Privacy Policy
Last updated: May 14, 2026
1. Who we are
LEDMarketplace is a B2B marketplace operated by [registered company name — to be confirmed], registered in [country of incorporation — to be confirmed] under number [company registration number — to be confirmed], with its registered office at [registered office address — to be confirmed]. For the purposes of the EU General Data Protection Regulation ("GDPR") and the UK GDPR, we are the data controller for the personal data described here.
Data protection contact: [email protected].
Note that most of what flows through the platform is business data about companies, which is not personal data. This policy covers the parts that do identify a person — your name, work email, phone number, and any identity documents submitted during verification.
2. Data we collect
We collect the following, all of it from you directly or generated by your use of the platform. We do not buy data or enrich your profile from third-party sources.
Account data
- Email address, hashed password, role (buyer or seller).
- Contact person's full name, phone number, and country.
- Email verification status and password-reset requests.
Business profile and KYC data
- Company name, business registration number, VAT number, legal form, founding date.
- Registered office address, warehouse address (sellers), billing address (buyers), and delivery addresses.
- Bank account details (IBAN, bank name, account holder) for invoicing reconciliation.
- Documents you upload for verification — for example company registration certificate, VAT certificate, identity document of a representative, or a bank statement — together with the outcome of our review and any rejection reason.
Transaction data
- Quote requests and offers, including product, quantity, pricing, currency, delivery terms, and the messages exchanged.
- Orders, delivery estimates, shipping and tracking information, and payment method and status.
- Product listings you submit as a seller, and our review decisions on them.
Technical and audit data
- IP address and user-agent string, recorded with key account events (sign-up, sign-in, KYC submission) for security and audit purposes.
- Session tokens for authentication, stored hashed.
- Your acceptance of these documents — timestamp and document version.
- Server logs generated automatically when your browser calls our API.
- Interface preferences: chosen language and colour theme.
Cookies and local storage
We use only strictly-necessary cookies plus a language preference cookie. No advertising, analytics, or tracking cookies are set. See our Cookie Policy for the full list.
3. How we use it
- To create and operate your account and verify your business.
- To let you request quotes, respond to quotes, and place or fulfil orders.
- To moderate the marketplace — our support team reviews profiles, product listings, quote requests, offers, and the messages exchanged before forwarding them.
- To send transactional email and in-app notifications (verification, password reset, quote and order updates).
- To prevent fraud, secure the platform, investigate abuse, and keep audit records.
- To comply with tax, accounting, anti-money-laundering, and sanctions obligations.
- To resolve disputes and to establish, exercise, or defend legal claims.
We do not use your data for advertising, we do not sell or rent personal data, we do not use it to train machine-learning models, and we do not currently run third-party analytics or tracking.
4. Legal basis (GDPR / UK GDPR)
- Contract performance (Art. 6(1)(b)) — running your account and processing quotes and orders.
- Legal obligation (Art. 6(1)(c)) — KYC, accounting, tax, sanctions screening, and AML record-keeping.
- Legitimate interests (Art. 6(1)(f)) — fraud prevention, platform security, moderation, audit logging, and defending legal claims. We balance these against your rights and keep the data minimal.
- Consent (Art. 6(1)(a)) — only for optional features that require it. You can withdraw consent at any time without affecting prior lawful processing.
5. How long we keep it
| Data | Retained for | Why |
|---|---|---|
| Account and profile data | Life of the account, then [retention period — to be confirmed] years | Handling post-closure queries and claims |
| KYC documents and decisions | [retention period — to be confirmed] years after the relationship ends | Anti-money-laundering record-keeping |
| Quote, order, and invoice records | [retention period — to be confirmed] years | Tax and accounting obligations |
| Audit and security logs | 12 months | Investigating abuse and security incidents |
| Terms acceptance records | As long as the related account data is kept | Proving which version you agreed to |
When a retention period ends we delete or irreversibly anonymise the data. Where a legal hold applies — an open dispute or an authority request — we keep the affected records until it lifts.
6. Who we share with
- Counterparties on the platform — once we forward a quote, the buyer and seller see each other's business details and contact person as needed to conclude and perform the deal. They become independent controllers of that data.
- Processors — the infrastructure and email providers listed below, who act only on our instructions under a data processing agreement.
- Professional advisers — accountants and lawyers bound by confidentiality.
- Authorities — tax, AML, customs, courts, or law enforcement where legally required.
- A successor — if the business is merged or acquired, subject to this policy continuing to apply.
We do not sell or rent personal data, and we do not share it with advertising networks.
7. Our processors
| Provider | Purpose | Data involved |
|---|---|---|
| Railway Corp. | Application hosting and managed database | All platform data |
| Cloudflare, Inc. | Object storage (R2) for uploaded files, DNS, and network protection | KYC documents, product images, request metadata |
| Zoho Corporation | Transactional and support email delivery | Email address, name, message contents |
If we add or replace a processor we will update this list. Ask us at [email protected] for the current version at any time.
8. International transfers
Some of our providers are established outside the EEA or the UK, or may process data there for support and redundancy. Where that happens we rely on appropriate safeguards — principally the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, and, where applicable, the EU–US Data Privacy Framework.
Separately, if you transact with a counterparty outside the EEA or UK, the business and contact data needed to complete that deal is transferred to them. That transfer is necessary for the performance of the contract you have chosen to enter into.
You can request a copy of the safeguards we rely on by writing to [email protected].
9. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means alone. KYC approval, product review, and quote moderation are decided by a person on our support team, and you can ask us to explain a decision or reconsider it.
10. Your rights
Under the GDPR and UK GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data corrected.
- Request erasure, where no legal retention obligation overrides it.
- Restrict or object to processing based on legitimate interests.
- Receive data you gave us in a portable, machine-readable form.
- Withdraw consent, without affecting processing carried out before.
- Complain to your national data protection authority.
To exercise any of these, write to [email protected]. We respond within one month, and will tell you if we need to extend that for a complex request. We may ask you to confirm your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.
11. Security
We protect your data with HTTPS in transit, bcrypt-hashed passwords, hashed refresh tokens, short-lived access tokens, role-based access control, audit logging, least-privilege database access, and access-controlled document storage. Access to KYC documents is limited to staff who need it for review.
No system is perfectly secure. If a breach is likely to result in a high risk to your rights, we will notify you and the competent supervisory authority as the GDPR requires.
12. Children
LEDMarketplace is a strictly business-to-business service intended for company representatives. It is not directed at, and we do not knowingly collect data from, anyone under 18.
13. Changes to this policy
If we make material changes we will update the "Last updated" date at the top of this page and notify affected users by email or a prominent in-app notice.
14. Contact
Questions, requests, or complaints? Reach our data protection contact at [email protected]. For anything else, email [email protected].