B2B.Africa

Privacy Policy

Last updated: 16 August 2026

This Privacy Policy explains how B2B.Africa processes information about users, business representatives, company profiles, requests, reports and other Platform activity.

1. Who we are

B2B.Africa is operated by Maya Tech Services LLC, a Delaware limited liability company, United States, with a registered address at 8 The Green, Suite A, Dover, DE 19901, USA ("Maya", "B2B.Africa", "we", "us").

For personal information that Maya determines the purposes and means of processing, Maya is the responsible party/controller/personal information processor as those concepts may apply under relevant law.

Privacy contact: support@b2b.africa.

For mainland-China users, additional information required by China's Personal Information Protection Law ("PIPL") will be provided in a PRC-specific Privacy & Cross-Border Notice, published before B2B.Africa actively scales mainland-China acquisition. Where PIPL Article 53 requires it, that notice will include the details of Maya's representative in the People's Republic of China.

2. Business-use context

B2B.Africa is designed for business and professional use.

Even in a B2B service, we process personal information about natural persons, such as: account users; company representatives; directors/officers appearing in lawful registry records; persons communicating through requests or messages; people who contact support; and persons identified in a report where the applicable source and law permit such processing.

South African law may also protect certain information relating to juristic persons. Where applicable, we handle such information in accordance with the relevant South African requirements.

3. Information we collect

Depending on how you use the Platform, we may collect:

3.1 Account and identity data

Name, where provided; business email address; authentication credentials/tokens; organisation and role; language/locale (English or Chinese); account status; evidence of authority or domain control where a feature requires it.

3.2 Company profile data

Company name, country and address, website/domain, registration number/status, industry/ categories, company description, products/services, documents or claims submitted by an authorised company representative, verification level and verification history, and profile-claim history.

3.3 Request, RFQ and matching data

Products/services sought or offered; target countries/regions; quantity/volume; budget or price range; timing/deadline; technical requirements; selected categories/HS codes where used; attachments; match and response history; request status.

3.4 Reports and research data

For Verify Company, Market Scan and related products: source URLs/references; retrieval dates; provenance/source class; publicly or lawfully available company facts; permitted registry/ government/tender records; company-published claims; licensed-provider facts where applicable; confidence labels; analyst/AI-assisted research notes; correction/dispute history.

A commissioned official-registry extract is used only within that specific report and is not copied into any public profile, catalogue, or matching data — see our data-sourcing rules (described on the Trust & methodology page) for how source terms restrict reuse.

3.5 Communications

In-platform messages; support requests; chat-assistant transcripts; email correspondence; correction/dispute submissions; consent/opt-out communications.

3.6 Payment/order information

We generally do not store full card data.

For Paddle transactions, we may receive information needed to provide and support the Product, such as buyer/account identifiers, order/subscription identifiers, product/plan, amount/ currency, transaction/refund status, and billing/business details made available to us by Paddle. Paddle separately processes payment information as Merchant of Record under its own privacy terms.

For direct T/T orders, we may process invoice details, remittance records, payer details and bank references needed to reconcile the payment and meet accounting/legal obligations.

3.7 Technical, security and usage data

IP address; timestamps; browser/device/user-agent information; session identifiers; security and authentication events; rate-limit/abuse signals; product lifecycle events such as signup, request creation and profile completion; acceptance/version records for legal documents.

We currently do not use third-party advertising trackers unless the Platform and this Policy are updated to say otherwise.

3.8 Consent and suppression records

We maintain records of the consent/notice version shown; purpose; acceptance or refusal; date/ time; withdrawal; unsubscribe; suppression/opt-out status; and direct-marketing screening evidence where applicable.

Suppression records may be retained longer than other account data where reasonably necessary to ensure we do not contact a person who opted out.

4. Where information comes from

Information may come from: you; your organisation; another authorised user in your organisation; a company website; official public registries; official government/tender/ sanctions sources; public professional/business sources used consistently with applicable law and source terms; licensed providers; permitted secondary sources; matching/request counterparties; Paddle or other payment providers; and service providers supporting Platform operation.

We do not treat a secondary source or registry aggregator as an official registry merely because it contains registry-like information.

5. Why we process information

We process information for the following purposes, using the legal basis required by the law that applies to the particular processing.

5.1 Provide the service / perform an agreement

For example: create and secure accounts; provide purchased reports; operate subscriptions; process requests; match companies; provide messages/notifications; fulfil verification orders; provide customer support.

5.2 Consent

Where required, we rely on specific consent for marketing; certain electronic communications; certain disclosures/transfers; mainland-China cross-border transfers or other processing requiring separate consent under PIPL; and any sensitive-personal-information processing that requires consent.

Consent captured for each purpose is unbundled: agreeing to one type of communication (for example, request notifications) does not bundle-in another (for example, marketing); consent checkboxes are not pre-ticked; and consent can be withdrawn where the law gives that right.

5.3 Legitimate/business interests where recognised by applicable law

For example: prevent fraud/abuse; secure the Platform; improve product usability; maintain audit evidence; protect legal rights; analyse aggregate product performance. We use this basis only where applicable law recognises it and after considering affected rights.

5.4 Publicly disclosed / legally permitted business information

Where applicable law permits, we may reasonably process information that has been lawfully made public, including certain business/directorship information, for report/profile purposes. We still apply data-minimisation, provenance and correction controls.

5.5 Legal obligations and legal claims

We process information where necessary to comply with law/regulator/court requirements; maintain tax/accounting records; respond to lawful requests; establish, exercise or defend legal claims; and comply with sanctions/trade or consumer-protection obligations.

6. AI-assisted and automated processing

We may use AI or automated tools to assist with classification, translation, summarisation, matching, research drafting, fraud/rate-limit signals, and chat assistance.

Our product design is intended to distinguish source facts from model-generated analysis.

We do not intend to use a fully automated process to make a decision about a natural person that has legal or similarly significant effects without the safeguards required by applicable law. Where PIPL or other applicable law requires an impact assessment for automated decision-making, we will perform and retain it as required.

Where an account/verification decision materially affects a person and applicable law provides a right to explanation or human review, a request can be submitted through the privacy/support contact channel.

7. Public profiles and research subjects

A public business profile can include information obtained from permitted sources even before a representative has claimed it. An Unclaimed status expressly means no authorised representative has yet claimed the profile.

For information about natural persons in a public company record, we limit publication to what is reasonably relevant to the business purpose and permitted by the source/law.

If you believe a public profile or report contains inaccurate personal or company-identifying information, you may request correction or challenge the source using the Platform's correction mechanism. We may preserve a version/audit history where reasonably required for integrity, disputes and legal compliance.

8. Who receives or processes information

We use service providers and counterparties only to the extent reasonably necessary for Platform operation.

  • Paddle — Merchant of Record/reseller for self-serve transactions, and handles buyer/ payment information under its own legal terms and privacy notice. Paddle is not accurately described as merely "our processor" for all payment data; each party is responsible for the data-processing role it actually performs.
  • Hosting — Hetzner (server infrastructure, Germany) and Neon (database, EU/Frankfurt); traffic is proxied through Cloudflare.
  • AI model provider — Anthropic, used to help draft report content, power the AI chat assistant, and support internal quality checks. Conversation and request content may be sent to this provider to generate a response. We do not rely on an AI provider as an authoritative source for a factual verification claim.
  • Transactional email provider — not yet engaged; this policy will be updated when one is added.
  • Licensed data / verification / inspection providers — where a product uses a contracted data provider or inspection partner, that provider receives only the information reasonably needed for the relevant service, subject to the applicable contract and legal role. None are under contract at present; this policy will be updated if that changes.
  • Matched companies / users — a request's permitted content is shared with selected potential counterparties as the feature describes. Requester identity/contact data is disclosed only under the feature's stated rules.
  • Professional advisers / legal requirements — information may be disclosed to lawyers, accountants, insurers, auditors, regulators, courts or authorities where reasonably required and lawful.

We require each processor to handle data only on our instructions and only for the purpose we engaged them for.

9. South Africa: POPIA and juristic-person data

Where the Protection of Personal Information Act, 2013 ("POPIA") applies to Maya or to a specific processing activity, we process relevant information in accordance with POPIA's applicable conditions.

South African identifying information about a juristic person may fall within POPIA's definition/scope. This may include a South African company profile or company-related verification data.

Maya will maintain the Information Officer / local-authorisation / PAIA arrangements required if South African law applies those requirements to Maya's current operations. If a South African Information Officer/local authorised person is required, their legally required contact/ registration details will be published in the appropriate notice/manual.

10. South Africa: outbound communication and direct marketing

We distinguish operational/request communications from marketing. We will not intentionally send electronic direct marketing to a South African recipient unless the legal preconditions applicable to that communication are satisfied.

Where required, controls include: a lawful permission/consent mechanism; the applicable POPIA section 69 process; screening/cleansing against the CPA Opt-Out Registry; registration as a direct marketer where required; sender identification; a simple opt-out/unsubscribe; suppression- list checks; and audit records.

Currently, for South African companies we use a once-off consent-request message, aligned with POPIA section 69(2)/Form 4, sent at most once per company across the Platform's entire history; every message type includes a one-click unsubscribe mechanism (RFC 8058); and for Kenyan/Nigerian companies, only role-based addresses (e.g. info@, sales@) are used — never a named individual's address obtained without their own consent.

A recipient who opts out is added to a suppression mechanism so the opt-out can be respected. A "real RFQ" or match does not automatically exempt a message from direct-marketing law; the classification depends on the actual message and purpose.

11. Cookies

We use only first-party cookies necessary or functional for the Platform to function:

  • b2b_session — necessary. Keeps you signed in to your account.
  • b2b_anon — necessary/functional. A random identifier that lets an unregistered visitor continue a draft request across visits.
  • chat_session — necessary/functional. Binds an AI chat-widget conversation to your browser session so the conversation continues correctly across messages and, if escalated, reaches the right human follow-up.

We set no third-party analytics or advertising cookies. If analytics, advertising or other non-essential cookies are added, this Policy and the applicable consent mechanism will be updated before such use where required.

12. Cross-border data transfer

Maya Tech Services LLC and its processing infrastructure are based in the United States and the European Union.

12.1 South Africa

Where POPIA section 72 applies to a transfer outside South Africa, we use the permitted mechanism applicable to the transfer, which may include a recipient subject to adequate protection, contractual safeguards/binding agreement, consent where valid and appropriate, or another statutory ground. We maintain the underlying contracts/assessment needed to support the statement we make publicly; a policy sentence alone is not treated as a transfer mechanism.

12.2 Mainland China

If PIPL applies to Maya's processing of personal information of natural persons within mainland China, before actively scaling that acquisition: a specific Chinese-language notice will be provided; separate consent for an overseas transfer will be obtained where Article 39 requires it; that notice will identify the overseas recipient(s), contact information, purposes/methods/ categories and how individuals may exercise rights; the applicable Article 38 transfer route or a documented exemption under then-current CAC rules will be assessed; a personal-information protection impact assessment will be performed/retained where required; and the Article 53 PRC representative/specialised-agency requirement will be implemented where applicable.

Our zh-CN registration flows present a separate, specific checkbox for consenting to cross-border transfer of personal information, as required by PIPL, alongside the Chinese- language privacy notice, once that notice is live.

13. Mainland-China PIPL representative

If Maya is a foreign personal-information processor within PIPL Article 3(2) and Article 53 applies, Maya will appoint or establish the required representative/agency in the People's Republic of China and submit the required details to the competent authority before actively scaling mainland-China acquisition. Once determined, the representative's name and contact details will be published here and in the PRC-specific notice referenced in §1. We do not publish invented representative details.

14. Retention

We retain information only for as long as reasonably necessary for the purpose and applicable legal obligations.

  • Account data. For the life of the account and ordinarily up to 24 months after account closure, unless a longer period is needed for legal, tax, fraud, dispute or security reasons.
  • Requests/messages. For the life of the account/service and ordinarily up to 24 months after closure or the end of the relevant business relationship, subject to legal/dispute needs.
  • Reports/provenance. For as long as needed to deliver/support the report and ordinarily up to 24 months after delivery/account closure, except where source terms require earlier deletion or law/dispute/audit obligations require longer retention.
  • Consent/acceptance/audit records. For as long as reasonably needed to demonstrate compliance. Where PIPL requires an impact-assessment/processing record to be kept for at least three years, we retain it for at least that period.
  • Suppression/opt-out records. As long as reasonably necessary to respect the opt-out and demonstrate compliance. We may retain a minimal hashed/suppression identifier rather than a full marketing profile.
  • Payment/tax/legal records. For the period required by the applicable accounting/tax/ payment law or to resolve disputes.
  • Official-registry extracts. Used only within the report they were purchased for and not retained for reuse outside it.

15. Your rights

Subject to applicable law (POPIA for South African data subjects; comparable rights are extended to other users), you may have rights to: access or obtain confirmation of personal information; receive a copy; correct/supplement inaccurate information; request deletion; object to/restrict processing (for example, marketing); withdraw consent; opt out of marketing; request information about automated processing; request human review where required; and complain to a competent regulator.

To exercise a right, contact us at support@b2b.africa. We may need to verify identity/ authority before disclosing or changing data. Access to personal data is logged in an internal audit log.

We will respond within the period required by applicable law. Where no shorter mandatory deadline applies, our operational target for routine verified access/correction/deletion requests is 30 days.

We may lawfully retain information despite a deletion request where retention is required for legal obligations, security, fraud prevention, suppression, records of consent/withdrawal or legal claims.

16. Security

We use reasonable administrative, technical and organisational safeguards appropriate to the nature of the Platform, including access control, authentication, rate limiting, logging, private/restricted storage where appropriate, secure transport, limited provider access, and incident response. Access to a company's data on the Platform is restricted to members of that company.

No internet service can guarantee absolute security. If a personal-information security compromise occurs, we will take reasonable remedial steps and make regulatory/data-subject notifications where and when applicable law requires.

17. Sensitive personal information

The self-serve Platform is not designed to collect unnecessary sensitive/special-category personal information. Do not upload identity documents, financial-account details, health data, precise location data or other sensitive personal information unless the relevant verification/ order flow expressly requests it and provides the required notice/security controls.

Where a specific verification service legitimately requires sensitive information, we apply the additional legal basis/consent, minimisation and safeguards required by applicable law.

18. Children

The Platform is intended for business users aged 18 or older and is not directed to children. We do not knowingly invite children to create accounts.

19. Data quality, adverse information and correction

Because B2B.Africa publishes business-verification information, data quality is a core control. We distinguish official facts, company-published claims, secondary facts, analysis, and confidence level.

For adverse or disputed information: wording should describe the source fact rather than make an unsupported accusation; absence of a record is not proof of absence; a subject may submit a correction/challenge; we may mark a materially disputed fact while reviewing it; and corrected reports/profiles may carry a version history.

20. Governing law and complaints

Privacy-related disputes are subject to the same governing law and forum as the Terms of Service §25, without limiting any mandatory data-protection rights you hold in your own jurisdiction or the right to complain to a competent data-protection authority. For Paddle payment processing, Paddle's own privacy notice governs Paddle's processing.

21. Changes to this policy

We will update this policy as the Platform and its data practices evolve, and will note the date of the latest revision at the top of this page. Material changes will be announced on this page and, for registered users, by email. Where new consent is legally required, we will request it rather than treating silence as consent.