Privacy and data use
Short, because there is not much to say about a site that loads no third-party code.
On the public site
We collect what the access-request form asks for: your name, work email, company, what needs checking, and a phone number only if you choose to give one. Nothing else is collected, and nothing is collected in advance of a request.
An access request is kept for 24 months and then deleted. Ask us and we will delete it sooner.
No analytics, no advertising, no third-party script
There is no Google Analytics, no tag manager, no advertising pixel and no embedded widget on this site. That is not a stylistic choice: verification links can carry single-use tokens, and the safest way to guarantee a token never leaks through a referrer or a third-party script is to have no third-party script at all. Demand is measured from our own delivery logs.
Inside the product
Public registry records are shared across customers. Everything else — your watchlist, your cases, your evidence, your policy, your private notes about a counterparty — carries your tenant and is not visible to anyone else. A reference belonging to another customer answers "not found" rather than "forbidden", because "forbidden" already reveals that it exists.
Derived records inherit the intersection of their inputs rights and the earliest retention deadline of their inputs. Revoking access takes effect immediately, including for anything already cached.
Contacting people
Consent is recorded per purpose. Agreeing that we may reply about your access request does not permit marketing, and consent obtained for verification is never reused for selling. Those are separate paths with separate records, deliberately.