Privacy Policy
How REGREP collects, uses and protects personal data, the legal bases we rely on, who we share data with and the rights you can exercise.
Section 1Who is responsible
REGREP, operated by REGTIFY LIMITED (HE355806, Apostolou Andrea 3A, Strovolos, Nicosia 2049, Cyprus), operated from Bockenheimer Landstraße 17–19, 60325 Frankfurt am Main, Germany, is the controller for personal data processed through this website and our platform, except where we act as a processor for customer filing data (see our GDPR statement). Company details are on our legal information page. For any privacy matter, contact [email protected].
Section 2Data we collect
We collect only what we need to run the service:
- Account data — name, work email, organisation and access details when you create or use an account.
- Enquiry and lead data — the details you submit through our request-access, demo and contact forms, plus the marketing attribution described in the advertising-measurement section.
- Filing and usage data — data you upload for conversion and validation, and operational logs about how the platform is used.
- Payment data — billing details processed by our payment provider; we do not store full card details.
- Site and device data — analytics and cookie data, subject to your consent.
Section 3Purposes and legal bases
Each form and feature has a defined purpose and legal basis. The main ones are:
| Purpose | Legal basis |
|---|---|
| Providing accounts and the platform | Performance of a contract |
| Responding to demo and contact enquiries | Steps prior to a contract; legitimate interests |
| Billing and record keeping | Contract; legal obligation |
| Security, fraud prevention and service improvement | Legitimate interests |
| Analytics, advertising measurement and marketing cookies | Consent |
| Marketing emails you sign up for | Consent, recorded separately from any gated-content download |
Where we rely on consent you can withdraw it at any time; where we rely on legitimate interests you can object.
Section 4Advertising measurement
When you submit a form, we create a lead record. Where your consent state and the applicable legal basis permit, we also store first-party advertising signals — click identifiers and landing and referrer information — against that lead so we can measure which campaigns generate genuine enquiries. This data is held server-side and is not placed in any public web address. If you have not given the relevant consent, these advertising signals are not stored.
Section 5Tax identification numbers
Tax identification numbers (TINs) are personal data. When you check or validate a TIN, it is processed in memory only to perform the structural check. We do not log it, store it, or pass it in any analytics parameter — in short, we don’t store what you check.
Section 6Cookies and consent
We use a consent management platform to obtain and record your cookie choices. Non-essential cookies — including analytics and advertising cookies — are set only after you consent, and a currency preference is remembered only once preference cookies are allowed. The full, current inventory of cookies is in the cookie declaration on our legal information page.
Section 7Subprocessors
We use a small number of vetted providers to run the service. Our EU data-residency commitment is scoped to customer regulatory filing data on the platform; supporting services may process limited operational data elsewhere, and each is disclosed here and in our subprocessor list:
| Provider | Purpose |
|---|---|
| Amazon Web Services | Platform hosting, compute and storage |
| Cloudflare | Hosting front end and content delivery |
| Stripe | Payments and billing |
| Google (Ads, Analytics) | Advertising measurement and site analytics (consent-based) |
| CookieYes | Consent management |
| Microsoft | Transactional and marketing email |
The current subprocessor list is maintained and available on request. The same register is reproduced in our data processing agreement.
Section 8Retention
We keep personal data only as long as needed for the purpose it was collected or as required by law. Account and billing records are kept for the life of the relationship and for at least six years from the end of the tax year to which they relate, as tax and company law require. Source files submitted for a run are deleted when the run completes; only the validation report is kept, for 30 days. Broken-link and error logs strip or hash query parameters and are retained for 90 days. After termination, customer data is read-only for 90 days and then deleted from live systems within a further 30 days. The complete schedule, including backup expiry, is set out in Section 12 of our data processing agreement and governs wherever another page states a period.
Section 9International transfers
Where a provider processes data outside the EEA, we rely on an approved transfer mechanism, such as the European Commission’s standard contractual clauses, together with additional safeguards where needed. Details of the mechanism for a given provider are available on request.
Section 10Your rights
You have the right to access, rectify, erase, restrict and port your personal data, to object to certain processing, and to withdraw consent. To make a request, email [email protected] or use our contact page; we will respond within the statutory time limit. Your rights are described more fully in our GDPR statement.
Section 11Security and breach contact
We protect personal data with encryption in transit and at rest, access controls and least-privilege roles, as described on our security page. If you need to report a security concern or a suspected data breach, contact [email protected].
Section 12Changes
We may update this policy. The “last updated” date at the top of this page shows when the current version took effect, and material changes will be notified where appropriate.
REGREP is an independent software provider. Nothing on this page is legal, tax or regulatory advice. Questions about this notice can be sent to [email protected] or via our contact page. See also our legal information, privacy policy, terms of service and GDPR statement.