Privacy Policy
Gloseg B2B Limited Effective Date: August 16, 2026 Version: 2.0
Definitions
- "Controller" means Gloseg B2B Limited, which determines the purposes and means of processing personal data described in this Policy.
- "Personal Data" means any information relating to an identified or identifiable individual, including individuals acting on behalf of an Organization.
- "Organization" means the business entity that holds a Gloseg account and on whose behalf Members act.
- "Member" means an individual associated with an Organization's account, such as an owner, admin, manager or member.
- "Verification Documents" means know-your-business and identity documents submitted to support Seller onboarding or Verification Tier assignment.
- "Trade Data" means information generated through Listings, RFQs, Quotes, Orders and escrow activity.
- "Sub-processor" means a third-party provider engaged by Gloseg to process Personal Data on Gloseg's behalf.
- "Data Subject Request" means a request made by an individual to exercise rights described in Clause 12.
- "NDPR" and "NDPA" mean the Nigeria Data Protection Regulation and the Nigeria Data Protection Act, respectively.
- "UK GDPR" and "EU GDPR" mean the retained and European Union General Data Protection Regulation regimes, respectively, as applicable.
1. Controller Identity and Scope
1.1 Who this Policy covers
This Policy describes how Gloseg B2B Limited, acting as controller, processes Personal Data of Members, prospective Members, and other individuals whose data reaches the Platform through Organization use, including individuals named in Verification Documents, invoices, or trade correspondence.
1.2 Relationship to other documents
This Policy should be read together with the Terms of Service, Cookie Policy and any Buyer or Seller specific terms. Where an Organization itself acts as controller of Personal Data it inputs about its own customers or contacts, this Policy does not govern that Organization's separate processing activities.
1.3 Scope of the platform
This Policy applies to Personal Data processed through the Gloseg website, applications, application programming interfaces, support channels and related services.
2. Categories of Personal Data
2.1 Data we collect
2.1.1 Account and organization data
- name, business email, phone number and role of each Member;
- Organization legal name, registration number, registered address and tax identifiers.
2.1.2 Verification documents
- business registration certificates, government identification, proof of address and beneficial ownership declarations submitted for Seller onboarding or Verification Tier upgrade.
2.1.3 Trade and transaction records
- Listing content, RFQ and Quote history, Order details, escrow and payout records, and invoices.
2.1.4 Messaging
- content of messages exchanged between Organizations through the Platform's communication tools, and dispute evidence submitted during a claim.
2.1.5 Device and usage data
- IP address, device identifiers, browser type, log data, and interaction data collected through cookies and similar technologies as described in the Cookie Policy.
2.1.6 Support and community data
- content of support tickets, survey responses and community forum posts, where such features are available.
2.2 Sources of data
2.2.1 Direct sources
Most Personal Data is provided directly by Members during account creation, verification, trading activity and support interactions.
2.2.2 Indirect sources
Some data is generated automatically through use of the Platform, such as device and usage data, or is received from third parties such as payment gateways, sanctions screening providers and identity verification providers.
3. Purposes and Lawful Basis
3.1 Lawful basis table
| Purpose | GDPR lawful basis | NDPR / Ghana DPA basis |
|---|---|---|
| Operating accounts, Orders and escrow | Performance of a contract | Performance of a contract |
| Seller verification and Verification Tier assignment | Performance of a contract, legitimate interests in trust and safety | Contractual necessity, legitimate interest |
| Fraud prevention and sanctions screening | Legal obligation, legitimate interests | Legal obligation |
| Product analytics and service improvement | Legitimate interests | Legitimate interest, with opt-out where required |
| Marketing communications | Consent, or legitimate interests for existing customers where permitted | Consent |
| Responding to Data Subject Requests | Legal obligation | Legal obligation |
| Litigation, regulatory reporting and audit | Legal obligation, legitimate interests | Legal obligation |
3.2 Balancing legitimate interests
Where Gloseg relies on legitimate interests, it has considered whether those interests are overridden by the interests or fundamental rights of the individual concerned, and applies additional safeguards, such as restricted access, where the processing is more sensitive.
4. Verification and KYB Document Handling
4.1 Purpose of collection
Verification Documents are collected to establish that a Seller Organization is a genuine, lawfully operating business, and to assign a Verification Tier reflecting the depth of review completed.
4.2 Restricted internal access
4.2.1 Access limitation
Verification Documents are accessible only to designated trust and safety personnel and compliance personnel, through role-based and row-level access controls that prevent general staff or other Organizations from viewing them.
4.2.2 Retention and disposal
Verification Documents are retained in accordance with the retention schedule in Clause 9 and are disposed of securely once retention periods expire, unless a longer period is required by law or an ongoing investigation.
5. Escrow, Payment and Sanctions Screening
5.1 Payment processing
Personal Data necessary to process escrow funding, milestone release and payouts, such as payment instrument details and banking information, is processed by Gloseg and by payment gateway Sub-processors engaged for that purpose. Gloseg does not itself store full card numbers.
5.2 Sanctions and screening
Gloseg screens Organizations and, where relevant, individuals associated with an Order against applicable sanctions and restricted party lists before enabling certain transactions, to comply with legal obligations and to protect the integrity of the Platform.
5.3 Fraud scoring
5.3.1 Automated indicators
Gloseg uses automated fraud scoring models to flag potentially anomalous account or transaction activity based on Trade Data and usage patterns.
5.3.2 Human review
No decision that produces a legal or similarly significant effect on an Organization, such as account suspension or Order cancellation, is made by solely automated means. Flagged activity is reviewed by trust and safety personnel before final action is taken.
6. Messaging and Dispute Evidence Retention
6.1 Messaging content
Messages sent through Platform communication tools are retained to support Order fulfilment, dispute resolution and compliance obligations, and may be reviewed by Gloseg personnel where necessary to investigate a dispute or suspected policy breach.
6.2 Dispute evidence
Evidence submitted during a Trade Assurance or dispute process, including documents, photographs and correspondence, is retained for the period necessary to resolve the dispute and to satisfy any subsequent audit, legal or regulatory requirement.
7. Cookies
Use of cookies and similar technologies on the Platform, including categories of cookies used and mechanisms for managing preferences, is described in the Cookie Policy, which is incorporated by reference into this Policy.
8. AI and Automated Processing
8.1 Automated features
The Platform uses automated processing, including AI-assisted trade intelligence, pricing suggestions and fraud scoring, to support marketplace functions described in the Terms of Service.
8.2 Safeguards
8.2.1 No solely automated legal effects
No automated process produces a decision with legal or similarly significant effect on an individual or Organization without human review, consistent with Clause 5.3.2.
8.2.2 Data minimisation in model inputs
Gloseg seeks to limit the Personal Data used as model inputs to what is proportionate to the fraud prevention, matching or recommendation purpose being served.
9. Disclosures and Retention Schedule
9.1 Categories of recipients
9.1.1 Sub-processors
Gloseg discloses Personal Data to Sub-processor categories including cloud hosting providers, transactional email providers, payment gateways, analytics providers and communication tooling providers, each engaged under contractual terms requiring appropriate security and confidentiality.
9.1.2 Authorities
Gloseg may disclose Personal Data to regulators, law enforcement or courts where required by law, or to protect the rights, property or safety of Gloseg, its users or the public.
9.2 Retention schedule
| Data category | Typical retention period | Basis for period |
|---|---|---|
| Account and organization data | Duration of account, plus 6 years after closure | Contractual and limitation period considerations |
| Verification documents | Duration of Verification Tier status, plus 6 years | Regulatory and audit requirements |
| Trade and transaction records | 7 years from Order completion | Tax and financial record-keeping obligations |
| Messaging and dispute evidence | 3 years from dispute closure, longer if litigation is ongoing | Evidentiary and legal necessity |
| Device and usage data | Up to 24 months | Security and analytics necessity |
| Support and community data | 3 years from last interaction | Service quality and audit purposes |
10. International Transfers and Safeguards
10.1 Cross-border processing
Given the pan-African and worldwide nature of the Platform, Personal Data may be transferred between and processed in countries outside the country where a Member or Organization is located, including the United Kingdom, European Union member states and other jurisdictions where Sub-processors operate.
10.2 Transfer safeguards
10.2.1 Adequacy and contractual mechanisms
Where Personal Data is transferred internationally, Gloseg relies on adequacy decisions where available, or on standard contractual clauses and equivalent contractual safeguards with Sub-processors, together with technical and organisational measures appropriate to the transfer.
11. Security Measures
11.1 Technical and organisational controls
11.1.1 Access control
Gloseg applies row-level access control so that Organizations and their Members can access only data relevant to their own account and Orders, and so that internal personnel access is limited by role.
11.1.2 Encryption
Personal Data is encrypted in transit using industry-standard transport security, and encrypted at rest within Gloseg's production data stores.
11.1.3 Audit logging
Access to sensitive data categories, including Verification Documents and payment information, is logged to support security monitoring and incident investigation.
11.1.4 Administrative access
Administrative access to production systems requires multi-factor authentication for internal personnel.
11.2 Incident response
Gloseg maintains procedures to detect, assess and respond to security incidents, including notification to affected Organizations and relevant authorities where required by applicable law.
12. Data Subject Rights
12.1 Rights available
Subject to applicable law, individuals may have rights to access, correct, delete, restrict or object to processing of their Personal Data, to receive a copy of certain data in a portable format, and to withdraw consent where processing is based on consent.
12.2 How to exercise rights
12.2.1 Submission channel
Data Subject Requests are submitted through the Privacy & My Data surface at /privacy/my-data, or by writing to legal@gloseg.com where the in-platform route is not accessible.
12.2.2 Identity verification
Gloseg verifies the identity of the requester before actioning a request, which may include confirming account credentials or requesting supporting identification, to prevent unauthorised disclosure of another individual's data.
12.2.3 Timelines
Gloseg responds to a verified Data Subject Request within 30 days of receipt. Where a request is complex or numerous, Gloseg may extend the response period by a further 60 days, and will notify the requester of the extension and the reason for it within the initial 30 day period, where such extension is permitted under applicable law.
12.2.4 Appeal
Where a requester disagrees with the outcome of a Data Subject Request, they may request internal review by writing to legal@gloseg.com, and may separately raise a complaint with a supervisory authority as described in Clause 14.
13. Children's Data
The Platform is a business-to-business service and is not directed at, and must not be used by, individuals under the age of 18. Gloseg does not knowingly collect Personal Data relating to children, and will delete any such data identified on the Platform.
14. Complaints to Supervisory Authorities
14.1 Right to complain
Individuals have the right to lodge a complaint with a supervisory authority in their place of residence, work, or the place of an alleged infringement, without prejudice to any other administrative or judicial remedy.
14.2 Relevant authorities
| Jurisdiction | Authority |
|---|---|
| United Kingdom | Information Commissioner's Office |
| Nigeria | Nigeria Data Protection Commission |
| Ghana | Data Protection Commission |
15. Changes to this Policy
15.1 Updates
Gloseg may update this Policy from time to time to reflect changes in processing activities, Sub-processors or legal requirements. Material changes will be notified through the Platform or by email, with the effective date updated accordingly.
15.2 Continued use
Continued use of the Platform following notice of a material change constitutes acknowledgement of the updated Policy, without limiting any separate re-acceptance requirement described in the Terms of Service.
16. Governing Law and Disputes
16.1 Governing law of this Policy
This Policy and any dispute about the processing described in it are governed by the laws of England and Wales, save that nothing in this clause removes a data subject's right to rely on the mandatory data protection law of their place of residence or work, including the NDPR and NDPA in Nigeria and the Data Protection Act 2012 in Ghana.
16.2 Resolution route
16.2.1 Order of escalation
- Raise the concern first with the Gloseg privacy team, which will respond within 30 calendar days.
- If the response is unsatisfactory, request an internal review, which is handled by a reviewer who was not involved in the original decision.
- If the matter remains unresolved, complain to a competent supervisory authority as described in clause 14, or pursue any judicial remedy available under applicable law.
16.2.2 Relationship to the Terms of Service
- Commercial disputes between an Organization and Gloseg remain subject to the arbitration provisions of the Terms of Service. This clause governs privacy complaints only, and does not require a data subject to arbitrate a statutory data protection right.
16.3 Severability
If any provision of this Policy is held unenforceable, the remaining provisions continue in force, and the unenforceable provision is applied to the fullest extent permitted by applicable law.
Contact
Legal notices, questions about this document, data protection requests and compliance enquiries: legal@gloseg.com
Data subject requests may also be submitted through the Privacy & My Data surface at /privacy/my-data.
Gloseg B2B Limited Accra, Ghana, West Africa