1. Who We Are (Data Controller)
Sanction List Check (sanctionlistcheck.com) is operated by Miguel Casares Robles, an individual sole trader ("autónomo") registered address: Horno de Haza, 34 2A, 18002 Granada, Spain (EU).
For the purposes of the General Data Protection Regulation (GDPR), Miguel Casares Robles is the data controller for the personal data we collect directly from you, such as your email address and billing metadata. When you upload lists of names for screening, you are the data controller for that data, and we act as a data processor on your behalf, strictly following your instructions to provide the screening service.
Our contact details for privacy and data protection requests are: [email protected].
Registration number: [to be added on autónomo registration]
2. What Data We Collect and Why
2.1. Account and Contact Data
- Data Collected: Your email address.
- Purpose: We collect your email address to enable secure login to our service using a magic-link authentication system. This allows you to access your purchased services and reports. We may also use it to communicate important service-related information, updates, or support messages.
- Legal Basis (GDPR): Processing is necessary for the performance of a contract with you (to provide the Sanction List Check service).
2.2. Billing Data
- Data Collected: When you make a paid purchase, billing information (such as your name, company name, address, and payment card details) is collected.
- Purpose: To process your payment and issue an invoice/receipt for your purchase.
- How it's Handled: All paid purchases are processed by Paddle.com, our Merchant of Record (MoR). Paddle, not Miguel Casares Robles, is the seller of record on your invoice/receipt. Paddle collects and remits VAT/sales tax, issues the receipt, and handles payment card processing and chargebacks under Paddle's own terms. This means Paddle acts as a separate data controller/processor for your billing data.
- Legal Basis (GDPR): Processing is necessary for the performance of a contract with you (for payment processing) and for compliance with legal obligations (tax and accounting).
- Paddle's Privacy Policy: We encourage you to review Paddle's privacy policy for details on how they handle your billing data: paddle.com/legal/privacy.
2.3. Customer Uploaded Data (Names for Screening)
- Data Collected: When you use our service, you upload CSV or XLSX lists of company/individual names, or type a single name for a free check. This data may include personal data of third parties (e.g., names of individuals).
- Purpose: This data is processed strictly to screen each name against the specified official sanctions and watch lists (OFAC SDN, US CSL, EU Consolidated, UK Sanctions, UN Consolidated) and to generate a PDF and CSV report showing matches, possible matches, and "no match" results.
- Your Responsibility: As the customer, you are the data controller for the names and other information you upload. You are solely responsible for ensuring you have a lawful basis (e.g., legitimate interest, consent, legal obligation) under GDPR and other applicable data protection laws to collect and process this data, and to provide it to us for screening.
- Our Role: We act as a data processor for this uploaded data, processing it only on your instructions to deliver the screening service.
- Legal Basis (GDPR): Processing is necessary for the performance of a contract with you (to deliver the screening report).
3. No AI Training or LLM Use
We want to be absolutely clear: no Artificial Intelligence (AI) or Large Language Model (LLM) is used to process, read, or judge customer data at any point in the Sanction List Check product. Our matching method relies on deterministic fuzzy-text matching algorithms (Jaro-Winkler and token-set) against official list snapshots.
Furthermore, uploaded data is never used to train any AI or machine learning model. Your data is used solely for the purpose of generating your specific screening report.
4. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases as defined by the GDPR:
- Performance of a Contract: This is our primary legal basis for processing your email address (for account access and service delivery), billing data (for payment processing), and customer-uploaded data (to perform the requested screening service).
- Legitimate Interests: We may process certain data for our legitimate interests, such as ensuring the security and integrity of our service, preventing fraud, and improving our service, provided these interests do not override your fundamental rights and freedoms.
- Compliance with Legal Obligations: We may process and retain certain data to comply with legal obligations, such as tax and accounting requirements.
5. Data Retention
- Uploaded Files and Generated Reports: All uploaded files and the generated reports (PDF/CSV) are stored temporarily in Cloudflare R2 in the EU region only. They are automatically deleted no later than 24 hours after upload.
- Account and Billing Metadata: Your email address and billing metadata (excluding sensitive payment card details handled by Paddle) may be retained for a longer period to comply with legal, accounting, and tax requirements, or to resolve disputes.
6. Where Your Data is Processed
All customer data, including uploaded files and generated reports, is processed and stored exclusively within the European Union (EU) region. No customer data leaves the EU.
7. Sub-processors
We use the following third-party sub-processors to provide our service:
- Cloudflare: Provides hosting, storage (Cloudflare R2), and compute services. All data processing by Cloudflare for Sanction List Check occurs in the EU region.
- Paddle: Acts as our Merchant of Record, handling payment processing and billing for all paid purchases.
8. Cookies
We use a single session cookie for authentication purposes:
- Session Cookie: This cookie is essential for our magic-link email authentication system. It is HttpOnly, Secure, and SameSite=Strict, meaning it is protected from cross-site scripting attacks, only sent over HTTPS, and only sent with requests originating from our site. It expires automatically after 24 hours of inactivity.
- No Third-Party Tracking: We do not use any third-party advertising or tracking cookies on sanctionlistcheck.com.
9. Your GDPR Data Protection Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right to Access: You have the right to request copies of your personal data.
- Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
- Right to Object to Processing: You have the right to object to our processing of your personal data, under certain conditions.
- Right to Data Portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month.
You also have the right to lodge a complaint with the Spanish data protection authority (Agencia Española de Protección de Datos, AEPD) or your own country's supervisory authority if you believe we have not handled your data appropriately.
10. Security Measures
We implement appropriate technical and organizational measures to protect your personal data. These include:
- Encrypted Storage: Uploaded files and generated reports are stored in encrypted storage.
- Private/Signed Access: Access to your files and reports is secured through private, signed URLs, ensuring only authorized users can retrieve them.
- Automatic Deletion: As stated, all uploaded files and reports are automatically deleted within 24 hours.
11. Important Disclaimers and Limitation of Liability
Please read these critical disclaimers carefully:
- The Sanction List Check product is a due-diligence screening AID. It is NOT a legal compliance certification and it is NOT legal advice.
- The product never states that a name or counterparty is "safe," "clear," or "approved." It only reports matches, possible matches, and no-match results against the screened lists, for the customer's own review.
- Every match or possible match is for human review by the customer. The customer is solely responsible for their own compliance decisions and for any action or inaction based on the report.
- Results are provided "as is," without warranty of completeness or accuracy.
- Known limitation: fuzzy matching can miss a true match when a name has more than one valid transliteration/romanization (e.g., from Cyrillic or Arabic script into Latin letters), because spellings can diverge beyond the matching thresholds.
- Miguel Casares Robles's total liability arising from the service is capped at the total fees actually paid by the customer for the relevant order/service in the 12 months before the claim.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will post any changes on this page and update the "Last Updated" date at the top of the page. We encourage you to review this Privacy Policy periodically.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
This Privacy Policy is governed by the laws of Spain.