Privacy Policy

Last updated: 5 August 2026

Public Insights aggregates UK public records about individuals, businesses and properties. That means we process personal data in two quite different ways: data about you when you use our services, and data about people who appear in public records — whether or not they have ever heard of us. This policy explains both, in that order, along with the rights everyone has in either case.

1. Who We Are

Public Insights is a trading name of DF W0RK5 LTD, the controller of the personal data described in this policy.

  • Company number: 14696593
  • Registered office: 2 Primrose Cottages, Basingstoke Road, Riseley, Reading, England, RG7 1QH
  • Email: [email protected]

We have not appointed a Data Protection Officer; the contact above handles all data protection matters.

2. This Policy Covers Three Groups of People

  • Customers and account holders — people who create an account, subscribe, buy credits or buy a one-off background report (including guests without an account). Sections 3–4.
  • People who appear in public records — individuals whose information is contained in the public and licensed sources we aggregate, indexed and made searchable by our platform. Sections 5–7. If someone has searched for you, or you have found yourself in our results, this is the part about you.
  • Website visitors — anyone browsing the site, including sections on cookies and analytics. Section 12.

3. Data We Process About Customers

What we collect

  • Account data: email address, password (stored hashed), optional name, avatar, language and timezone preferences.
  • Billing data: your subscription status, purchases and invoices. Payment is handled by Stripe — card details go directly to Stripe and we never hold your full card number.
  • Search and usage history: the searches you run (including subject names, addresses, postcodes and dates of birth you enter), saved Canvas networks, monitoring configurations, AI Assistant runs, and generated reports. We keep a history of your searches to operate your account, enforce quotas and provide your account history to you.
  • One-off report purchases: the subject details you enter, the report we generate, and — for guest purchases — the email address you give us for delivery.
  • Terms acceptance records: when you accept our Terms of Service (at signup or when buying a background report) we record the date and time, the version of the terms you accepted, your email address, IP address and browser identifier, as evidence of the agreement.
  • Support messages: whatever you send us through the contact form or by email.

Why we process it (lawful bases)

  • Performing our contract with you — operating your account, running your searches, generating and delivering reports, billing.
  • Legal obligation — keeping billing and accounting records for the periods required by tax law.
  • Legitimate interests — securing the service (abuse prevention, captcha, rate limiting), keeping evidence of contract acceptance, understanding usage, and sending service and lifecycle emails. You can unsubscribe from marketing-stream emails at any time via the link in each message; transactional messages (such as payment-failure notices) are sent while you hold an account.

4. Where Customer Data Goes

See section 8 for the full list of service providers and section 10 for how long we keep things.

5. Data We Process About People in Public Records

Our platform indexes and makes searchable information from public and licensed sources. If you are recorded in those sources, our systems may hold and return information about you, including your name, addresses, approximate age or date of birth, company appointments and shareholdings, and the other categories listed below. We process this data as an independent controller. We rely on the lawful basis of legitimate interests (UK GDPR Article 6(1)(f)): making public-record information practically accessible for fraud prevention, due diligence, tracing, journalism and other verification purposes carried out by our customers. We have carried out a Legitimate Interest Assessment covering this processing, weighing those interests against the rights of the people recorded; you can request a copy using the contact details in section 1.

The sources

Companies House (companies, officers, persons with significant control, confirmation statements, shareholdings, insolvency and disqualification records, filed documents); the UK electoral register via a licensed commercial supplier — open (edited) register only, which contains only electors who have not opted out of it; planning application registers; licensing registers including houses in multiple occupation; professional registers; charity trustee records; court, tribunal and insolvency records; police-published crime and incident data; Football Association participation data; the Financial Conduct Authority register; published risk, sanctions and enforcement information; and, for AI-assisted features, searches of the open web including news and regulatory sources.

6. Criminal-Offence Data

Some of our sources — court and tribunal records, police-published crime data, insolvency and disqualification records — contain information about criminal convictions, offences and related proceedings. Under UK GDPR Article 10 and the Data Protection Act 2018 we may only process this category of data under a specific condition set out in Schedule 1 of the Act. We rely on the conditions for preventing or detecting unlawful acts and protecting the public (Schedule 1, Part 2, paragraphs 10 and 11, extended for criminal-offence data by Part 3, paragraph 36), and we maintain an Appropriate Policy Document for this processing, available to the ICO on request.

7. Analysis We Generate

Beyond reproducing source records, the platform generates new information: it matches and merges records that appear to relate to the same person, maps connections between people, companies and addresses, and — in the AI Assistant, background reports and monitoring features — uses automated systems including large language models to read documents, expand networks and flag patterns, including risk indicators (such as proximity to entities associated with suspicious corporate networks). This generated analysis is inferential: it can be wrong, and it can connect records that in fact relate to different people with similar details. Our Terms of Service require customers to verify results against original sources before relying on them, and prohibit using the service to make automated decisions with legal or similarly significant effects about individuals.

8. Who We Share Personal Data With

We use these categories of service providers (processors), and the named providers currently:

  • Hosting and storage: DigitalOcean (application hosting and file storage, including generated report PDFs); MongoDB Atlas (databases behind our search, Canvas and graph services).
  • Payments: Stripe (checkout, subscriptions, billing portal). Stripe acts as an independent controller for its own fraud-prevention and compliance processing.
  • Email delivery: Postmark (ActiveCampaign) — transactional and lifecycle email.
  • AI processing: Anthropic — AI Assistant, report analysis and related features send relevant search-result content, which can include personal data from our sources, to Anthropic's API for processing on our instructions.
  • Site security: Cloudflare (Turnstile captcha on signup and login forms).
  • Analytics and advertising: Google (Google Analytics; Google Ads conversion tag) and Contentsquare (usage analytics). These run only with your consent — see section 12.
  • Data sources: queries against licensed suppliers (including the electoral-register supplier) and public APIs (including Companies House and the FCA) necessarily transmit the search terms you enter — typically a name, address or postcode — to the source being queried.

We also disclose personal data where the law requires it, and search results themselves are disclosures of public-record data to the customer who ran the search.

For business customers, our Data Processing Agreement — including a maintained sub-processor schedule — is available on request from the contact address in section 1.

9. International Transfers

Some providers process data outside the UK, principally in the United States: Anthropic, Postmark and Google. Where personal data leaves the UK we rely on recognised UK transfer safeguards: the UK Extension to the EU–US Data Privacy Framework where the provider is certified under it, and otherwise the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Contentsquare processes analytics data in the European Union, which the UK recognises as providing adequate protection.

10. How Long We Keep Personal Data

  • Search-result and source data (our aggregated public-record indexes): records are refreshed from source and records no longer present at source are removed within 12 months.
  • Customer search history, saved networks and generated reports: kept while your account is open; deleted or anonymised within 12 months of account closure.
  • One-off report records (including guest email addresses and the generated PDF): kept for 12 months from purchase, then deleted.
  • Billing and accounting records: kept for 6 years plus the current year, as required by tax law.
  • Terms-acceptance records: kept for the life of the account or contract and for 6 years afterwards, as evidence of the agreement.
  • Support correspondence: 2 years from the last message.

11. Your Rights

Everyone this policy covers — customers, people in public records, and visitors — has the right to:

  • Access the personal data we hold about them (a "subject access request");
  • Rectification of inaccurate data — for source records, note that we reproduce records as published, so corrections usually need to be made at the source (for example Companies House), after which our copy updates on refresh; we will annotate or suppress demonstrably inaccurate records in the meantime;
  • Erasure of their data in certain circumstances;
  • Object to processing based on legitimate interests — including, for people who appear in our public-record indexes, objecting to their records being returned in search results. Where an objection is upheld we suppress the records concerned from results;
  • Restriction of processing while a complaint is investigated;
  • Portability of data you provided to us, where processing is based on contract.

To exercise any of these rights, email [email protected]. We respond within one month. You can get a sense of what our search returns about you using the public footprint search on this site.

If you are unhappy with our response you can complain to the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to resolve the issue first.

12. Cookies & Analytics

  • Strictly necessary: session and CSRF cookies (signing in, form security), the cookie that remembers your cookie-consent choice, and Cloudflare Turnstile's own cookies/local state when a protected form is displayed. These do not require consent.
  • Analytics and advertising (consent only): Google Analytics, a Google Ads conversion tag, and Contentsquare usage analytics, which set cookies and process your IP address and page interactions. These load only after you choose "Accept analytics" on our cookie banner; choosing "Reject" stores your choice and loads none of them. You can change your mind by clearing the pi_cookie_consent cookie in your browser, after which the banner will ask again.

13. Children

Our services are not directed at children and we do not knowingly hold accounts for anyone under 18. Public records aggregated by the platform are overwhelmingly about adults (directors, electors, trustees, registrants); where a source record relates to a minor we will suppress it on request.

14. Security

We use appropriate technical and organisational measures: TLS in transit, hashed passwords, captcha and rate-limiting on authentication endpoints, access controls on our infrastructure, and payment handling delegated to Stripe. No system is perfectly secure; if a breach affecting your rights occurs we will notify the ICO and, where required, you, within the statutory timescales.

15. Changes to This Policy

We may update this policy from time to time. Material changes will be notified to account holders by email and the "Last updated" date above always reflects the current version.