Company records come from official national business registers and other public datasets. We do not track website visitors, and we do not buy personal contact lists.
Each record names the register it was read from and the date it was retrieved, so you can always go back to the authoritative source.
All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Database access is restricted via Row-Level Security (RLS) policies.
Our infrastructure is hosted on SOC2-compliant cloud providers. Data processing agreements are available for enterprise customers.
Where a register publishes director or officer names, we show them exactly as published and cite that register. Where it does not, we show nothing.
If a register corrects a record, our next re-check picks it up. You can ask us to remove a mirrored record or delete your account data at any time.
Checking a company in its own official register — and being told when that record changes — serves the legitimate interest of businesses verifying suppliers, customers and counterparties. The underlying information is published by the register itself.
Public sources only: Records come from official national registers and public datasets, never from tracking people.
Attribution: Every record names its source register and the date it was retrieved.
Proportionate processing: Officer details appear only where the register publishes them, and only as published.
Data minimization: We keep your account, searches, watchlists and delivered records — nothing more — and you can delete them at any time.
Yes. We process company information published by official national business registers, plus the account data you give us. Where a register publishes officer names, that is personal data made public by the register itself, and we process it under legitimate interest for business verification and due diligence. We do not track website visitors.
Official national business registers wherever we can reach them directly — the record links back to the register's own page. Where a register requires paid credentials, we fall back to a public dataset such as GLEIF and label the record as a non-official fallback.
You can ask us to remove a mirrored record from our site and we will action it. We cannot change what the official register publishes — corrections must be filed with the register, and our next re-check will reflect them.
All data is stored in SOC2-compliant infrastructure with AES-256 encryption at rest. Data is processed in accordance with applicable data protection laws.
No. We never sell your account data or your searches. Registry records are retrieved on your behalf from public sources. See our Privacy Policy for the full list of sub-processors.
Yes. Enterprise customers receive a DPA as part of their subscription. Contact support@lemreveal.com to request one.