Privacy Policy
Last updated: 25 July 2026
Who we are
Rotuli is operated by Innovaduck Ltd, a company registered in England and Wales (company no. 16016584). Innovaduck Ltd is the data controller for the processing described in this policy.
This policy covers the Rotuli website (rotuli.co.uk), the Rotuli API, and the Rotuli MCP interface, which exposes the same data as the API to AI agents.
For anything privacy-related, contact us at privacy@rotuli.co.uk.
This policy has two parts. Part A is for people who use Rotuli — visitors to this website and holders of API accounts. Part B is for people who appear in the public-register data our product aggregates — for example, persons with significant control of UK companies — who may never have visited this site.
Part A — Customers and site visitors
What we collect
- Account data — your name, your email address, and a hashed version of your password (bcrypt), plus your organisation if you choose to give it. We never store your password in plain text. Email verification tokens are also stored hashed.
- API key data — a name, tier, and last-used timestamp for each key. Keys themselves are stored only as SHA-256 hashes and are shown to you once, at creation.
- Billing data — references to your Stripe customer and subscription records. Payment card details are collected and held by Stripe, never by us.
- Usage data — request counts against your API key for rate limiting and billing, and an access record of API requests (the key used, the time, the endpoint, and the originating IP address) which we are required to retain under our HM Land Registry data licence.
- Technical data — IP addresses and request metadata processed by our hosting providers to serve and secure the service.
Purposes and lawful bases
- Creating and operating your account, provisioning API keys, and providing the service — performance of a contract.
- Billing and subscription management via Stripe — performance of a contract.
- Transactional email (email verification, payment failure and subscription notices) — performance of a contract and our legitimate interests in administering the service.
- Security, fraud prevention, and rate limiting — our legitimate interests in protecting the service and the upstream registries it depends on.
- Keeping a record of who uses the service — your name, contact details, and the IP addresses your API requests come from. HM Land Registry requires this of us as a condition of the licence under which we use their corporate land-ownership data, so that misuse can be traced and our compliance with that licence audited. Our legal obligation and our legitimate interests in holding a licence to that data. This is why a name is required when you create an account.
We do not send marketing email, we do not use analytics or tracking technologies on this site (see the Cookies Policy), we do not profile our customers, and we do not sell personal data.
Part B — Public-register data about UK companies
Rotuli aggregates data about UK companies from official public registers into a single profile, with machine-readable risk signals, for business customers performing due diligence and know-your-business (KYB) checks. Some of that register data relates to identifiable people. This section is the notice required by Article 14 UK GDPR for those people, because we obtain the data from public registers rather than from them directly.
Where the data comes from
- Companies House — company profiles and the register of persons with significant control (PSC).
- The Insolvency Service (via Companies House) — corporate insolvency case records.
- HM Land Registry — the UK Companies that Own Property dataset (CCOD), which records corporate ownership of land titles in England and Wales.
See Data sources for licensing and attribution details.
What personal data this includes
- Persons with significant control — name, nationality, country of residence, the nature of their control, and the date it was notified. We deliberately do not process dates of birth at all, even though Companies House publishes the month and year.
- Land-title proprietors— proprietor names as they appear in the CCOD dataset. HM Land Registry compiles that dataset from corporate proprietors only — companies, LLPs, local authorities, housing associations and similar bodies — and excludes private individuals from it, so these names are company names rather than people's names. They are held internally for data-quality purposes and are not published through the API. Property addresses are reduced to postcode only.
Why, and on what basis
We process this data in our legitimate interests, and those of our customers, in making official UK public-register data usable for due diligence, fraud prevention, and regulatory-compliance checks. The data is already public by law; we aggregate and normalise it. We minimise what we take (no dates of birth, postcode-only addresses), and our copies refresh automatically from the source registers, so corrections made at the registers propagate to us.
Customers who retrieve register data through the API act as independent data controllers of their own use of it.
How long we keep it
Register data is cached for short periods — between 4 hours and 7 days depending on the source — and then expires and is re-fetched. Our copy of the CCOD land-ownership dataset is refreshed against HM Land Registry's monthly files, including removals.
Recipients and processors
- Hetzner Online GmbH (Germany) — hosts the Rotuli API, its database, and its cache.
- Cloudflare, Inc. — hosts this website and its account database, and serves traffic through its global edge network.
- Stripe — payment processing and billing.
- Resend — delivery of transactional email.
- HM Land Registry — not a processor, but entitled under our data licence to inspect our records of who uses the service, for the purpose of auditing our compliance with that licence or of preventing or detecting crime.
Each provider processes personal data under a data processing agreement with us.
International transfers
Register data and API account records are stored in Germany (Hetzner). Website traffic and account data pass through Cloudflare's global edge network, and Stripe and Resend operate partly from the United States; in each case transfers outside the UK are protected by the provider's data processing agreement incorporating standard contractual clauses / the UK Addendum, or an applicable adequacy arrangement.
Retention (summary)
- Register-data caches: 4 hours to 7 days, self-expiring; CCOD land data refreshed monthly.
- Account and billing data: kept while your account is active, deleted on verified request when no longer needed for legal or accounting obligations.
- API access records held under our HM Land Registry licence: kept for as long as we hold that licence and for twelve months after it ends, which is the period over which HM Land Registry may audit them.
- Operational logs: kept for a short period for security and troubleshooting, then deleted.
Your rights
You have the right to access, rectify, and erase personal data we hold about you, to restrict or object to our processing of it, and to data portability. To exercise any of these, email privacy@rotuli.co.uk. We respond within one month.
One limit is worth stating plainly: while you hold an account we cannot erase your name or your API access records, because HM Land Registry requires us to keep them as a condition of our data licence. Closing your account ends that requirement, subject to the retention period above.
If your data appears in Rotuli because it appears in a public register (Part B), the most effective correction route is usually the register itself — Companies House or HM Land Registry — because our copies refresh from the registers automatically. We will still act on requests about the data we hold.
You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Security
All traffic is encrypted in transit (TLS). Passwords are hashed with bcrypt; API keys are high-entropy random tokens stored only as SHA-256 hashes; session cookies are httpOnly and secure. We hold no payment card data.
Changes to this policy
We will update this page when our processing changes and revise the "last updated" date above. Significant changes affecting account holders will be notified by email.