Privacy Policy
Last updated: 21 July 2026
We respect your privacy. This Policy explains how we handle personal data. We act in two roles: (i) as a data controller for information about our own account holders and their businesses; and (ii) as a data processor for the contact data our customers upload to enrich on their behalf.
1. Data we collect as controller (about account holders)
Registration & account data: name, business email, company name, role, phone, and login credentials (passwords are stored only as salted hashes).
Business onboarding (KYB/KYC) documents: for example, certificate of incorporation, incumbency, shareholders, director/owner ID and proof of address, and any licence you provide. These are stored in private, access-controlled storage and viewable only by authorised operators via short-lived signed links.
Billing data: invoices and the crypto-payment details you provide (we do not store card numbers).
Usage & technical data: log data, IP address, actions taken, and an essential session cookie.
2. Customer-uploaded contact data (our role as processor)
When you upload contacts (for example, names, emails, addresses) to enrich, you are the controller and we process that data only on your documented instructions to provide the service, as set out in our Terms and any DPA. If you are an individual whose data a C-Intelli customer has uploaded, please contact that customer to exercise your rights; we will assist them as required.
3. How enrichment works
To produce indicators, we combine the identifiers you supply — including, where you hold one, the person’s national identification number — with public official registries and other lawful sources, and apply automated models to identify the businesses a person owns or holds a stake in and to generate estimates such as income, affluence and deposit-potential indicators. These are estimates for prioritization, as described in our Disclaimer. We do not perform PEP, sanctions or adverse-media screening.
These public sources may include official business/company registers and, where publicly available, records relevant to deposit capacity such as insolvency registers. Some sources are matched on the available identifiers — which may be a name alone, without a date of birth — so a result can reflect a namesake; any such indicator is therefore presented for prioritization and must be independently verified at onboarding. It is a commercial capacity signal, never a regulated compliance finding. Because we may combine several public sources about the same individual, we handle that processing in accordance with the source providers’ terms of use and applicable data-protection law.
4. How we use data & legal bases
We use personal data to provide, secure, and improve the service; authenticate users; process billing; carry out onboarding and fraud/abuse prevention; communicate with you; and comply with law. Depending on your location, our legal bases include performance of a contract, legitimate interests, compliance with legal obligations, and consent where required.
5. Sharing & sub-processors
We share data only as needed with vetted service providers acting on our behalf, in categories including: data-enrichment providers; cloud hosting and database; text-generation; email delivery; and secure document storage. We do not sell personal data and do not use it for third-party advertising. A current list of sub-processors is available on request. We may disclose data where required by law or to protect our rights.
6. Cookies
We use a single essential session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
7. International transfers
Data may be processed in countries other than yours. Where it is transferred internationally, we rely on appropriate safeguards (such as standard contractual clauses) as required by applicable law.
8. Retention
We keep account, KYB, and billing data for as long as your account is active and thereafter as required for legal, tax, accounting, and dispute-resolution purposes. Customer-uploaded contact data is retained per your instructions and deleted or returned on termination, subject to legal requirements.
9. Security
We use encryption in transit and at rest, private storage with signed-URL access for sensitive documents, hashed passwords, role-based access, and per-company user accounts. No system is perfectly secure, but we work to protect your data.
10. Your rights
Subject to your jurisdiction (for example, GDPR/UK GDPR, or comparable laws), you may have rights to access, correct, delete, restrict, or object to processing, to data portability, and to withdraw consent. To exercise rights over data we control, contact support@c-intelli.io. For data we process on a customer’s behalf, contact that customer.
11. Children
The service is for business users and is not directed to children; we do not collect children’s data.
12. Changes
We may update this Policy; the “last updated” date will change and, for material changes, we will provide notice.
13. Contact
support@c-intelli.io