Legal
Privacy policy
What we collect, why we are allowed to, who can see it, and how to take it back.
Last updated 25 August 2026
This describes what B2Pair does with personal data. It is written to be read rather than to be survived, and it describes the product as it is actually built.
Who we are
B2Pair is operated by Limitless Outsourcing LLC, a company registered in Kosovo under number 812361880, at Bill Klinton 3, Prishtina 10000, Kosovo.
For anything about your own data, write to privacy@b2pair.com. We answer within thirty days, and sooner where we can.
Who is responsible for what
There are two relationships here and they are governed differently.
Your own account
When you sign up, create a profile, message somebody or attend an event, B2Pair is the controller of that data. This policy covers it.
An event you attend
When an organiser runs an event on B2Pair, that organiser is the controller of the attendee list for their event and we act as their processor. What they may do with it is set out in our data processing terms, and their own privacy notice governs what they collect and why.
What we collect
- Your account: name, email address, password (stored hashed, never in readable form), and the times you signed in.
- Your profile: headline, biography, photo, cover image, city and country, languages, seniority, website and LinkedIn address, and where you work — all of it optional except your name.
- What you said you came for, per event: the direction you are facing, what you offer, what you are looking for, and your answers to the organiser's registration questions.
- What you do here: meetings requested and answered, messages sent, connections made, sessions you joined, posts you wrote, and whether you came through the door.
- Anything you attach to a message: pictures, GIFs and PDFs you send to somebody in a conversation. They are readable only by the two of you.
- What you write about a meeting afterwards, if you use the debrief: your own account of how it went, which necessarily mentions the person you met.
- Your card: the contact details you choose to hand to exhibitors who scan your badge, and a record of which stands scanned you, when, and what your card said at that moment.
- Payments, where an event charges for tickets: the amount, the currency, the tax, your billing details and your VAT number if you gave one. We do not see or store card numbers.
- Technical records kept to run the service: session cookies, rate-limit counters, error logs, and the record of files you upload.
What we do not collect
- No advertising or analytics trackers. There is no third-party tag on any page of this product.
- No location beyond the city and country you type yourself.
- No contact-book uploads, and no scraping of your other accounts.
- No photographs beyond the ones you choose to upload — and every image is re-encoded on the way in, which removes the EXIF data, including the coordinates a phone camera records.
- No special categories of data. Nothing here asks about your health, beliefs, politics or anything else in that class, and nothing infers them.
Why we are allowed to
Every use below has a lawful basis under the GDPR, and they are not interchangeable: the basis decides which rights you have over it.
- Running your account, your profile and the events you join — performance of a contract with you (Article 6(1)(b)). This is everything you would call “the product working”: signing in, being matched, sending a message, holding a meeting.
- The AI features you press a button for — also contract (Article 6(1)(b)). None of them runs on its own, and none of them runs for anybody who has not asked.
- Keeping the service up and unabused — our legitimate interests (Article 6(1)(f)): rate limiting, error logs, the audit trail behind administrator access, and the checks that stop one account scraping the directory. Our interest is a service that works; the effect on you is a counter with your account id on it, kept a week.
- Financial records where money changed hands — a legal obligation (Article 6(1)(c)). This is the one thing on this page that deleting your account does not remove.
- Handing your card to an exhibitor — your own act. You present the badge, you decide what is on the card, and nothing goes anywhere until you do.
Who can see what
This is the part most policies leave vague, so it is set out precisely. Each of these is enforced in the database itself rather than in the application, which means a mistake in our own code cannot get round it.
Other people on B2Pair
Your name, photo, headline, what you wrote about yourself, where you work and the city you gave. Not your email address, your phone number, or anything else on your card. Somebody who wants to reach you writes to you here — which is a message you can ignore rather than an address you cannot take back.
Somebody can only look you up at all if they share an event with you, are connected to you, work at the same company, or administer your employer’s page.
Anybody whose scan of your badge you allow
This is the one place your contact details leave B2Pair, and it only happens when you do something: hold your badge up for somebody to scan.
Anybody at the same event can scan you and you can scan them, exactly as two people swap business cards. It goes both ways: when a scan happens, you each receive your card — your name, where you work, your job title, what you said you came to that event for, and whichever contact details you have chosen to put on it. They become a connection of yours, and you of theirs.
If the person scanning you works a stand, their stand gets a copy. Somebody on a stand is there for the company paying for it, so the people they meet are that company’s leads as well as their own contacts. You are told when it happens and which stand it was. The same person scanning you at an event where their company is not exhibiting is simply a person you met, and no company receives anything.
Every scan of your badge is announced to you: who scanned it, when, and the stand if there was one. That notice is how you find out about a scan you were not present for, which matters because a badge can be photographed and a code can be forwarded.
Your email address is on your card unless you take it off. People come to these events to be contacted, and an exhibitor you spoke to for ten minutes who then cannot reach you is the failure the whole exercise exists to avoid. Your phone number is there only if you typed one; nobody needs a phone number to use this product.
You decide what is on it, and change it whenever you like, on your card. A change applies to every scan after it. What somebody already has, they already have — the same as a business card you handed over last week, and we will not pretend otherwise.
Three things this is not:
- It is not the directory. Nothing on your card appears when somebody browses the people at an event, reads a match, or opens your profile.
- It is not the organiser's. Running an event does not hand somebody every attendee's contact details, and an organiser cannot read a stand's leads either.
- It is not automatic. Attending, being matched, messaging somebody or walking past a stand share nothing. A badge held up and scanned is the whole of it.
Somebody you have made yourself invisible to cannot scan you at all, and is told only that the badge cannot be scanned.
Hiding from a companyworks differently, and it is worth being exact about it. A person who works there can still meet you and swap cards with you, because they are a person and you held your badge up to them. What we do not do is pass that on: the company’s stand receives nothing, and is not told why. What somebody already has, they already have, and we will not pretend a company cannot be told something by its own employee.
The organiser of an event you attend
What you said you are at their event for — what you offer and what you are looking for — because that is what makes matching work. It stays with that event rather than following you to the next one. They cannot read your messages, and the briefing written for you before a meeting is yours alone.
Nobody at all
Who you have hidden from, which profiles you looked at, what you were matched with but did not meet, and what you wrote in a meeting debrief.
Making yourself invisible
You can make yourself invisible to a company or to one person. They are not told, there is no mark on their side, and it holds even if that person is running the event. It stops you being found; it does not unsend a message or cancel a meeting either of you already agreed.
Artificial intelligence, and what is sent where
Thirteen features send text to a model provider (Anthropic) to produce a result. Each is a button somebody presses, each says what it costs before they press it, and none of them runs on its own.
- About you: building your profile summary from your own words.
- About a pairing: why two people were matched, the short briefing before a meeting, a suggested opening line, and who else in the room is worth meeting. What goes over is the two sides of that one pairing.
- About your own notes: the write-up of a meeting you had, which is your account of it and mentions the person you met. It is sent to be turned into a record and is visible to nobody but you.
- About a room: answering a question about the people at one event, and picking sessions worth attending. What goes over is what those people said they came for, which is what the organiser can see anyway.
- For organisers: suggesting the questions to ask at registration. That one is about the event rather than about anybody.
- For exhibitors: finding who at their event is worth approaching, qualifying their own leads, drafting invitations, and summarising what a stand got out of it.
- Your data is not used to train anybody's model. That is a term of our agreement with the provider, not a hope.
- Nothing is sent that the feature does not need. Not your messages, not your card, and not people unrelated to the task.
- Every generated claim about a person carries the source it came from, so you can see what it was built from and correct it.
- You can correct or replace anything written about you, and what you write yourself always outranks it.
Nothing here decides anything about you
Matching suggests; it does not admit, reject, price or rank you for any purpose that affects your rights. Every suggestion carries its reasoning, a person chooses whether to act on it, and you can correct the material it was built from. There is no automated decision-making in the sense of Article 22.
How long it is kept
- Your account and profile: until you delete them, which you can do yourself and which takes effect immediately.
- Event data — your intent, meetings and messages at an event: kept while the organiser keeps the event, because it is their record of what happened. When they delete the event, it goes with it.
- Financial records where money changed hands: kept as long as tax law requires, which is typically seven years and is not ours to shorten.
- Uploaded files you remove: stopped being served immediately, and the bytes are swept within a day.
- Files nobody ever attached to anything: swept after a day.
- Rate-limit counters: seven days from the last time they moved, then deleted by a job that runs daily.
- A card you handed to an exhibitor: theirs, from the moment you presented your badge. We keep the record of the exchange while the organiser keeps the event; what the exhibitor has already downloaded is out of our hands, exactly as a business card would be.
Where it is processed
Your data is stored in Frankfurt, Germany. Every company that touches it on our behalf is named, with what they do and what makes each transfer lawful, on the sub-processor page. There are three of them.
B2Pair is operated from Kosovo, which does not hold an adequacy decision from the European Commission. Attendee data is stored in Frankfurt, and we access it from Kosovo. That access is a restricted transfer, and it is covered by the standard contractual clauses in our data processing terms.
The AI features send text to Anthropic in the United States. That transfer relies on the standard contractual clauses in their data processing terms.
What you can do
The first two are in the product, do not need to be asked for, and never ask you why.
- Download everything: one file with your profile, your events, what you said you were there for, your matches and their reasons, your meetings, your messages, your connections and your tickets.
- Delete your account: immediate and permanent, with no recovery window.
You also have the right to be told what we hold, to correct what is wrong, to have processing restricted while a dispute is resolved, to object to anything we do on the basis of legitimate interests, and to receive your data in a portable form — which is what the export is. Where an organiser is the controller, those requests go to them and we help them answer.
You can also complain to a data protection authority: the one where you live or work, or the Information and Privacy Agency in Kosovo, where we are established. You do not have to come to us first, though we would rather you did.
One thing deleting your account cannot do is reach into the systems of an exhibitor you handed your card to. We can stop showing it to them and we do; we cannot unsend it, and any product that tells you otherwise is describing something it does not control. Their own obligations to you continue, and you can ask them directly.
Security
- Access is enforced at the database, not only in the application. Every rule above is a policy the database applies to every query.
- Passwords are hashed. We cannot read them and neither can anybody who reads the database.
- Images are re-encoded rather than passed through, which strips anything hidden in them, including the location a phone camera records.
- A PDF you send in a message is stored exactly as you sent it, because re-encoding would mean rewriting your document. It carries whatever its author put in it, the same as one sent by email, and it is never displayed in the browser — only downloaded.
- Files sent in a conversation are served only to the two people in it. They are not readable from a link, and nothing about them is cached by anything in between.
- Administrator access to an account is logged with a reason, the person is told it happened, and they can end it themselves.
If something goes wrong
If personal data is exposed in a way that puts somebody at risk, we tell the relevant authority within seventy-two hours of knowing, and we tell the people affected where the risk to them is high. Where the data belongs to an organiser’s event, we tell the organiser without undue delay so they can meet their own obligation.
Changes
If this changes in a way that affects you, we will say so rather than quietly updating the date at the top.
This document describes the product accurately as of the date above. It is not legal advice, and where an organiser is the controller their own notice governs the data they collect.