Legal

Privacy Policy

This policy explains how Red Flags Verification handles personal information when you use our website, products and services.

Last updated: August 2026

This document is a draft prepared for review. It has not been reviewed or approved by a qualified legal professional, and sections marked for legal review must be completed before launch.

1.Who we are

Red Flags Verification provides business intelligence and risk verification tools that help organisations investigate companies, suppliers, customers and counterparties.

Red Flags Verification is the service and brand. It is operated by Red Flags Ai Ltd, the registered company responsible for this website and service and the data controller for personal information processed through it. Where this policy refers to “we”, “us” or “our”, it means Red Flags Ai Ltd.

The registered details of Red Flags Ai Ltd are:

[LEGAL REVIEW REQUIRED: registered company number][LEGAL REVIEW REQUIRED: registered address]

2.Information we may collect

Information you provide

  • Name
  • Email address
  • Company name
  • Account details
  • Contact enquiries and their content
  • Information submitted when requesting a company verification
  • Billing-related information
  • Other communications with Red Flags Verification

We do not store full payment card details on our own systems. Where payments are enabled, card information is handled by the applicable payment provider.

[LEGAL REVIEW REQUIRED: confirm payment processor/data flow]

Information about businesses submitted for verification

Customers may submit information relating to companies and to individuals associated with those companies, such as directors, officers or contacts. This may include:

  • Business name
  • Registration identifiers
  • Business address
  • Website
  • Telephone number
  • Names of directors, officers or contacts

Much of this information relates to a company rather than to an identifiable individual. Where information does identify an individual, we treat it as personal information under this policy.

Technical information

Where our website or hosting infrastructure processes technical information, this may include IP address, browser and device information, pages viewed, referral information and cookie identifiers. Analytics and marketing tracking are not currently implemented on this website, and this section will be updated if that changes.

[LEGAL REVIEW REQUIRED: confirm which technical/log data is actually collected and retained by hosting and infrastructure providers]

3.How we use information

Information may be used to:

  • Provide requested verification services
  • Create and operate user accounts
  • Process transactions where payments are enabled
  • Respond to enquiries and provide support
  • Improve product functionality and reliability
  • Protect platform security and prevent abuse
  • Meet legal and regulatory obligations
  • Send service and administrative communications
  • Send marketing communications only where there is an appropriate lawful basis

5.Company-verification data

When a customer requests a verification, we process the information they submit together with information obtained from available business, compliance and digital sources. The purpose is to produce business intelligence and risk-verification findings for the requesting customer.

Findings describe what available information does and does not support. Red Flags Verification does not make legal determinations about companies or individuals, and a verification score is not a credit score, a credit rating or a statement about creditworthiness.

6.Automated analysis

Automated systems may assist in identifying inconsistencies, organising intelligence and generating risk indicators. These outputs are designed to support commercial decision-making and are not guarantees of legitimacy or wrongdoing.

[LEGAL REVIEW REQUIRED: confirm whether any processing constitutes automated decision-making or profiling with legal or similarly significant effects, and what safeguards or disclosures are required]

7.Sharing information

Information may be shared with categories of recipients such as:

  • Hosting and infrastructure providers
  • Payment providers, where payments are enabled
  • Email and communications providers
  • Business-intelligence and data providers
  • Professional advisers
  • Government or regulatory authorities where legally required

We do not sell personal information. Individual vendors are not named in this policy until their role in production has been confirmed.

[LEGAL REVIEW REQUIRED: confirm current processors/subprocessors before launch]

8.International transfers

Service providers and information sources may operate in more than one country, so information may be processed outside the country in which you are located.

[LEGAL REVIEW REQUIRED: confirm international-transfer mechanism and applicable jurisdictions]

9.Data retention

We retain information only for as long as reasonably necessary for the purposes described in this policy and to meet applicable legal, accounting, security or contractual requirements.

[LEGAL REVIEW REQUIRED: define actual retention periods for account, verification, contact and payment records]

10.Security

We use reasonable technical and organisational measures designed to protect information against unauthorised access, loss, misuse or alteration. No method of transmission or storage is completely secure, and we do not claim any security certification that has not been independently verified.

11.Your rights

Depending on the law that applies to you, you may have rights to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion in certain circumstances
  • Request restriction of processing
  • Object to certain processing
  • Request portability of information you provided
  • Withdraw consent where processing relies on consent
  • Complain to a supervisory authority or regulator

[LEGAL REVIEW REQUIRED: confirm applicable regulator and jurisdiction-specific rights]

12.Marketing communications

Submitting a contact enquiry does not subscribe you to marketing communications. Marketing is only sent where there is an appropriate legal basis, and you can opt out at any time using the unsubscribe mechanism included in those messages.

Service and administrative messages relating to an account or a requested verification are not marketing and may still be sent.

13.Children

The service is intended for business and commercial users. It is not designed for or directed at children, and we do not knowingly collect information from them.

15.Changes to this policy

We may update this policy from time to time. The current version and its last updated date are shown on this page.

16.Contact

Questions about this policy can be sent through our contact page.

[LEGAL REVIEW REQUIRED: privacy contact email][LEGAL REVIEW REQUIRED: legal entity/address details for privacy correspondence]

See also our Terms of Service and Cookie Policy.