Legal · Privacy Policy
Effective July 1, 2026. This policy explains what personal data clearbound, Inc. ("clearbound", "we") collects, why, who we share it with, how long we keep it, and the rights you have over it — whether you are our customer, a visitor, or a person whose data passes through a verification.
clearbound provides business verification (KYB) infrastructure. That means we handle personal data in two distinct roles, and your rights differ depending on which one applies:
If your data was processed because a company you are associated with was verified by one of our customers, that customer is the controller. We will always tell you who they are when you ask, and we will pass your request to them where the law requires them to answer it.
We do not buy personal data from data brokers, and we do not sell personal data to anyone.
When a customer runs a verification, we process the data needed to complete the checks they request:
This data is processed because our customers are legally required to know who they do business with under anti-money-laundering law. We never use business-subject data to build our own profiles, marketing lists, or products, and we do not retain raw registry or watchlist source dumps — sources are queried live, and only the resulting decision record is kept.
We use personal data to: provide and operate the service; authenticate users and secure the platform; bill for usage; respond to support requests; send operational notices (incident, deprecation, and security emails are not optional; product marketing is opt-in and every message has an unsubscribe link); comply with our own legal obligations; and improve the service using aggregated, de-identified usage statistics that cannot be traced back to a person.
Where GDPR or UK GDPR applies, we rely on: contract (providing the service you signed up for), legitimate interests (securing the platform, preventing abuse, limited first-party analytics), legal obligation (tax, accounting, and lawful requests), and consent (marketing communications and non-essential cookies). Our customers rely on their own legal bases — typically legal obligation under AML law — for the verifications they run.
We share personal data only with: subprocessors that host and operate the service (cloud infrastructure, payment processing, email delivery, error monitoring — the current list is available on request and customers are notified 30 days before any addition); data sources, to the minimal extent required to run a query you requested (for example sending a company number to a registry); authorities, when we receive a legally binding request, which we review, narrow where possible, and disclose to the affected customer unless we are prohibited from doing so; and a successor entity in the event of a merger or acquisition, under this same policy.
Customers choose a hosting region (United States or European Union) and verification data stays there. Where personal data does cross borders — for example a support ticket handled from another region — the transfer is protected by the EU Standard Contractual Clauses and the UK Addendum, with supplementary measures where required.
When a retention period ends, data is purged from primary stores within 24 hours and from encrypted backups within 30 days.
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. Write to privacy@clearbound.xyz and we will respond within 30 days. If we process your data as a processor, we will route the request to the responsible customer and help them answer it. You also have the right to complain to your supervisory authority; we would appreciate the chance to resolve the issue directly first.
clearbound.xyz uses a strictly necessary session cookie for login and a first-party, cookieless analytics measurement of page views. We set no advertising or cross-site tracking cookies, and we honor the Global Privacy Control signal.
Personal data is protected by the controls described on our security page: encryption in transit and at rest, hard tenant isolation, just-in-time least-privilege access, and an append-only audit log, attested under SOC 2 Type II and ISO 27001. If a breach affects your personal data, we will notify the affected controller within 72 hours of confirming it, and affected individuals where the law requires.
The service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe we hold any, contact us and we will delete it.
When we change this policy we will update the effective date above, and for material changes we will email account owners at least 30 days before the change takes effect. Prior versions are available on request.
clearbound, Inc. · Attn: Privacy · 548 Market Street, PMB 61429, San Francisco, CA 94104, USA. Email privacy@clearbound.xyz. Our EU representative and Data Protection Officer can be reached at dpo@clearbound.xyz.