Legal · Privacy Policy

Privacy Policy

Effective July 1, 2026. This policy explains what personal data clearbound, Inc. ("clearbound", "we") collects, why, who we share it with, how long we keep it, and the rights you have over it — whether you are our customer, a visitor, or a person whose data passes through a verification.

Scope & roles

clearbound provides business verification (KYB) infrastructure. That means we handle personal data in two distinct roles, and your rights differ depending on which one applies:

  • As a controller, for data about our customers and site visitors: account details, billing information, support conversations, and usage of clearbound.xyz and the dashboard.
  • As a processor, for data about the businesses our customers verify and the people connected to them — directors, beneficial owners, and document subjects. Our customer decides why and whether that data is processed; we process it on their documented instructions under a data processing agreement.

If your data was processed because a company you are associated with was verified by one of our customers, that customer is the controller. We will always tell you who they are when you ask, and we will pass your request to them where the law requires them to answer it.

Data we collect as a controller

  • Account data: name, work email, company, role, password hash, and MFA configuration when you create an account.
  • Billing data: plan, invoices, and payment method details, held by our payment processor; we store only the last four digits and expiry.
  • Usage data: API request metadata (endpoint, timestamp, status, key ID — never request bodies), dashboard actions, and device/browser information.
  • Communications: support tickets, sales conversations, and emails you exchange with us.

We do not buy personal data from data brokers, and we do not sell personal data to anyone.

Business-subject data we process for customers

When a customer runs a verification, we process the data needed to complete the checks they request:

  • Registry data: company records from official registries, including named officers and directors.
  • Ownership data: beneficial-owner names, dates of birth, nationalities, and ownership percentages, minimized to what the UBO determination requires.
  • Screening data: matches (and non-matches) against public sanctions, PEP, and adverse-media sources.
  • Document data: identity and corporate documents uploaded by the customer, plus the structured fields extracted from them.

This data is processed because our customers are legally required to know who they do business with under anti-money-laundering law. We never use business-subject data to build our own profiles, marketing lists, or products, and we do not retain raw registry or watchlist source dumps — sources are queried live, and only the resulting decision record is kept.

Purposes

We use personal data to: provide and operate the service; authenticate users and secure the platform; bill for usage; respond to support requests; send operational notices (incident, deprecation, and security emails are not optional; product marketing is opt-in and every message has an unsubscribe link); comply with our own legal obligations; and improve the service using aggregated, de-identified usage statistics that cannot be traced back to a person.

Where GDPR or UK GDPR applies, we rely on: contract (providing the service you signed up for), legitimate interests (securing the platform, preventing abuse, limited first-party analytics), legal obligation (tax, accounting, and lawful requests), and consent (marketing communications and non-essential cookies). Our customers rely on their own legal bases — typically legal obligation under AML law — for the verifications they run.

Sharing & subprocessors

We share personal data only with: subprocessors that host and operate the service (cloud infrastructure, payment processing, email delivery, error monitoring — the current list is available on request and customers are notified 30 days before any addition); data sources, to the minimal extent required to run a query you requested (for example sending a company number to a registry); authorities, when we receive a legally binding request, which we review, narrow where possible, and disclose to the affected customer unless we are prohibited from doing so; and a successor entity in the event of a merger or acquisition, under this same policy.

International transfers

Customers choose a hosting region (United States or European Union) and verification data stays there. Where personal data does cross borders — for example a support ticket handled from another region — the transfer is protected by the EU Standard Contractual Clauses and the UK Addendum, with supplementary measures where required.

Retention

  • Verification records: retained per the customer's configured policy, which defaults to the regulatory minimum in their jurisdiction (typically five years after the relationship ends).
  • Original documents: 90 days by default, configurable per customer policy.
  • Account data: for the life of the account plus 90 days.
  • Billing records: as long as tax law requires, typically seven years.
  • Audit logs: per customer policy, because our customers rely on them for their own compliance.

When a retention period ends, data is purged from primary stores within 24 hours and from encrypted backups within 30 days.

Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. Write to privacy@clearbound.xyz and we will respond within 30 days. If we process your data as a processor, we will route the request to the responsible customer and help them answer it. You also have the right to complain to your supervisory authority; we would appreciate the chance to resolve the issue directly first.

One important limit: where a verification record exists to satisfy an anti-money-laundering obligation, the law requires it to be kept for a minimum period even if deletion is requested. In that case we restrict the record — it is frozen, inaccessible for any other purpose, and purged the moment the mandatory period ends.

Cookies

clearbound.xyz uses a strictly necessary session cookie for login and a first-party, cookieless analytics measurement of page views. We set no advertising or cross-site tracking cookies, and we honor the Global Privacy Control signal.

Security

Personal data is protected by the controls described on our security page: encryption in transit and at rest, hard tenant isolation, just-in-time least-privilege access, and an append-only audit log, attested under SOC 2 Type II and ISO 27001. If a breach affects your personal data, we will notify the affected controller within 72 hours of confirming it, and affected individuals where the law requires.

Children

The service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe we hold any, contact us and we will delete it.

Changes

When we change this policy we will update the effective date above, and for material changes we will email account owners at least 30 days before the change takes effect. Prior versions are available on request.

Contact

clearbound, Inc. · Attn: Privacy · 548 Market Street, PMB 61429, San Francisco, CA 94104, USA. Email privacy@clearbound.xyz. Our EU representative and Data Protection Officer can be reached at dpo@clearbound.xyz.