
Great things are on the way.
ICOBS is building the future of B2B commerce, verified sourcing for Buyers, powerful selling tools for Suppliers, and global event management for Institutions. This section will be live soon.

ICOBS is building the future of B2B commerce, verified sourcing for Buyers, powerful selling tools for Suppliers, and global event management for Institutions. This section will be live soon.
Last updated: 10 July 2026ICOBS Global Technologies Private LimitedCIN U63112KA2026PTC215100
Read together with our Terms & Conditions.
1.1 This Privacy Policy ("Policy") explains how ICOBS collects, uses, discloses, stores, transfers, and otherwise processes Personal Data when you access or use the Platform, comprising the web application at https://icobs.biz, our associated mobile applications for Android and iOS, our application programming interfaces (APIs), and all related Services.
1.2 ICOBS is a business-to-business ("B2B") marketplace operated by ICOBS Global Technologies Private Limited. We act as an intermediary and marketplace e-commerce entity; we do not own, manufacture, store, or sell the goods or services listed by Sellers, and contracts for goods and services are entered into directly between Buyer and Seller.
1.3 This Policy applies to all Users, including Visitors, Buyers, Sellers, Institutions, Association members, Event organisers, and administrators acting on behalf of any of these, across all channels through which the Platform is made available.
1.4 This Policy is drafted with the Digital Personal Data Protection Act, 2023 ("DPDP Act") as its primary framework, and is aligned, where applicable, with the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"). Nothing in this Policy is intended to grant rights beyond those available under Applicable Law.
1.5 This Policy should be read together with our Terms & Conditions. In the event of a conflict between this Policy and the Terms & Conditions on a matter of Personal Data processing, this Policy governs.
1.6 By accessing or using the Platform, you acknowledge that you have read and understood this Policy. Where processing is based on your consent, we will obtain that consent as described in Section 8, and your use of the Platform does not by itself constitute consent to processing that requires separate, specific consent under Applicable Law.
2.1 Capitalised terms used but not defined in this Policy have the meanings given in our Terms & Conditions. For the purposes of this Policy:
3.1 As Data Fiduciary / Controller. For most processing of Personal Data described in this Policy — including Account registration, verification, communications, payments administration, security, analytics, and compliance — ICOBS acts as the Data Fiduciary under the DPDP Act and as the Controller under the GDPR/UK GDPR, because we determine the purposes and means of that processing.
3.2 As Data Processor. In certain circumstances, ICOBS acts as a Data Processor on behalf of a business User who is itself a Data Fiduciary/Controller — for example, where a Seller, Institution, or Association uploads or manages Personal Data of its own personnel, members, or contacts through the Platform, or where a User transmits Personal Data of third parties through RFQs, quotations, messages, or Content. In such cases, the business User remains responsible as the Data Fiduciary/Controller for that Personal Data, must have a lawful basis for providing it to us, and our processing is limited to what is necessary to provide the Services.
3.3 Joint arrangements. Where two or more Users, or a User and ICOBS, jointly determine purposes and means of processing (for example, in the course of a Buyer–Seller transaction), each party is responsible for its own compliance obligations in respect of the Personal Data it controls.
3.4 Significant Data Fiduciary. If ICOBS is notified by the Central Government that it is a Significant Data Fiduciary under the DPDP Act, we will comply with the additional obligations that apply to such a designation, including the appointment of a Data Protection Officer based in India, engagement of an independent data auditor, and periodic Data Protection Impact Assessments.
4.1 We collect the categories of Personal Data set out in the table below. The specific data collected depends on your persona (Visitor, Buyer, Seller, Institution/Association) and the features you use. The lawful basis for each purpose is set out in Section 7.
| # | Category | Data elements (examples) | Personas | Sensitivity |
|---|---|---|---|---|
| 4.2.1 | Account and identity data | First and last name, email address, phone number (in E.164 format), password (stored only as a salted hash — we never store plaintext passwords), designation/job title, company name, avatar/profile image, email- and phone-verification flags, account status, last login timestamp | All registered Users | Standard |
| 4.2.2 | Business and company information | Company/organisation name, company description, year founded, employee count, annual revenue band, export markets, export capability, facility size, business contact email and phone, website URL, company logo and banner | Sellers, Institutions | Standard (may include business-confidential information) |
| 4.2.3 | Seller profile data | Ratings and review data, follower and product counts, badges/certifications, verification fields and status | Sellers | Standard |
| 4.2.4 | Institution / Association profile data | Institution name, type (association, event organiser, government body, NGO), description, contacts, website, member/event/follower counts, key figures, verification fields and status, membership and member-application records | Institutions, Associations | Standard |
| 4.2.5 | Business office address and geolocation | Street address, city, state, country, PIN code, office email and phone, office type, and geolocation (latitude/longitude) associated with a business office | Sellers, Institutions | Standard (precise geolocation of a business office; not device-level tracking) |
| 4.2.6 | KYC and verification documents | PAN, Aadhaar, GST certificate/GSTIN, Trade License, Udyam Registration, Company Registration, Registration Certificate, MOU/Bylaws, Signatory PAN, Signatory Aadhaar, 12A, 80G, FCRA, Government Order, bank account details (with IFSC), and other uploaded documents, together with document type, values, and bank-verification (penny-drop) status | Sellers, Institutions, authorised signatories | Sensitive / regulated (see Section 5) |
| 4.2.7 | Payment information | Billing details, transaction identifiers, Razorpay customer identifier, subscription and credit-pack records, invoices, GST details, and refund records. Full card numbers, CVV, and complete bank credentials for card/UPI/netbanking payments are collected and processed directly by our Payment Processor; ICOBS does not store full payment-card data (see Section 4.5) | Buyers, Sellers, Institutions who transact | Sensitive / regulated (financial) |
| 4.2.8 | Uploaded media | Images, videos, and PDF documents uploaded as profile media, gallery media, listing media, message attachments, or Content | All Users who upload | Standard (may embed metadata; see 4.3) |
| 4.2.9 | Community and user-generated Content | Community posts, comments, reactions/likes, follows, saved posts, blogs, and reports you submit | All Users who participate | Standard |
| 4.2.10 | RFQ, quotation, and order data | RFQs, quotations, counter-offers, orders, escrow/milestone records, and associated line items and terms | Buyers, Sellers | Standard (may include commercial-confidential information) |
| 4.2.11 | Messages and chat | Messages, attachments, and metadata exchanged in RFQ, quotation, and order contexts | Buyers, Sellers, Institutions | Standard (may contain Personal Data supplied by you) |
| 4.2.12 | Ratings and reviews | Ratings, written reviews, and responses relating to Sellers and transactions | Buyers, Sellers | Standard |
| 4.2.13 | Support and dispute data | Support tickets, dispute and escalation records, and correspondence with our teams | All Users who contact us | Standard |
| 4.2.14 | Moderation and enforcement data | Reports, blocks, moderation cases, enforcement actions (warn/soft-disable/hard-disable), content-hiding/removal records, restriction reasons and periods | Users subject to or raising these | Standard |
| 4.2.15 | Cookies and device information | Cookie and similar-technology identifiers, device type and model, operating system, browser, app version, language, screen attributes, and push-notification tokens | All Users | Standard |
| 4.2.16 | Log files and network data | IP address, access timestamps, referring/exit pages, request and error logs, and security event logs | All Users | Standard |
| 4.2.17 | Analytics and usage data | Pages and screens viewed, features used, searches performed, interactions, session duration, and derived usage metrics | All Users | Standard |
| 4.2.18 | Marketing preferences | Email, push, and SMS communication preferences and opt-in/opt-out status | All Users | Standard |
| 4.2.19 | Social-login data | Where you sign in via Google, GitHub, Apple, or LinkedIn: the profile identifier, name, email, and profile image that the provider shares with us, subject to the permissions you grant | Users who use social login | Standard |
| 4.2.20 | Integration and webhook configuration data | Where you register an outbound webhook or integration: the destination endpoint URL(s), the signing secrets/keys used to authenticate deliveries to you, the event types you subscribe to, and the event payloads we deliver to your endpoint — which may themselves contain Personal Data (for example, RFQ, quotation, order, or lead details) | Users who configure integrations/webhooks | Standard (delivered payloads may contain Personal Data) |
| 4.2.21 | Referral, rewards and ambassador data | Referral codes and links, and referral activity and funnel data (for example, sign-ups, conversions, and attributions); Rewards Wallet balances and transactions; and — for Ambassadors, who may be individuals who are not registered Users — name, contact details, city/state, organisation/designation, PAN, GST (optional), and bank account details (account holder name, account number, IFSC, branch) collected for commission payout and tax compliance | Referrers, Ambassadors (including non-Users), and Users participating in the programmes | Standard, save for PAN/GST/bank details which are Sensitive / regulated (financial) (see Section 5) |
4.3 Metadata in uploads. Media files may contain embedded metadata (for example, EXIF data such as capture time or, in some cases, location). You are responsible for the Content you upload; where you do not wish to share such metadata, remove it before uploading.
4.4 Aggregated and de-identified data. We may create aggregated, anonymised, or de-identified data that does not identify you. Such data is not Personal Data, and we may use it for any lawful purpose, including analytics, product improvement, and reporting, provided we do not attempt to re-identify it.
4.5.1 Payments on the Platform are processed by our Payment Processor, Razorpay, and (in future) other RBI-authorised payment service providers (PSPs). ICOBS is not a payment aggregator, payment intermediary, or escrow service provider. We act solely as a technology facilitator that connects Users to RBI-authorised PSPs for payment collection, payouts, refunds, and related financial transactions. When you make a payment, sensitive payment credentials (such as full card number, CVV, UPI PIN, or netbanking credentials) are collected and processed directly by the relevant RBI-authorised PSP in a PCI-DSS-compliant environment.
4.5.2 ICOBS does not store full payment-card numbers or CVV. We retain only transaction metadata necessary to administer subscriptions, credit packs, promotions, one-time payments, refunds, invoicing, and GST compliance, together with a Payment Processor customer identifier and tokens/references returned by the Payment Processor. Any escrow or milestone-payment features displayed on the Platform are facilitated through third-party RBI-authorised PSPs; ICOBS does not hold, control, or safeguard User funds.
5.1 Certain data we process attracts heightened protection under Applicable Law, including financial information and government-issued identity documents collected for KYC and verification (see Section 4.2.6 and Section 4.2.7).
5.2 We handle such data on the following principles:
5.3 Aadhaar. Where an Aadhaar number or Aadhaar-linked document is collected, it is used solely for identity verification of the relevant Seller, Institution, or authorised signatory, in a manner consistent with Applicable Law and any applicable UIDAI requirements. We do not use Aadhaar for any purpose beyond verification and record-keeping required by law.
5.4 GDPR special categories. We do not intentionally collect special categories of personal data under Article 9 of the GDPR (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health, or sexual orientation). Please do not submit such data through Content, messages, or uploads unless strictly necessary; if you do, you consent to its processing solely to provide the Services.
6.1 We collect Personal Data from the following sources:
| Source | Examples |
|---|---|
| Directly from you | Registration and profile details, KYC uploads, RFQs/quotations/orders, messages, Content, support requests, and preferences |
| Automatically | Cookies and similar technologies, device and log data, IP address, and usage/analytics data collected as you interact with the Platform |
| Third parties | Social-login providers (Google, GitHub, Apple, LinkedIn); the Payment Processor (transaction status and tokens); verification/penny-drop services; and other Users who provide your data in the course of a transaction or interaction (for example, a Buyer naming a contact in an RFQ) |
| Publicly available or lawful third-party sources | Business registries or verification data used to corroborate KYC information, where permitted by Applicable Law |
7.1 We process Personal Data only for specified, lawful purposes. The table below maps each purpose to the categories of data involved, the DPDP Act basis (consent or a "legitimate use" permitted under Section 7 of the DPDP Act), and the corresponding GDPR lawful basis (Article 6). Where more than one basis applies, we rely on the most appropriate basis for the purpose.
| # | Purpose | Data categories (ref. Section 4) | DPDP Act basis | GDPR lawful basis |
|---|---|---|---|---|
| 7.2.1 | Create and administer your Account; authenticate logins | 4.2.1, 4.2.15, 4.2.19 | Consent / performance of Account arrangement | Contract (Art. 6(1)(b)) |
| 7.2.2 | Provide the Services (marketplace, RFQ/quotation/order, chat, community, events, subscriptions, credits) | 4.2.1–4.2.14 | Consent / legitimate use | Contract (Art. 6(1)(b)) |
| 7.2.3 | Verify Sellers and Institutions (KYC), including bank verification | 4.2.6, 4.2.7 | Legitimate use; compliance with law | Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f)) |
| 7.2.4 | Process payments, subscriptions, credit packs, promotions, refunds, invoicing, and GST | 4.2.7, 4.2.1 | Performance of arrangement; compliance with law | Contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) |
| 7.2.5 | Enable communications between Users and deliver transactional notifications | 4.2.1, 4.2.11, 4.2.15 | Legitimate use | Contract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f)) |
| 7.2.6 | Maintain security, prevent fraud, abuse, and money laundering; enforce our terms and moderation | 4.2.6, 4.2.7, 4.2.14, 4.2.16 | Legitimate use (security); compliance with law | Legitimate interests (Art. 6(1)(f)); Legal obligation (Art. 6(1)(c)) |
| 7.2.7 | Operate, maintain, debug, and improve the Platform; analytics and product development | 4.2.15, 4.2.16, 4.2.17 | Legitimate use | Legitimate interests (Art. 6(1)(f)); Consent for non-essential analytics |
| 7.2.8 | Personalise your experience and recommendations | 4.2.15, 4.2.17 | Consent / legitimate use | Legitimate interests (Art. 6(1)(f)); Consent where required |
| 7.2.9 | Send marketing and promotional communications | 4.2.1, 4.2.18 | Consent | Consent (Art. 6(1)(a)); Legitimate interests for existing-customer B2B communications where permitted |
| 7.2.10 | Provide support, handle disputes, and administer grievances | 4.2.1, 4.2.13, 4.2.14 | Legitimate use; compliance with law | Contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) |
| 7.2.11 | Comply with legal, regulatory, tax, and law-enforcement obligations; establish, exercise, or defend legal claims | Any relevant category | Compliance with law; legitimate use | Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f)) |
| 7.2.12 | Provide AI-assisted features (see Section 20) | 4.2.9, 4.2.10, 4.2.11, 4.2.17 | Consent / legitimate use | Legitimate interests (Art. 6(1)(f)); Consent where required |
| 7.2.13 | Operate the Referral, Rewards Wallet, and Ambassador programmes — calculate, track, and pay rewards and commissions; comply with tax/TDS obligations; and prevent and detect fraud and abuse | 4.2.21, 4.2.1, 4.2.7 | Performance of arrangement; compliance with law; legitimate use (anti-fraud) | Contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f)) |
| 7.2.14 | Effect a business transfer (merger, acquisition, restructuring) | Any relevant category | Legitimate use | Legitimate interests (Art. 6(1)(f)) |
7.3 Change of purpose. If we intend to process your Personal Data for a purpose other than that for which it was collected, and that purpose is not compatible with the original purpose, we will notify you and, where required, obtain your consent before doing so.
7.4 Public Ambassador lookup portal. The public Ambassador lookup portal is read-only and displays only performance and commission summary information (for example, an Ambassador's referral performance and commission tier). It does not expose personal information, bank details, or PAN. Full programme rules are set out in the Referral, Rewards Wallet & Ambassador Program Terms.
7.5 Personal data about prospective referrals. Where a Referrer or Ambassador submits Personal Data about a prospective referral or other third party (for example, a name or contact detail), they must have a lawful basis and any necessary consent to provide that data to us; in respect of such data, the Referrer or Ambassador acts as a Data Fiduciary/Controller, and our processing is limited to operating the programmes (see also Section 3.2).
8.1 How we obtain consent. Where processing relies on your consent, we obtain it through a clear affirmative action — for example, checking an unticked box, clicking an "I agree"/"Accept" control, or enabling a specific feature — accompanied by, or with access to, the information required under the DPDP Act, including the purposes of processing, the manner of exercising your rights, and how to complain to the Data Protection Board of India.
8.2 Notice. At or before the time of obtaining consent, we provide a notice describing the Personal Data to be processed and the purpose. This Policy, together with any just-in-time notices shown in the Platform, constitutes that notice.
8.3 Granularity. Where we seek consent for multiple purposes, you may consent to some purposes and decline others, except where a purpose is essential to providing a Service you have requested.
8.4 Consent for those unable to consent. Where the Data Principal is a child or a person with a disability who has a lawful guardian, consent will be sought from the parent or lawful guardian in accordance with the DPDP Act. See also Section 18.
8.5 Withdrawal of consent. You may withdraw your consent at any time, and it will be as easy to withdraw as it was to give. You can withdraw consent by adjusting the relevant setting in your Account, using the unsubscribe or opt-out controls in communications, or contacting us at support@icobs.biz.
8.6 Effect of withdrawal. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. Following withdrawal, we will cease the relevant processing and cause our Sub-Processors to do the same, unless another lawful basis (such as a legal obligation or the establishment/defence of legal claims) permits continued processing. Withdrawing consent essential to a Service may mean we can no longer provide that Service.
8.7 Consent Manager. Where a Consent Manager framework is operative under the DPDP Act, you may be able to give, manage, review, and withdraw consent through a registered Consent Manager. We will honour valid instructions received through such a mechanism.
9.1 The Platform is a marketplace, and certain information is public by design. Depending on your persona and settings, the following may be visible to other Users and to the general public, including persons who are not registered:
9.2 Search-engine indexing. Public pages (including profiles, listings, community posts, and event pages) may be crawled and indexed by third-party search engines and may appear in their results and caches. We do not control third-party search engines, and content removed from the Platform may persist in third-party caches for a time.
9.3 Your control. Do not publish Personal Data (yours or others') in public fields, Content, or Listings that you do not wish to be public. Where the Platform provides visibility controls, you may use them to limit disclosure; contact-level details shared within a specific transaction are visible to the counterpart to that transaction.
12.1 We engage the following categories of Sub-Processors to provide the Services. The specific providers engaged may change; we maintain contractual and security safeguards with each. Locations are indicative and subject to the hosting configuration referenced in Section 13. ICOBS is not a payment aggregator, payment intermediary, or escrow service provider. Payment processing, payouts, refunds, and any escrow or milestone-payment functionality are performed by RBI-authorised payment service providers (PSPs) such as Razorpay; ICOBS acts solely as a technology facilitator and does not hold or safeguard User funds.
| Sub-Processor / category | Purpose | Indicative location |
|---|---|---|
| Razorpay Software Private Limited | Payment processing, payouts, refunds; RBI-authorised payment service provider (PSP) | India |
| Amazon Web Services — S3 and CloudFront (Cloudinary as an alternative) | Object storage, media hosting, and content delivery (CDN) | India (AWS ap-south-1) |
| Amazon Web Services — SES / SMTP / SendGrid (with Nodemailer) | Transactional and notification email delivery | India (AWS ap-south-1) / provider regions |
| Twilio / Amazon Web Services SNS (with otplib) | SMS and OTP delivery for verification | Provider regions |
| Firebase Cloud Messaging (Google) | Push notifications to mobile and web | Provider regions |
| Google, GitHub, Apple, LinkedIn (OAuth) | Social login/authentication (data shared per the permissions you grant) | Provider regions |
| Anthropic / OpenAI | AI-assisted features (see Section 20) | Provider regions (may include the United States) |
| OpenTelemetry / Prometheus / Grafana / Loki | Observability, logging, and performance monitoring | India (AWS ap-south-1) |
| Redis / Amazon Web Services SQS / BullMQ | Caching and asynchronous job/queue processing | India (AWS ap-south-1) |
| PostgreSQL with pgvector | Primary application database and vector search | India (AWS ap-south-1) |
| Bank-verification (penny-drop) service | Verification of Seller/Institution bank details | India |
12.2 We remain responsible for Personal Data processed by our Sub-Processors and require each to implement appropriate technical and organisational measures and to process Personal Data only on our documented instructions.
12.3 When your Account is anonymised on deletion (see Section 17), we instruct our processors and Sub-Processors — including the Payment Processor, email/marketing, and push-notification providers — to delete or de-identify your Personal Data, subject to any retention each is required to maintain under Applicable Law.
13.1 The Platform is hosted in India (AWS ap-south-1). Some Sub-Processors process Personal Data outside India, including in the United States and other jurisdictions.
13.2 DPDP Act transfer regime. We transfer Personal Data outside India only in a manner permitted under the DPDP Act, and we will not transfer Personal Data to any country or territory that the Central Government restricts by notification. Where such restrictions or conditions are notified, we will comply with them.
13.3 GDPR/UK GDPR transfers. Where we transfer Personal Data of individuals in the European Economic Area or the United Kingdom to a country not benefiting from an adequacy decision, we implement appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Agreement or Addendum, as applicable), together with supplementary measures where necessary.
13.4 Your rights. You may request information about the safeguards applied to international transfers of your Personal Data by contacting us at support@icobs.biz.
14.1 We implement appropriate technical and organisational measures designed to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. Our security programme is aligned with ISO/IEC 27001 principles and OWASP secure-development guidance.
14.2 Measures include, without limitation:
14.3 Audit and change-history logs. We maintain audit and change-history logs of significant actions and record changes on the Platform. These logs may capture the IP address, device/user-agent, and the before-and-after state of changed records, and we retain them for security, fraud-prevention, dispute-resolution, and compliance purposes.
14.4 PCI-DSS. Payment-card processing is handled by our PCI-DSS-compliant Payment Processor; ICOBS does not store full card data (see Section 4.5).
14.5 Breach notification. In the event of a Personal Data breach, we will take remedial action and will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines required by the DPDP Act. Where the GDPR applies, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, and will notify affected data subjects where the breach is likely to result in a high risk to their rights and freedoms.
14.6 Your responsibility. No method of transmission or storage is completely secure. You are responsible for keeping your Account credentials confidential and for the security of your own devices and networks. Notify us promptly at support@icobs.biz if you suspect any unauthorised use of your Account.
15.1 We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including to provide the Services, comply with legal, tax, accounting, and regulatory obligations (for example, financial and GST records), resolve disputes, prevent fraud, and enforce our agreements.
15.2 The Platform uses soft deletion (via a "deleted" marker) for certain records — including products, certifications, community posts, and institution profiles — before eventual hard deletion. Soft-deleted data is retained for a limited period and remains subject to this Policy; hard deletion removes the data from active systems, subject to residual copies in backups as described in Section 15.4.
15.3 Retention after Account deletion. When an Account is permanently deleted, we do not, as a rule, physically delete every associated row. Instead, we anonymise the Account so that it can no longer be linked to you (see Section 17), and we retain business, transactional, financial, legal, and audit records only where retention is required or permitted by Applicable Law (for example, tax/GST records, records under the Prevention of Money Laundering Act and other AML rules, and records under the Companies Act) or is necessary to establish, exercise, or defend legal claims. Retained records are stripped of, or dissociated from, directly identifying Personal Data, consistent with Article 17(3) of the GDPR and the retention-for-legal-compliance grounds under the DPDP Act.
15.4 Backups. Personal Data may persist in secure, access-controlled backups after it has been removed or anonymised in active systems, until those backups are overwritten or expunged in the ordinary course of our backup-rotation cycle. If a backup is restored, we re-apply anonymisation to any Account that had been deleted before the restore.
15.5 Detailed, category-by-category retention periods (and any pending system-enforced schedules) are set out in our Data Retention Policy, and the end-to-end deletion lifecycle is described in our Account Suspension & Termination Policy. Where our systems do not yet automatically enforce a period, we apply the intended period as a matter of policy and honour deletion requests as described in Section 17.
16.1 Subject to Applicable Law and appropriate verification of your identity, you have the following rights. The rights available to you depend on the law that applies to your Personal Data.
| Right | What it means |
|---|---|
| Right to access | Obtain a summary of the Personal Data we process about you, the processing activities, and the identities of Data Fiduciaries/Processors with whom it has been shared |
| Right to correction and completion | Have inaccurate or misleading Personal Data corrected, and incomplete data completed, and outdated data updated |
| Right to erasure | Request erasure of your Account and Personal Data that is no longer necessary for the purpose for which it was processed, unless retention is required by law. You may exercise this in-product or via the Grievance Officer / Data Protection Officer; see Section 17 for how deletion works |
| Right to grievance redressal | Have a readily available means of registering a grievance with us (see Section 22) |
| Right to nominate | Nominate another individual to exercise your rights in the event of your death or incapacity |
| Right | What it means |
|---|---|
| Access | Obtain confirmation of processing and a copy of your Personal Data |
| Rectification | Have inaccurate Personal Data corrected and incomplete data completed |
| Erasure ("right to be forgotten") | Have your Account and Personal Data erased in the circumstances set out in Article 17. Where retention is permitted under Article 17(3) (for example, legal compliance or legal claims), we retain the minimum necessary records stripped of directly identifying data; see Section 17 |
| Restriction | Restrict processing in the circumstances set out in Article 18 |
| Data portability | Receive Personal Data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible |
| Objection | Object to processing based on legitimate interests, and to direct marketing at any time |
| Rights re automated decisions | Not be subject to solely automated decisions producing legal or similarly significant effects, except as permitted (see Section 20) |
| Withdraw consent | Withdraw consent at any time where processing is based on consent |
| Lodge a complaint | Complain to a supervisory authority |
| Right | What it means |
|---|---|
| Right to know | Request the categories and specific pieces of personal information collected, the sources, purposes, and categories of recipients |
| Right to delete | Request deletion of personal information, subject to exceptions |
| Right to correct | Request correction of inaccurate personal information |
| Right to opt out of sale/sharing | We do not sell or "share" (for cross-context behavioural advertising) personal information as those terms are defined under the CCPA/CPRA |
| Right to limit use of sensitive personal information | Direct us to limit use of sensitive personal information to permitted purposes |
| Right to non-discrimination | Not be discriminated against for exercising your rights |
16.5 How to exercise your rights. Submit a request to support@icobs.biz, through your Account settings where available, or via our Grievance Redressal Policy contacts. You may use an authorised agent where permitted by Applicable Law.
16.6 Verification. To protect your Personal Data, we will take reasonable steps to verify your identity before acting on a request, and may ask for information sufficient to confirm you are the person to whom the data relates.
16.7 Timelines and fees. We respond to rights requests within the timelines required by Applicable Law (for example, without undue delay and generally within one month under the GDPR, extendable where permitted; and within the periods prescribed under the DPDP Act and CCPA/CPRA). Requests are generally free; we may charge a reasonable fee or decline requests that are manifestly unfounded, excessive, or repetitive, as permitted by law.
16.8 Limitations. We may decline or limit a request where required or permitted by Applicable Law, for example where compliance would adversely affect the rights of others, or where we must retain data for legal, security, or fraud-prevention purposes.
17.1 Correction. You can update most Account and profile data directly in the Platform, or request correction at support@icobs.biz.
17.2 Right to request deletion. You have the right to request deletion/erasure of your Account and Personal Data (DPDP Act 2023, Section 12; GDPR Article 17). You may exercise this right in-product using the Account-deletion controls where available, or by contacting the Grievance Officer / Data Protection Officer or support@icobs.biz / support@icobs.biz (see Section 22).
17.3 Grace and recovery period. When you request deletion, a 28-day grace/recovery period begins. During this period the request can be revoked and your Account remains usable. If you do not revoke the request within the grace period, the Account proceeds to permanent deletion.
17.4 How permanent deletion works — anonymisation. We permanently delete your Account by anonymisation rather than by physically deleting every associated database row. Anonymisation removes or irreversibly dissociates your directly identifying data — including your name, email address, phone number, profile information, authentication credentials, and other identifiers — so that the residual records can no longer be linked to you. Your email address and phone number are released so they may be reused.
17.5 What is retained, and why. As described in Section 15.3, certain business, transactional, financial, legal, and audit records may be retained after anonymisation where required or permitted by Applicable Law (for example, tax/GST, PMLA/AML, and Companies Act obligations) or to establish, exercise, or defend legal claims. Such retained records are stripped of, or dissociated from, directly identifying Personal Data, consistent with Article 17(3) of the GDPR and the DPDP Act's retention-for-legal-compliance grounds. Content you shared with other Users or published publicly (and copies made by them or by search engines) may persist independently of your Account.
17.6 Grounds that may delay deletion. Completion of deletion may be temporarily blocked by legitimate grounds — for example, a legal hold, an open escrow, dispute, payment, order, or RFQ, or a pending KYC/verification process. Where such grounds apply, deletion completes within a bounded time once they lapse.
17.7 Instructions to processors and backups. On anonymisation, we instruct our processors and Sub-Processors (including the Payment Processor, email/marketing, and push providers referenced in Section 12) to delete or de-identify your data, subject to their own lawful retention obligations. Personal Data may persist in secure backups until routine rotation overwrites or expunges them, and any restored backup is re-anonymised, as described in Section 15.4.
17.8 Acknowledgement and timelines. We acknowledge deletion/erasure requests and confirm completion, consistent with the timelines in our Grievance Redressal Policy. The end-to-end deletion lifecycle is described in our Account Suspension & Termination Policy.
17.9 Effect on transactions; no refund eligibility. Deleting your Account may terminate access to the Services and to records associated with your Account, including active RFQs, orders, subscriptions, or credits, subject to the Terms & Conditions. Requesting or completing deletion does not by itself create any refund entitlement; refund eligibility is governed solely by the Refund & Cancellation Policy.
18.1 The Platform is a B2B service intended for use by businesses and individuals aged 18 years and over. It is not directed to, and we do not knowingly collect Personal Data from, children (persons under the age of 18) except as permitted under the DPDP Act with verifiable parental or lawful-guardian consent.
18.2 We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If we become aware that we have collected a child's Personal Data without the requisite consent, we will delete it promptly.
18.3 Further detail is set out in our Children's Privacy Statement.
19.1 Transactional messages. We send service and transactional communications (for example, verification, security, billing, RFQ/order, and support messages) that are necessary to operate the Services; these are not marketing and cannot generally be opted out of while you maintain an Account.
19.2 Marketing. We send marketing and promotional communications by email, push, or SMS only where permitted by Applicable Law, including with your consent where required. You can opt out at any time using unsubscribe links, push-notification settings on your device, or your Account communication preferences, or by contacting support@icobs.biz.
19.3 Push notifications. You can manage or disable push notifications through your device or app settings; disabling them may affect delivery of certain alerts.
20.1 We use automated processing to operate the Platform, including search, recommendations, ranking, fraud and abuse detection, and content moderation, and we offer AI-assisted features that use Sub-Processors such as Anthropic and OpenAI (see Section 12).
20.2 We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without a lawful basis and, where required, suitable safeguards, including the ability to request human review. Where the GDPR applies, we honour the rights described in Section 16.3.
20.3 The scope, limitations, data handling, and content-ownership implications of our AI features are described in our AI Usage & Generated Content Policy.
21.1 The Platform may contain links to third-party websites, applications, or services (including Sellers', Institutions', and Users' external sites and social-login providers). We are not responsible for the privacy practices or content of those third parties. This Policy does not apply to them; review their privacy notices before providing your Personal Data.
22.1 If you have a question, request, or complaint about this Policy or our processing of your Personal Data, you may contact:
22.2 We will acknowledge and respond to grievances within the timelines prescribed under Applicable Law. Further detail on our grievance process is set out in our Grievance Redressal Policy.
22.3 Escalation. If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India established under the DPDP Act. If the GDPR applies to you, you may lodge a complaint with your local supervisory authority; if the CCPA/CPRA applies, you may contact the California Privacy Protection Agency or the California Attorney General.
23.1 We may update this Policy from time to time to reflect changes in our practices, technology, or Applicable Law. The current version is identified by the "Version" and "Last Updated" fields at the top of this document.
23.2 Where changes are material, we will provide reasonable notice — for example, by posting a notice on the Platform, updating the effective date, or, where required, notifying you directly or obtaining fresh consent. Your continued use of the Platform after a change takes effect constitutes acceptance of the revised Policy to the extent permitted by Applicable Law.
24.1 Governing law. This Policy is governed by and construed in accordance with the laws of India, without regard to conflict-of-laws principles. This does not deprive you of the protection of mandatory provisions of the law applicable in your place of residence.
24.2 Jurisdiction. Subject to Applicable Law, the courts at Bengaluru, India, shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.
24.3 Severability. If any provision of this Policy is held to be invalid or unenforceable, that provision shall be modified to the minimum extent necessary, or severed, and the remaining provisions shall continue in full force and effect.
24.4 Entire agreement. This Policy, together with the Terms & Conditions and the other policies referenced herein, constitutes the entire understanding between you and us regarding the processing of your Personal Data and supersedes prior privacy statements. In the event of a conflict regarding Personal Data processing, this Policy prevails over the Terms & Conditions.
24.5 No waiver. Our failure to enforce any provision of this Policy is not a waiver of that or any other provision.
25.1 For any privacy-related matter, you may contact us at: