1. Introduction & Scope
HALBEX is committed to protecting the personal data of buyers, exporters, logistics partners and visitors to the platform. This policy explains what personal data we process, why we process it, the legal bases we rely on, and the rights you have over your data under the DPDP Act 2023, the GDPR and GCC data regulations.
This policy applies to all HALBEX surfaces, including the public website, the buyer portal, the seller portal and any related services.
2. Data Controller
Halbex Private Limited, Mumbai, Maharashtra, India, is the data controller (or equivalent data fiduciary under the DPDP Act 2023) for personal data processed through the platform. Contact details for our Grievance Officer are set out in the final section.
3. Data We Collect
We collect only the personal data needed to operate a compliant, escrow-protected trade platform. We minimise collection by design and never share buyer and seller identities with each other.
- Business identity data — company name, trade licence, registration and tax identifiers.
- Contact data — business email, phone number and authorised-user names.
- Verification data — KYB/KYC documents, bank account and beneficiary details.
- Trade data — orders, RFQs, shipping documents, certificates and escrow instructions.
- Technical data — IP address, device, browser, and usage logs for security and fraud prevention.
4. Purposes & Legal Bases
Purpose and applicable lawful basis
| Purpose | GDPR basis | DPDP / GCC basis |
|---|---|---|
| Performing a contract (orders, escrow, logistics). | Performance of a contract. | Performance of a contract / legitimate business purpose. |
| KYB/KYC and sanctions screening. | Legal obligation. | Legal obligation / compliance with law. |
| Security, fraud prevention and platform integrity. | Legitimate interests. | Legitimate use / legitimate interests. |
| Marketing (with consent where required). | Consent. | Consent. |
Consent
Where we rely on consent (for example for marketing communications), you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
5. Blind-Trade Confidentiality Guarantees
HALBEX operates a strict Blind-Trade architecture. Buyer and Seller personal data is never shared between the parties: buyer identity, seller identity, pricing and margins are withheld from each other throughout the trade lifecycle.
- Zero PII sharing — no buyer personal data is disclosed to the Seller, and no seller personal data is disclosed to the Buyer.
- Switch Bill of Lading — carriers and logistics partners cannot see buyer or seller identities or trade margins.
- Encrypted trade vaults — trade documents and counterparty data are stored in AES-256 encrypted vaults with access controls and audit logs.
Encryption at rest
Trade vaults and counterparty records are encrypted at rest using AES-256, with transport protected using TLS, so data is unreadable to unauthorised parties even if storage is compromised.
6. Data Subject Rights
Depending on your location, you may have the following rights. We honour them across the platform regardless of the specific statute that gives rise to them.
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Erasure — request deletion where no legal basis for retention remains.
- Restriction and objection — restrict or object to processing in defined circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Consent withdrawal and grievance — withdraw consent and lodge a complaint with our Grievance Officer or your supervisory authority.
7. Cross-Border Transfers & GCC Data Regulations
Because HALBEX serves approved buyers across international markets including GCC member states, personal data may be transferred across borders. Where data leaves its home jurisdiction we apply appropriate safeguards, including standard contractual clauses and data-localisation requirements where mandated (for example under DPDP or applicable GCC data regulations).
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy and to satisfy legal, tax, accounting and dispute-resolution obligations. Where statute requires longer retention (for example tax records), we retain only the minimum required and then delete or anonymise the data.
9. Data Security
We implement technical and organisational measures to protect personal data, including AES-256 encryption at rest, TLS in transit, role-based access controls, immutable audit logs, and periodic security reviews. In the event of a personal-data breach that poses a risk to your rights, we notify affected parties and regulators as required by law.
11. Children's Data
HALBEX is a business-to-business platform and does not knowingly collect personal data from children. If you believe a child has provided personal data, contact our Grievance Officer and we will delete it promptly.
12. Grievance Officer & Contact
To exercise your rights, withdraw consent, or raise a privacy concern, contact our Grievance Officer at privacy@halbex.com or write to Halbex Private Limited, Mumbai, Maharashtra, India. You may also lodge a complaint with your local data-protection supervisory authority.