Privacy Policy

Last updated 31 August 2026

Two kinds of data

Your account data (you are the data subject): email address, hashed password if you set one, sign-in tokens, billing records.

Screening data (your customers are the data subjects, you are the controller): the names, dates of birth, countries and identifiers you submit, and the results. We process it only to run the check, keep the audit trail you asked for, and re-check monitored entities when lists change. See the Data Processing Agreement.

Usage and security data

API request metadata (time, duration, status, key used), server logs including IP addresses for security and abuse prevention, and Cloudflare Turnstile signals on sign-up.

What we do not do

We do not sell personal data, do not run third-party advertising trackers, do not enrich your queries with data from anywhere except the official lists, and do not read your screening records except when you ask us to investigate a problem.

Processors and sub-processors

Hosting: OVH (EU). DNS and bot protection: Cloudflare. Card payments: Stripe (card data never touches our servers). Crypto payments: CoinGate and Heleket (they see the amount, not your queries). Email delivery: our own mail server. We will announce any new sub-processor 14 days in advance.

Sanctions list data

The lists themselves are public records published by governments. We republish entity records from them with attribution to the publisher; see Coverage for licences.

Retention and deletion

Screening records are kept for the retention period of your plan (30 days on Free, up to 3 years on Scale) and then deleted; you can delete them earlier from the API. Account data is kept while your account exists. Request deletion at any time by emailing [email protected] from your account address; we delete within 30 days, except records we must keep for tax or fraud-prevention purposes.

Your rights

You can access, correct, export or delete your data, and object to processing. Contact [email protected]. If you are in the EU/UK you may also complain to your local data protection authority. Requests from your customers about their data should go to you as the controller; we will help you fulfil them.