Last updated: 5 August 2026
Public Insights aggregates UK public records about individuals, businesses and properties. That means we process personal data in two quite different ways: data about you when you use our services, and data about people who appear in public records — whether or not they have ever heard of us. This policy explains both, in that order, along with the rights everyone has in either case.
Public Insights is a trading name of DF W0RK5 LTD, the controller of the personal data described in this policy.
We have not appointed a Data Protection Officer; the contact above handles all data protection matters.
See section 8 for the full list of service providers and section 10 for how long we keep things.
Our platform indexes and makes searchable information from public and licensed sources. If you are recorded in those sources, our systems may hold and return information about you, including your name, addresses, approximate age or date of birth, company appointments and shareholdings, and the other categories listed below. We process this data as an independent controller. We rely on the lawful basis of legitimate interests (UK GDPR Article 6(1)(f)): making public-record information practically accessible for fraud prevention, due diligence, tracing, journalism and other verification purposes carried out by our customers. We have carried out a Legitimate Interest Assessment covering this processing, weighing those interests against the rights of the people recorded; you can request a copy using the contact details in section 1.
Companies House (companies, officers, persons with significant control, confirmation statements, shareholdings, insolvency and disqualification records, filed documents); the UK electoral register via a licensed commercial supplier — open (edited) register only, which contains only electors who have not opted out of it; planning application registers; licensing registers including houses in multiple occupation; professional registers; charity trustee records; court, tribunal and insolvency records; police-published crime and incident data; Football Association participation data; the Financial Conduct Authority register; published risk, sanctions and enforcement information; and, for AI-assisted features, searches of the open web including news and regulatory sources.
Some of our sources — court and tribunal records, police-published crime data, insolvency and disqualification records — contain information about criminal convictions, offences and related proceedings. Under UK GDPR Article 10 and the Data Protection Act 2018 we may only process this category of data under a specific condition set out in Schedule 1 of the Act. We rely on the conditions for preventing or detecting unlawful acts and protecting the public (Schedule 1, Part 2, paragraphs 10 and 11, extended for criminal-offence data by Part 3, paragraph 36), and we maintain an Appropriate Policy Document for this processing, available to the ICO on request.
Beyond reproducing source records, the platform generates new information: it matches and merges records that appear to relate to the same person, maps connections between people, companies and addresses, and — in the AI Assistant, background reports and monitoring features — uses automated systems including large language models to read documents, expand networks and flag patterns, including risk indicators (such as proximity to entities associated with suspicious corporate networks). This generated analysis is inferential: it can be wrong, and it can connect records that in fact relate to different people with similar details. Our Terms of Service require customers to verify results against original sources before relying on them, and prohibit using the service to make automated decisions with legal or similarly significant effects about individuals.
We use these categories of service providers (processors), and the named providers currently:
We also disclose personal data where the law requires it, and search results themselves are disclosures of public-record data to the customer who ran the search.
For business customers, our Data Processing Agreement — including a maintained sub-processor schedule — is available on request from the contact address in section 1.
Some providers process data outside the UK, principally in the United States: Anthropic, Postmark and Google. Where personal data leaves the UK we rely on recognised UK transfer safeguards: the UK Extension to the EU–US Data Privacy Framework where the provider is certified under it, and otherwise the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Contentsquare processes analytics data in the European Union, which the UK recognises as providing adequate protection.
Everyone this policy covers — customers, people in public records, and visitors — has the right to:
To exercise any of these rights, email [email protected]. We respond within one month. You can get a sense of what our search returns about you using the public footprint search on this site.
If you are unhappy with our response you can complain to the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to resolve the issue first.
pi_cookie_consent cookie in your browser, after which the banner will ask again.Our services are not directed at children and we do not knowingly hold accounts for anyone under 18. Public records aggregated by the platform are overwhelmingly about adults (directors, electors, trustees, registrants); where a source record relates to a minor we will suppress it on request.
We use appropriate technical and organisational measures: TLS in transit, hashed passwords, captcha and rate-limiting on authentication endpoints, access controls on our infrastructure, and payment handling delegated to Stripe. No system is perfectly secure; if a breach affecting your rights occurs we will notify the ICO and, where required, you, within the statutory timescales.
We may update this policy from time to time. Material changes will be notified to account holders by email and the "Last updated" date above always reflects the current version.