Privacy Policy
Last updated 5 August 2026
Who we are
Incorporated Scotland ("we", "us") operates a subscription platform that imports publicly available Scottish company records from Companies House and presents them alongside clearly labelled AI interpretation. For the purposes of UK data protection law we are the data controller for account data and for the way we organise and present register data within the platform.
Privacy questions can be raised through the contact route provided inside your account.
The data we hold
Account data. Your email address, authentication records, role, saved filters, saved reports and the actions you take inside the platform.
Public register data. Company records published by Companies House under the Open Government Licence. These records can include limited personal data such as the names, roles, partial dates of birth and correspondence addresses of directors and persons with significant control, where Companies House itself publishes them.
Technical data. Log data required to operate the service securely, such as request timestamps, error records and import or enrichment job history.
We do not knowingly collect special category data, and we do not collect it deliberately from the register.
Why we process it, and our lawful basis
Contract. To create and operate your account and to deliver the subscription service you have signed up for.
Legitimate interests. To organise, search and interpret public register information so that business users can understand newly incorporated companies; to keep the service secure and reliable; and to improve the accuracy of our interpretation. We have considered the rights of the individuals appearing in the register and limit our processing to information they are already legally required to publish.
Legal obligation. To meet accounting, tax and other statutory duties.
What we do not do
We do not sell personal data. We are not a data broker, a lead list, a contact database, a cold-email tool or a marketing platform. We do not enrich register data with personal contact details obtained from elsewhere, and we do not send marketing on behalf of our subscribers.
Sharing and processors
We share data only with service providers who help us run the platform: cloud hosting and database infrastructure, authentication services, and the AI provider that generates interpretation from stored company facts. Each processor acts on our documented instructions under a written agreement. We may also disclose data where we are required to do so by law.
International transfers
Some processors operate outside the United Kingdom. Where personal data is transferred internationally we rely on UK adequacy regulations or the International Data Transfer Agreement or Addendum, together with appropriate supplementary safeguards.
Retention
Account data is retained for the life of your subscription and for up to six years afterwards where required for legal, tax or dispute purposes. Public register records and their provenance history are retained as an historical record of what the register said at the time it was retrieved, because the integrity of that record is central to the service. Operational logs are retained for a limited period proportionate to security and troubleshooting needs.
Your rights
Under UK GDPR you have the right to access your personal data, to have inaccurate data corrected, to request erasure or restriction, to object to processing carried out under legitimate interests, and to data portability. Requests can be made through your account and will be answered within one month.
Where information originates from Companies House, the authoritative record is held by Companies House. We cannot alter the public register; corrections to register data must be made with Companies House, and we will reflect those corrections when we next import the record.
You may complain to the Information Commissioner's Office at ico.org.uk if you are unhappy with how we have handled your data.
Security
Access to the platform requires authentication, data access is restricted by row level security policies, and all external API credentials are held server side and never exposed to the browser. Access to production data is limited to the people who need it to operate the service.
Changes
We will update this notice as the platform develops and will change the date shown above when we do. Material changes will be communicated to account holders.