PRIVACY & DATA USE
Privacy policy
Effective: 20 September 2026
Who operates the service
Sanction Search operates this website and the SanctionSearch application. For privacy questions or requests, email privacy@sanction-search.com.
Information we handle
Depending on how you use the service, we handle:
- account email, password hash, organisation, access role and session records;
- screening inputs, search activity, result snapshots, review decisions, case records and report references;
- CSV batch inputs and results;
- business contact details and messages submitted through an enquiry form;
- payment and subscription references when billing is enabled, while payment-card details are handled by the payment provider; and
- limited technical and security information needed to operate, protect and diagnose the service.
The service also retains published sanctions records with their source, publication and retrieval information so screening evidence can be understood later.
Why we use information
We use information to provide accounts and screening features, maintain an audit trail, secure and troubleshoot the service, respond to enquiries, deliver essential emails, administer subscriptions and meet applicable legal obligations. Optional analytics are used only after consent and can be withdrawn through Cookie preferences.
Depending on the context, our basis is providing the requested service, our legitimate interests in operating and securing it, consent, or compliance with a legal obligation. An organisation using SanctionSearch is responsible for determining whether it may submit personal information for screening and for responding to requests concerning its own screening records.
Providers and disclosures
We use infrastructure, database and email-delivery providers to operate the service. When enabled, we may also use payment, customer-relationship, analytics and error monitoring providers. They receive only the information needed for their function and act under their own terms and data-processing commitments. We may disclose information when required by law, to protect the service or its users, or as part of a properly managed business transfer.
Retention and security
Batch inputs and results expire after 30 days. Website enquiries are retained in the application for up to 30 days. Session, delivery and operational records have their own bounded retention periods. Screening evidence and review records are retained according to the customer organisation’s requirements and our documented operational policy.
We use access controls, encrypted transport, hashed credentials, tenant separation and operational monitoring. No online service can guarantee absolute security.
Cookies and analytics
A secure session cookie is necessary for signed-in use. Optional website and product analytics are disabled until permission is given. Screening names, search text, passwords, access tokens and session recordings are excluded from analytics. Use the Cookie preferences control in the footer to change your choice.
Your choices and rights
You may ask for access, correction, deletion, restriction or portability of personal information, or object to certain uses, where applicable. You may also withdraw consent. Contact your organisation administrator for organisation-controlled screening records, or email us at the address above. You may complain to the data-protection authority that applies where you live or work.
Changes
We may update this policy as the service or its providers change. The effective date at the top identifies the current published version.