Legal
Privacy Policy
1. Who We Are (Data Controller)
Sanction List Check (sanctionlistcheck.com) is operated by Miguel Casares Robles, an individual sole trader ("autónomo") registered address: Horno de Haza, 34 2A, 18002 Granada, Spain (EU).
For the purposes of the General Data Protection Regulation (GDPR), Miguel Casares Robles is the data controller for the personal data we collect directly from you, such as your email address and billing metadata. When you upload lists of names for screening, you are the data controller for that data, and we act as a data processor on your behalf, strictly following your instructions to provide the screening service.
Our contact details for privacy and data protection requests are: [email protected].
2. What Data We Collect and Why
2.1. Account and Contact Data
- Data Collected: Your email address.
- Purpose: We collect your email address to enable secure login to our service using a magic-link authentication system. This allows you to access your purchased services and reports. We may also use it to communicate important service-related information, updates, or support messages.
- Legal Basis (GDPR): Processing is necessary for the performance of a contract with you (to provide the Sanction List Check service).
2.2. Billing Data
- Data Collected: When you make a paid purchase, billing information (such as your name, company name, address, and payment card details) is collected.
- Purpose: To process your payment and issue an invoice/receipt for your purchase.
- How it's Handled: All paid purchases are handled by Paddle.com Market Limited (England and Wales, company no. 8172165, registered office 30 Old Bailey, London EC4M 7AU), our Merchant of Record. Depending on your billing location, the contracting Paddle entity may instead be the regional entity named on your invoice: Paddle.com Inc. for buyers in the United States, or Paddle.com (Canada) Ltd for buyers in Canada. Paddle, not Miguel Casares Robles, is the seller of record on your invoice or receipt. Paddle collects and remits VAT and sales tax, issues the receipt, and handles payment card processing and chargebacks under the Paddle Buyer Terms. Paddle acts as an independent controller for the payment, tax and invoicing data it collects, under the Paddle Privacy Notice.
- Email Address Handling: When you open the checkout, we pass the email address you enter for your report to Paddle. Paddle uses it to prefill the checkout form and returns it to us in the payment confirmation; we use it to link the payment to your screening job. Paddle processes this email address as an independent controller under the Paddle Privacy Notice. Our legal basis for this processing is the performance of a contract, GDPR Art. 6(1)(b). For API credit packs, the checkout passes your API key ID and a signed purchase token to Paddle, not your email address.
- Campaign Tags: If you accept analytics cookies and arrive through a link with campaign tags (utm_source, utm_medium, utm_campaign), we store these tags in your browser's local storage for 30 days; the first campaign seen is kept, and the tags are removed after 30 days. Tag values that look like an email address are dropped. When you open a checkout, the campaign tags are sent to Paddle with the purchase and returned to us in the payment confirmation, allowing us to store the campaign name (utm_campaign) with the paid job or credit-pack purchase to measure which campaign led to it. If you did not accept analytics cookies, no campaign tags are stored or sent, and you can withdraw consent at any time by clearing your browser's site data for this domain.
- Legal Basis (GDPR): Processing is necessary for the performance of a contract with you (for payment processing) and for compliance with legal obligations (tax and accounting).
2.3. Customer Uploaded Data (Names for Screening)
- Data Collected: When you use our service, you upload CSV or XLSX lists of company/individual names, or type a single name for a free check. This data may include personal data of third parties (e.g., names of individuals).
- Purpose: This data is processed strictly to screen each name against the specified official sanctions and watch lists (OFAC SDN, US CSL, EU Consolidated, UK Sanctions, UN Consolidated, France — Registre national des gels, Poland — Lista sankcyjna MSWiA, Switzerland — SECO consolidated list) and to generate a PDF, CSV, and JSON report showing matches, possible matches, and associated data. "no match" results.
- Your Responsibility: As the customer, you are the data controller for the names and other information you upload. You are solely responsible for ensuring you have a lawful basis (e.g., legitimate interest, consent, legal obligation) under GDPR and other applicable data protection laws to collect and process this data, and to provide it to us for screening.
- Report Content (identifiers published by the authority): Where an uploaded name potentially matches a designation, the report may reproduce identifiers that the sanctioning authority publishes alongside that designation. These can include national register numbers (for example KRS, NIP, REGON, DUNS), personal identification numbers (for example PESEL), and tax or vessel identification numbers (for example IMO). This information is taken from the official public sanctions list as published by the authority. We do not derive it, and it is never used to decide a match. It is shown only so that you can tell similarly named parties apart during your own review.
- Our Role: We act as a data processor for this uploaded data, processing it only on your instructions to deliver the screening service.
- Legal Basis (GDPR): Processing is necessary for the performance of a contract with you (to deliver the screening report).
3. No AI Training or LLM Use
We want to be absolutely clear: no Artificial Intelligence (AI) or Large Language Model (LLM) is used to process, read, or judge customer data at any point in the Sanction List Check product. Our matching method relies on deterministic fuzzy-text matching algorithms (Jaro-Winkler and token-set) against official list snapshots.
Furthermore, uploaded data is never used to train any AI or machine learning model. Your data is used solely for the purpose of generating your specific screening report.
4. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases as defined by the GDPR:
- Performance of a Contract: This is our primary legal basis for processing your email address (for account access and service delivery), billing data (for payment processing), and customer-uploaded data (to perform the requested screening service).
- Legitimate Interests: We may process certain data for our legitimate interests, such as ensuring the security and integrity of our service, preventing fraud, and improving our service, provided these interests do not override your fundamental rights and freedoms.
- Compliance with Legal Obligations: We may process and retain certain data to comply with legal obligations, such as tax and accounting requirements.
5. Data Retention
- Uploaded Files and Generated Reports: Your uploaded files (CSV/XLSX) and generated reports (CSV, JSON, PDF) are stored temporarily in Cloudflare R2 in Cloudflare's Eastern Europe region (location hint EEUR) and are automatically deleted no later than 24 hours after upload.
- Account and Billing Metadata: Your email address and billing metadata (excluding sensitive payment card details handled by Paddle) may be retained for a longer period to comply with legal, accounting, and tax requirements, or to resolve disputes.
- Free Check Diagnostics: For free single-name checks, we record a one-way hashed form of your IP address, check duration, number of matches, query length and word count, country, data-centre location, and device category to measure service performance. We do not record the name searched, any date of birth, your raw IP address, or the identity of any matched entity. All diagnostic log entries are automatically deleted after 90 days.
- API Screening Records: API screening records, which include the screened names, any hits, and the list versions used, are kept for 90 days by default. You can set the retention period from 1 to 365 days per API key, and you can delete any single record or the entire key with its records at any time. You can also export these records, and this applies only when you use the API.
- MCP Usage Log: For requests to our MCP server with a valid API key, we record the time, MCP method and tool name, AI client name and version, API key identifier, number of names, success status or error code, and response time. This usage log does not contain the screened names or any other query text and entries are deleted automatically after 90 days. Requests without a valid API key are only counted in Cloudflare Workers Analytics Engine, noting the method, tool name, client name, status, and response time, without an IP address, API key, screened names, or query text. Cloudflare keeps these counts for 3 months.
6. Where Your Data is Processed
Your stored data, including our database in Cloudflare D1 and file storage in Cloudflare R2, is placed in Cloudflare's Eastern Europe region using the location hint EEUR. Cloudflare may process requests at its global edge network, which can be outside the EU, and no legal EU-jurisdiction pinning is applied as a location hint is a placement preference, not a legal jurisdiction restriction. The name-matching engine normally runs on a server of Hetzner Online GmbH in Helsinki, Finland, which processes the screened names and fields sent for matching in memory only for the duration of the request and does not store them; Finland is in the EU, so this processing by Hetzner is not a transfer to a third country. If that server is not available or returns an error, or if we switch it off, the matching runs in Cloudflare's network instead, which can be outside the EU.
7. Sub-processors
We use the following third-party sub-processors to provide our service:
- Cloudflare: Cloudflare provides our hosting, storage (Cloudflare R2), database (Cloudflare D1), and compute services. While stored data uses the Eastern Europe location hint EEUR, requests may be processed at Cloudflare's global edge network, and no legal EU-jurisdiction pinning is applied.
- Resend: Resend sends our transactional email, including sign-in links, job notifications, alerts, and API key delivery emails; its location is EU or US.
- Hetzner: Hetzner Online GmbH (Germany) hosts our name-matching engine on a server in Helsinki, Finland; normally, the service sends the screened names and the fields sent for matching (country, date of birth and entity type, where given) to that server. The engine processes them in memory only for the duration of the request, does not write screened names to disk, and its logs do not contain screened names; if that server is not available or returns an error, or if we switch it off, the matching runs in Cloudflare's network instead, which can be outside the EU.
Paddle (Merchant of Record): For paid purchases, Paddle acts as our Merchant of Record, handling payment processing and billing. The contracting entity is Paddle.com Market Limited, England and Wales, company no. 8172165, registered office 30 Old Bailey, London EC4M 7AU, or the regional Paddle entity named on your invoice (Paddle.com Inc. in the United States; Paddle.com (Canada) Ltd in Canada). Paddle acts as an independent controller for the payment, tax and invoicing data it collects, under the Paddle Privacy Notice.
8. Cookies and Access Tokens
We do not use a session cookie for authentication. Instead, access to your screening job is controlled by a per-job access token:
- Per-Job Access Token: Each job you create is protected by a random, single-purpose access token. This token is not stored as a browser cookie -- it is delivered to you directly, either in the link we email you (our magic-link sign-in) or as a request header, and it is only ever valid for that one job. It expires automatically after 24 hours of inactivity, and each sign-in link we email can be opened at most 5 times. Before you upload a file, it works until your upload, for at most 90 days. After your upload, it stops working when your file and report are deleted, 24 hours after your upload.
- No Third-Party Tracking: We do not use any third-party advertising or tracking cookies on sanctionlistcheck.com.
- Analytics Cookies: Analytics cookies are only set with your explicit consent, which you can withdraw at any time by clearing your browser's site data for this domain.
9. Your GDPR Data Protection Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right to Access: You have the right to request copies of your personal data.
- Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
- Right to Object to Processing: You have the right to object to our processing of your personal data, under certain conditions.
- Right to Data Portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month.
You also have the right to lodge a complaint with the Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) or your own country's supervisory authority if you believe we have not handled your data appropriately.
10. Security Measures
We implement appropriate technical and organizational measures to protect your personal data. These include:
- Encrypted Storage: Uploaded files and generated reports are stored in encrypted storage.
- Token Access: Access to reports requires the random 128-bit access token created for each job, and uploaded files are not downloadable through the site.
- Automatic Deletion: As stated, all uploaded files and reports are automatically deleted within 24 hours.
11. Important Disclaimers and Limitation of Liability
Please read these critical disclaimers carefully:
- The Sanction List Check product is a due-diligence screening AID. It is NOT a legal compliance certification and it is NOT legal advice.
- The product never states that a name or counterparty is "safe," "clear," or "approved." It only reports matches, possible matches, and no-match results against the screened lists, for the customer's own review.
- Every match or possible match is for human review by the customer. The customer is solely responsible for their own compliance decisions and for any action or inaction based on the report.
- Results are provided "as is," without warranty of completeness or accuracy.
- Known limitation: fuzzy matching can miss a true match when a name has more than one valid transliteration/romanization (e.g., from Cyrillic or Arabic script into Latin letters), because spellings can diverge beyond the matching thresholds.
- Miguel Casares Robles's total liability arising from the service is capped at the total fees actually paid by the customer for the relevant order/service in the 12 months before the claim.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will post any changes on this page and update the "Last Updated" date at the top of the page. We encourage you to review this Privacy Policy periodically.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- For general support inquiries: [email protected]
- For privacy or data protection requests: [email protected]
This Privacy Policy is governed by the laws of Spain.