ICOBS
MarketplaceSellersInstitutionsEventsCommunity
iCOBS marketplace preview
Launching soon

Great things are on the way.

ICOBS is building the future of B2B commerce, verified sourcing for Buyers, powerful selling tools for Suppliers, and global event management for Institutions. This section will be live soon.

ICOBS

India's B2B industrial commerce platform connecting manufacturers, buyers, and trade institutions.

Platform

  • Marketplace
  • Community

Company

  • About Us
  • Contact

Legal

  • Terms & Conditions
  • Privacy Policy

© 2026 ICOBS. All rights reserved.

SSL SecuredMSME RegisteredDPIIT RegisteredGST Compliant

Privacy Policy

Last updated: 10 July 2026·ICOBS Global Technologies Private Limited·CIN U63112KA2026PTC215100

Read together with our Terms & Conditions.

On this page

  1. 1.Introduction and Scope
  2. 2.Definitions
  3. 3.Our Role: Data Fiduciary, Controller, and Processor
  4. 4.Information We Collect
  5. 5.Sensitive and Regulated Data — Special Handling
  6. 6.Sources of Data
  7. 7.Purposes of Processing and Lawful Basis
  8. 8.Consent and Withdrawal of Consent
  9. 9.Public Profiles, Listings, and Search Indexing
  10. 10.Cookies and Analytics
  11. 11.How We Share and Disclose Personal Data
  12. 12.Sub-Processors
  13. 13.Cross-Border and International Transfers
  14. 14.Security Measures
  15. 15.Data Retention
  16. 16.Your Rights
  17. 17.Data Deletion and Correction
  18. 18.Children's Privacy
  19. 19.Marketing Communications and Notifications
  20. 20.Automated Processing and AI Features
  21. 21.Third-Party Links
  22. 22.Grievance Redressal and Complaints
  23. 23.Changes to This Policy
  24. 24.Governing Law, Jurisdiction, and General Provisions
  25. 25.Contact Us
On this page
  1. 1.Introduction and Scope
  2. 2.Definitions
  3. 3.Our Role: Data Fiduciary, Controller, and Processor
  4. 4.Information We Collect
  5. 5.Sensitive and Regulated Data — Special Handling
  6. 6.Sources of Data
  7. 7.Purposes of Processing and Lawful Basis
  8. 8.Consent and Withdrawal of Consent
  9. 9.Public Profiles, Listings, and Search Indexing
  10. 10.Cookies and Analytics
  11. 11.How We Share and Disclose Personal Data
  12. 12.Sub-Processors
  13. 13.Cross-Border and International Transfers
  14. 14.Security Measures
  15. 15.Data Retention
  16. 16.Your Rights
  17. 17.Data Deletion and Correction
  18. 18.Children's Privacy
  19. 19.Marketing Communications and Notifications
  20. 20.Automated Processing and AI Features
  21. 21.Third-Party Links
  22. 22.Grievance Redressal and Complaints
  23. 23.Changes to This Policy
  24. 24.Governing Law, Jurisdiction, and General Provisions
  25. 25.Contact Us

1. Introduction and Scope

1.1 This Privacy Policy ("Policy") explains how ICOBS collects, uses, discloses, stores, transfers, and otherwise processes Personal Data when you access or use the Platform, comprising the web application at https://icobs.biz, our associated mobile applications for Android and iOS, our application programming interfaces (APIs), and all related Services.

1.2 ICOBS is a business-to-business ("B2B") marketplace operated by ICOBS Global Technologies Private Limited. We act as an intermediary and marketplace e-commerce entity; we do not own, manufacture, store, or sell the goods or services listed by Sellers, and contracts for goods and services are entered into directly between Buyer and Seller.

1.3 This Policy applies to all Users, including Visitors, Buyers, Sellers, Institutions, Association members, Event organisers, and administrators acting on behalf of any of these, across all channels through which the Platform is made available.

1.4 This Policy is drafted with the Digital Personal Data Protection Act, 2023 ("DPDP Act") as its primary framework, and is aligned, where applicable, with the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"). Nothing in this Policy is intended to grant rights beyond those available under Applicable Law.

1.5 This Policy should be read together with our Terms & Conditions. In the event of a conflict between this Policy and the Terms & Conditions on a matter of Personal Data processing, this Policy governs.

1.6 By accessing or using the Platform, you acknowledge that you have read and understood this Policy. Where processing is based on your consent, we will obtain that consent as described in Section 8, and your use of the Platform does not by itself constitute consent to processing that requires separate, specific consent under Applicable Law.

2. Definitions

2.1 Capitalised terms used but not defined in this Policy have the meanings given in our Terms & Conditions. For the purposes of this Policy:

  • "ICOBS", "Platform", "we", "us", "our" — the ICOBS B2B marketplace, comprising the web application at https://icobs.biz, associated mobile applications (Android/iOS), APIs, and related services, operated by ICOBS Global Technologies Private Limited.
  • "Company" — ICOBS Global Technologies Private Limited, the operator of the Platform.
  • "User", "you", "your" — any person or entity that accesses or uses the Platform, whether registered or not, in any capacity (Visitor, Buyer, Seller, Institution, Association member, Event organiser, or administrator acting on behalf of any of these).
  • "Account" — a registered profile on the Platform.
  • "Personal Data" — as defined under the DPDP Act, meaning any data about an individual who is identifiable by or in relation to such data; "personal information" and "personal data" are used interchangeably in this Policy and, where the GDPR applies, bear the meaning given there.
  • "Data Principal" / "Data Subject" — the individual to whom Personal Data relates. Under the DPDP Act, the term includes, where the Data Principal is a child, the parent or lawful guardian.
  • "Data Fiduciary" — the person who, alone or in conjunction with others, determines the purpose and means of processing Personal Data (the DPDP Act term corresponding to a "Controller" under the GDPR).
  • "Data Processor" — a person who processes Personal Data on behalf of a Data Fiduciary (corresponding to a "Processor" under the GDPR).
  • "Processing" — a wholly or partly automated operation or set of operations performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, sharing, disclosure, dissemination, restriction, erasure, or destruction.
  • "Consent" — any freely given, specific, informed, unconditional, and unambiguous indication of the Data Principal's wishes by which, through a clear affirmative action, the Data Principal signifies agreement to the processing of their Personal Data for a specified purpose.
  • "Sensitive Personal Data" — Personal Data revealing or comprising financial information, official identifiers, government-issued identity documents, biometric or health data, and similar categories that attract heightened protection under Applicable Law, and any "special categories of personal data" under Article 9 of the GDPR.
  • "Sub-Processor" — a third party engaged by us to process Personal Data in connection with the Services.
  • "Applicable Law" — all laws, rules, and regulations applicable to the Platform and the Users, including the DPDP Act and, where relevant, the GDPR, UK GDPR, and CCPA/CPRA.
  • "Payment Processor" — Razorpay Software Private Limited and/or other RBI-authorised payment service providers (PSPs) engaged by the Company.

3. Our Role: Data Fiduciary, Controller, and Processor

3.1 As Data Fiduciary / Controller. For most processing of Personal Data described in this Policy — including Account registration, verification, communications, payments administration, security, analytics, and compliance — ICOBS acts as the Data Fiduciary under the DPDP Act and as the Controller under the GDPR/UK GDPR, because we determine the purposes and means of that processing.

3.2 As Data Processor. In certain circumstances, ICOBS acts as a Data Processor on behalf of a business User who is itself a Data Fiduciary/Controller — for example, where a Seller, Institution, or Association uploads or manages Personal Data of its own personnel, members, or contacts through the Platform, or where a User transmits Personal Data of third parties through RFQs, quotations, messages, or Content. In such cases, the business User remains responsible as the Data Fiduciary/Controller for that Personal Data, must have a lawful basis for providing it to us, and our processing is limited to what is necessary to provide the Services.

3.3 Joint arrangements. Where two or more Users, or a User and ICOBS, jointly determine purposes and means of processing (for example, in the course of a Buyer–Seller transaction), each party is responsible for its own compliance obligations in respect of the Personal Data it controls.

3.4 Significant Data Fiduciary. If ICOBS is notified by the Central Government that it is a Significant Data Fiduciary under the DPDP Act, we will comply with the additional obligations that apply to such a designation, including the appointment of a Data Protection Officer based in India, engagement of an independent data auditor, and periodic Data Protection Impact Assessments.

4. Information We Collect

4.1 We collect the categories of Personal Data set out in the table below. The specific data collected depends on your persona (Visitor, Buyer, Seller, Institution/Association) and the features you use. The lawful basis for each purpose is set out in Section 7.

#CategoryData elements (examples)PersonasSensitivity
4.2.1Account and identity dataFirst and last name, email address, phone number (in E.164 format), password (stored only as a salted hash — we never store plaintext passwords), designation/job title, company name, avatar/profile image, email- and phone-verification flags, account status, last login timestampAll registered UsersStandard
4.2.2Business and company informationCompany/organisation name, company description, year founded, employee count, annual revenue band, export markets, export capability, facility size, business contact email and phone, website URL, company logo and bannerSellers, InstitutionsStandard (may include business-confidential information)
4.2.3Seller profile dataRatings and review data, follower and product counts, badges/certifications, verification fields and statusSellersStandard
4.2.4Institution / Association profile dataInstitution name, type (association, event organiser, government body, NGO), description, contacts, website, member/event/follower counts, key figures, verification fields and status, membership and member-application recordsInstitutions, AssociationsStandard
4.2.5Business office address and geolocationStreet address, city, state, country, PIN code, office email and phone, office type, and geolocation (latitude/longitude) associated with a business officeSellers, InstitutionsStandard (precise geolocation of a business office; not device-level tracking)
4.2.6KYC and verification documentsPAN, Aadhaar, GST certificate/GSTIN, Trade License, Udyam Registration, Company Registration, Registration Certificate, MOU/Bylaws, Signatory PAN, Signatory Aadhaar, 12A, 80G, FCRA, Government Order, bank account details (with IFSC), and other uploaded documents, together with document type, values, and bank-verification (penny-drop) statusSellers, Institutions, authorised signatoriesSensitive / regulated (see Section 5)
4.2.7Payment informationBilling details, transaction identifiers, Razorpay customer identifier, subscription and credit-pack records, invoices, GST details, and refund records. Full card numbers, CVV, and complete bank credentials for card/UPI/netbanking payments are collected and processed directly by our Payment Processor; ICOBS does not store full payment-card data (see Section 4.5)Buyers, Sellers, Institutions who transactSensitive / regulated (financial)
4.2.8Uploaded mediaImages, videos, and PDF documents uploaded as profile media, gallery media, listing media, message attachments, or ContentAll Users who uploadStandard (may embed metadata; see 4.3)
4.2.9Community and user-generated ContentCommunity posts, comments, reactions/likes, follows, saved posts, blogs, and reports you submitAll Users who participateStandard
4.2.10RFQ, quotation, and order dataRFQs, quotations, counter-offers, orders, escrow/milestone records, and associated line items and termsBuyers, SellersStandard (may include commercial-confidential information)
4.2.11Messages and chatMessages, attachments, and metadata exchanged in RFQ, quotation, and order contextsBuyers, Sellers, InstitutionsStandard (may contain Personal Data supplied by you)
4.2.12Ratings and reviewsRatings, written reviews, and responses relating to Sellers and transactionsBuyers, SellersStandard
4.2.13Support and dispute dataSupport tickets, dispute and escalation records, and correspondence with our teamsAll Users who contact usStandard
4.2.14Moderation and enforcement dataReports, blocks, moderation cases, enforcement actions (warn/soft-disable/hard-disable), content-hiding/removal records, restriction reasons and periodsUsers subject to or raising theseStandard
4.2.15Cookies and device informationCookie and similar-technology identifiers, device type and model, operating system, browser, app version, language, screen attributes, and push-notification tokensAll UsersStandard
4.2.16Log files and network dataIP address, access timestamps, referring/exit pages, request and error logs, and security event logsAll UsersStandard
4.2.17Analytics and usage dataPages and screens viewed, features used, searches performed, interactions, session duration, and derived usage metricsAll UsersStandard
4.2.18Marketing preferencesEmail, push, and SMS communication preferences and opt-in/opt-out statusAll UsersStandard
4.2.19Social-login dataWhere you sign in via Google, GitHub, Apple, or LinkedIn: the profile identifier, name, email, and profile image that the provider shares with us, subject to the permissions you grantUsers who use social loginStandard
4.2.20Integration and webhook configuration dataWhere you register an outbound webhook or integration: the destination endpoint URL(s), the signing secrets/keys used to authenticate deliveries to you, the event types you subscribe to, and the event payloads we deliver to your endpoint — which may themselves contain Personal Data (for example, RFQ, quotation, order, or lead details)Users who configure integrations/webhooksStandard (delivered payloads may contain Personal Data)
4.2.21Referral, rewards and ambassador dataReferral codes and links, and referral activity and funnel data (for example, sign-ups, conversions, and attributions); Rewards Wallet balances and transactions; and — for Ambassadors, who may be individuals who are not registered Users — name, contact details, city/state, organisation/designation, PAN, GST (optional), and bank account details (account holder name, account number, IFSC, branch) collected for commission payout and tax complianceReferrers, Ambassadors (including non-Users), and Users participating in the programmesStandard, save for PAN/GST/bank details which are Sensitive / regulated (financial) (see Section 5)

4.3 Metadata in uploads. Media files may contain embedded metadata (for example, EXIF data such as capture time or, in some cases, location). You are responsible for the Content you upload; where you do not wish to share such metadata, remove it before uploading.

4.4 Aggregated and de-identified data. We may create aggregated, anonymised, or de-identified data that does not identify you. Such data is not Personal Data, and we may use it for any lawful purpose, including analytics, product improvement, and reporting, provided we do not attempt to re-identify it.

4.5 Payment data and PCI-DSS

4.5.1 Payments on the Platform are processed by our Payment Processor, Razorpay, and (in future) other RBI-authorised payment service providers (PSPs). ICOBS is not a payment aggregator, payment intermediary, or escrow service provider. We act solely as a technology facilitator that connects Users to RBI-authorised PSPs for payment collection, payouts, refunds, and related financial transactions. When you make a payment, sensitive payment credentials (such as full card number, CVV, UPI PIN, or netbanking credentials) are collected and processed directly by the relevant RBI-authorised PSP in a PCI-DSS-compliant environment.

4.5.2 ICOBS does not store full payment-card numbers or CVV. We retain only transaction metadata necessary to administer subscriptions, credit packs, promotions, one-time payments, refunds, invoicing, and GST compliance, together with a Payment Processor customer identifier and tokens/references returned by the Payment Processor. Any escrow or milestone-payment features displayed on the Platform are facilitated through third-party RBI-authorised PSPs; ICOBS does not hold, control, or safeguard User funds.

5. Sensitive and Regulated Data — Special Handling

5.1 Certain data we process attracts heightened protection under Applicable Law, including financial information and government-issued identity documents collected for KYC and verification (see Section 4.2.6 and Section 4.2.7).

5.2 We handle such data on the following principles:

  • Minimisation. We collect KYC and financial data only from Sellers and Institutions, and only to the extent necessary to verify identity and eligibility, enable payments and payouts, prevent fraud and money laundering, and meet legal obligations.
  • Purpose limitation. We do not use KYC/verification documents for marketing, and we do not disclose them to other Users. Verification results (approved/rejected status and any resulting verified badge) may be displayed; the underlying documents are not.
  • Restricted access. Access to KYC and financial data is limited to authorised personnel and Sub-Processors on a need-to-know basis, subject to confidentiality obligations.
  • Encryption and safeguards. Such data is encrypted in transit and at rest and is subject to the controls in Section 14.
  • Bank verification. Bank account details may be verified via a penny-drop mechanism; we record only the verification status and necessary references.

5.3 Aadhaar. Where an Aadhaar number or Aadhaar-linked document is collected, it is used solely for identity verification of the relevant Seller, Institution, or authorised signatory, in a manner consistent with Applicable Law and any applicable UIDAI requirements. We do not use Aadhaar for any purpose beyond verification and record-keeping required by law.

5.4 GDPR special categories. We do not intentionally collect special categories of personal data under Article 9 of the GDPR (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health, or sexual orientation). Please do not submit such data through Content, messages, or uploads unless strictly necessary; if you do, you consent to its processing solely to provide the Services.

6. Sources of Data

6.1 We collect Personal Data from the following sources:

SourceExamples
Directly from youRegistration and profile details, KYC uploads, RFQs/quotations/orders, messages, Content, support requests, and preferences
AutomaticallyCookies and similar technologies, device and log data, IP address, and usage/analytics data collected as you interact with the Platform
Third partiesSocial-login providers (Google, GitHub, Apple, LinkedIn); the Payment Processor (transaction status and tokens); verification/penny-drop services; and other Users who provide your data in the course of a transaction or interaction (for example, a Buyer naming a contact in an RFQ)
Publicly available or lawful third-party sourcesBusiness registries or verification data used to corroborate KYC information, where permitted by Applicable Law

7. Purposes of Processing and Lawful Basis

7.1 We process Personal Data only for specified, lawful purposes. The table below maps each purpose to the categories of data involved, the DPDP Act basis (consent or a "legitimate use" permitted under Section 7 of the DPDP Act), and the corresponding GDPR lawful basis (Article 6). Where more than one basis applies, we rely on the most appropriate basis for the purpose.

#PurposeData categories (ref. Section 4)DPDP Act basisGDPR lawful basis
7.2.1Create and administer your Account; authenticate logins4.2.1, 4.2.15, 4.2.19Consent / performance of Account arrangementContract (Art. 6(1)(b))
7.2.2Provide the Services (marketplace, RFQ/quotation/order, chat, community, events, subscriptions, credits)4.2.1–4.2.14Consent / legitimate useContract (Art. 6(1)(b))
7.2.3Verify Sellers and Institutions (KYC), including bank verification4.2.6, 4.2.7Legitimate use; compliance with lawLegal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f))
7.2.4Process payments, subscriptions, credit packs, promotions, refunds, invoicing, and GST4.2.7, 4.2.1Performance of arrangement; compliance with lawContract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c))
7.2.5Enable communications between Users and deliver transactional notifications4.2.1, 4.2.11, 4.2.15Legitimate useContract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f))
7.2.6Maintain security, prevent fraud, abuse, and money laundering; enforce our terms and moderation4.2.6, 4.2.7, 4.2.14, 4.2.16Legitimate use (security); compliance with lawLegitimate interests (Art. 6(1)(f)); Legal obligation (Art. 6(1)(c))
7.2.7Operate, maintain, debug, and improve the Platform; analytics and product development4.2.15, 4.2.16, 4.2.17Legitimate useLegitimate interests (Art. 6(1)(f)); Consent for non-essential analytics
7.2.8Personalise your experience and recommendations4.2.15, 4.2.17Consent / legitimate useLegitimate interests (Art. 6(1)(f)); Consent where required
7.2.9Send marketing and promotional communications4.2.1, 4.2.18ConsentConsent (Art. 6(1)(a)); Legitimate interests for existing-customer B2B communications where permitted
7.2.10Provide support, handle disputes, and administer grievances4.2.1, 4.2.13, 4.2.14Legitimate use; compliance with lawContract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c))
7.2.11Comply with legal, regulatory, tax, and law-enforcement obligations; establish, exercise, or defend legal claimsAny relevant categoryCompliance with law; legitimate useLegal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f))
7.2.12Provide AI-assisted features (see Section 20)4.2.9, 4.2.10, 4.2.11, 4.2.17Consent / legitimate useLegitimate interests (Art. 6(1)(f)); Consent where required
7.2.13Operate the Referral, Rewards Wallet, and Ambassador programmes — calculate, track, and pay rewards and commissions; comply with tax/TDS obligations; and prevent and detect fraud and abuse4.2.21, 4.2.1, 4.2.7Performance of arrangement; compliance with law; legitimate use (anti-fraud)Contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f))
7.2.14Effect a business transfer (merger, acquisition, restructuring)Any relevant categoryLegitimate useLegitimate interests (Art. 6(1)(f))

7.3 Change of purpose. If we intend to process your Personal Data for a purpose other than that for which it was collected, and that purpose is not compatible with the original purpose, we will notify you and, where required, obtain your consent before doing so.

7.4 Public Ambassador lookup portal. The public Ambassador lookup portal is read-only and displays only performance and commission summary information (for example, an Ambassador's referral performance and commission tier). It does not expose personal information, bank details, or PAN. Full programme rules are set out in the Referral, Rewards Wallet & Ambassador Program Terms.

7.5 Personal data about prospective referrals. Where a Referrer or Ambassador submits Personal Data about a prospective referral or other third party (for example, a name or contact detail), they must have a lawful basis and any necessary consent to provide that data to us; in respect of such data, the Referrer or Ambassador acts as a Data Fiduciary/Controller, and our processing is limited to operating the programmes (see also Section 3.2).

8. Consent and Withdrawal of Consent

8.1 How we obtain consent. Where processing relies on your consent, we obtain it through a clear affirmative action — for example, checking an unticked box, clicking an "I agree"/"Accept" control, or enabling a specific feature — accompanied by, or with access to, the information required under the DPDP Act, including the purposes of processing, the manner of exercising your rights, and how to complain to the Data Protection Board of India.

8.2 Notice. At or before the time of obtaining consent, we provide a notice describing the Personal Data to be processed and the purpose. This Policy, together with any just-in-time notices shown in the Platform, constitutes that notice.

8.3 Granularity. Where we seek consent for multiple purposes, you may consent to some purposes and decline others, except where a purpose is essential to providing a Service you have requested.

8.4 Consent for those unable to consent. Where the Data Principal is a child or a person with a disability who has a lawful guardian, consent will be sought from the parent or lawful guardian in accordance with the DPDP Act. See also Section 18.

8.5 Withdrawal of consent. You may withdraw your consent at any time, and it will be as easy to withdraw as it was to give. You can withdraw consent by adjusting the relevant setting in your Account, using the unsubscribe or opt-out controls in communications, or contacting us at support@icobs.biz.

8.6 Effect of withdrawal. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. Following withdrawal, we will cease the relevant processing and cause our Sub-Processors to do the same, unless another lawful basis (such as a legal obligation or the establishment/defence of legal claims) permits continued processing. Withdrawing consent essential to a Service may mean we can no longer provide that Service.

8.7 Consent Manager. Where a Consent Manager framework is operative under the DPDP Act, you may be able to give, manage, review, and withdraw consent through a registered Consent Manager. We will honour valid instructions received through such a mechanism.

9. Public Profiles, Listings, and Search Indexing

9.1 The Platform is a marketplace, and certain information is public by design. Depending on your persona and settings, the following may be visible to other Users and to the general public, including persons who are not registered:

  • Seller and Institution profiles, including company name, description, logo/banner, location (city/state/country), export/business attributes, verified badges, ratings, reviews, follower and product counts;
  • Product and service Listings and their media and details;
  • Community Content you publish (posts, comments, blogs), and your public display name and avatar;
  • Event pages and organiser information; and
  • Ratings and reviews you submit.

9.2 Search-engine indexing. Public pages (including profiles, listings, community posts, and event pages) may be crawled and indexed by third-party search engines and may appear in their results and caches. We do not control third-party search engines, and content removed from the Platform may persist in third-party caches for a time.

9.3 Your control. Do not publish Personal Data (yours or others') in public fields, Content, or Listings that you do not wish to be public. Where the Platform provides visibility controls, you may use them to limit disclosure; contact-level details shared within a specific transaction are visible to the counterpart to that transaction.

10. Cookies and Analytics

10.1 We and our Sub-Processors use cookies, SDKs, pixels, local storage, device identifiers, and similar technologies to operate the Platform, remember your preferences, secure your session, measure usage, and (where you consent) personalise content and measure marketing.

10.2 Non-essential cookies and analytics are set only with your consent where required by Applicable Law (including the ePrivacy regime and the GDPR). You can manage preferences through our cookie controls and your browser or device settings.

10.3 Full details of the categories of cookies, their purposes, durations, and how to manage them are set out in our Cookie Policy.

11. How We Share and Disclose Personal Data

11.1 We do not sell your Personal Data. We share Personal Data only as described below.

11.2 With other Users (marketplace interactions). To operate the marketplace, we share necessary information between Buyers, Sellers, and Institutions — for example, contact and transaction details exchanged through RFQs, quotations, orders, escrow, and chat. Information you publish publicly is shared as described in Section 9.

11.3 With Sub-Processors. We share Personal Data with the Sub-Processors listed in Section 12, which process it on our behalf under contractual terms requiring confidentiality, security, purpose limitation, and compliance with Applicable Law.

11.4 With the Payment Processor and financial partners. Payment and KYC/verification data is shared with Razorpay and other RBI-authorised payment service providers (PSPs), and with bank-verification services, to process payments, payouts, refunds, and verification. ICOBS is not a payment aggregator, payment intermediary, or escrow service provider; we act solely as a technology facilitator connecting Users to RBI-authorised PSPs. ICOBS does not receive, hold, or safeguard User funds.

11.5 For legal and regulatory reasons. We may disclose Personal Data where necessary to comply with Applicable Law, a lawful request or order of a court, regulator, or law-enforcement authority (including the Nodal Contact Person process under the IT Rules), to enforce our terms, to prevent fraud or harm, or to establish, exercise, or defend legal claims.

11.6 Business transfers. If we are involved in a merger, acquisition, financing, reorganisation, sale of assets, or insolvency, Personal Data may be transferred as part of that transaction, subject to the recipient being bound by protections consistent with this Policy. We will notify you of any such transfer that materially affects your Personal Data as required by Applicable Law.

11.7 With your direction or consent. We share Personal Data with third parties where you direct us to do so or otherwise consent.

11.8 Professional advisers and auditors. We may share Personal Data with our auditors, insurers, and legal, tax, and financial advisers where necessary and subject to confidentiality.

11.9 User-configured outbound webhooks, integrations, and exports. Where you configure an outbound webhook, integration, or data export, ICOBS transmits the relevant data — which may include Personal Data such as RFQ, quotation, order, or lead details (see Section 4.2.20) — to the destination endpoint or third party you designate. Such transmissions are made on your instruction. You are solely responsible for the security of your endpoints and for the lawful use of any data received there, and, in respect of that data, you act as an independent recipient and Data Fiduciary/Controller. We are not responsible for the acts, omissions, or data-protection practices of any destination you designate.

12. Sub-Processors

12.1 We engage the following categories of Sub-Processors to provide the Services. The specific providers engaged may change; we maintain contractual and security safeguards with each. Locations are indicative and subject to the hosting configuration referenced in Section 13. ICOBS is not a payment aggregator, payment intermediary, or escrow service provider. Payment processing, payouts, refunds, and any escrow or milestone-payment functionality are performed by RBI-authorised payment service providers (PSPs) such as Razorpay; ICOBS acts solely as a technology facilitator and does not hold or safeguard User funds.

Sub-Processor / categoryPurposeIndicative location
Razorpay Software Private LimitedPayment processing, payouts, refunds; RBI-authorised payment service provider (PSP)India
Amazon Web Services — S3 and CloudFront (Cloudinary as an alternative)Object storage, media hosting, and content delivery (CDN)India (AWS ap-south-1)
Amazon Web Services — SES / SMTP / SendGrid (with Nodemailer)Transactional and notification email deliveryIndia (AWS ap-south-1) / provider regions
Twilio / Amazon Web Services SNS (with otplib)SMS and OTP delivery for verificationProvider regions
Firebase Cloud Messaging (Google)Push notifications to mobile and webProvider regions
Google, GitHub, Apple, LinkedIn (OAuth)Social login/authentication (data shared per the permissions you grant)Provider regions
Anthropic / OpenAIAI-assisted features (see Section 20)Provider regions (may include the United States)
OpenTelemetry / Prometheus / Grafana / LokiObservability, logging, and performance monitoringIndia (AWS ap-south-1)
Redis / Amazon Web Services SQS / BullMQCaching and asynchronous job/queue processingIndia (AWS ap-south-1)
PostgreSQL with pgvectorPrimary application database and vector searchIndia (AWS ap-south-1)
Bank-verification (penny-drop) serviceVerification of Seller/Institution bank detailsIndia

12.2 We remain responsible for Personal Data processed by our Sub-Processors and require each to implement appropriate technical and organisational measures and to process Personal Data only on our documented instructions.

12.3 When your Account is anonymised on deletion (see Section 17), we instruct our processors and Sub-Processors — including the Payment Processor, email/marketing, and push-notification providers — to delete or de-identify your Personal Data, subject to any retention each is required to maintain under Applicable Law.

13. Cross-Border and International Transfers

13.1 The Platform is hosted in India (AWS ap-south-1). Some Sub-Processors process Personal Data outside India, including in the United States and other jurisdictions.

13.2 DPDP Act transfer regime. We transfer Personal Data outside India only in a manner permitted under the DPDP Act, and we will not transfer Personal Data to any country or territory that the Central Government restricts by notification. Where such restrictions or conditions are notified, we will comply with them.

13.3 GDPR/UK GDPR transfers. Where we transfer Personal Data of individuals in the European Economic Area or the United Kingdom to a country not benefiting from an adequacy decision, we implement appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Agreement or Addendum, as applicable), together with supplementary measures where necessary.

13.4 Your rights. You may request information about the safeguards applied to international transfers of your Personal Data by contacting us at support@icobs.biz.

14. Security Measures

14.1 We implement appropriate technical and organisational measures designed to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. Our security programme is aligned with ISO/IEC 27001 principles and OWASP secure-development guidance.

14.2 Measures include, without limitation:

  • Encryption of Personal Data in transit (TLS) and at rest;
  • Password protection using salted one-way hashing; plaintext passwords are never stored;
  • Access controls based on least privilege, role-based access, and need-to-know, with authentication for administrative access;
  • Network and application safeguards, including input validation, secure coding practices, and monitoring/logging of security events;
  • Segregation and restriction of sensitive KYC and financial data;
  • Sub-processor diligence and contractual security obligations; and
  • Operational controls, including backups, and periodic review of our measures.

14.3 Audit and change-history logs. We maintain audit and change-history logs of significant actions and record changes on the Platform. These logs may capture the IP address, device/user-agent, and the before-and-after state of changed records, and we retain them for security, fraud-prevention, dispute-resolution, and compliance purposes.

14.4 PCI-DSS. Payment-card processing is handled by our PCI-DSS-compliant Payment Processor; ICOBS does not store full card data (see Section 4.5).

14.5 Breach notification. In the event of a Personal Data breach, we will take remedial action and will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines required by the DPDP Act. Where the GDPR applies, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, and will notify affected data subjects where the breach is likely to result in a high risk to their rights and freedoms.

14.6 Your responsibility. No method of transmission or storage is completely secure. You are responsible for keeping your Account credentials confidential and for the security of your own devices and networks. Notify us promptly at support@icobs.biz if you suspect any unauthorised use of your Account.

15. Data Retention

15.1 We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including to provide the Services, comply with legal, tax, accounting, and regulatory obligations (for example, financial and GST records), resolve disputes, prevent fraud, and enforce our agreements.

15.2 The Platform uses soft deletion (via a "deleted" marker) for certain records — including products, certifications, community posts, and institution profiles — before eventual hard deletion. Soft-deleted data is retained for a limited period and remains subject to this Policy; hard deletion removes the data from active systems, subject to residual copies in backups as described in Section 15.4.

15.3 Retention after Account deletion. When an Account is permanently deleted, we do not, as a rule, physically delete every associated row. Instead, we anonymise the Account so that it can no longer be linked to you (see Section 17), and we retain business, transactional, financial, legal, and audit records only where retention is required or permitted by Applicable Law (for example, tax/GST records, records under the Prevention of Money Laundering Act and other AML rules, and records under the Companies Act) or is necessary to establish, exercise, or defend legal claims. Retained records are stripped of, or dissociated from, directly identifying Personal Data, consistent with Article 17(3) of the GDPR and the retention-for-legal-compliance grounds under the DPDP Act.

15.4 Backups. Personal Data may persist in secure, access-controlled backups after it has been removed or anonymised in active systems, until those backups are overwritten or expunged in the ordinary course of our backup-rotation cycle. If a backup is restored, we re-apply anonymisation to any Account that had been deleted before the restore.

15.5 Detailed, category-by-category retention periods (and any pending system-enforced schedules) are set out in our Data Retention Policy, and the end-to-end deletion lifecycle is described in our Account Suspension & Termination Policy. Where our systems do not yet automatically enforce a period, we apply the intended period as a matter of policy and honour deletion requests as described in Section 17.

16. Your Rights

16.1 Subject to Applicable Law and appropriate verification of your identity, you have the following rights. The rights available to you depend on the law that applies to your Personal Data.

16.2 Rights under the DPDP Act

RightWhat it means
Right to accessObtain a summary of the Personal Data we process about you, the processing activities, and the identities of Data Fiduciaries/Processors with whom it has been shared
Right to correction and completionHave inaccurate or misleading Personal Data corrected, and incomplete data completed, and outdated data updated
Right to erasureRequest erasure of your Account and Personal Data that is no longer necessary for the purpose for which it was processed, unless retention is required by law. You may exercise this in-product or via the Grievance Officer / Data Protection Officer; see Section 17 for how deletion works
Right to grievance redressalHave a readily available means of registering a grievance with us (see Section 22)
Right to nominateNominate another individual to exercise your rights in the event of your death or incapacity

16.3 Rights under the GDPR / UK GDPR (where applicable)

RightWhat it means
AccessObtain confirmation of processing and a copy of your Personal Data
RectificationHave inaccurate Personal Data corrected and incomplete data completed
Erasure ("right to be forgotten")Have your Account and Personal Data erased in the circumstances set out in Article 17. Where retention is permitted under Article 17(3) (for example, legal compliance or legal claims), we retain the minimum necessary records stripped of directly identifying data; see Section 17
RestrictionRestrict processing in the circumstances set out in Article 18
Data portabilityReceive Personal Data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible
ObjectionObject to processing based on legitimate interests, and to direct marketing at any time
Rights re automated decisionsNot be subject to solely automated decisions producing legal or similarly significant effects, except as permitted (see Section 20)
Withdraw consentWithdraw consent at any time where processing is based on consent
Lodge a complaintComplain to a supervisory authority

16.4 Rights under CCPA/CPRA (where applicable)

RightWhat it means
Right to knowRequest the categories and specific pieces of personal information collected, the sources, purposes, and categories of recipients
Right to deleteRequest deletion of personal information, subject to exceptions
Right to correctRequest correction of inaccurate personal information
Right to opt out of sale/sharingWe do not sell or "share" (for cross-context behavioural advertising) personal information as those terms are defined under the CCPA/CPRA
Right to limit use of sensitive personal informationDirect us to limit use of sensitive personal information to permitted purposes
Right to non-discriminationNot be discriminated against for exercising your rights

16.5 How to exercise your rights. Submit a request to support@icobs.biz, through your Account settings where available, or via our Grievance Redressal Policy contacts. You may use an authorised agent where permitted by Applicable Law.

16.6 Verification. To protect your Personal Data, we will take reasonable steps to verify your identity before acting on a request, and may ask for information sufficient to confirm you are the person to whom the data relates.

16.7 Timelines and fees. We respond to rights requests within the timelines required by Applicable Law (for example, without undue delay and generally within one month under the GDPR, extendable where permitted; and within the periods prescribed under the DPDP Act and CCPA/CPRA). Requests are generally free; we may charge a reasonable fee or decline requests that are manifestly unfounded, excessive, or repetitive, as permitted by law.

16.8 Limitations. We may decline or limit a request where required or permitted by Applicable Law, for example where compliance would adversely affect the rights of others, or where we must retain data for legal, security, or fraud-prevention purposes.

17. Data Deletion and Correction

17.1 Correction. You can update most Account and profile data directly in the Platform, or request correction at support@icobs.biz.

17.2 Right to request deletion. You have the right to request deletion/erasure of your Account and Personal Data (DPDP Act 2023, Section 12; GDPR Article 17). You may exercise this right in-product using the Account-deletion controls where available, or by contacting the Grievance Officer / Data Protection Officer or support@icobs.biz / support@icobs.biz (see Section 22).

17.3 Grace and recovery period. When you request deletion, a 28-day grace/recovery period begins. During this period the request can be revoked and your Account remains usable. If you do not revoke the request within the grace period, the Account proceeds to permanent deletion.

17.4 How permanent deletion works — anonymisation. We permanently delete your Account by anonymisation rather than by physically deleting every associated database row. Anonymisation removes or irreversibly dissociates your directly identifying data — including your name, email address, phone number, profile information, authentication credentials, and other identifiers — so that the residual records can no longer be linked to you. Your email address and phone number are released so they may be reused.

17.5 What is retained, and why. As described in Section 15.3, certain business, transactional, financial, legal, and audit records may be retained after anonymisation where required or permitted by Applicable Law (for example, tax/GST, PMLA/AML, and Companies Act obligations) or to establish, exercise, or defend legal claims. Such retained records are stripped of, or dissociated from, directly identifying Personal Data, consistent with Article 17(3) of the GDPR and the DPDP Act's retention-for-legal-compliance grounds. Content you shared with other Users or published publicly (and copies made by them or by search engines) may persist independently of your Account.

17.6 Grounds that may delay deletion. Completion of deletion may be temporarily blocked by legitimate grounds — for example, a legal hold, an open escrow, dispute, payment, order, or RFQ, or a pending KYC/verification process. Where such grounds apply, deletion completes within a bounded time once they lapse.

17.7 Instructions to processors and backups. On anonymisation, we instruct our processors and Sub-Processors (including the Payment Processor, email/marketing, and push providers referenced in Section 12) to delete or de-identify your data, subject to their own lawful retention obligations. Personal Data may persist in secure backups until routine rotation overwrites or expunges them, and any restored backup is re-anonymised, as described in Section 15.4.

17.8 Acknowledgement and timelines. We acknowledge deletion/erasure requests and confirm completion, consistent with the timelines in our Grievance Redressal Policy. The end-to-end deletion lifecycle is described in our Account Suspension & Termination Policy.

17.9 Effect on transactions; no refund eligibility. Deleting your Account may terminate access to the Services and to records associated with your Account, including active RFQs, orders, subscriptions, or credits, subject to the Terms & Conditions. Requesting or completing deletion does not by itself create any refund entitlement; refund eligibility is governed solely by the Refund & Cancellation Policy.

18. Children's Privacy

18.1 The Platform is a B2B service intended for use by businesses and individuals aged 18 years and over. It is not directed to, and we do not knowingly collect Personal Data from, children (persons under the age of 18) except as permitted under the DPDP Act with verifiable parental or lawful-guardian consent.

18.2 We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If we become aware that we have collected a child's Personal Data without the requisite consent, we will delete it promptly.

18.3 Further detail is set out in our Children's Privacy Statement.

19. Marketing Communications and Notifications

19.1 Transactional messages. We send service and transactional communications (for example, verification, security, billing, RFQ/order, and support messages) that are necessary to operate the Services; these are not marketing and cannot generally be opted out of while you maintain an Account.

19.2 Marketing. We send marketing and promotional communications by email, push, or SMS only where permitted by Applicable Law, including with your consent where required. You can opt out at any time using unsubscribe links, push-notification settings on your device, or your Account communication preferences, or by contacting support@icobs.biz.

19.3 Push notifications. You can manage or disable push notifications through your device or app settings; disabling them may affect delivery of certain alerts.

20. Automated Processing and AI Features

20.1 We use automated processing to operate the Platform, including search, recommendations, ranking, fraud and abuse detection, and content moderation, and we offer AI-assisted features that use Sub-Processors such as Anthropic and OpenAI (see Section 12).

20.2 We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without a lawful basis and, where required, suitable safeguards, including the ability to request human review. Where the GDPR applies, we honour the rights described in Section 16.3.

20.3 The scope, limitations, data handling, and content-ownership implications of our AI features are described in our AI Usage & Generated Content Policy.

21. Third-Party Links

21.1 The Platform may contain links to third-party websites, applications, or services (including Sellers', Institutions', and Users' external sites and social-login providers). We are not responsible for the privacy practices or content of those third parties. This Policy does not apply to them; review their privacy notices before providing your Personal Data.

22. Grievance Redressal and Complaints

22.1 If you have a question, request, or complaint about this Policy or our processing of your Personal Data, you may contact:

  • Data Protection Officer: Manjunath A. C., Chief Executive Officer (CEO). Email: support@icobs.biz
  • Grievance Officer (IT Rules 2021 and Consumer Protection (E-Commerce) Rules 2020): Manjunath A. C., Chief Executive Officer (CEO). Email: support@icobs.biz. Address: No. 21, 3rd Floor, 21st Main, BSK 2nd Stage, Bangalore South, Bengaluru – 560070, Karnataka, India.

22.2 We will acknowledge and respond to grievances within the timelines prescribed under Applicable Law. Further detail on our grievance process is set out in our Grievance Redressal Policy.

22.3 Escalation. If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India established under the DPDP Act. If the GDPR applies to you, you may lodge a complaint with your local supervisory authority; if the CCPA/CPRA applies, you may contact the California Privacy Protection Agency or the California Attorney General.

23. Changes to This Policy

23.1 We may update this Policy from time to time to reflect changes in our practices, technology, or Applicable Law. The current version is identified by the "Version" and "Last Updated" fields at the top of this document.

23.2 Where changes are material, we will provide reasonable notice — for example, by posting a notice on the Platform, updating the effective date, or, where required, notifying you directly or obtaining fresh consent. Your continued use of the Platform after a change takes effect constitutes acceptance of the revised Policy to the extent permitted by Applicable Law.

24. Governing Law, Jurisdiction, and General Provisions

24.1 Governing law. This Policy is governed by and construed in accordance with the laws of India, without regard to conflict-of-laws principles. This does not deprive you of the protection of mandatory provisions of the law applicable in your place of residence.

24.2 Jurisdiction. Subject to Applicable Law, the courts at Bengaluru, India, shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.

24.3 Severability. If any provision of this Policy is held to be invalid or unenforceable, that provision shall be modified to the minimum extent necessary, or severed, and the remaining provisions shall continue in full force and effect.

24.4 Entire agreement. This Policy, together with the Terms & Conditions and the other policies referenced herein, constitutes the entire understanding between you and us regarding the processing of your Personal Data and supersedes prior privacy statements. In the event of a conflict regarding Personal Data processing, this Policy prevails over the Terms & Conditions.

24.5 No waiver. Our failure to enforce any provision of this Policy is not a waiver of that or any other provision.

25. Contact Us

25.1 For any privacy-related matter, you may contact us at:

  • ICOBS Global Technologies Private Limited
  • Registered office: No. 21, 3rd Floor, 21st Main, BSK 2nd Stage, Bangalore South, Bengaluru – 560070, Karnataka, India.
  • CIN: U63112KA2026PTC215100
  • Privacy: support@icobs.biz
  • Support: support@icobs.biz
  • Data Protection Officer: Manjunath A. C., support@icobs.biz