This policy explains how DDcheck ("we", "us", "our") handles personal data. Two groups are relevant: the people who use our Service (account holders), and the people who are screened through it (company officers, owners and others named in public and private records). We process the minimum needed to run screening, we rely on legitimate interests for the screening itself, and we do not sell your data or re-use it beyond running the Service (section 8 explains what we store, and for how long).

1Who we are

DDcheck provides know-your-business (KYB) and anti-money-laundering (AML) screening software. DDcheck is operated by [OPERATOR LEGAL ENTITY — registered name, company number and registered office to be inserted] ("we", "us"). Because the Service is aimed at obligated entities across the EU/EEA and processes data about EU-based companies and individuals, the EU GDPR (Regulation (EU) 2016/679) applies as the primary framework for those data subjects; the UK GDPR and the Data Protection Act 2018 apply to processing in the UK context. For the processing described in this policy we are the data controller, except where we act as a processor on a customer's behalf (see section 3). Where we are established outside the EU, we will appoint and name an Art. 27 EU representative [to be confirmed] as the contact point for EU data subjects and supervisory authorities. The controller's legal identity and lead supervisory authority are being finalised and will be stated here before general availability.

2Whose data we process

This policy covers two distinct groups of people:

3Controller and processor roles

Our role depends on the activity:

We do not make decisions or recommendations about any screened person; any decision based on a result is yours.

4What data we process

About users

About screened persons

5Where the data comes from

User data comes from you. Data about screened persons is aggregated from public and private third-party sources, including: official company and beneficial-ownership registries; sanctions and watchlists (such as OFAC, EU, UN and UK OFSI consolidated lists); PEP and adverse-media sources; aggregators such as OpenSanctions and ICIJ Offshore Leaks; insolvency and tax registers; and commercial data providers. We do not control these sources and do not independently verify their content.

6Why we process data, and our lawful basis

Our customers are typically regulated firms that rely on their own legal obligation and/or legitimate interests for their use of the results.

7Sanctions, PEP and other sensitive data

Some screening information — for example sanctions designations, PEP status or adverse-media references — may amount to criminal-offence data (UK GDPR Art. 10 / DPA 2018) or special-category data (Art. 9). Where it does, we process it under the substantial-public-interest and crime-prevention conditions in Schedule 1 to the Data Protection Act 2018 (including preventing or detecting unlawful acts and the prevention of money laundering or terrorist financing), together with the safeguards and policy documentation those conditions require.

8Searches, results and what we store

We are not a data broker: we do not sell personal data and we do not re-use your screening activity for any purpose other than running the Service for you. We do, however, store some search and result data — for caching, monitoring, case files and logs — as described here.

What we keep, and why:

You can ask us to delete a case, monitoring entry or other stored data at any time (see section 13); some records may be retained where the law requires it.

9Notifying screened individuals

Because data about screened persons is collected from public and third-party sources — often without reliable contact details and at scale — providing individual notice to each person would involve disproportionate effort, and notice may also be restricted where it would prejudice the prevention of crime. We therefore rely on the exemptions in UK GDPR Art. 14(5) and the relevant DPA 2018 crime-prevention provisions, and we generally do not notify each screened person directly. Where you use results to make decisions about an individual, you are responsible for any notice or transparency obligation that your own law places on you.

10Who we share data with

We do not sell personal data. We share it only with:

The current list of sub-processors is available on request.

11International transfers

We store our own data within the UK and the EEA. However, some of the screening, adverse-media and search providers we query (section 10) operate outside the UK/EEA — so a query we send to them (for example, a name being screened) may be processed in another country, including the United States. Where data is transferred outside the UK or EEA, we put appropriate safeguards in place — such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, and EU Standard Contractual Clauses where relevant — together with a transfer risk assessment.

12How long we keep data

We keep personal data only for as long as reasonably necessary for the purposes set out above, taking into account its sensitivity, the risk of harm, and applicable legal, regulatory, tax and accounting requirements. Indicative periods (see section 8):

13Your rights

Subject to applicable law, you have the right to: access your personal data; have inaccurate data corrected; request erasure; restrict or object to processing; data portability; and to withdraw consent where we rely on it. To exercise a right, contact us at privacy@ddcheck.uk; we do not charge for genuine requests.

These rights have limits. Where we process data for AML, crime-prevention or other legitimate-interest or legal-obligation purposes, we may be unable to erase or stop processing it, and we may decline manifestly unfounded or excessive requests. If you are unhappy with how we handle your data you can complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.

You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions: any risk score, flag or rating we provide is decision-support only, and the decision is taken by a person in the customer's organisation.

14Security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, hashed credentials and least-privilege access. No system is perfectly secure, and we cannot guarantee absolute security.

15Children

The Service is intended for business use by adults and is not directed at children. We do not knowingly collect data from children as users.

16Changes to this policy

We may update this policy from time to time. We will post the updated version here and change the "Last updated" date; material changes will be notified by reasonable means.

17Contact

For privacy questions or to exercise your rights, contact privacy@ddcheck.uk.