DATA PROTECTION & GDPR Effective: 2026.08.17 until withdrawal

GDPR Privacy & Data Protection Policy

Information regarding the processing of personal data, corporate credentials, technical audit logs and masked IMEI identifiers by GSM B2B Hub.

1. Data Controller Identification

The data processing operations on the platform are executed by the operator of GSM B2B Hub (hereinafter: "Controller"):

Platform Name: GSM B2B Hub B2B Network
Website: https://www.sellnck.com
Privacy Contact: info@www.sellnck.com

2. Scope of Processed Corporate & Personal Data

In providing our exclusive B2B wholesale services, we process strictly necessary data:

  • Company credentials: Registered entity name, shop name, registered office address, tax/VAT number, EU VAT ID, company registration number, activity scope.
  • Authorized contact details: Full name, job title, business phone number, business email address.
  • Verification documents: Business registry certificate, trade license (for authentication only).
  • Technical & security logs: Login IP addresses, timestamped failed login attempts, browser user-agent headers, encrypted session IDs.

3. Legal Grounds & Purposes of Processing

  • Contract Performance (GDPR Art. 6(1)(b)): Providing B2B marketplace features, messaging, inventory tracking and forum access.
  • Legitimate Interest (GDPR Art. 6(1)(f)): Protecting the verified B2B ecosystem against stolen devices, credential-stuffing attacks and financial fraud.
  • Legal Obligation (GDPR Art. 6(1)(c)): Fulfilling commercial accounting, tax invoice auditing, and official statutory disclosures.

4. Device Identifiers (IMEI) & Audit Trail Protection

Device IMEI serial numbers constitute sensitive commercial and identification data. Full 15-digit IMEI numbers are never publicly disclosed on the platform; they are displayed exclusively in masked format (e.g. 358921••••••475) to prevent duplication while enabling authenticity checks.

5. Data Retention Periods

  • Active business profile data: Retained for the duration of verified membership or until explicit account termination.
  • Login security records: Retained for a maximum of 90 days.
  • Audit trail and transaction messages: Retained for 5 years in compliance with statutory commercial limitation periods.

6. Technical Security Measures

  • Adaptive Password Hashing: Argon2id and Bcrypt one-way cryptographic algorithms.
  • Mandatory 2FA (TOTP): Time-based one-time password security (RFC 6238) with single-use backup recovery codes.
  • Brute-Force & CSRF Defense: Rate-limiting lockouts (3/5 tier) and cryptographic token validation on every modifying request.
  • Encrypted Transport: 256-bit SSL/TLS end-to-end transport security.

7. Rights of Data Subjects

Registered business representatives are entitled to exercise their rights under GDPR: right of access, rectification, erasure, restriction of processing, data portability and objection. Requests can be submitted via profile settings or directly to the privacy contact.

8. Legal Remedies & Supervisory Authority

Should you consider data processing non-compliant with applicable regulations, you have the right to lodge a complaint with your national Data Protection Authority (DPA) or the Hungarian National Authority for Data Protection and Freedom of Information (NAIH - https://naih.hu).