Privacy Policy
Last updated 3 September 2026
This policy explains what personal data T.I.M.E. Network collects from applicants, members and their staff, why, how long it is kept, and the choices available. It is written to meet the GDPR and UK GDPR standard, which the Operator applies globally.
1.What we collect
Account data: name, work email, job title, phone, and login activity. Company data: registration documents, principals’ names, addresses, and the results of sanctions screening. Deal data: RFQs, quotes, shipments, documents, messages and settlements created on the platform. Technical data: IP address, device and browser, and pages viewed, used for security and to operate the service.
2.Why we use it
To verify applicants and enforce membership terms (contract and legitimate interest). To operate the deal, escrow and dispute workflows (contract). To compute TrustScore and publish the Risk Register and claims ledger (legitimate interest in a trustworthy network, and the terms members accept). To send transactional notifications (contract) and, with consent, event and product news. To meet legal obligations including sanctions compliance and anti-money-laundering rules.
3.Sanctions and screening
Company names and principals are screened against consolidated sanctions lists at application and periodically thereafter. Matches are reviewed by a person before any action is taken. Screening records are retained for six years as required by compliance rules.
4.What is public
A member’s public profile shows company name, location, tier, specialties, TrustScore and its component breakdown, tenure, and any current suspension. Individual staff names are visible only to signed-in members. Quotes, invoices, messages and documents are never public.
6.Retention
Account data is kept for the life of the membership and 12 months after. Deal and ledger records are kept for 7 years to satisfy accounting and dispute rules. Screening records for 6 years. Server logs for 90 days.
7.Security
Data is encrypted in transit and at rest. Access is role-based. Sessions are signed and expire after 14 days; a company admin can remove a user's seat, which ends their access at their next request. The Operator runs a nightly integrity check of the ledger.
8.Your rights
Individuals may request access, correction, deletion, restriction or portability of their personal data, and may object to processing based on legitimate interest, by writing to privacy@time-network.example. Requests are answered within 30 days. Individuals in the EU/UK may complain to their supervisory authority.
10.Changes
Material changes are notified to company admins by email 30 days before they take effect.
This page is a plain-language statement of the platform's rules and is provided as a template for review by counsel before commercial launch. Questions: legal@time-network.example.