Privacy Policy
Last updated 31 August 2026
Two kinds of data
Your account data (you are the data subject): email address, hashed password if you set one, sign-in tokens, billing records.
Screening data (your customers are the data subjects, you are the controller): the names, dates of birth, countries and identifiers you submit, and the results. We process it only to run the check, keep the audit trail you asked for, and re-check monitored entities when lists change. See the Data Processing Agreement.
Usage and security data
API request metadata (time, duration, status, key used), server logs including IP addresses for security and abuse prevention, and Cloudflare Turnstile signals on sign-up.
What we do not do
We do not sell personal data, do not run third-party advertising trackers, do not enrich your queries with data from anywhere except the official lists, and do not read your screening records except when you ask us to investigate a problem.
Processors and sub-processors
Hosting: OVH (EU). DNS and bot protection: Cloudflare. Card payments: Stripe (card data never touches our servers). Crypto payments: CoinGate and Heleket (they see the amount, not your queries). Email delivery: our own mail server. We will announce any new sub-processor 14 days in advance.
Sanctions list data
The lists themselves are public records published by governments. We republish entity records from them with attribution to the publisher; see Coverage for licences.
Retention and deletion
Screening records are kept for the retention period of your plan (30 days on Free, up to 3 years on Scale) and then deleted; you can delete them earlier from the API. Account data is kept while your account exists. Request deletion at any time by emailing [email protected] from your account address; we delete within 30 days, except records we must keep for tax or fraud-prevention purposes.
Your rights
You can access, correct, export or delete your data, and object to processing. Contact [email protected]. If you are in the EU/UK you may also complain to your local data protection authority. Requests from your customers about their data should go to you as the controller; we will help you fulfil them.