ITB Privacy Policy
Purpose
The purpose of this Policy is to establish the internal governance framework for how ITB collects, processes, stores, and protects personal and business data and business information obtained through its websites, software applications, cloud-based platforms, and related services.
This Policy ensures ITB complies with applicable data protection laws, industry standards, and contractual obligations relating to third-party platforms, service providers, and technology integrations.
This Policy is intended to provide transparency regarding our data handling practices, inform users of their privacy rights, and demonstrate our commitment to safeguarding personal information in accordance with applicable data protection laws, industry standards, and contractual obligations. This Privacy Policy also outlines the measures we take to ensure the confidentiality, integrity, and security of information processed through our systems, including data received through integrations with third-party platforms, social media services, messaging applications, authentication providers, and other external service providers. By using our Services, users acknowledge and agree to the collection, use, and processing of their information as described in this Privacy Policy.
Scope
This Policy applies to all ITB employees, contractors, consultants, and third-party service providers who access or manage personal information on behalf of ITB including:
- Customers subscribing to our Services;
- Users accessing our software platforms;
- Website visitors;
- Business contacts and prospects; and
- Individuals whose information is processed through our Services by our customers.
1. Data Classification and Handling
All data processed by ITB must be classified according to its sensitivity. Personal data, including data obtained through third-party platform integrations, customer records, user account information, and employee information, is classified as Confidential.
Confidential data must be encrypted in transit and at rest.
Employees must not store Confidential data on unauthorized local devices or unapproved cloud services.
2. Access Control and Segregation of Duties
Access to personal data is governed by the principle of least privilege.
Employees are granted access only to the data necessary to perform their specific job functions.
System administrators must enforce segregation of duties to prevent unilateral access to entire database structures without secondary oversight.
Access logs must be maintained and subject to periodic review by the Internal Audit Department.
3. Data Breach and Incident Response
Any employee who suspects or identifies a data breach, unauthorized access, or loss of personal data must immediately report the incident to the IT Operations and Audit Departments.
Employees must not attempt to investigate or remediate the breach independently.
The Audit Department will lead the incident response, determine regulatory reporting requirements, and manage external communications.
Insider involvement shall be formally assessed.
4. Vendor and Sub-Processor Management
ITB utilizes third-party vendors (e.g., cloud hosts, Meta platforms).
ITB management must conduct security and privacy assessments prior to onboarding any new vendor that will process ITB data.
Contracts must include mandatory data protection clauses and strict data deletion SLAs.
5. Responsibilities
IT technical manager: Responsible for implementing technical security controls, access management, and infrastructure encryption.
ITB Management: Responsible for policy oversight, managing data subject requests (including deletion), and breach notification.
Internal Audit: Responsible for periodic assessments of data handling practices and access log integrity.
Appendix A: Public Instructions
Information We Collect
A. Account and Registration Information: When creating an account or subscribing to our Services, account and registration information is required:
- Full name,
- Business name,
- Job title,
- Email address,
- Telephone number,
- Physical address,
- Username and password,
- Tax and billing information.
B. Business Data: We may collect information entered into the POS system, including:
- Products and inventory records,
- Purchase and Sales transactions,
- Customer records,
- Supplier information,
- Employee information,
- Loyalty program information,
- Reports and analytics.
C. Device and Technical Information: We automatically collect certain information, including:
- IP address,
- Browser type and version,
- Device identifiers,
- Operating system,
- Access dates and times,
- Usage logs,
- Cookies and similar technologies,
- Application performance metrics,
- Geographic location derived from IP address.
D. Payment Information: Payment transactions may be processed through third-party payment providers. We do not store complete payment card information on our servers.
How We Use Information
We use collected information to:
- Provide and maintain our POS services
- Process transactions and subscriptions
- Manage customer accounts
- Improve system performance
- Provide customer support
- Monitor system performance
- Improve products and features
- Send service-related notifications
- Prevent fraud and unauthorized access
- Comply with legal obligations
Third-Party Platform Integrations
Our Service may integrate with third-party platforms, communication services, authentication providers, social networks, messaging applications, e-commerce platforms, and other external business services.
When authorized by you, we may access information made available through such integrations, including:
- Public profile information
- Account and business profile information
- Organization or page information
- Communication and interaction metadata
- Customer communication data
- Transactional and operational data necessary to provide the service
We use this information solely to provide the requested functionality within our platform and in accordance with applicable agreements, platform terms, and laws. We do not sell personal data obtained through third-party integrations to third parties.
Messaging and Communication Services
If you use messaging, communication, or customer engagement integrations through our platform:
- Communications are processed to provide the requested services and functionality.
- Communication content may be stored securely for operational, support, security, and compliance purposes.
- We only access and process information necessary to provide and improve the service.
- We comply with applicable contractual requirements, industry standards, platform policies, and privacy regulations governing such integrations.
Sharing of Information
We may share information with:
- Service Providers: Third-party vendors that assist us with:
- Hosting services
- Cloud infrastructure
- Payment processing
- Analytics
- Customer support
- Legal Requirements: We may disclose information when required by law or when necessary to:
- Comply with legal obligations
- Protect our rights
- Investigate fraud or security incidents
- We do not sell personal information to third parties.
Data Retention
We retain information only as long as necessary to:
- Provide our services
- Meet legal obligations
- Resolve disputes
- Enforce agreements
Upon account termination, data may be deleted or anonymized in accordance with applicable laws and our retention policies.
Data Security
We implement appropriate technical and organizational measures to protect information, including:
- Encryption in transit
- Secure cloud infrastructure
- Access controls
- Regular security monitoring
However, no method of transmission or storage is completely secure.
International Data Transfers
Your information may be processed and stored in countries other than your country of residence. We take appropriate safeguards to protect personal information during such transfers.
Your Rights
Depending on your jurisdiction, you may have rights to:
- Access your personal information
- Correct inaccurate information
- Delete personal information
- Restrict processing
- Object to processing
- Request data portability
To exercise these rights, contact us using the information provided in the Contact Information section below.
Cookies and Tracking Technologies
We may use cookies and similar technologies to:
- Maintain user sessions
- Improve performance
- Analyze usage
- Enhance security
Users may control cookies through browser settings.
Children’s Privacy
Our Service is not directed to children under 13 years of age. We do not knowingly collect personal information from children.
Changes to This Privacy Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated effective date.
Contact Information
If you have questions regarding this Privacy Policy or your personal data, contact us:
- Website: www.itb-me.com
- Email: info@itb-me.com
Data Deletion Request
Users may request deletion of their personal information by contacting us at:
- Email: info@itb-me.com
We will process verified deletion requests within 30 days of identity verification, subject to legal and operational requirements. For third-party platform users, data deletion requests may also be submitted through the applicable platform’s privacy controls, where available