On this page
- 1. Who we are
- 2. What we collect
- 3. Legal basis
- 4. How we use your data
- 5. Personal data in company records
- 6. Retention
- 7. Who we share data with
- 8. International transfers
- 9. Cookies
- 10. Your rights
- 11. Complaints
- 12. Security
- 13. Automated decision-making
- 14. Children's privacy
- 15. Changes to this policy
1 Who we are
The controller responsible for your personal data is
This policy covers two different groups: people who hold an account with us, and people whose details appear in the company records we publish. Section 5 deals with the second group.
2 What we collect
Account information: name, email address, company name, VAT number for business accounts, an encrypted password, and your preferences and settings.
Payment information: billing address and transaction history. Card details are handled by our payment provider and are never stored on our systems.
Usage data: pages visited and features used, search queries and saved lists, API usage, and the date and time of access.
Technical data: IP address, browser type and version, device information, operating system and referring website.
3 Legal basis
- Contract performance (Art. 6(1)(b)): providing the service, managing your account and subscription, and supporting you.
- Legitimate interests (Art. 6(1)(f)): fraud and abuse prevention, security, service improvement, and publishing company information of public and economic interest. We balance these against your rights and freedoms.
- Legal obligation (Art. 6(1)(c)): tax and accounting requirements.
- Consent (Art. 6(1)(a)): marketing communications and non-essential cookies. You may withdraw consent at any time.
4 How we use your data
- operate and maintain the website, the API and your account;
- process payments and send related information;
- respond to enquiries and provide support;
- send service communications such as security and billing notices;
- send marketing communications, only with your consent;
- analyse usage to improve the service;
- detect and prevent fraud, abuse and security incidents;
- comply with legal obligations.
5 Personal data in company records
Our database contains information about companies in Belgium, France, Luxembourg and Norway. Some of that information is personal data — typically the names, functions, mandate dates and, where the register publishes them, the addresses of directors, managers, shareholders and sole traders.
Where it comes from. We did not obtain this data from you. It comes from official public registers and publications, listed in Section 8 of our terms and conditions. We combine and present it; we do not create it.
Why we process it. On the basis of legitimate interests: transparency of economic life, counterparty and credit risk assessment, and fraud prevention. These are the same purposes for which the registers are public. For sole traders, the company record and the person are the same, which we take into account when weighing those interests.
Your rights over it. You may request access, rectification, erasure or restriction, and you may object to the processing on grounds relating to your particular situation. Use our data removal request form or email [email protected].
What we can and cannot do. We can remove or restrict a record on our platform. We cannot correct the underlying public register — a correction there has to be requested from the register itself, and until it is made the original data may reappear through a later import. Where the law requires a publication to remain public, we may be unable to erase it, and will tell you why.
6 Retention
- Account data: kept while your account is active, deleted within 30 days of account deletion, except where the law requires retention.
- Transaction records: kept for 7 years to meet Belgian tax and accounting requirements.
- Usage data (pages viewed, searches, API calls): kept while your account exists, and afterwards where we still need it for security, fraud prevention, billing history and understanding how the service is used over time. We do not delete it on a fixed schedule. If you ask us to erase your data, we delete or anonymise it as described under your rights below.
- Marketing preferences: kept until you withdraw consent or delete your account.
- Company records: kept for as long as they remain relevant to the purposes in Section 5, and updated as the source registers publish changes.
8 International transfers
Data is primarily processed within the European Economic Area. Some of the providers in Section 7 are established outside the EEA, principally in the United States. Where data is transferred outside the EEA we rely on an adequacy decision, Standard Contractual Clauses approved by the European Commission, or another recognised transfer mechanism.
10 Your rights
- Access (Art. 15) — request a copy of your personal data.
- Rectification (Art. 16) — have inaccurate or incomplete data corrected.
- Erasure (Art. 17) — have your data deleted, subject to legal retention.
- Restriction (Art. 18) — limit how we use your data.
- Portability (Art. 20) — receive your data in a structured, commonly used format.
- Objection (Art. 21) — object to processing based on legitimate interests, or to direct marketing at any time.
- Withdraw consent — at any time, where processing relies on consent.
To exercise any of these, email [email protected] or use our data removal request form. We respond within 30 days. Account settings can also be changed directly in your account.
11 Complaints
If something about your data looks wrong, please tell us first — email [email protected] or use the contact page. Most issues are a mistake in a source register or a setting on your account, and we can usually resolve those quickly.
You do not have to contact us first. You are entitled at any time to lodge a complaint with a supervisory authority. In Belgium:
Gegevensbeschermingsautoriteit (GBA)
Drukpersstraat 35, 1000 Brussels, Belgium
Phone: +32 (0)2 274 48 00
Email: [email protected]
12 Security
- encryption in transit (HTTPS/TLS) and at rest;
- secure password hashing;
- access controls and authentication measures;
- regular updates and security review.
13 Automated decision-making
We calculate scores and indicators about companies automatically, including health scores, Z-scores and suggested credit limits. These are informational outputs about a business, not decisions we take about a person, and we do not use them to make decisions producing legal or similarly significant effects about you.
Where a business is a sole trader, information about the business is also information about a person. If you believe an automated output about your business affects you personally, contact us and we will review it. You may request human intervention and contest the result.
14 Children's privacy
The service is not directed at people under 16 and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact us and we will delete it.
15 Changes to this policy
We may update this policy. Significant changes will be notified by email or a notice on the website, and the "last updated" date above will change.
Questions about this document?
Write to [email protected] or use the contact page.