corween Business Partner Monitoring
Why Us Scenarios Pricing Cases Blog
English Deutsch Česky Polski Slovensky
Why Us Scenarios Pricing Cases Blog
English Deutsch Česky Polski Slovensky
Privacy Policy

Privacy Policy

This notice explains how corween processes personal data in connection with our website and business monitoring and risk intelligence service. It applies to users of corween as well as individuals whose information may be processed as part of company monitoring, due diligence, sanctions screening or other supported monitoring activities.

Last updated: 11 August 2026

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws. This notice is designed to be clear and transparent about what we do with personal data.

Information for monitored individuals

This section is for individuals whose personal data may be processed by corween even if they do not use our service.

You may appear in corween even if you do not have a corween account. This may occur where you are associated with a monitored business or where a customer has selected you for monitoring or screening for a legitimate business, compliance, due diligence or risk management purpose.

We may process identifying information such as your name, date of birth or other identifiers, together with information obtained from public registers, sanctions lists, watchlists and other supported sources, including potential match results and reported changes.

These data may be provided by our customers, obtained from official or publicly accessible sources, or generated through automated matching and monitoring processes within our service.

We process this information to provide business monitoring, due diligence, sanctions screening and risk intelligence services to our customers, to detect and report relevant changes, and to support compliance and risk management activities carried out by our customers in connection with their business relationships.

We retain this information while it remains relevant to an active monitoring relationship and, where appropriate, for a limited period afterwards to maintain monitoring history, demonstrate the source and timing of reported events and handle disputes or data accuracy requests.

Personal data may be shared with our customers who initiated or are associated with the relevant monitoring activity, as well as with service providers who help us operate the service, as described in the section on Sharing and subprocessors below.

If you believe your personal data is processed by corween, you may have the rights described in the "Your rights" section below, including the right to access, rectification, erasure, restriction, objection and to lodge a complaint with a supervisory authority. To exercise these rights, contact us at [email protected].

What personal data we process

Depending on how you use corween, we may process the following categories of personal data:

Account data

Name, email address, company name, job role and other authentication or account information needed to create and manage your user account.

Billing data

Company details, billing address, VAT number and subscription or payment information related to your plan.

Technical data

IP address, browser and device information, timestamps, security logs and access logs generated when you use our website or application.

Support and communication data

Support requests, emails and other communication you send to us, including any information you choose to include.

Customer-provided data

Subjects, contracts, contact persons and other data that you or your organisation import or submit through the user interface, CSV import, API, CRM integration, AI integration or MCP integration.

Public-source data

Information obtained from business registers, insolvency registers, court publications and other official or publicly accessible sources as part of business monitoring.

Monitored individual data

Where customers use features for monitoring or screening individuals, we may process identifying information such as name, date of birth or other identifiers provided by the customer or obtained from supported public or official sources. We may compare these identifiers with sanctions lists, business registers and other supported compliance or business information sources and process information about potential matches and relevant changes.

Why we process personal data

We process personal data for the following purposes and on the legal bases indicated:

  • Providing and operating the corween service — performance of a contract (Art. 6(1)(b) GDPR)
  • Creating and managing user accounts — performance of a contract (Art. 6(1)(b) GDPR)
  • Monitoring companies and other business entities selected by customers — performance of a contract (Art. 6(1)(b) GDPR)
  • Detecting and reporting changes in public records — performance of a contract and, where applicable, legitimate interests in providing business monitoring services (Art. 6(1)(b) and (f) GDPR)
  • Sending alerts, notifications and reports — performance of a contract (Art. 6(1)(b) GDPR)
  • Processing subscriptions and payments — performance of a contract and compliance with legal obligations, including accounting and tax requirements (Art. 6(1)(b) and (c) GDPR)
  • Providing customer support — performance of a contract and legitimate interests in responding to enquiries (Art. 6(1)(b) and (f) GDPR)
  • Maintaining security, preventing abuse and protecting our systems — legitimate interests (Art. 6(1)(f) GDPR)
  • Complying with legal obligations — legal obligation (Art. 6(1)(c) GDPR)
  • Monitoring and screening individuals for business due diligence, sanctions compliance and risk management — legitimate interests pursued by corween and our customers in identifying compliance, legal and business risks associated with persons relevant to their business relationships (Art. 6(1)(f) GDPR)

Public registers and publicly available information

corween may process names of directors, statutory representatives, shareholders or other persons associated with monitored entities, where such information is available from official or publicly accessible sources.

These data may come from business registers, insolvency registers, court publications and similar official sources across the countries we monitor.

corween processes publicly available information to provide business monitoring, due diligence and risk intelligence services to its customers.

The legal basis for this processing is typically our legitimate interests in providing supplier monitoring and risk intelligence services, balanced against the rights of data subjects. Where required, we also rely on performance of a contract with our customers.

Customer data and our role as processor

When customers submit personal data to corween as part of their use of the service — for example, contact persons linked to monitored suppliers — the customer generally acts as the data controller and corween acts as a data processor on the customers behalf, processing data according to the customers instructions.

This processor relationship is governed by a separate Data Processing Agreement (DPA), available on request or as part of enterprise onboarding. The same organisation may act as controller in one context and processor in another; this notice describes both roles where relevant.

Sharing and subprocessors

We do not sell personal data. We may share personal data with the following categories of recipients where necessary to operate the service:

  • Hosting and infrastructure providers
  • Email delivery providers
  • Payment providers
  • Monitoring and error reporting providers
  • Customer support infrastructure

A current list of subprocessors is available on request. We require subprocessors to protect personal data under appropriate contractual obligations.

International transfers

We store and process personal data exclusively within the European Union / European Economic Area. We do not transfer personal data outside the EEA.

Data retention

We retain personal data only for as long as necessary for the purposes described in this notice, or as required by law. Retention periods depend on the type of data:

  • Account data — for the duration of the account and for a defined period thereafter to handle disputes, enforce terms or comply with legal obligations.
  • Billing records — in accordance with applicable accounting, tax and commercial laws.
  • Security and access logs — typically up to 90 days, unless a longer period is required for security investigations or legal compliance.
  • Customer-provided data — until deleted by the customer or, after termination of the service, in accordance with the Data Processing Agreement and applicable law.
  • Monitoring and public-source data — retained while relevant to an active monitoring relationship and, where appropriate, for a limited period afterwards to maintain monitoring history, demonstrate the source and timing of reported events and handle disputes or data accuracy requests.

Your rights

Under GDPR, you may have the following rights in relation to your personal data, depending on the circumstances:

  • Right of access — to obtain confirmation as to whether we process your data and to receive a copy
  • Right to rectification — to have inaccurate personal data corrected
  • Right to erasure — to request deletion of your data in certain circumstances
  • Right to restriction of processing — to request that we limit how we use your data
  • Right to data portability — to receive your data in a structured, commonly used format where applicable
  • Right to object — to object to processing based on legitimate interests
  • Right to withdraw consent — where processing is based on consent, without affecting the lawfulness of processing before withdrawal
  • Right to lodge a complaint with a supervisory authority

If you are in Slovakia, you may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR, www.dataprotection.gov.sk). You may also contact the supervisory authority in your country of residence or workplace.

To exercise your rights, contact us at [email protected]. We will respond within the time limits required by GDPR, generally within one month.

Automated processing and risk indicators

corween automatically analyses changes in public records and may assign severity levels or risk indicators to detected events — for example, flagging an insolvency filing as critical or a director change as high severity. This may include automated matching against sanctions or other supported compliance lists. Such matching may produce potential matches that require verification. This supports alerting and reporting for our customers. These classifications are operational risk indicators for business monitoring purposes; corween does not determine whether an individual is legally subject to sanctions and does not make legal or similarly significant decisions about individuals within the meaning of Article 22 GDPR.

Cookies and analytics

corween is designed with privacy in mind. We do not use advertising trackers or third-party advertising cookies on our website.

We do not use marketing or behavioural advertising cookies. Our public website does not rely on third-party analytics trackers for advertising purposes.

We may use strictly necessary cookies or similar technologies required for login, session management, security and the proper functioning of the application. These are essential for providing the service and are not used for advertising or cross-site tracking.

Changes to this notice

We may update this Privacy Policy from time to time. We will publish the updated version on this page and adjust the "Last updated" date. Where changes are material, we will provide additional notice where appropriate.

Contact

For questions about this Privacy Policy or our processing of personal data, contact [email protected].

corween

Real-time supplier monitoring across Central & Eastern Europe — AT, BG, CZ, EE, GR, HR, HU, LT, LV, PL, RO, SK, and UA.

AustriaBulgariaCzechiaEstoniaGreeceCroatiaHungaryLithuaniaLatviaPolandRomaniaSlovakiaUkraine

Product

Monitoring Scenarios Pricing Case Studies Countries Datasets

Company

About Us Blog Careers Contact

Support

CRM integration AI Integration MCP documentation API Documentation Custom webhook Status

Legal

Terms of Service Privacy Policy

© 2026 corween. All rights reserved.

We're cookieless :)