Privacy policy.

Last updated: 13 August 2026

EntityWatch is operated by AddonNordic ApS, CVR 46495985, Denmark. We are the data controller for this website and for your account with us. For the registry data you monitor, you are the controller and we are the processor — that relationship is set out in the data processing agreement.

Contact for any privacy question: contact@addonnordic.dk.

This website sets no cookies

There is no analytics on entitywatch.app. No Google Analytics, no advertising pixels, no session recording, no third-party fonts or scripts of any kind. We do not set cookies on visitors, which is why you were not asked to accept any.

Our web host keeps standard server logs, which include IP addresses, for security and troubleshooting. We do not build profiles from them and we do not combine them with anything else.

What we collect, and why

If you write to us

The contact form sends us your name, email address, company and message. It is emailed to us and not stored on this website — there is no database of enquiries here to leak or to be asked for. We keep the email for as long as the conversation is useful and delete it after. Lawful basis: legitimate interests in answering the person who wrote to us.

If you create an account

We store your email address, your plan, and your usage against it. Your password is held by our authentication provider and we never see it. Lawful basis: performance of the contract with you. For paid plans we also process billing details and VAT number, which we are required to keep for accounting purposes under Danish law.

The registry data you monitor

When you add a company, we retrieve what its national business register publishes about it. That includes named individuals — directors, and beneficial owners where a register makes them available — so it is personal data even though it is public. We process it on your instructions, as your processor, to enable your due diligence and anti-money-laundering obligations.

We do not enrich this data with anything else, do not sell it, do not use it to train models, and do not use it to build profiles of individuals. Where a register restricts access, we respect the restriction rather than looking for a way around it.

Where it goes

We use a small number of service providers to run EntityWatch — hosting, database, authentication and payment. Each one is named at /subprocessors with what it does and where it processes data. That list is authoritative and we update it before a change takes effect.

We do not sell personal data, and we do not share it with anyone for their own purposes.

Your rights

Under the GDPR you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, object to processing based on legitimate interests, and ask us to restrict processing. Write to contact@addonnordic.dk and we will respond within one month.

If your request concerns registry data that one of our customers monitors, we will pass it to that customer, who is the controller for that processing, and assist them in answering you.

You can also complain to a supervisory authority. In Denmark that is Datatilsynet, datatilsynet.dk.

Changes to this policy

If we change this policy in a way that affects you, we will say so — by email for account holders, and by updating the date at the top of this page. We do not quietly revise it and rely on you re-reading it.