REGULATEDREGULATORY INTELLIGENCE
DevelopersPrivacyTermsReturn home

Privacy and data protection

Privacy notice

How Regulated collects, uses, protects and retains information across our website, platform, APIs and regulatory-intelligence services.

Last updated 27 July 2026 · Version 2026-07

On this page

01Who we are02Information we process03Where information comes from04Why we use information05Risk scoring and human review06Who receives information07International transfers08Retention and deletion09Security10Your rights11Cookies and communications12Questions and complaints
01

Who we are

Regulated is a regulatory-intelligence product operated by InsurSystems Limited (company number 17254443), registered in England and Wales. Our registered office is 21 Bryn Eglur Road, Morriston, Swansea, SA6 7PG.

For account, website, billing and product-administration data, InsurSystems Limited is the controller. When a customer submits people or organisations for screening, the customer will normally be the controller and we act as its processor under a data-processing agreement. We may act as a controller for limited processing needed to secure, operate and evidence the service, and for information we independently obtain from public or regulatory sources.

Privacy enquiries and rights requests can be sent to [email protected].

02

Information we process

Depending on how you use Regulated, we may process:

  • Account and identity data, including name, work email, organisation, role, authentication records and security settings.
  • Customer and commercial data, including plans, entitlements, API keys, usage, invoices, payments, credits, disputes and support communications.
  • Screening data about companies, directors, officers, beneficial owners and other individuals, such as names, aliases, month and year of birth where available, nationality, appointments, ownership, regulatory status, sanctions or PEP indicators and adverse-media references.
  • Investigation material, including cases, alerts, evidence snapshots, decisions, notes, tasks, reviewer information and audit events.
  • Technical data, including IP address, device and browser information, session identifiers, request logs, correlation IDs, webhook deliveries and security events.

We do not need customers to provide more personal information than is necessary for a lawful compliance purpose. Full dates of birth should not be entered unless required and appropriately protected.

03

Where information comes from

Information may come directly from account holders and customer systems, or from connected public, regulatory and commercial sources. These can include Companies House, the FCA Register, UK and international sanctions lists, PEP datasets, official notices, court or insolvency records, news sources and contracted data providers.

We record source, retrieval time, dataset version and evidence provenance where the service supports it. Public-source information can be incomplete, delayed or inaccurate; customers must investigate material results before acting.

04

Why we use information

We use personal information to provide identity, sanctions, PEP, regulatory, ownership, financial-risk and adverse-media screening; monitor changes; generate alerts and certificates; support investigations; operate APIs and webhooks; administer subscriptions and billing; prevent misuse; maintain security and auditability; meet legal obligations; and improve service reliability.

Our lawful bases may include performance of a contract, compliance with a legal obligation, legitimate interests in providing secure compliance and fraud-prevention services, and recognised legitimate interests where applicable. Customers are responsible for identifying and documenting their own lawful basis and any additional condition required for special-category or criminal-offence data.

05

Risk scoring and human review

Regulated uses rules, matching, confidence scores and risk indicators to prioritise possible matches and material changes. These outputs are investigative signals, not findings of wrongdoing.

Regulated is designed for human review. We do not intend to make solely automated decisions about individuals that produce legal or similarly significant effects. Customers must assess source evidence, identity resolution, context and proportionality before making a decision.

06

Who receives information

Information may be shared with authorised users of the relevant tenant; infrastructure, security, communications, analytics and data providers acting under contract; payment providers such as Stripe for billing; professional advisers; and public authorities where lawfully required.

We do not sell personal information. Tenant data is separated through access controls and tenant-scoped application rules. Customers control their users, roles, integrations and onward disclosure.

07

International transfers

Some providers or datasets may involve processing outside the UK. Where required, we use an applicable UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful safeguard. Details of relevant safeguards can be requested from us.

08

Retention and deletion

We retain information only for as long as needed for the relevant purpose, customer configuration, contractual requirement, audit need or legal obligation. Retention can differ for account records, screening evidence, cases, billing records, security logs and backups.

Customers can configure permitted retention periods for tenant records. On termination, data is returned or deleted in accordance with the contract and data-processing agreement, subject to legal holds, immutable accounting records, security evidence and time-limited backup cycles.

09

Security

We use controls including tenant isolation, role-based access, encryption in transit, credential hashing, MFA controls, audit logs, monitoring, backups, provider-health checks and incident procedures. No online service can guarantee absolute security, and customers must protect credentials, rotate API keys and promptly report suspected compromise.

10

Your rights

Depending on the circumstances, you may have rights to access, correct or erase personal information, restrict processing, receive portable data, and object to processing. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing.

Your right to object

You may object to processing based on legitimate interests. You may always object to direct marketing. We will assess objections in light of the applicable law and any compelling lawful grounds.

If a Regulated customer controls the information, we may direct your request to that customer and assist it as processor. We may need to verify your identity and protect information relating to other people.

11

Cookies and communications

We use essential cookies or similar storage for authentication, security, preferences and service operation. We will request consent before using non-essential analytics or advertising cookies where required. Operational messages about accounts, security, monitoring or billing are not marketing.

12

Questions and complaints

Please contact [email protected] first so we can investigate. You may also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or by telephone on 0303 123 1113.

We may update this notice when our services, providers or legal obligations change. Material changes will be brought to account holders’ attention where appropriate.

© 2026 Regulated

Regulated is a trading style of InsurSystems Limited.

Registered in England and Wales · Company no. 17254443

Registered office: 21 Bryn Eglur Road, Morriston, Swansea, SA6 7PG.