Security and data protection.
EntityWatch is operated by AddonNordic ApS, a Danish company registered under CVR 46495985. Your monitoring data and your account are processed and stored inside the EU. The one exception is email delivery, and we say so rather than rounding it off: our email provider sends from Ireland but keeps its logs in the United States, under standard contractual clauses. It is listed at /subprocessors like everything else.
The data we hold is public registry information about companies, plus your own account details — we do not ingest your customer database, and we do not ask you to upload one.
This page is written for the person who has to approve a supplier. It says what we do, and it names the things we have deliberately not claimed.
What we store
Three things, and nothing else:
- The list of companies you monitor — country and registration number, plus a label if you set one.
- What the registers published about them — status, officers, addresses, ownership where available, and the screening results, each with the date it was recorded and a link to the source.
- Your account — the email address you sign in with, your plan, and your usage against it.
Company officers are named people, so registry data is personal data even though it is public. We treat it that way rather than pretending that “it was already public” settles the question.
Where it runs
The application and its database run in the EU. EntityWatch keeps its own database rather than sharing one with our other products, so your monitoring data is not co-mingled with another service’s tenants.
Registry lookups are made server-side. The credentials that reach the upstream registries exist only on our backend — they are never present in the browser, in a mobile app, or in any client bundle. There is exactly one code path that talks to the upstream data service, which is what makes that statement checkable rather than aspirational.
Access and authentication
You sign in with an email address and password held by our authentication provider; we never see or store your password. Every request to the API carries your session token, and the account it resolves to determines which data you can read. An account can only ever see its own monitored companies — the check is applied on the server for every request, not chosen by the client.
Lawful basis
Our position, stated plainly so you can assess it rather than take it on trust: we process public registry data — including the names of company officers and, where a register makes it available, beneficial owners — on the basis of legitimate interests, namely enabling businesses to meet their due-diligence and anti-money-laundering obligations. That is the same basis on which the registers themselves publish the information.
Where a register restricts access — as the beneficial ownership registers in Ireland, the Netherlands and Germany now do — we do not seek a way around it. We publish those gaps on the coverage page instead.
You act as controller for the companies you choose to monitor; we act as processor for that activity. A data processing agreement is available at /dpa.
Subprocessors
We use a small number of third parties to run the service — hosting, database, authentication, payment and email. Each one is listed at /subprocessors with what it does and where it processes data. That page is the authoritative list; if it is not on that page, it does not touch your data.
What we do not claim
Security pages usually list certifications. Ours does not, because we do not hold any, and a page that implies otherwise is the first thing a serious reviewer catches.
- No ISO 27001 or SOC 2. We are a small company and have not been audited against either.
- No uptime guarantee. We do not publish an availability figure we have not measured over a meaningful period, and we do not offer an SLA today.
- No penetration test to show you. When there is one, it will be named here with its date.
If your procurement process requires any of these, tell us before you buy rather than after. We would rather lose the deal honestly than pass a questionnaire we should have failed.
Reporting a vulnerability
Write to contact@addonnordic.dk with enough detail to reproduce the issue. A person reads it. We will confirm receipt, tell you what we found, and let you know when it is fixed. We do not run a bounty programme and we will not threaten you for reporting something in good faith.
Getting your data out, or deleted
Your monitoring history exports from the product at any time, with the source links intact — that is a core feature, not a retention lever. If you close your account, write to us and we will delete your account data. Note that an audit trail you have already exported is yours; the copy we hold is what gets deleted.
Questions from procurement.
Where is our data processed?
In the EU. EntityWatch is operated by AddonNordic ApS, a Danish company registered under CVR 46495985, and the application and its database run on EU infrastructure.
Do you have ISO 27001 or SOC 2?
No. We hold no security certifications and do not imply otherwise. If your process requires one, we are not a fit yet, and it is better for both of us to know that early.
Are we the controller or the processor?
You are the controller for the companies you choose to monitor; we act as processor for that activity. A data processing agreement is available at /dpa.
Who are your subprocessors?
They are listed at /subprocessors, with what each one does and where it processes data. That list is authoritative — nothing outside it touches your data.
Does EntityWatch see our customer database?
No. You add the companies you want monitored, by registration number or name. There is no import of your CRM, your ledger or your contact records, and we do not ask for one.
Can we get an export if we leave?
Yes, at any time and without asking us — the audit trail export is a product feature, not something withheld as leverage at renewal.