation performed on personal data, automated or manual. | GDPR Article 4(8) | Storing records, sending payroll emails |
GDPR article: gdpr-info.eu/art-4-gdpr/
Information provided to us
Information we collect when you use our Services
| Purpose | Legal Basis / Quick Example |
|---|---|
| Transaction & Payment Processing | Contractual / Consent (VCN, EFT) |
| KYC / AML Verification | Consent (special category) |
| Marketing / Promotional Offers | Legitimate interest / Consent |
| Service Provider Communications | Legitimate interest |
| Sharing with Trading Partners | Contractual |
| Regulatory Reporting (AML, tax) | Lawful obligation |
| Security & Fraud Prevention | Legitimate interest |
If you have consented to a specific purpose, you may change your mind at any time; this does not affect already-processed data.
Information Storage & Retention
| Data Type | Minimum Retention | Legal / Regulatory Retention | Deletion Method |
|---|---|---|---|
| Personal Data (name, email, phone) | 6 months | 12 months | Secure deletion (AES wipe, key destruction) |
| Payment Information (VCN, bank details) | 12 months | 12 months | Secure deletion |
| KYC/AML Documents | 7 years | 7 years | Secure deletion (destroy all copies, keys, backups) |
| Technical Data (IP, device ID) | 12 months | 12 months | Secure deletion |
Upon request, or at the end of the retention period, data is securely deleted (e.g., encryption keys destroyed).
Security of Your Information
Breach Notification
International Transfer of Information
For EU personal data transferred outside the EU, we use Standard Contractual Clauses (SCCs) and maintain a documented Transfer Impact Assessment (TIA). Servers are located worldwide; data is protected at the same level as within the EU.
Your Rights
How to Exercise These Rights
Requests can be made via email address in the Contact Us section below.
Our Services are primarily provided to organisations, which then make the Services available to you. The contracting organisation is the administrator and is responsible for end-user privacy controls; contact them for any specific privacy questions.
We may update this Privacy Policy from time to time. For material changes, we provide a prominent banner within the Service and send an email to users who have opted in to receive updates at least 14 days before the change. "Material change" includes new services or data uses that differ from the original consent agreement.
Data Protection Officer:
| Country | Supervisory Authority (Data Protection Authority) | Website |
|---|---|---|
| European Union (EU) | European Data Protection Board (EDPB) – coordinates national authorities. National authorities – each member state has its own DPA | edpb.europa.eu |
| Austria | Datenschutzbehörde | dsb.gv.at |
| Belgium | Commission voor de privacy | dataprotectioncommission.be |
| Bulgaria | Commission for Personal Data Protection | csdps.bg |
| Croatia | Independent Commission for Personal Data Protection | pdpa.hr |
| Cyprus | Office of the Commissioner for Personal Data Protection | dpo.gov.cy |
| Czech Republic | Office for Personal Data Protection | uoou.cz |
| Denmark | Danish Data Protection Agency (Datatilsynet) | datatilsynet.dk |
| Estonia | Personal Data Protection Inspectorate (Isikuandmete Kaitseinspektsioon) | iva.ee |
| Finland | Office of the Data Protection Ombudsman | tietooikeus.fi |
| France | Commission Nationale de l'Informatique et des Libertés (CNIL) | cnil.fr |
| Germany | Federal Commissioner for Data Protection and Freedom of Information (BfDI). State-level authorities (Landesdatenschutzbeauftragter) | bfdi.bund.de |
| Greece | Independent Authority for Personal Data Protection (OAED) | oaed.gr |
| Hungary | Hungarian Personal Data Protection Office | adathivatal.gov.hu |
| Ireland | Data Protection Commission (DPC) | dataprotection.ie |
| Italy | Italian Data Protection Authority (Garante) | garanteprivacy.it |
| Latvia | Data Controller Commissioner | dcc.gov.lv |
| Lithuania | State Data Protection Inspectorate | dpat.lt |
| Luxembourg | Commission nationale pour la protection des données | cnddp.lu |
| Malta | Information Technology & Data Protection Commissioner | dataprotection.gov.mt |
| Netherlands | Dutch Data Protection Authority | autoriteitpersoonsgegevens.nl |
| Poland | Office of the Data Protection Commissioner (UODO) | uodo.gov.pl |
| Portugal | National Data Protection Authority | anpd.pt |
| Romania | National Data Protection Authority | ans.dp.ro |
| Slovakia | Office for Personal Data Protection | uko.sk |
| Slovenia | Information Commissioner | uvp.gov.si |
| Spain | Spanish Data Protection Agency | aepd.es |
| Sweden | Swedish Authority for Privacy Protection | imy.se |
| United Kingdom | Information Commissioner's Office (ICO) | ico.org.uk |
| United States | Federal Trade Commission (FTC). California CCPA – Attorney General. New York Privacy Law – Attorney General. Washington Privacy Act – Attorney General. Other states with individual AG offices | ftc.gov · oag.ca.gov/privacy |
| Canada | Office of the Privacy Commissioner of Canada (OPC) | priv.gc.ca |
| Australia | Office of the Australian Information Commissioner (OAIC) | oaic.gov.au |
| Brazil | National Data Protection Authority (ANPD) | gov.br/anpd |
| China | Ministry of Public Security (MPS). Cyberspace Administration (CAC) | mps.gov.cn · cac.gov.cn |
| India | Data Protection Authority (under establishment) | data-protection.gov.in |
| Japan | Personal Information Protection Commission (PPC) | ppc.go.jp |
| South Africa | Information Regulator | justice.gov.za |
| South Korea | Personal Information Protection Commission (PIPC) | pipc.go.kr |
| Singapore | Personal Data Protection Commission (PDPC) | pdpc.gov.sg |
| New Zealand | Privacy Commissioner | privacy.org.nz |
| Mexico | National Institute for Transparency (INAI) | inai.org.mx |
| Argentina | National Directorate for Personal Data Protection (DNEPD) | argentina.gob.ar/dnepd |
| Chile | National Commission for the Protection of Personal Data (CONPDP) | conpdp.cl |
| Colombia | Superintendency of Industry and Commerce | sic.gov.co |
| Russia | Roskomnadzor | rkn.gov.ru |
| Turkey | Data Protection Authority (KVKK) | kvkk.gov.tr |
| Iran | Data Protection Authority | dpo.ir |