Veritain — Privacy Policy
Effective date: 31 August 2026 · Version: 1.4 Controller: Abacie Gamma Limited (registered in England & Wales, company no. 14707586), trading as "Veritain"; registered office 40 Broadway Lane, Bournemouth, England, BH8 0AA. ICO registration ZB617388. Contact / data protection: privacy@veritain.co.uk
1. Who we are and what this covers
Veritain provides business-to-business due-diligence reports ("Counterparty Reports", including the consumer-facing "Reverse Check"), and an optional Monitoring service that alerts a business customer to changes on a company it is watching. Both are compiled from UK public registers. This notice explains how we handle personal data — principally director and officer information — when we prepare those reports and run that monitoring. Most of the data we process concerns companies (which is not personal data); the personal-data element is the information about the individuals connected to a company. Our headline risk indicator is a company-level assessment; information about an individual is presented only as a cited public-record fact (see section 5).
We are a data controller for this processing.
2. Whose data we process
- Directors, officers, persons with significant control (PSCs) and other individuals named in public records relating to a company that a customer asks us to check.
- Our customers (business users) — account and billing information.
We are not a "people search" service and do not offer products for tracing or monitoring private individuals outside a legitimate business-risk context.
3. What personal data we process, and where it comes from (Article 14)
Because we obtain most personal data from third-party public sources rather than from the individual, the following serves as our Article 14 notice.
| Data | Source |
|---|---|
| Name, role, partial date of birth (month/year), nationality, appointment history | Companies House REST API (Open Government Licence) |
| Director disqualifications (order, dates, court, case, reason) | Companies House disqualified-officers register (Open Government Licence) |
| Insolvency / strike-off associations; winding-up petitions | The Gazette |
| Sanctions-list matches | UK Sanctions List (OFSI / FCDO) |
| FCA authorisation status / permissions, where a company or its firm is FCA-regulated | FCA Financial Services Register |
| VAT-registration validity and registered name, where a VAT number is checked | HMRC "Check a UK VAT number" service |
| County Court Judgments — only if and when we enable this paid source (opt-in; fact cited, not redistributed) | Registry Trust / a licensed CCJ data provider |
| Personal insolvency of a company's serving controlling directors (bankruptcy, IVA, DRO — type, case number, dates, court, status) — only if and when we enable our Recoverability report | Individual Insolvency Register (The Insolvency Service) |
| Registered property titles held by a company (title number, tenure, outward postcode district) — only if and when we enable this paid source | HM Land Registry CCOD / OCOD |
| Address and status tracing on a named individual — only if and when we enable our Locate & Serve report | A licensed tracing-data provider, under a data agreement |
We list a source here only where we actually process it. At launch we process the free registers above (Companies House, the disqualified-officers register, The Gazette, the UK Sanctions List, the FCA Register, and the HMRC VAT-check service). The last four rows are shown for transparency and are processed only if and when we enable the report or source they belong to — each is switched off today. We do not process employment-tribunal data, and we will update this notice before we do.
Reports that name an individual
Two reports we have built but not yet switched on — Recoverability and Locate & Serve — can report a finding about a named person rather than only about a company. Because that is a meaningful step beyond our other reports, these limits are part of how they are built, not just policy:
- You cannot search for a person. A report can only reach someone who is a serving controlling officer of the company being checked, taken from the Companies House register. There is no free-text name search anywhere in the service.
- We only name someone when the identity is confirmed. A record is attached to a person only on the register's own identity evidence, or on a strong match corroborated by date of birth. A possible match is never printed — it goes to a person here to resolve.
- A person always checks before we issue. No report containing a finding about a named individual is ever sent automatically.
- We record why the customer asked. Every such report requires the customer to state a lawful purpose (debt recovery, legal proceedings, service of legal documents, or diligence before a contract) before we look anything up.
- We report the record, not a judgement about you. Findings are dated facts from a named public source, presented as indicators. We do not score individuals and we do not state whether anyone can or cannot pay.
If you are named in one of these reports and think a record has been matched to you in error, tell us (section 9). We suppress the finding, correct the record, and re-issue at no charge.
For Monitoring, we periodically re-check the free public registers above (company status, filings, charges, disqualifications, Gazette insolvency/petition notices, sanctions) for the company a customer is watching, and alert the customer to a material change. We minimise what we collect to what the purchased report tier (or the monitoring subscription) requires. We do not collect special-category data as part of the standard service.
4. Why we process it, and our lawful basis
- Purpose: to help businesses assess the standing and counterparty risk of a company and its directors before trading, lending, or contracting — i.e. fraud prevention, credit-risk reduction, and due diligence.
- Lawful basis (UK GDPR Art. 6(1)(f)): legitimate interests. We have completed a Legitimate Interests Assessment (LIA) balancing our and our customers' interests against individuals' rights. Because the data is already public and we add linkage and context rather than new exposure, and because we apply the safeguards in section 8, we consider legitimate interests appropriate. You can request a summary of our LIA at privacy@veritain.co.uk.
- Monitoring (recurring subscription): where a customer subscribes to Monitoring, we process the above on a continuing basis — re-checking the free public registers daily for each company on the customer's watchlist and keeping a minimal snapshot while the subscription is active so we can detect change — on the same legitimate-interests basis (the customer's own ongoing counterparty diligence), assessed in our LIA. The watchlist is the subscriber's own, need-to-know list, not a shared or searchable database.
- Billing/account data: processed to perform our contract with the customer (including the recurring Monitoring subscription, via Stripe) and to meet legal (e.g. tax) obligations.
- Account management & report history: if you create an account, we use the email you provided at purchase to let you sign in (a passwordless magic link) and re-access the reports you already bought. This is bounded self-service access to reports we already hold for you — it adds account authentication (a minimal amount of personal data — your email), with a clear purpose and an account you can delete on request. It does not extend how long we keep a report, and it does not add any new keep-forever storage (that would be a separate Monitoring subscription). We rely on legitimate interests for this bounded access, within our existing report retention window.
5. Automated processing and human involvement
Reports include an automated GREEN / AMBER / RED indicator. We want to be clear about how it works and your rights in relation to it (UK GDPR Arts 22A–22D, as amended by the Data (Use and Access) Act 2025).
- It assesses the company, not the person. The indicator is a company-level risk assessment. Information about an individual (for example a director disqualification, or a director's other failed companies) is presented only as a cited public-record fact, with its source and date, as an indicator, not a conclusion — never as our own opinion or characterisation of that person.
- The logic is deterministic and rules-based, not "AI guesswork". The colour is decided by a fixed, auditable set of rules applied to the public records; the same inputs always give the same result. Any written summary is generated only from those structured findings and is automatically checked so it cannot introduce a fact that is not in the records, and cannot make an adverse judgement or inference about a named individual — if it tries, it is rejected and replaced with a plain factual summary.
- It is decision-support — you decide. The report is input to the business customer's own decision; the customer makes the commercial call and is required to exercise their own judgement. The report states that it provides evidential support and is not conclusive.
- Human involvement. Straightforward (GREEN) reports may be issued automatically. Reports that raise the most significant concerns — for example a RED outcome, a confirmed sanctions match, a safeguarding concern, or a low-or-conflicting-confidence result — are reviewed by a person before release. A possible-but-unconfirmed personal match (for example a name match to the disqualification register without a date-of-birth match) is shown as "possible — needs verification", never as an asserted fact.
- Your rights here. You can request meaningful information about the logic involved, request human review of an assessment that concerns you, and contest it, by contacting privacy@veritain.co.uk (see sections 8 and 9).
6. Who we share it with (sub-processors)
We do not sell personal data. We share it with service providers under written data-processing terms:
| Provider | Purpose | Location |
|---|---|---|
| Render | Application hosting | UK/EU |
| Supabase (Database & storage) | Report/record database & storage | UK/EU |
| Supabase (Auth) | Customer & admin account sign-in (passwordless authentication) | UK/EU |
| Stripe | Payment processing — one-off report purchases and recurring Monitoring subscription billing | See note below |
| Resend | Transactional email (order, report, and receipt emails) | See note below |
Some providers (e.g. our payment processor and email provider) may process personal data outside the UK under appropriate safeguards such as Standard Contractual Clauses. We update this list before enabling any new sub-processor. We may disclose data where required by law, or to establish, exercise or defend legal claims.
7. Where we store it, and for how long
- Location / residency: the UK (and/or EU). We do not transfer personal data outside the UK/EU without an appropriate safeguard.
- Retention: we keep the personal data in a report only as long as needed for the report and any dispute/limitation window (by default 12 months from issue plus a 30-day dispute window), after which the report's personal data is erased (redacted); non-personal billing/accounting records are kept for the period required by law. Erasure runs on an automated retention process, and we can also erase a specific report on request. For an active Monitoring subscription we keep a minimal snapshot of the watched company's public-record state so we can detect change; this is erased when the subscription ends (plus any dispute window). We retain a minimal provenance/audit record (who accessed what, and when) for accountability. Reports are stored in a UK-region database that encrypts data at rest (AES-256) and in transit (TLS).
- Account / authentication data: if you create an account, your account and sign-in data are retained while the account is active (or until you ask us to delete it). Creating an account does not extend how long we keep a report: re-download of a report is available only while that report is still within its retention window above — once the erase job removes a report, it is no longer downloadable, whether or not you have an account.
8. How we protect it and keep it fair
- Encryption in transit and at rest; least-privilege access; audit logging of every access to personal data; UK/EU data residency; secrets held in a secrets manager, never in code.
- Accuracy & fairness: we prefer exact record links; a possible-but-unconfirmed personal match is shown as "possible — needs verification", not asserted; adverse and phoenix indicators are shown as dated, sourced facts — indicators, not conclusions — with the most significant cases human-reviewed before release; and our written summaries are prevented from making any adverse judgement about a named individual. Where we "couldn't check" a source, we say so and lower our confidence — we never treat it as "clear".
- Correction / objection route: if you believe a record about you is wrong or unfairly presented, contact privacy@veritain.co.uk and we will investigate and, where appropriate, correct, annotate, or remove it. (Where the underlying error is on a public register, we will help you identify how to correct it at source.)
9. Your rights
Subject to UK GDPR, you have the right to: access your data; rectification; erasure; restriction; objection (including to processing based on legitimate interests); and, where applicable, portability. To exercise any right, contact privacy@veritain.co.uk; we respond within one month. You can also complain to the Information Commissioner's Office (ICO) at ico.org.uk — though we'd appreciate the chance to resolve it first.
Account deletion. If you have an account, you can ask us to close it at any time (privacy@veritain.co.uk). Closing your account removes your account/sign-in data; it does not shortcut the report erase job, which already runs on the retention schedule above.
10. Cookies / the website
We set only strictly necessary cookies — the ones required to sign you in and to process a secure checkout. We set no advertising cookies, no tracking cookies and no third-party cookies, and we never sell or share cookie data.
We do measure aggregate site usage (page views and referrers) using a cookieless analytics service, which sets no cookies, stores no identifier on your device, and does not follow you across other websites. Because none of this relies on non-essential storage, there is nothing for you to consent to under PECR — which is why the site shows a short notice rather than a consent banner. If any of this changes, we will update this policy and ask for your consent where the law requires it.
11. Changes
We will post any changes here and update the version and effective date.
