Privacy notice
Two quite different things live here: what we hold about you as a customer, and what the public registers publish about people that we republish. They are governed differently, so they are set out separately.
Last updated
1. As a customer of ours
What we hold, and why we are allowed to:
- Your account — name, email address, the sign-in identity from Keycloak
- To give you the service you asked for. Lawful basis: performance of a contract.
- Payment records — what you bought, when, and the last four digits of the card
- To meet our legal obligations under company and tax law. We never see or store a full card number: Stripe takes the payment as merchant of record and holds the card details. Lawful basis: legal obligation.
- API keys, as a SHA-256 hash and never the key itself
- To authenticate your calls. Lawful basis: performance of a contract.
- Usage events — which endpoint, when, which company it was about
- To meter the balance, to evidence that a service was delivered if a payment is disputed, and to work out what is popular. Lawful basis: performance of a contract, and our legitimate interest in running and defending the service.
- Access log — which personal record was disclosed to which key, and when
- Kept deliberately: if we disclose personal data we should be able to say to whom. Lawful basis: legal obligation, and our legitimate interest in being accountable.
- Marketing consent, and its withdrawal, with the date of each
- So that silence is never read as agreement. Lawful basis: consent, and legal obligation to show we have it.
How long
- Account and payment records: while the account exists, and six years after it closes.
- Access log: twelve months.
- Usage events: ninety days, after which only monthly totals per key and endpoint remain.
- Requests about your own data: six years from the answer.
These are enforced by a job that runs nightly and deletes what has passed its date — not by somebody remembering.
2. As a person a register publishes
Companies House publishes the directors, secretaries and people with significant control of every UK company, with a service address, a nationality, a country of residence and a month and year of birth. The Gazette publishes insolvency and strike-off notices. The consolidated sanctions lists publish designated persons. All of it is published by law, to be used.
We republish it, with the source and the date it was read against each figure. Our lawful basis is legitimate interest: the transparency the registers exist to create only works if the data can be searched. We do not add anything the registers do not publish — no inferences, no enrichment from other sources, no profiles.
A name matching a sanctions list is a name match and not an identification, and every page that shows one says so.
If that is you
You can ask us to stop showing you. Use the data rights form and we will suppress the entry here, which survives the next reload of the register. But note what that does and does not achieve: the register itself will still publish you, and anyone can read it there. Where the entry should not be public at all, Companies House runs its own schemes for protected details and for suppressing a residential address, and that is where the real remedy lies. We will say so rather than let you think the problem is solved.
3. Who else sees it
- Stripe — payments, as merchant of record. Stripe is the seller in the transaction and holds the card details; we never do.
- Keycloak, on our own infrastructure — sign-in, passwords and second factors. There is no password field anywhere in our database, by design.
- Amazon Web Services (Simple Email Service, London region) — sending the email we send you.
- Google Analytics — only if you accepted analytics cookies. See the cookie policy.
We do not sell personal data, and we do not share it for anybody else's marketing. Where a processor is outside the UK, the transfer relies on the terms that provider publishes and the UK's own adequacy or standard clauses.
4. Your rights
You can ask to see what we hold, to correct it, to erase it, to restrict or object to what we do with it, and to have it sent to you in a portable form. Use the data rights form — it opens a request with a reference and a deadline, rather than an email somebody may or may not see.
We answer within one month. Where we refuse, we say on what ground. If you are unhappy with how we handled it you can complain to the Information Commissioner's Office at ico.org.uk, and you do not have to come to us first.
5. Children
This service is not aimed at children and we do not knowingly hold data about them. A person under 16 can, however, be named in the register of persons with significant control, and where they are, section 2 applies to them as it does to anyone else.
Who you are dealing with
NOETIKOS LTD, a company registered in England and Wales under number 17154674, with its registered office at 66 Paul Street, London, EC2A 4NA, United Kingdom. Registered with the Information Commissioner's Office under ZC229911 — the entry is public, and checking it beats taking our word for it.
Write to [email protected] about anything on this page. For security, see security.txt.