GDPR & CCPA Compliant

    Privacy & Compliance Center

    LemReveal works from official public company registers, and cites the source on every record. Here's exactly how we handle that data and yours.

    How We Protect Privacy

    Public register data only

    Company records come from official national business registers and other public datasets. We do not track website visitors, and we do not buy personal contact lists.

    Source cited on every record

    Each record names the register it was read from and the date it was retrieved, so you can always go back to the authoritative source.

    Data encrypted at rest & in transit

    All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Database access is restricted via Row-Level Security (RLS) policies.

    EU data processing

    Our infrastructure is hosted on SOC2-compliant cloud providers. Data processing agreements are available for enterprise customers.

    Officer details as the register publishes them

    Where a register publishes director or officer names, we show them exactly as published and cite that register. Where it does not, we show nothing.

    Removal and correction requests

    If a register corrects a record, our next re-check picks it up. You can ask us to remove a mirrored record or delete your account data at any time.

    Compliance Status

    SOC2 Type II Infrastructure
    Compliant
    GDPR
    Compliant
    CCPA
    Compliant
    ISO 27001 Hosting
    Compliant
    Data Processing Agreement
    Available
    Source attribution on every record
    Implemented

    Our Legal Basis

    GDPR Article 6(1)(f): Legitimate Interest

    Checking a company in its own official register — and being told when that record changes — serves the legitimate interest of businesses verifying suppliers, customers and counterparties. The underlying information is published by the register itself.

    Public sources only: Records come from official national registers and public datasets, never from tracking people.

    Attribution: Every record names its source register and the date it was retrieved.

    Proportionate processing: Officer details appear only where the register publishes them, and only as published.

    Data minimization: We keep your account, searches, watchlists and delivered records — nothing more — and you can delete them at any time.

    Compliance FAQ

    Is LemReveal GDPR compliant?

    Yes. We process company information published by official national business registers, plus the account data you give us. Where a register publishes officer names, that is personal data made public by the register itself, and we process it under legitimate interest for business verification and due diligence. We do not track website visitors.

    Where does the data come from?

    Official national business registers wherever we can reach them directly — the record links back to the register's own page. Where a register requires paid credentials, we fall back to a public dataset such as GLEIF and label the record as a non-official fallback.

    Can a director ask to be removed?

    You can ask us to remove a mirrored record from our site and we will action it. We cannot change what the official register publishes — corrections must be filed with the register, and our next re-check will reflect them.

    Where is my data stored?

    All data is stored in SOC2-compliant infrastructure with AES-256 encryption at rest. Data is processed in accordance with applicable data protection laws.

    Do you sell data to third parties?

    No. We never sell your account data or your searches. Registry records are retrieved on your behalf from public sources. See our Privacy Policy for the full list of sub-processors.

    Can I get a Data Processing Agreement (DPA)?

    Yes. Enterprise customers receive a DPA as part of their subscription. Contact support@lemreveal.com to request one.

    Still Have Questions?

    Our team is happy to discuss compliance requirements and provide documentation for your legal review.