1. Overview
1. Overview
IXF separates public information from authenticated, role-restricted and operational records.
2. Public website boundary
2. Public website boundary
Public pages provide approved information and must not be used to submit identity documents, invoices or banking credentials.
3. Protected platform boundary
3. Protected platform boundary
Authenticated routes apply role, verification and permission controls to account and workflow information.
4. Private uploads
4. Private uploads
Upload requested sensitive documents only through the authenticated route presented for the applicable workflow.
5. Data minimisation
5. Data minimisation
Provide only information relevant to the stated purpose and requested stage.
6. Role-based sharing
7. Support boundaries
7. Support boundaries
Public support can guide you to the right route but should not receive passwords, OTPs or unnecessary private records.
8. Report a privacy concern
8. Report a privacy concern
Use the Contact, Grievance or Responsible Disclosure route appropriate to the concern.