Legal

Privacy Policy

Last updated 3 September 2026

This policy explains what personal data T.I.M.E. Network collects from applicants, members and their staff, why, how long it is kept, and the choices available. It is written to meet the GDPR and UK GDPR standard, which the Operator applies globally.

1.What we collect

Account data: name, work email, job title, phone, and login activity. Company data: registration documents, principals’ names, addresses, and the results of sanctions screening. Deal data: RFQs, quotes, shipments, documents, messages and settlements created on the platform. Technical data: IP address, device and browser, and pages viewed, used for security and to operate the service.

2.Why we use it

To verify applicants and enforce membership terms (contract and legitimate interest). To operate the deal, escrow and dispute workflows (contract). To compute TrustScore and publish the Risk Register and claims ledger (legitimate interest in a trustworthy network, and the terms members accept). To send transactional notifications (contract) and, with consent, event and product news. To meet legal obligations including sanctions compliance and anti-money-laundering rules.

3.Sanctions and screening

Company names and principals are screened against consolidated sanctions lists at application and periodically thereafter. Matches are reviewed by a person before any action is taken. Screening records are retained for six years as required by compliance rules.

4.What is public

A member’s public profile shows company name, location, tier, specialties, TrustScore and its component breakdown, tenure, and any current suspension. Individual staff names are visible only to signed-in members. Quotes, invoices, messages and documents are never public.

5.Sharing

Data is shared with counterparties in a deal to the extent needed to complete it; with processors under contract (hosting in the EU, email delivery, payment and screening providers); and with authorities where the law requires. The Operator does not sell personal data and does not share it with advertisers.

6.Retention

Account data is kept for the life of the membership and 12 months after. Deal and ledger records are kept for 7 years to satisfy accounting and dispute rules. Screening records for 6 years. Server logs for 90 days.

7.Security

Data is encrypted in transit and at rest. Access is role-based. Sessions are signed and expire after 14 days; a company admin can remove a user's seat, which ends their access at their next request. The Operator runs a nightly integrity check of the ledger.

8.Your rights

Individuals may request access, correction, deletion, restriction or portability of their personal data, and may object to processing based on legitimate interest, by writing to privacy@time-network.example. Requests are answered within 30 days. Individuals in the EU/UK may complain to their supervisory authority.

9.Cookies

The platform uses a single strictly necessary session cookie and a theme preference. No advertising or cross-site tracking cookies are set.

10.Changes

Material changes are notified to company admins by email 30 days before they take effect.

This page is a plain-language statement of the platform's rules and is provided as a template for review by counsel before commercial launch. Questions: legal@time-network.example.