Legal

Privacy Policy

Last updated 4 October 2026

Who we are

DataSteak is a trading name of Digevo Limited, a company registered in England and Wales under number 16415485, with its registered office at Flat 104 Peninsula Apartments, 4 Praed Street, London, England, W2 1JE.

We are the data controller for the personal information described in this policy. For anything relating to privacy or your personal data, contact privacy@datasteak.co.uk.

We are registered with the Information Commissioner's Office under registration number ZC233969.

What we collect

When you contact us

Our contact form asks for your name, email address and message, and optionally your company name. We also record which category of enquiry you selected. This is stored in our database and sent to our own mailbox.

We do not record your IP address or place any tracking identifier on the form.

When you create an account

Registration asks for your name, email address and a password. The password is stored only as a hash, which means we cannot read it and nobody here can tell you what it is. You may also add company details later in your account settings - company name, company number, sector, VAT number and address - which we use on invoices and to understand who our customers are. Those are optional and you can leave them blank.

Registration includes an optional tick box asking whether you want occasional email about new datasets. It is off unless you tick it, and it has nothing to do with whether you can buy or download.

When you buy a dataset

We store your email address, an order reference, which product you bought, the amount paid, the licence type, a download token and the time of purchase. We also record that you agreed to immediate delivery and which version of the terms applied, because that is what waives the 14-day cancellation right.

Checkout asks for your name and billing address, because a business reclaiming VAT needs them on the invoice. Those are collected and held by Stripe and printed on your invoice; they are not stored in our own database.

We never see or store your card details. Payments are handled by Stripe, who process your payment information as a separate controller under their own privacy policy.

When someone invites you to an account

An account owner can invite colleagues by email address. If someone invites you, we hold that email address and the invitation's status so we can send the invitation and let you accept it. You will not have given us that address yourself, and if you would rather we did not hold it, reply to the invitation email or write to privacy@datasteak.co.uk and we will delete it.

When you use your account

Signed in, a few things you do are stored against your account so the account can do its job:

  • Favourites and alerts - which datasets you have saved, and which you have asked to be told about when they refresh. This tells us which datasets a given person is interested in, so we are naming it rather than leaving it implied.
  • Support messages - the subject, category and content of anything you send us through support, so we can answer it and refer back to it.
  • API keys - if you use the API, we store a name for each key and a SHA-256 hash of the key itself. We cannot recover a key once issued, which is why a lost key is replaced rather than looked up.
  • Password resets - when you ask for a reset we store a single-use token against your email address until it is used or expires.

Automatically

Our web server keeps a log of the requests it serves. These logs are ours, on our own server, rather than something our host holds on our behalf. Each request writes one line, which records the IP address it came from, the date and time, what was requested, the response code, how many bytes were sent, the page you arrived from if your browser sent one, and the browser and operating system your browser identifies itself as.

We use them to keep the site secure and to work out what has gone wrong when something breaks. We do not use them to build a profile of you, we do not connect them to your account, and we do not share them.

Each day's log is kept for fourteen days and then deleted automatically, so nothing in them is ever more than fifteen days old.

Separately, we keep our own record of sign-in and password-reset attempts so that nobody can hammer those forms. That record holds a salted one-way hash of the IP address or email address involved, never the address itself, together with the time and the kind of attempt. The hash cannot be reversed to recover the address; it only lets us recognise that the same source is trying repeatedly.

Why, and our lawful basis

WhatWhyLawful basis
Contact form detailsTo answer your enquiry, and to understand what data people are asking for so we know what to buildLegitimate interests
Order detailsTo deliver what you bought, provide your download and keep proper accounting recordsContract, and legal obligation for the accounting part
Account detailsTo let you sign in, see your purchases and re-download what you boughtContract
Email preferenceTo send occasional email about new datasets, only if you asked for itConsent, which you can withdraw at any time
InvitationsTo let an account owner add colleagues, and to let the invited person acceptLegitimate interests, being the owner's in running their account and yours in being able to use it
Favourites and alertsTo show you what you saved and tell you when a dataset you follow refreshesContract
Support messagesTo answer you and keep a record of what was asked and agreedContract, and legitimate interests
API keysTo authenticate API requests and let you manage your own keysContract
Password reset tokensTo let you set a new password without us ever knowing the old oneContract
Hashed sign-in and reset attemptsTo rate limit those forms so they cannot be attackedLegitimate interests, specifically the security of your account
Server logsSecurity and troubleshootingLegitimate interests

Email we send

Email about your order is part of the service, not marketing. Receipts, download links, invoices, password resets and replies to your enquiries are sent because you bought something or asked us something, and they are not affected by any preference setting. Turning email off does not stop your receipt arriving.

Anything else only happens if you asked for it. We send occasional email about new datasets only to people who ticked the box at registration. Every one of those carries an unsubscribe link that works in one click, with no need to sign in, and you can change the setting yourself in your account at any time.

We do not sell, rent or share your contact details with anyone for their own marketing, and we never send email on behalf of anyone who has bought data from us. Buyers download a file and do their own sending; none of it goes through us.

If your address permanently rejects our mail, or you report it as spam, we add it to a suppression list and stop sending to it entirely.

How long we keep it

  • Enquiries - kept for up to 24 months, then deleted, unless the enquiry became an order or an ongoing conversation.
  • Order records - kept for six years from the end of the accounting period they fall in, to meet UK tax and accounting requirements.
  • Account records - kept while the account exists. Ask us to close it and we delete it, except where an order attached to it still falls inside the six years above.
  • Invitations - kept while the invitation is open. Once it is accepted the person has an account of their own; if it is declined, withdrawn or left to expire, the address is deleted with it.
  • Favourites, alerts and API keys - kept while the account exists, and deleted with it. You can remove any of them yourself at any time.
  • Support messages - kept while the account exists, because the history of what was asked and answered is usually the point.
  • Password reset tokens - single use, and dead once used or expired.
  • Hashed sign-in and reset attempts - short-lived, kept only as long as the rate-limit window they serve.
  • Suppression list - kept indefinitely, because its entire purpose is to remember not to email an address. It holds the address and nothing else.
  • Copies of emails we send - held by our email provider for 30 days, then deleted.
  • Server logs - each day's log is kept for fourteen days and then deleted automatically. Nothing in them is ever more than fifteen days old.

Where a period above ends in deletion, it means the record is removed once it is no longer needed for the reason it was collected. If you want to know what we still hold about you, ask, and we will tell you.

Who we share it with

We use a small number of service providers to run the site. They act on our instructions and cannot use your data for their own purposes.

  • Hostinger - website hosting and the database
  • Resend - sending our emails (receipts, download links, password resets, verification and invitations)
  • Microsoft - our mailboxes, through Microsoft 365
  • Stripe - payment processing, as a separate controller

Resend sends our email from Ireland but stores it in the United States: the recipient address, subject and content of each email, including any links in it, plus delivery records. That is a transfer of personal data outside the UK. It is covered by the UK Extension to the EU-US Data Privacy Framework, in which Resend participates, and by the International Data Transfer Addendum to the EU Standard Contractual Clauses in Resend's data processing agreement.

We do not sell your personal information. We may disclose information where we are legally required to.

Personal data in our products

This section is for people named in data we publish, rather than for our customers.

We build datasets from public registers and other lawfully obtained sources. We clean and structure that information, and we combine sources where doing so produces something more useful. Some of it relates to identifiable people, for example company officers and registered office addresses, and a registered office is sometimes a person's home address.

Where we combine or enrich data, we do it to make business information more complete and more accurate. We do not set out to build profiles of individuals, and we do not infer anything about anyone's private life.

We publish information as recorded at its source on a stated date. We do not warrant the accuracy of the underlying registers, which remains a matter for the bodies that maintain them.

We assess every source before it becomes a product, including its licence terms and whether it carries personal data. A source is only published where we are satisfied that doing so is lawful.

If you believe information we publish about you should not be published, or is being used unfairly, contact privacy@datasteak.co.uk and we will review it. Where a source record itself is wrong, it needs correcting at the source, because our copy is refreshed from theirs.

Cookies

Strictly necessary, and at present the only kind

This site sets one cookie. It is a session cookie, and it appears when you do something that needs the site to remember you for the length of your visit: signing in, using the contact form, or starting a checkout. It holds a session identifier and nothing else, it carries no tracking identifier, and it is gone when you sign out or close your browser. Cookies in this group make the site work and cannot be turned off, and no consent is required for them.

Analytics and your choice

Since 4 October 2026 this site keeps its own record of how it is used. We built it for one reason: to find out what people come here looking for and cannot find, so we know which datasets to build next. A search that returns nothing is the single most useful thing this site can learn, and nobody can tell us in six months what somebody typed into the search box today.

What is recorded

When you search or browse the marketplace we record the search term, any filters you chose, how many results came back, which page you were on, and the website that sent you here, if any. We also record which products are viewed and which parts of a product page are opened.

The two cookies, and the switch that turns them off

Two cookies make those records countable rather than a pile of disconnected lines. One lasts up to a year and lets us tell a returning visitor from a new one. The other lasts thirty minutes and groups one visit together, so we can see that a search led to a product page rather than guessing. Both are random identifiers generated here. Neither is derived from your IP address or your browser's characteristics, which means clearing your cookies genuinely resets them.

There is a switch in the footer of every page, marked Usage analytics. Turn it off and both cookies are deleted immediately, no new identifier is created, and nothing further is tied to you. We still count that a search happened, because a bare count with no identifier is not information about you and is what keeps the catalogue honest, but it is not connected to you or to anything else you do here.

Our lawful basis, plainly

UK cookie rules allow a site to store an identifier without asking first when the only purpose is working out how the site is used in order to improve it, provided there is a simple way to object. That exception came into force on 5 February 2026. The footer switch is the way to object, and the purpose above is the only purpose these records have. For the data protection side we rely on legitimate interests: understanding our own catalogue so we can improve it, which has minimal effect on anyone and is what you would reasonably expect a shop to do.

If we ever wanted to use these records for advertising, or to build a profile of an individual, that exception would no longer apply and we would have to come back and ask you properly. We would rather not, so we do not.

What we deliberately do not do

  • We do not store your IP address in these records. Our web server logs IP addresses in order to serve pages at all, as every web server must, and those logs are overwritten within about a fortnight.
  • We do not use fingerprinting. We do not identify you from your browser, your screen, your fonts or your device.
  • We do not share this with anyone, sell it, or send it to an advertising network. It stays in our own database.
  • We do not track you across other websites. These cookies work on this site and nowhere else.
  • We do not include search terms that look like an email address. If one is typed into the search box it is discarded before the record is written.

How long we keep it

The detailed records are kept for no more than 12 months. After that what remains is counts with no identifier in them, such as how many people searched for a term in a given month, which is no longer information about any individual and is kept so we can compare one year against another.

Third-party analytics

We do not currently use Google Analytics or any other third-party analytics, no advertising cookies and no tracking pixels. If that changes, this page will say so before it happens rather than after.

Your rights

Under UK data protection law you have the right to:

  • ask for a copy of the personal data we hold about you
  • ask us to correct anything inaccurate
  • ask us to delete it, where we have no overriding reason to keep it
  • ask us to restrict how we use it
  • object to our use of it where we rely on legitimate interests
  • ask for it in a portable format

Email privacy@datasteak.co.uk and we will respond within one month. There is no charge.

Complaints

If you are unhappy with how we have handled your personal data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office, the UK regulator, at ico.org.uk.

Changes to this policy

We will update this page when what we do with personal data changes, and the date at the top will tell you when it last changed.