Every document,
in force, in plain English.
Six documents, all current, all dated. Nothing here is drafted to be unreadable, and nothing material is kept in a PDF you have to ask for.
Privacy Policy
What we hold about you as a visitor and as a customer, what we hold about company officers in the register data, and how each is lawful.
GDPR Arts. 13–14 · effective 1 June 2026Terms of Service
The contract for self-serve plans: what your licence covers, what fair use means at 500 rps, and how either side ends it.
Self-serve MSA · effective 1 June 2026Data Processing Addendum
Incorporated into every paid plan. Roles, instructions, security measures, SCCs, sub-processors and audit rights.
GDPR Art. 28 · effective 1 June 2026Sub-processors
The complete list, with the purpose and hosting region of each. Changes are announced 30 days before they take effect.
11 entries · effective 1 June 2026Cookie Notice
Four cookies, none of them for advertising. What each one stores, how long it lives, and how to refuse the optional one.
4 cookies · effective 1 June 2026Acceptable Use
Registry data is public, and it is still regulated. What the API may not be used for, and what happens when a key breaks the rule.
AUP v3 · effective 1 June 2026What your security review will ask
These are the six questions that arrive in every questionnaire. Answering them here saves both sides a week.
Do we need to sign the DPA before going live?
No. It is incorporated into every paid plan and is in force from day one. If your process needs an executed copy naming your entity, ask and you will have it back the same day.
Where does our data sit?
In the EU by default — Frankfurt with Dublin as failover, and failover stays in the EU. Keys can be pinned to us-east-1 or ap-southeast-1 if you want them there. The full breakdown is on the sub-processor page.
Can we redline the self-serve terms?
Yes, and the redlines get read rather than filed. Below roughly €25k a year we will not run a negotiation on our side, but we do change the document when someone is right.
Do you train models on our query inputs?
No. Inputs are retained for 30 days for caching, dispute resolution and abuse detection, they are excluded from logs and traces, and they never enter the public entity graph. Business and Enterprise can set retention to zero.
Someone is named in your data and wants it removed.
Write to dsr@spotit.ai. If the register is wrong, only the register can fix it and we will say which authority to file with. If we are wrong about the register, that is our defect and we fix it, usually inside two working days.
Which certifications do you hold?
SOC 2 Type II, audited annually, and ISO 27001 covering ingest, API and support. Reports go out under NDA. The control detail is in Annex B of the DPA.
Documents on request
Available under NDA to any customer or serious evaluator, without a sales call in front of them. Ask legal@spotit.ai.
| SOC 2 Type II report | annual |
| ISO 27001 certificate & SoA | current |
| Penetration test summary | 2× / year |
| Transfer impact assessment | 2026-02 |
| DPIA pack for the service | 2026-05 |
| Legitimate interests balancing test | 2026-05 |
| Business continuity & DR plan | 2026-04 |
| Executed DPA on your paper | on request |
Spotit Ltd · Registered in Ireland, company no. 742118 · 14 Hanover Quay, Grand Canal Dock, Dublin 2, D02 XY88, Ireland · VAT IE4218806T