Legal · Acceptable Use

Public data is still
regulated data.

A company register is open to anyone. That does not make every use of it lawful, and a few uses would put both of us in front of a regulator.

Effective
1 June 2026
Last updated
28 August 2026
Contracting entity
Spotit Ltd

1Why this exists#

Registers publish corporate facts so that the public can see who controls a company. That purpose is narrow, and the lawful basis we rely on to serve register data — legitimate interests — is measured against it.

This policy is part of the Terms of Service. It applies to every key, including free ones, and to anyone you give access to your key.

2Prohibited uses#

You may not use spotit, or data obtained from it, to:

  1. Target an individual in a personal capacity. Officer records exist to show corporate control. Using them to locate, contact, profile or pressure a person outside their business role is prohibited, and so is enriching them with data from anywhere else to that end.
  2. Harass, threaten, defame or stalk. Including compiling a dossier on a named person, or publishing officer data in a context designed to invite harassment.
  3. Discriminate unlawfully. Using entity or officer attributes as a proxy for a protected characteristic in a credit, employment, insurance, housing or pricing decision.
  4. Make an automated decision with legal effect on a person using a confidence score as the deciding input, without human review.
  5. Re-identify or de-anonymise individuals, or combine spotit data with another dataset for that purpose.
  6. Send unsolicited bulk communications in breach of ePrivacy, GDPR, CAN-SPAM or the equivalent law where the recipient sits. spotit gives you a legal entity, not permission to email it.
  7. Rebuild or resell the database, in whole or in substantial part, as a dataset, feed, or competing lookup service. See clause 3 of the terms; reseller arrangements are available and are not the problem.
  8. Break the law or someone else’s rights — sanctions evasion, money laundering, fraud, infringement of a third party’s intellectual property, or circumvention of a court order.

3Technical limits#

  • Do not circumvent rate limits, credit metering or authentication, including by rotating accounts to reset a free quota.
  • Do not enumerate the ID space. Resolve records you actually hold; that is what the endpoint is for.
  • Do not probe, scan or load-test the service without written permission. Ask at security@spotit.ai and you will usually get it, with a window and a rate.
  • Do not embed a live key in client-side code, a mobile binary, or a public repository.
  • Do not strip lineage or confidence from a record before handing it to a system that acts on it.

4What spotit is not#

spotit supplies registry facts. It is not a sanctions, PEP or adverse-media screening service, not a credit bureau, and not a consumer reporting agency under the US FCRA. Nothing it returns is a recommendation about a person’s creditworthiness, character or eligibility.

Use it to give your screening vendor clean LEI, VAT and EUID keys to work from — that is the worked example on the product page. Do not use it as the screening step itself.

In plain terms

If your compliance answer to a regulator would be “spotit said so”, the design is wrong before the data is.

5Enforcement#

We investigate reports and anomalies ourselves; we do not act on an unexamined complaint. Where we find a breach, the response is proportionate to it.

  1. For a technical breach — a scraper pattern, a leaked key — we email you and usually rate-limit rather than revoke.
  2. For a first substantive breach we give written notice and a period to fix it, normally 7 days.
  3. For a serious or repeated breach, or where a person is at risk, we suspend the key immediately and tell you as soon as practicable.
  4. Termination for cause follows clause 11 of the terms.

Appeals go to legal@spotit.ai and are read by a person who was not part of the original decision. We publish the number of suspensions we make each year in our transparency note.

6Reporting abuse#

If you believe spotit data is being misused, write to abuse@spotit.ai with whatever detail you have. We acknowledge within one working day.

If you are named in register data and something about it worries you, you do not need to make an abuse report — go to your rights and write to dsr@spotit.ai. Where a register has suppressed a person’s details for personal safety, we suppress them too, on the same cadence as the source.

Something here that does not work for you?

Redlines on the self-serve terms are read, not filed. Send them and you will get an answer from someone who can change the document, usually inside two working days.

Spotit Ltd · Registered in Ireland, company no. 742118 · 14 Hanover Quay, Grand Canal Dock, Dublin 2, D02 XY88, Ireland · VAT IE4218806T