GDPR Privacy & Data Protection Policy
Information regarding the processing of personal data, corporate credentials, technical audit logs and masked IMEI identifiers by GSM B2B Hub.
Privacy Sections
- 1. Data Controller Details
- 2. Scope of Processed Data
- 3. Legal Grounds & Purposes
- 4. IMEI & Audit Logs
- 5. Data Retention Periods
- 6. Technical Security
- 7. Rights of Data Subjects
- 8. Legal Remedies & Authorities
1. Data Controller Identification
The data processing operations on the platform are executed by the operator of GSM B2B Hub (hereinafter: "Controller"):
2. Scope of Processed Corporate & Personal Data
In providing our exclusive B2B wholesale services, we process strictly necessary data:
- Company credentials: Registered entity name, shop name, registered office address, tax/VAT number, EU VAT ID, company registration number, activity scope.
- Authorized contact details: Full name, job title, business phone number, business email address.
- Verification documents: Business registry certificate, trade license (for authentication only).
- Technical & security logs: Login IP addresses, timestamped failed login attempts, browser user-agent headers, encrypted session IDs.
3. Legal Grounds & Purposes of Processing
- Contract Performance (GDPR Art. 6(1)(b)): Providing B2B marketplace features, messaging, inventory tracking and forum access.
- Legitimate Interest (GDPR Art. 6(1)(f)): Protecting the verified B2B ecosystem against stolen devices, credential-stuffing attacks and financial fraud.
- Legal Obligation (GDPR Art. 6(1)(c)): Fulfilling commercial accounting, tax invoice auditing, and official statutory disclosures.
4. Device Identifiers (IMEI) & Audit Trail Protection
Device IMEI serial numbers constitute sensitive commercial and identification data. Full 15-digit IMEI numbers are never publicly disclosed on the platform; they are displayed exclusively in masked format (e.g. 358921••••••475) to prevent duplication while enabling authenticity checks.
5. Data Retention Periods
- Active business profile data: Retained for the duration of verified membership or until explicit account termination.
- Login security records: Retained for a maximum of 90 days.
- Audit trail and transaction messages: Retained for 5 years in compliance with statutory commercial limitation periods.
6. Technical Security Measures
- Adaptive Password Hashing: Argon2id and Bcrypt one-way cryptographic algorithms.
- Mandatory 2FA (TOTP): Time-based one-time password security (RFC 6238) with single-use backup recovery codes.
- Brute-Force & CSRF Defense: Rate-limiting lockouts (3/5 tier) and cryptographic token validation on every modifying request.
- Encrypted Transport: 256-bit SSL/TLS end-to-end transport security.
7. Rights of Data Subjects
Registered business representatives are entitled to exercise their rights under GDPR: right of access, rectification, erasure, restriction of processing, data portability and objection. Requests can be submitted via profile settings or directly to the privacy contact.
8. Legal Remedies & Supervisory Authority
Should you consider data processing non-compliant with applicable regulations, you have the right to lodge a complaint with your national Data Protection Authority (DPA) or the Hungarian National Authority for Data Protection and Freedom of Information (NAIH - https://naih.hu).