Privacy Policy
How EDD processes personal data of platform users and of investigated subjects under EU/UK GDPR.
Who we are
EDD provides Enhanced Due Diligence decision-support software to regulated organisations. For investigation data, your organisation is the controller and EDD acts as processor. For account and billing data, EDD is the controller.
Data we process about users (Art. 13)
Name, business email, organisation, organisation settings, and payment records. Purpose: providing the service and meeting contractual and legal obligations. Lawful basis: contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
Data about investigated subjects (Art. 14)
Identity details, corporate roles, ownership, PEP status, sanctions results, adverse media and, where relevant, criminal-offence data (Art. 10). Sources: public registries, sanctions and PEP lists, court records, regulators and news media. Lawful basis: legal obligation and legitimate interest in preventing financial crime, processed under the AML laws that apply to the customer organisation.
Retention
Case data stays only in a temporary session store and is deleted automatically after it expires (currently two hours) or when you close the case. EDD keeps no permanent case archive. Your organisation is responsible for keeping downloaded reports as its AML record-keeping rules require. We do not claim that third-party data sources retain nothing.
Your rights
Access, rectification, erasure, restriction, objection and portability, subject to AML exemptions (for example, rules against tipping off). Investigated subjects should contact the organisation that ran the check. You may complain to your supervisory authority.
International transfers
Where data leaves the EEA/UK, we rely on adequacy decisions or Standard Contractual Clauses with supplementary measures.
Contact
Data protection enquiries: privacy@example.com (placeholder — replace before launch).
