Privacy Policy

Last updated: January 2026

1. Who we are

Companyfile B.V. ("Companyfile", "we", "us") is a Dutch company registered at the Chamber of Commerce under number 12345678. We operate the Companyfile platform at companyfile.io. We are the data controller for all personal data processed through our platform.

2. What data we collect

We collect and process the following categories of personal data:

  • Account data: Name, email address, password (hashed), company role
  • Company disclosure data: Company name, registration number, address, legal form, industry sector, business model description, revenue figures, UBO details (name, date of birth, nationality, shareholding percentage, PEP status)
  • Uploaded documents: Chamber of commerce extracts, articles of association, financial statements, identification documents
  • Technical data: IP address, browser type, session data, access logs

3. Why we process your data

We process personal data for the following purposes:

  • Service delivery: To provide the Companyfile platform, generate disclosure reports, and manage your account (legal basis: contract performance)
  • Security: To protect our platform and detect fraud (legal basis: legitimate interest)
  • Communication: To send you service-related notifications (legal basis: contract performance)
  • Legal compliance: To comply with applicable laws and regulations (legal basis: legal obligation)

4. Data storage and security

All data is stored on servers located in the European Union. We implement appropriate technical and organizational security measures including:

  • Encryption at rest and in transit (TLS 1.2+)
  • Access controls and role-based permissions
  • Regular security audits and monitoring
  • Secure password hashing

5. Data sharing

We do not sell, rent, or share your personal data with third parties for marketing purposes. We may share data with:

  • Infrastructure providers: EU-based hosting and cloud services required to operate the platform
  • Legal authorities: When required by law or court order

Your disclosure report is only shared when you explicitly choose to download and distribute it yourself.

6. Your rights (GDPR)

Under the General Data Protection Regulation, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Portability: Receive your data in a machine-readable format
  • Restriction: Limit how we process your data
  • Objection: Object to processing based on legitimate interest

To exercise any of these rights, contact us at privacy@companyfile.io.

7. Data retention

We retain your data for as long as your account is active. After account deletion, we remove personal data within 30 days, except where retention is required by law. Anonymized, aggregated data may be retained for analytics purposes.

8. Cookies

We use essential cookies required for the platform to function (session management, CSRF protection). We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

9. Contact

For privacy-related questions or requests:

Companyfile B.V.
Email: privacy@companyfile.io
Amsterdam, the Netherlands

You also have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.