Legal

Privacy Policy

Version v2.0 · Last updated: 21 July 2026 · Governing law: Republic of Cyprus

Role of FishMatch Group. FishMatch Group is an independent B2B marketplace that introduces buyers to independent third-party aquaculture Suppliers, EPC contractors, technology providers and financing partners. FishMatch Group is not a manufacturer, distributor, hatchery, fish farm, seafood producer, insurer or financial institution and is not a party to any supply, engineering or financing contract. Once you engage a third party, that party acts as an independent data controller for the personal data it processes to perform its services, and its own privacy policy applies. FishMatch Group is not responsible for any third party's data practices.

1. Who we are (Controller)

The data controller for personal data collected through the Platform is FishMatch Group, a specialised aquaculture procurement platform of Global B2B Group, operated from the Republic of Cyprus. Contact: privacy@fishmatchgroup.com.

2. Personal data we collect

  • RFQ / project data: name, business email, phone / WhatsApp, company, role, country, farm or project location, aquaculture type, species, equipment category, production capacity, project type, budget range, timeline, financing needs, preferred language and free-text notes.
  • Buyer / supplier account data: business contact details, company registration, VAT / EIN, ultimate beneficial owner information (where required), certifications, product catalogues, references.
  • Compliance data: information collected for fraud, AML/CTF, sanctions and export-control screening (where applicable).
  • Communications: messages, uploaded documents, RFQ attachments, chat transcripts with our AI assistant, support tickets, email metadata.
  • Usage & device data: pages viewed, referrer / UTM parameters, language, approximate location (from IP), device, browser, cookies, log data, security events.

3. How we use personal data & legal bases (GDPR Art. 6)

  • Perform the service (Art. 6(1)(b)): match RFQs, forward enquiries to relevant Suppliers or financing partners, deliver requested documents, operate accounts.
  • Legitimate interests (Art. 6(1)(f)): improve the Platform, prevent fraud and abuse, secure our systems, run limited direct B2B marketing to existing users, defend legal claims.
  • Consent (Art. 6(1)(a)): optional analytics cookies, marketing emails to new leads, downloadable-resource opt-ins.
  • Legal obligation (Art. 6(1)(c)): tax, accounting, AML/CTF, sanctions, export-control and lawful requests from authorities.

4. Content downloads & checklists

When you request a downloadable resource (e.g. the Commercial Aquaculture Project Checklist), we ask you to tick a consent box with this exact wording:

"I agree that FishMatch Group may contact me by email about aquaculture procurement, financing, and related content. I can unsubscribe at any time. See our Privacy Policy."

If you tick the box we store your email, optional name / company / country, the page you downloaded from, the exact consent wording, timestamp, IP address and browser user-agent (GDPR Art. 7 record of consent). You may withdraw consent at any time via any email's unsubscribe link or by writing to privacy@fishmatchgroup.com. Withdrawal does not affect prior lawful processing. A "Direct PDF (no email)" link is offered next to every download.

5. Sharing with suppliers, partners and processors

Essential RFQ details required to prepare a quotation are shared with selected Suppliers or financing partners. Personal contact details are only shared with the third party you choose to engage. Each such third party becomes an independent controller and is bound by its own privacy and regulatory obligations. We use trusted processors for hosting, authentication, email delivery, analytics, AI processing, translation, customer messaging, KYC / AML screening and payments, each bound by a data-processing agreement (GDPR Art. 28).

6. International transfers

Personal data may be processed in countries outside the EEA. Where required, we rely on appropriate safeguards including the European Commission's Standard Contractual Clauses (SCCs), the UK IDTA / Addendum, and equivalent mechanisms, together with a transfer impact assessment.

7. Retention

We retain RFQ, account, communications and compliance records for as long as needed to (a) provide the service, (b) meet legal, tax, AML/CTF and audit obligations (typically 5–7 years from last activity in Cyprus), and (c) establish, exercise or defend legal claims. Marketing consents are retained until withdrawn or 24 months of inactivity, whichever is earlier. You may request deletion earlier where no overriding lawful ground applies.

8. Your rights (GDPR)

Subject to applicable law, you have the right to: access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interests or direct marketing. You may withdraw consent at any time. You have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of Cyprus, or with the supervisory authority of your EU country of residence. Contact us first at privacy@fishmatchgroup.com.

9. Automated decision-making & AI

The Platform uses AI-assisted tools to enrich RFQs, match Suppliers, translate content, generate insights and answer questions. These tools do not make legally or similarly significant decisions about you within the meaning of GDPR Art. 22 without human involvement. AI output is informational only — see the AI Content Disclaimer in our Terms of Service and Disclaimer.

10. Security

We apply industry-standard administrative, technical and organisational safeguards, including encryption in transit, access controls, monitoring, logging and least-privilege principles. No system is perfectly secure; please use strong unique passwords and contact security@fishmatchgroup.com immediately if you suspect unauthorised access. Security researchers: see the Responsible Disclosure section of our Terms.

11. Fraud, AML/CTF, sanctions & export-control screening

Where appropriate, we may process limited personal and company data for fraud prevention, AML/CTF, PEP / adverse-media screening, sanctions screening (EU / UN / OFAC / OFSI / Cyprus) and export-control screening. Legal bases include our legitimate interests in preventing crime, compliance with legal obligations, and the substantial public interest.

12. Cookie Policy

We use the following cookie categories:

  • Strictly necessary (authentication, session, security, load-balancing, consent state) — used at all times; no consent required.
  • Preference (language, locale, UI settings) — used to remember your choices.
  • Analytics (aggregate usage insights) — set only with your consent where required by law.
  • Third-party (embedded content, chat, video, messaging) — subject to the third party's own policy.

You can withdraw or change cookie consent at any time via your browser settings or the on-site consent banner. Blocking strictly-necessary cookies may impair the Platform.

13. Children

The Platform is a B2B service intended for professional use and is not directed at children under 16. We do not knowingly collect personal data from children.

14. Changes

We may update this Policy. Material changes will be communicated on the Platform and reflected in the version number and "Last updated" date above.

15. Related policies

Terms of Service · Disclaimer · Legal Notice · Accessibility Statement · Trust Center

16. Contact

Privacy / GDPR: privacy@fishmatchgroup.com · Security: security@fishmatchgroup.com · Compliance: compliance@fishmatchgroup.com.

Get Free QuotesFinancing