Legal
Privacy
Last updated 2026-09-08
What we hold about you
Account data: your name, email address, an optional job title, and a hashed password if you use one. Organization data: the organizations you belong to, your role in each, and the watchlists, monitoring settings, alerts, reports and AI conversations those organizations create. Operational data: sign-in timestamps and an audit log of significant actions, which exists so an organization can see who changed what.
Company records
The platform stores information about companies drawn from public registers, regulatory filings, company-operated sources and licensed providers. Where a record concerns an identifiable person — a director, officer or beneficial owner — it is held because it has been published by an official register or by the company itself, and it is stored with the source it came from. See our data sources policy for the detail.
AI processing
When an AI provider is configured, company records and your question are sent to that provider to generate an answer. Only data already held in this platform is sent. If no provider is configured, analysis is produced by a built-in deterministic analyst and nothing leaves the deployment. Answers are stored so conversations can be resumed and so a claim can be traced back to the records that produced it.
Processors
Depending on how this deployment is configured, data may be processed by a payment provider (Stripe), an AI provider (such as OpenAI), an email provider, and the company-data providers you have licensed. The settings page shows exactly which integrations are active on this deployment.
Retention
Account and organization data is retained while the account is active. When an organization is deleted, its watchlists, monitoring subscriptions, alerts, reports and conversations are deleted with it. Company records are shared reference data and are not deleted with an individual account.
Your rights
Subject to the law that applies to you, you may request access to the personal data we hold about you, ask for it to be corrected or erased, object to processing, or request a portable copy. Where a company record originates from an official register, a correction is usually most durable when made at the register itself, since the record will otherwise be re-read from source.
Security
Access is controlled per organization and verified on the server for every request; membership is never inferred from a value supplied by the browser. Passwords are stored hashed. API credentials for data providers are held in server-side environment configuration and are never exposed to the client.
This document describes how the software behaves. It is not legal advice. Before operating this platform commercially, have counsel review it against the jurisdictions you operate in and the processing you actually perform.