Legal · Privacy Policy

What we hold,
and why we are allowed to.

Two populations of personal data sit behind this product, and they are governed differently. This policy separates them rather than averaging them into one paragraph.

Effective
1 June 2026
Last updated
28 August 2026
Contracting entity
Spotit Ltd

1Scope#

This policy describes how Spotit Ltd (“spotit”, “we”) processes personal data. It covers the marketing site at spotit.ai, the customer console, the API at api.spotit.ai, and the entity database served through them.

Where you use spotit as a customer and send us records about your own contacts or accounts, you are the controller of that content and we are your processor. Those dealings are governed by the Data Processing Addendum, which is incorporated into every paid plan and takes precedence over this policy for that content.

2Two kinds of personal data#

Almost every question we get about privacy comes from conflating these, so they are set out separately here and treated separately everywhere else.

Relationship data is data about you as a visitor to the site, an evaluator with a test key, or a named user on a customer account. We are the controller for it.

Register data is data published by company registers, gazettes and intellectual property offices. Most of it is about companies, and companies are not natural persons. A minority of it — the names of directors, managers, signatories and beneficial owners, as published — is personal data about identifiable individuals. We are also the controller for that, and clause 4 explains what that means.

In plain terms

If you emailed us or signed up, that is relationship data. If you appear in a company register because you are a director, that is register data. The rights in clause 10 apply to both, but they resolve differently.

3What we collect from you#

Visiting the site

The marketing site sets no advertising or cross-site cookies and runs no third-party tag manager. Page views are counted with a cookieless analytics service that stores an aggregate count and no identifier for you. Our edge provider logs IP address and request metadata for abuse prevention. See the Cookie Notice for the four cookies that exist.

Creating an account

Work email address, name, the organisation you say you belong to, a hashed password or your SSO subject identifier, and the region you pin your keys to. If you buy a paid plan, our payment processor collects billing name, address, VAT number and a card token; we never receive or store your card number.

Using the API

We record which key made which call, the endpoint, response status, latency and credits consumed, because that is what a bill and a rate limit are made of. We also record query inputs — the strings you send to /v1/resolve and /v1/match — for 30 days, to serve the 24-hour cache, to debug a match you dispute, and to detect abuse.

  • Query inputs are excluded from our observability tooling. Traces carry the request ID and the shape of the input, never its content.
  • Query inputs are never used to train a model, never sold, and never merged into the public entity graph. A record you send us does not become a record we publish.
  • You can shorten the input retention window to zero on Business and Enterprise, at the cost of the cache discount and of our ability to reproduce a disputed match.

Talking to us

Support tickets, shared Slack channels, sales correspondence and the contents of any sample file you send for a match report. Sample files are deleted within 30 days of the report unless you ask us to keep them for a follow-up.

4Register data and Article 14#

spotit ingests 1,340 sources across 192 jurisdictions. The personal data among them is limited to what the source itself publishes about a person in a business capacity: name, role, appointment and resignation dates, the year and month of birth where a register prints it, a business address, and the filing reference the fact came from.

We do not collect or infer private addresses, personal contact details, national identifiers, or any special category of data under Article 9. Where a register publishes a residential address as a service address, we store it as the address the register published and mark it as such in lineage.

Because we obtain this data from a public source rather than from you, Article 14 applies. This policy is the notice it requires. Each field is traceable: calling GET /v1/entities/{id}/lineage returns the source document, the publication date and the retrieval date behind every attribute, so you can see exactly which register said what.

In plain terms

We republish what a register printed, with a pointer to where it printed it. We do not enrich officers with data from anywhere else, and we do not build profiles of individuals.

5Lawful basis#

Each processing purpose rests on one basis, stated here rather than left to inference.

ProcessingBasisNotes
Providing the account and the APIContract, Art. 6(1)(b)Performance of the plan you signed up to
Billing, tax and accounting recordsLegal obligation, Art. 6(1)(c)Irish and EU statutory retention
Register data on officersLegitimate interests, Art. 6(1)(f)Transparency of corporate control; balancing test on request
Abuse prevention and rate limitingLegitimate interests, Art. 6(1)(f)Keeping the service available to everyone else
Product analytics and error monitoringLegitimate interests, Art. 6(1)(f)Aggregate and pseudonymous; no profiling
Marketing email to a business addressConsent, Art. 6(1)(a)Opt-in only, withdrawable in one click

The balancing test behind the legitimate-interests entries is written down. Ask privacy@spotit.ai and you will get the current version, not a summary of it.

6How we use it#

  • To run the service you asked for: resolve, read, search, watch, batch and warehouse share.
  • To meter usage, apply rate limits, and produce an invoice you can check line by line.
  • To answer support requests and to reproduce a match you tell us is wrong.
  • To keep the platform up: capacity planning, incident response, security monitoring.
  • To tell you about breaking API changes, incidents and deprecations. These are service messages and you cannot opt out of them while you hold a key.

We do not sell personal data, we do not share it with advertising networks, and we make no decision about you by automated means that produces a legal effect.

7Who we share it with#

We disclose personal data to the sub-processors listed on the sub-processor page, each under a written contract that limits them to our instructions. That list is complete, not illustrative, and it names the hosting region for each entry.

Beyond that, we disclose data only to our professional advisers under confidentiality, to an acquirer in the event of a merger or sale of assets — you will be told before your data moves — and to a public authority where we are legally compelled. We publish the number of compelled requests we receive each year, including zeroes.

8International transfers#

By default your account and its data live in the EU: eu-central-1 in Frankfurt and eu-west-1 in Dublin. Ingest, storage, logs and backups for an EU-pinned key stay in the EU, including on failover between those two regions.

If you pin a key to us-east-1 or ap-southeast-1, content for that key is processed there at your instruction. Some of our support and tooling providers are US-headquartered; those transfers rely on the EU Commission’s Standard Contractual Clauses, on the EU-US Data Privacy Framework where the provider is certified, and on a transfer impact assessment we will share on request.

9Retention#

CategoryKept for
Query inputs30 days, or zero if you disable input retention
API access logs90 days hot, 13 months aggregated with no input content
Account and profile dataLife of the account, then 30 days
Support correspondence24 months from the last message
Invoices and tax records6 years, as Irish law requires
Register data, including officer namesFor as long as the source publishes it, plus the historical record from 2009

The last row is the one that surprises people. Point-in-time reads are the product: an audit in 2029 has to be able to ask what a register said in 2019. We therefore retain superseded values as history rather than overwriting them, and we mark them with the date they ceased to be current.

10Your rights#

If you are in the EEA or the UK you have the rights to access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where consent is the basis. Write to dsr@spotit.ai. We answer inside 30 days, free of charge, and we will tell you at the start if we think an exemption applies.

If you are named in register data

Send the entity ID or the register number and we will show you every field we hold about you and the source document behind each one.

  • If the register is wrong, we cannot correct it — only the register can. We will tell you which authority to file with, and we will re-ingest within the normal cadence once the correction is published.
  • If we are wrong about the register — a bad parse, a misattributed officer, the wrong entity — that is our defect. Report it and we will fix it, usually within two working days, and the correction is stamped in the entity’s history.
  • If you object under Art. 21, we assess your particular situation against the transparency interest the register exists to serve, and we tell you the outcome with reasons. Where a register has suppressed a person’s details for personal safety, we suppress them too, automatically and on the same cadence as the source.

Our lead supervisory authority is the Irish Data Protection Commission, and you may complain to them or to the authority where you live. We would rather you came to us first, but nothing here requires it.

11Security#

Encryption in transit with TLS 1.3 and at rest with AES-256, SSO and SCIM, scoped keys, a full audit log, annual SOC 2 Type II and ISO 27001, and an independent penetration test twice a year. The control detail, the certifications and the current status page are on the security section.

Report a vulnerability to security@spotit.ai. We acknowledge within one working day, we do not pursue good-faith researchers, and we will credit you if you want the credit. A personal data breach is notified to affected controllers without undue delay and in any case within 72 hours of us becoming aware.

12Changes to this policy#

Material changes are announced by email to account owners and on the changelog at least 30 days before they take effect. Every version stays online with its effective date, so you can diff what changed rather than take our word for it. This version is effective 1 June 2026 and was last updated 28 August 2026.

13Contact#

Spotit Ltd, 14 Hanover Quay, Grand Canal Dock, Dublin 2, D02 XY88, Ireland. Registered in Ireland, company no. 742118.

Something here that does not work for you?

Redlines on the self-serve terms are read, not filed. Send them and you will get an answer from someone who can change the document, usually inside two working days.

Spotit Ltd · Registered in Ireland, company no. 742118 · 14 Hanover Quay, Grand Canal Dock, Dublin 2, D02 XY88, Ireland · VAT IE4218806T