Legal

Privacy Policy

Last updated: 2 September 2026.

This policy explains what personal data Company Watch collects, why, and what rights you have over it. It applies both if you hold a Company Watch account, and if you're an individual whose details appear in Companies House data that reaches us through a subscriber's watchlist — for example, as a company officer or a person with significant control. See Section 8 if the second case is yours.

1. Who we are

The Service is provided by Akeman Financial Solutions Ltd, trading as Company Watch, a company registered in England and Wales under company number 13138620, whose registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ ("we", "us", "our"). We're the data controller for the personal data described in Section 2 below. You can contact us at hello@company-watch.co.uk, or see Section 9 for how to complain to our regulator.

For the Companies House personal data described in Section 3, our role is different — we act as a processor on behalf of the subscriber whose watchlist it flows through, not as controller. That distinction matters for how you exercise your rights, and is explained where it's relevant below.

2. Data we collect directly, and why

We collect the following about account holders:

  • Email address — required to create an account, verify it's really you, issue your API key, and send account-related messages (verification links, security notices, and — if you're on a paid tier — billing communications). This is the only field the sign-up form asks for.
  • IP address at sign-up — kept briefly to rate-limit sign-ups per IP address and reduce abuse of the free tier.
  • API key metadata — the key's prefix and its created/last-used timestamps. We never store your plaintext API key; only a one-way hash of it is kept, so we can verify a request without being able to recover the key itself. This is also why we can only show it to you once, at sign-up.
  • API call logs — for authenticated requests, we log the method, path, status code, and timestamp against your account and key, generally including the request and response content itself. We use this to operate the Service (rate limiting, debugging, and support), and to investigate misuse. Your API key is never written into these logs.
  • Payment details, if you're on a paid tier — handled directly by our payment processor, Stripe. We never see or store your full card number; see Section 6.

We don't ask for your name or your company's name at sign-up, and we don't use cookies or any analytics or tracking technology on this site — see Section 7.

3. Companies House data relayed through the Service

The core of the Service is relaying change events sourced from Companies House's own public register — including personal data about company officers and people with significant control (PSC) that Companies House itself publishes. We process that data only as instructed by the subscriber who configured the watchlist it flows through: they decide which companies to monitor and for what purpose (typically AML/KYC or credit-risk monitoring — see our homepage), and we deliver matching events to them by webhook or polling. We don't use this data for our own purposes, and we don't sell it or share it beyond delivering it to the subscriber who requested it.

This data originates from Companies House under the Open Government Licence and remains subject to Crown copyright, as set out in our Terms of Service, Section 7.

4. Lawful basis for processing

We rely on the following lawful bases under UK GDPR:

  • Performance of a contract — for your email address and API key metadata, to create and operate your account and deliver the Service you signed up for.
  • Legitimate interests — for sign-up IP addresses and API call logs, in keeping the Service secure, investigating abuse, and providing support, in a way that doesn't override your own rights and interests.
  • Legal obligation — for billing records we're required to keep for tax purposes.

For the Companies House data described in Section 3, the lawful basis is set by the subscriber acting as controller for their own monitoring purpose, not by us.

5. How long we keep data

We keep account data (your email address and API key metadata) for as long as your account is open, and for a reasonable period afterwards to deal with any disputes, billing queries, or legal obligations, after which we delete it.

6. Who we share data with

We share personal data with a small number of service providers who help us run the Service:

  • Microsoft Azure — hosts our infrastructure and stores the data described in Section 2 in the UK South Azure region.
  • Stripe, for paid tiers only — processes your payment. Stripe is a payment institution in its own right and acts as controller for the payment data it collects directly from you; see Stripe's own privacy policy. We only ever see that a payment succeeded or failed, not your full card details.
  • Google Fonts — this site loads typefaces from Google Fonts. That's the only third-party request our website itself makes; we don't run any analytics, advertising, or tracking scripts.

We don't sell personal data, and we don't share it with anyone for their own marketing purposes. We'll disclose it beyond the above only if we're required to by law, or to protect the security of the Service.

7. Cookies

This site doesn't set cookies, and doesn't use analytics, advertising, or tracking technology of any kind. Your API key is sent as a bearer token on each request, not stored in a cookie.

8. If you're named in Companies House data relayed through the Service

If you're a company officer or a person with significant control and your details reach us through a subscriber's watchlist, we act as a processor for that data, not controller — the subscriber decides why they're monitoring your company. Companies House remains the original source and controller of its own published register, and their own privacy notice explains your rights over that underlying data directly. If you have a question specifically about how a Company Watch subscriber is using their monitoring of your company, we'd encourage you to raise it with them directly where you know who they are; if you're not sure, contact us at hello@company-watch.co.uk and we'll help route it.

9. Your rights

Under UK GDPR, you have the right to:

  • ask us for a copy of the personal data we hold about you;
  • ask us to correct it if it's inaccurate or incomplete;
  • ask us to delete it, in certain circumstances;
  • ask us to restrict or object to certain processing; and
  • ask us to provide your data to you, or transfer it to someone else, in a portable format.

To exercise any of these, email hello@company-watch.co.uk. If you're not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator.

10. Children

The Service is aimed at organisations with their own technical teams, not at individual consumers, and isn't directed at or knowingly used by children. We don't knowingly collect personal data from anyone under 18.

11. Changes to this policy

We may update this policy from time to time. If we make a material change, we'll email account holders and update the date at the top of this page.

12. Contact

Questions about this policy or how we handle personal data? Email us at hello@company-watch.co.uk.