Text je k dispozici pouze v angličtině. Jde o pracovní návrh (verze 4), který zatím neprošel právní revizí.

MatchDC Privacy Policy

Effective [effective date] (Version 4)

This Privacy Policy explains how [MatchDC registered company name], [Registered office address, state of incorporation, and entity number] (“MatchDC,” “we,” “us”) collects, uses, discloses, and retains personal information in connection with the MatchDC business-to-business marketplace, public pages, and communications (“Services”). Contact: legal@matchdc.com.

1. Scope

The Services launch in the United States and are intended for business representatives. This Policy applies to information that identifies, relates to, describes, or could reasonably be linked with an individual or household (“Personal Information”). It does not cover information that is lawfully public, aggregated, or de-identified as defined by applicable law, or third-party services governed by their own policies.

2. Information we collect

Depending on use, we collect the following categories and examples:

  • Identifiers and account data: name, business email and telephone number, username, IP address, organization, job title, typed signature, and account identifiers.
  • Organization and verification data: legal and trade names, business address, EIN or tax identifier, formation and ownership or control information, licenses, supporting documents, verification result, and sanctions-screening information. Some organization records may contain Personal Information.
  • Commercial and transaction-workflow data: membership, payments and invoices, listings, RFQs, quotes, budget ranges, delivery needs, Introduction confirmations, deal-desk opt-ins, fee calculations, and transaction status. Stripe processes card details; MatchDC does not store full card numbers.
  • Communications and content: messages, attachments, support requests, survey responses, and redacted or flagged contact details. Before Introduction, automated systems inspect messages for contact details and may route flagged content for authorized human review.
  • Internet and device activity: browser and device type, operating system, user agent, referring pages, pages and features used, clicks, timestamps, approximate location inferred from IP, cookies, logs, and security events.
  • Inferences: matching scores based on stated category, quantity, delivery window, region, and certification, and fraud, abuse, or account-risk signals. Matching is not used to make legal, employment, credit, housing, insurance, healthcare, or similarly significant decisions about individuals.
  • Contract evidence: accepting user and organization, typed name and title, email, IP address, browser user agent, acceptance timestamp, exact rendered document, its SHA-256 hash, version, PDF, and delivery record.

We collect information directly from Users, automatically from devices, from an Organization and its authorized users, from payment and infrastructure providers, and from lawful public business records or verification sources.

For California disclosure purposes, during the preceding 12 months we collected the statutory categories of identifiers; personal-record information; commercial information; internet or other electronic-network activity; professional or employment-related information; approximate geolocation inferred from IP; and inferences described above. Depending on verification material supplied, we may receive sensitive Personal Information consisting of account credentials and government identifiers such as tax identification numbers. We use sensitive Personal Information only for permitted purposes such as account access, identity verification, security, service performance, and legal compliance—not to infer characteristics.

Statutory category Sources Business purposes Recipient categories Sold/shared in prior 12 months Retention criteria
Identifiers, personal records, professional information User, Organization, public business records, verification providers Account, KYB, contracting, support, security, compliance Hosting, database, email, verification, advisers, authorities where required No Relationship plus applicable contract, tax, security, and claims periods
Commercial and marketplace information User, Organization, counterparties, Platform activity Membership, listings, RFQs, matching, Introductions, billing, enforcement Hosting, database, payment, email, counterparties after opt-in, advisers No Relationship plus applicable contract, tax, audit, and claims periods
Internet, device, approximate location, security activity Browser, device, cookies, logs Authentication, operation, fraud prevention, debugging, analytics Hosting, database, security and analytics providers No Shortest period reasonably necessary for operation, security, and claims
Communications and contract evidence User, Organization, Platform Messaging, screening, support, execution, proof, disputes Hosting, database, email, advisers, authorities where required No Message lifecycle and legal need; contract evidence as stated in Section 6
Inferences Platform matching and risk systems Matching, ranking, security, abuse prevention Hosting, database, authorized Users as part of matches No While relevant to the account, RFQ, security event, or claim

“Sold” and “shared” use their meanings under the California Consumer Privacy Act. We disclosed the categories above for the stated business purposes during the preceding 12 months, subject to service-provider or contractor restrictions where applicable.

3. Why we use it

We use Personal Information to provide and administer accounts; verify business identity; publish authorized supplier-register fields and anonymized listings or RFQs; match demand and supply; screen and redact pre-introduction messages; record mutual consent and release contact details; process membership payments; deliver transactional email; support Users; secure, debug, and improve the Services; prevent fraud, circumvention, Bid Shopping, and unlawful activity; enforce contracts and preserve evidence; comply with law, sanctions, tax, accounting, and legal process; and establish, exercise, or defend legal claims.

Where a law requires a legal basis, the bases are performance of or steps toward a contract, legitimate interests in operating and securing a B2B marketplace and preserving reliable contract evidence, compliance with legal obligations, and consent where specifically requested. We balance legitimate interests against individual rights and use information only as reasonably necessary and proportionate.

4. Public information

With an active applicable membership, the public supplier register may show organization name, city, state, categories, delivery coverage, founded year, project count, and approved track record. It intentionally shows no contact person, email, telephone number, street address, or website. Public catalog listings are anonymized until Introduction. Public RFQs show only fields selected for public visibility and must not include Personal Information or confidential site details. Users are responsible for avoiding Personal Information in public free-text fields.

5. How we disclose information

We disclose Personal Information as needed to:

  • Vercel, for application hosting and delivery;
  • Supabase, for database and file storage;
  • Stripe, for payment processing, fraud controls, and billing;
  • Resend, for transactional email;
  • professional advisers, auditors, insurers, and authorities subject to appropriate duties or law;
  • a counterparty after both sides complete the Introduction opt-in;
  • an Organization administering its users; and
  • a successor in a merger, financing, reorganization, or sale, subject to this Policy and applicable notice requirements.

Providers may change; the current list may be requested at legal@matchdc.com. We contractually require service providers and contractors to process information only for specified business purposes, protect it, and comply with applicable privacy law.

MatchDC does not sell Personal Information for money or other valuable consideration. MatchDC does not share Personal Information for cross-context behavioral advertising and does not use or disclose sensitive Personal Information to infer characteristics. If that practice changes, we will provide required notice and opt-out mechanisms before the change. We do not knowingly collect Personal Information from children under 18; the Services are not directed to them.

6. Retention

We retain each category only as long as reasonably necessary for the purposes described, considering contract duration, account status, security, disputes, legal limitation periods, tax and accounting duties, and backup cycles. Ordinarily, account and marketplace content is retained during the relationship and up to 7 years afterward where needed for contracts, tax, audit, fraud prevention, or claims; short-lived security logs may be kept for a shorter period; backups expire on scheduled cycles unless preserved for a legal hold.

Contract evidence—the identity and authority record, IP address, user agent, timestamp, exact rendered text, SHA-256 hash, tamper-evident PDF and acceptance record, version, and delivery record—is retained for the life of the contract and afterward for the applicable legal-claims and recordkeeping period. It cannot be deleted while the contract is in force because it is reasonably necessary to perform and prove the contract, ensure security and integrity, comply with legal obligations, and establish, exercise, or defend claims. A deletion request does not override those exceptions. We will delete information not covered by an exception and explain any retained categories and reason.

7. Security

We use administrative, technical, and physical safeguards appropriate to the nature of the information, including access controls, encryption in transit, restricted production access, logging, and versioned contract records. No system is perfectly secure. Users must protect credentials and promptly report suspected compromise to legal@matchdc.com.

8. United States privacy rights

Subject to applicable state law and exemptions, an individual may request: confirmation and access; correction; deletion; a portable copy; categories and specific pieces collected; sources, purposes, and recipients; and appeal of a denied request. Where applicable, an individual may opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, or qualifying profiling. MatchDC currently does not engage in those opt-out activities. We will not unlawfully discriminate for exercising a right.

Submit a request through the privacy-request control in the account or to legal@matchdc.com and identify the right and account or Organization. We will verify identity using information reasonably matched to our records and may verify authority for an agent. We will use request information only to verify and respond. If we cannot verify or an exception applies, we will explain. California residents may also ask for the categories collected, sources, business or commercial purposes, categories of third parties, and specific pieces for the applicable statutory lookback period. California residents may limit use of sensitive Personal Information only where the statutory right applies; MatchDC does not presently use it beyond permitted business purposes.

9. Cookies and communications

We use necessary cookies or similar storage for authentication, security, preferences, and core operation, and may use measured analytics disclosed in the cookie interface. Because MatchDC does not sell or share Personal Information or use it for targeted advertising, browser opt-out preference signals such as Global Privacy Control do not presently change a sale or sharing setting; if those practices change, MatchDC will honor legally recognized signals. Browser “Do Not Track” signals are not a uniform legal standard and do not alter necessary Platform operation; optional analytics choices are controlled through the cookie interface where offered. Browser controls can remove cookies but may impair the Services. Transactional and legal messages are part of the Services. Marketing email, if sent, includes an unsubscribe method; opting out of marketing does not stop operational messages.

10. International expansion

The Services are currently U.S.-only. Before onboarding individuals located in the European Economic Area, United Kingdom, Switzerland, or another jurisdiction requiring additional safeguards, MatchDC will implement the applicable privacy notice, controller/processor allocation and data processing agreement, data-subject procedures, international-transfer mechanism such as approved standard contractual clauses where required, and local representative or impact assessment where applicable. This Policy does not claim those measures are currently in place.

11. Changes and contact

We may update this Policy prospectively. We will post the new version and give prominent or direct notice of material changes before they take effect where required. Earlier versions remain associated with the contract records to which they applied.

Privacy inquiries, rights requests, and complaints: legal@matchdc.com or [MatchDC registered company name], [Registered office address, state of incorporation, and entity number]. An individual may appeal a denied request by replying “Privacy Appeal” with the reasons for appeal; we will respond within the period required by applicable law and identify any right to contact a state regulator.