VATFIND LEGAL
Data processing terms
Contract terms for personal data that VATFind processes on a business customer’s documented instructions.
Updated 8 September 2026
When these terms apply
These terms are available for incorporation into a signed VATFind order or data processing agreement between Global Data Intelligence Limited (“VATFind”) and the identified business customer (“Customer”). They take effect for that order when expressly incorporated by both parties. The applicable processing, security, subprocessor and transfer schedules must be completed for the customer’s workflow before that processing begins. Viewing this page does not execute an agreement.
For customer-directed personal data, the Customer is controller and VATFind is processor, or the Customer is processor acting with its controller’s authority and VATFind is subprocessor. VATFind acts separately as controller for its account administration, billing, fraud prevention, relationship management and any company-information processing for which it independently determines purposes. The privacy notice covers those activities; not every service provider or data supplier is a subprocessor.
“Data Protection Law” means the UK GDPR and Data Protection Act 2018, the EU GDPR where applicable, and other applicable privacy law. Terms such as personal data, processing and personal data breach have their statutory meaning. Mandatory transfer clauses prevail over inconsistent terms; these terms prevail over general service terms for their processing scope.
Processing schedule
| Subject and purpose | Operate the Customer’s instructed company lookup, evidence storage, scheduled company monitoring, API/MCP delivery, support and agreed data delivery workflow. |
|---|---|
| Operations and frequency | Receive, validate, retrieve, organise, store, compare, transmit, export, restrict and delete data; on request and at the monitoring cadence selected by the Customer. |
| Data subjects | Customer users and business contacts; people connected to companies submitted by the Customer, such as sole traders, directors, officers, shareholders and beneficial owners, to the extent included in the agreed service. |
| Personal data | Business identifiers that relate to an individual, name, business role or connection, relevant business address, Customer-supplied reference and necessary request or delivery metadata. The order must identify any additional fields. |
| Excluded data | Special-category data, criminal-offence records, children’s information and personal identity documents are outside ordinary processing unless specifically agreed with a lawful condition and suitable safeguards. |
| Duration | The ordered service term and the agreed return/deletion period, subject to a binding legal retention requirement. |
| Customer responsibilities | Determine the purpose, lawful basis, notices, lawful disclosure, accuracy and scope of instructions; manage authorised users and exported copies; verify that the service and safeguards suit the intended risk. |
The order identifies the Customer’s legal name, address, controller where different, privacy and incident contacts, selected service, processing locations, authorised subprocessors and any cross-border transfer instruments. Neither a provider’s marketing material nor this general schedule substitutes for those agreed particulars.
Instructions and confidentiality
VATFind will process the covered data only on documented lawful instructions, including the order and actions of authorised Customer users, and only for the agreed service. This includes instructions concerning transfers. If law requires other processing, VATFind will inform the Customer beforehand unless that law prohibits notice. VATFind will promptly tell the Customer if, in its opinion, an instruction infringes Data Protection Law and may suspend that instruction while the parties resolve it.
VATFind will ensure personnel authorised to process the data are bound by confidentiality or an appropriate statutory duty, and access is limited to what their role requires. Customer-directed personal data will not be used to train a general-purpose model, build an unrelated data product or support an independent marketing purpose under these processor instructions.
Security measures
Taking account of the processing, risks, state of the art and implementation cost, VATFind will maintain appropriate technical and organisational measures. The agreed security schedule will cover access permissions, authentication and credential handling, transmission protection, private storage, confidentiality, integrity, availability, incident response, restoration arrangements and regular assessment of control effectiveness.
The security page describes application controls currently visible in VATFind. Contractual assurances about hosting region, backups, recovery objectives, testing, certifications and supplier controls must be specified and supported in the agreed schedule. VATFind will not materially reduce the agreed protection during the processing term.
Subprocessors and changes
The Customer gives general written authorisation only to subprocessors identified in the agreed schedule. VATFind will impose written data protection duties that provide equivalent protection for the delegated processing and remains responsible to the Customer for the subprocessor’s performance of those duties.
VATFind will give at least 30 days’ advance written notice to the agreed contact before adding or replacing a subprocessor for covered processing. The Customer may object on reasonable documented data protection grounds within that period. The parties will seek a practical alternative. If none resolves the objection, the Customer may end the affected service before the new processing begins, with a refund of fees prepaid for the unused affected period. A general service-provider list is disclosure information and does not replace the agreed authorisation schedule.
Rights requests and compliance assistance
Taking account of the processing and information available, VATFind will help the Customer respond to individuals’ rights requests and meet its duties concerning security, breach notification, data protection impact assessments and prior regulatory consultation. VATFind will forward a request concerning Customer-controlled data without undue delay and will not respond substantively except on instructions or where law requires it.
VATFind will make information needed to demonstrate compliance with these processor duties available and allow and contribute to audits and inspections by the Customer or an independent auditor it appoints. The parties may agree reasonable confidentiality, scheduling and scope safeguards that protect other customers and service security; these must not prevent a legally required audit, urgent incident investigation or regulator access. Any separately chargeable assistance must be agreed in advance and cannot excuse a statutory obligation.
Personal data breaches
VATFind will notify the Customer without undue delay after becoming aware of a personal data breach affecting the covered data. As information becomes available, notice will describe the nature of the breach, affected data and people as far as known, likely consequences, contact point and measures taken or proposed. Information may be supplied in phases, with updates as the investigation proceeds.
VATFind will take reasonable steps to contain and remedy the incident, preserve relevant evidence and assist the Customer. The Customer determines its controller notifications; VATFind will not notify affected people on the Customer’s behalf without instructions unless required by law. A customer notice is not delayed until a full investigation is finished.
International transfers
VATFind will not initiate a restricted transfer of covered data without a valid legal mechanism and required assessment. The agreed schedule identifies the exporter, importer, countries, applicable roles, transfer mechanism and supplementary measures. Where necessary, the parties will execute the relevant EU Standard Contractual Clauses and UK Addendum or UK International Data Transfer Agreement with completed annexes before transfer.
This page does not by itself sign those instruments, select a module, establish adequacy or certify participation in a transfer framework. Hosting, support access and onward transfers all need to be considered. Notify VATFind before submitting data subject to a country restriction so the parties can establish a supported arrangement.
Return and deletion
At the Customer’s choice, VATFind will return or delete covered personal data after the relevant service ends and delete existing copies, unless applicable law requires retention. The order specifies the export format, handover period, deletion deadline and backup lifecycle. Retained data will be limited to the legal purpose and protected; backups awaiting expiry must remain isolated from ordinary use and be deleted through the agreed cycle. On request, VATFind will confirm completion and identify a legal-retention exception.
Independently controlled payment or security records follow the privacy notice and applicable law. Deleting search history alone does not constitute a complete account or processor-data deletion instruction.
Request an agreement
Send your legal entity name, service, countries, required fields, data protection role, residency restrictions and procurement requirements. VATFind will use these to complete the applicable schedules and identify any processing that requires a separate agreement.
For legal, privacy or support requests, click here with “VATFind” and the nature of your request in the subject, or use the support centre. Do not send passwords, API keys or full payment-card details.