Data protection
This page is Orkora Limited's data-protection statement for the Kortex platform, and serves as the public transparency notice under Articles 13 and 14 UK/EU GDPR for personal data we did not collect from the individuals concerned. Plain statements, no claims of absence where the honest answer is "some".
Who is responsible
Orkora Limited (registered in England and Wales, company no. 16555987; registered office Wsm, Connect House, 133-137 Alexandra Road, Wimbledon, London SW19 7JY) is the controller for the personal data described on this page. Contact for all data-protection matters: kortex@orkora.com. Orkora Limited is the UK operating company of the Orkora Inc. group; the group parent is not a controller of platform data.
Three kinds of data, three positions
1 · Personal data inside the product
The graph is infrastructure and corporate-entity records: power plants, substations, grids, legal entities, jurisdictions. Within the corporate layer, some records are personal data even though they arise in a business context:
- Company officers and persons with significant control, as published by statutory registers (Companies House and international equivalents, the FCA Mutuals Register, LEI reference data).
- Named officers in the ICIJ Offshore Leaks datasets, held internally for derived corporate-screening analytics and not served through the API; the diligence screen serves entity-level matches only.
Lawful basis: legitimate interests (Article 6(1)(f)): enabling evidence-based screening of corporate counterparties and infrastructure ownership using records that statutory regimes publish precisely so that the public can know who controls what. The data is limited to what the registers publish (names, roles, appointments, control relationships), is not enriched with private-life information, and concerns individuals in their corporate capacity, where the privacy expectation over register-published facts is at its lowest. We rely on Article 14(5)(b): individually notifying every officer named in public registers would be disproportionate, and this page is the public notice instead.
- No special-category data. No consumer profiles. No selling of personal data.
- No automated decisions about individuals: screen verdicts attach to sites and legal entities, not to natural persons, and are decision support for professional users, not decisions with legal effect on anyone.
- Retention mirrors the source registers: records refresh from the registers on published cadences (see /sources), and corrections in the register flow through on the next refresh.
2 · Customer account data
Contact details, hashed API keys, and usage records, processed to operate the service (Article 6(1)(b), contract) and to secure it (legitimate interests). Retained for the life of the account plus statutory record-keeping periods.
3 · Customer candidate data (your shortlists and counterparties)
When you run a screen, your candidate coordinates or counterparty identifiers are archived inside your receipt so the answer stays retrievable and auditable. Counterparty identifiers can include personal data where a counterparty is an individual officer-rich small company. For this data you are the controller and Orkora Limited processes it on your instructions: receipts are private to your organisation by default, shareable and deletable only by you. Data-processing terms covering this processing are part of every pilot agreement; our standard draft is available to your DPO on request while it completes external counsel review.
Subprocessors, by name
| Provider | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and offsite encrypted backups | Germany (EU) |
| Resend, Inc. | Transactional email (alerts, sign-in links) | United States |
That is the complete list. The Resend transfer is limited to email address and message content and is safeguarded by standard contractual clauses per Resend's data-processing terms. Platform databases and backups do not leave the EU.
Your rights
Individuals whose data appears in the product, and users of the platform, have the UK/EU GDPR rights of access, rectification, erasure, restriction and objection. Write to kortex@orkora.com; we respond within one calendar month. Where a record mirrors a statutory register, correction at the register is the durable fix and we will point you to it as well as reflecting the register's correction on our next refresh. You may complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
Stated plainly. This page was rewritten after an external vendor-risk review correctly called out that our earlier wording, "no personal data in the product", was overstated: register-published officer records are personal data in law. The position above is the honest one. This statement is maintained by the operators of the platform and reviewed as sources change; material changes are noted on the /changelog.