Privacy Policy
This Policy explains how Industrial Automation Marketplace processes personal data.
Last updated: October 1, 2026 · Effective from: October 1, 20261. Who We Are
Industrial Automation Marketplace is a B2B platform connecting industrial automation buyers and suppliers.
The controller responsible for personal data processed through the Service is:
This Policy applies to personal data processed through accounts, Organizations, Supplier profiles, Project Requests, Leads, Direct Inquiries, billing, support, moderation, security and related Marketplace activities.
Our separate B2B Outreach Privacy Notice explains how we use business contact information for external outreach.
2. Personal Data We Process
Depending on how you use the Service, we may process:
- Account data such as email address, User ID, authentication and account status information.
- Organization data such as membership, role, invitations and ownership information.
- Business profile data such as company information, location, website, services, technologies, industries, logos, certifications and Showcase content.
- Project and inquiry data such as contact details, project descriptions, budgets, locations, technologies, services and messages.
- Billing data such as business name, billing address, tax information, subscription status and payment references.
- Technical and security data such as IP address, request information, security events and relevant application logs.
- Analytics and usage data such as traffic classification, acquisition source, medium and campaign, referrer host, filtered request path, country code, event timing and context, and a pseudonymous visitor identifier where available.
- Support and compliance data such as communications, privacy requests, content reports, moderation records and legal acceptance information.
Our first-party server-side analytics may transiently process a public IP address and User-Agent to derive analytics metadata. The public IP may be used locally to determine an ISO country code. Raw IP addresses and full User-Agent strings are not persisted in the analytics record.
For eligible human, non-internal traffic, we may generate a pseudonymous VisitorKey using HMAC-SHA256 over the normalized public IP address, User-Agent and a version marker with a server-side secret. The VisitorKey is pseudonymous and should not be understood as anonymous data. Sessions are currently derived from VisitorKey and event timing rather than from an analytics identifier stored in the browser.
Payment-card details are handled by our payment provider. We do not intend to store complete payment-card numbers or card security codes in our own Marketplace database.
Data may be provided directly by you, another authorized User, a Buyer or Supplier, our service providers, or obtained from lawful public business sources where appropriate.
3. Why We Process Personal Data
We process personal data for purposes including:
- providing accounts and Organization workspaces;
- publishing Supplier profiles;
- receiving and matching Project Requests;
- providing Leads and Direct Inquiries;
- managing subscriptions, billing and payments;
- sending necessary Service communications;
- providing support;
- protecting the Service and preventing fraud or abuse;
- moderating content and handling reports;
- understanding Service usage, traffic acquisition and Marketplace funnel performance;
- improving and maintaining the Service; and
- complying with legal obligations and establishing or defending legal claims.
Depending on the processing activity, we rely on the following legal bases:
- Contract or pre-contractual steps (GDPR Article 6(1)(b)) — where processing is necessary to provide requested accounts, Organization workspaces, Supplier profiles, Project Requests, Leads, Direct Inquiries and other requested Marketplace functionality, or to manage subscriptions and process payments.
- Legal obligation (GDPR Article 6(1)(c)) — where processing is necessary to comply with invoicing, accounting, tax, regulatory or other legal obligations.
- Legitimate interests (GDPR Article 6(1)(f)) — where processing is necessary for the secure and reliable operation of the B2B Marketplace, preventing and detecting fraud or abuse, maintaining relevant technical and security records, providing support, improving the Service, moderating content, handling reports, or establishing, exercising or defending legal claims, provided those interests are not overridden by the rights and freedoms of the affected individual.
- Consent (GDPR Article 6(1)(a)) — where we specifically request consent and consent is the appropriate legal basis for the processing.
Where we rely on legitimate interests, the interests pursued may include Service security, abuse and fraud prevention, reliable operation, support, Service improvement, understanding Service usage, traffic acquisition and Marketplace funnel performance, and the protection or defence of legal claims, as applicable.
Our first-party server-side analytics is used on this legitimate-interests basis to understand how the Service is used and acquired, measure Marketplace funnel performance, and improve and maintain the Service.
Where information is necessary to create an account, submit a project, purchase a subscription or use another requested feature, failure to provide the required information may prevent us from providing that functionality.
5. How Long We Keep Personal Data
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, subject to legal, accounting, security and dispute-related requirements.
In general:
- active account and Organization information is retained while needed to provide the Service;
- closed Organization and profile information enters our deletion or anonymization process after closure;
- completed Marketplace, support, moderation and technical records are retained for defined operational periods;
- first-party analytics events are generally retained for up to 13 months, while pseudonymous VisitorKey and SessionKey identity material, where present, is removed after 90 days;
- billing and accounting records are retained for legally required periods; and
- records needed for legal claims, security, privacy requests or compliance may be kept longer where justified.
When an Organization is closed, its Organization and Supplier profile information generally becomes eligible for scheduled deletion or anonymization after a 30-day post-closure period. Other record categories may follow different retention periods.
Account deactivation and personal-data erasure are separate processes. A privacy erasure request may be submitted at any time and will be handled subject to applicable legal exceptions.
Where applicable to an account privacy erasure request, restriction of processing or an accepted objection, subject-linked analytics identifiers such as User ID, VisitorKey and SessionKey are removed from the relevant analytics records in accordance with our privacy-handling process.
6. Your Data Protection Rights
Subject to applicable conditions and exceptions, you may have the right to:
- access your personal data;
- correct inaccurate data;
- request erasure;
- request restriction of processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests;
- object at any time to processing for direct marketing; and
- withdraw consent where processing relies on consent.
Privacy requests may be sent to:
We may request reasonable information to verify your identity before acting on a request.
We respond within the period required by applicable data-protection law. Under the GDPR, the ordinary response period is one month, with a possible extension where legally permitted.
You also have the right to lodge a complaint with a competent supervisory authority.
7. Security and Data Breaches
We use technical and organizational measures appropriate to the nature and risks of the Service.
These measures may include authentication, access controls, secure network transport, protected credentials, rate limiting, logging, backups and administrative controls.
No internet service can guarantee absolute security.
We maintain a process for investigating and handling suspected personal-data breaches and will notify supervisory authorities or affected individuals where required by law.
9. Changes and Contact
We may update this Privacy Policy when the Service, our providers, our processing activities or applicable law changes.
Where required, we will provide appropriate notice of material changes.
Privacy questions and requests may be sent to: