How refdatum collects, uses, and protects personal data across refdatum.com and its data products.
refdatum ("refdatum," "we," "us," or "our") operates refdatum.com and its product sites — including TickerTruth, TradeRef, SanctionShield, ProcureRef, EntityGraph, and the ESG/BRSR reference catalogue (each a "Site," collectively the "Sites") — publishing versioned, queryable reference datasets for India and emerging markets. This policy explains what personal data we collect when you visit our Sites, request a demo, subscribe to a product, or contact us, and what rights you have over that data.
This policy covers personal data collected through refdatum.com and its product subdomains (e.g. trade.refdatum.com, sanctions.refdatum.com), our contact and inquiry forms, and our checkout/subscription flows. It does not cover the content of the reference datasets themselves — see Section 15 for how we handle personal data that may appear inside a dataset (e.g. a company director's name in a public registry).
We collect the minimum data needed to respond to inquiries, deliver purchased data products, and operate the Sites reliably.
| Category | Examples | When collected |
|---|---|---|
| Contact form data | Name, email address, phone number (optional), stated interest, free-text notes | When you submit an inquiry via /contact |
| Purchase & billing data | Name, email address, payment method details | When you buy an Evaluation Pass, Data Pack, or Monthly subscription — payment details are collected and processed directly by our payment processor, Razorpay; refdatum does not receive or store card/UPI details |
| Product access data | Email address linked to an issued access token (Evaluation Pass), subscription status | After a completed purchase, to unlock the relevant product explorer/download |
| Technical & usage data | IP-derived approximate location, browser/device type, pages visited, referring source — collected in aggregate, not tied to a named individual | Automatically, via Cloudflare Web Analytics (see Section 7) |
| Correspondence | Emails you send us, including any information you choose to include | When you email connect@refdatum.com directly |
We do not knowingly collect sensitive personal data (health, biometric, government ID numbers) through the Sites, and our forms do not ask for it. Please do not include sensitive personal data in free-text fields.
We do not sell personal data, and we do not use it for third-party advertising or ad-targeting.
Where applicable law requires a stated legal basis (e.g. GDPR Article 6), we rely on:
We share personal data only with service providers who process it on our behalf, under contract, to operate the Sites and fulfil orders:
We do not share personal data with data brokers or use it to train third-party AI models. We may disclose personal data if required by law, court order, or to protect the rights, safety, or property of refdatum or others.
The Sites use Cloudflare Web Analytics, a privacy-focused analytics service that does not use cookies and does not track individuals across sites. We do not currently use advertising or cross-site tracking cookies. Session-necessary cookies may be set by our payment processor (Razorpay) during checkout to complete a transaction securely.
We retain contact-form submissions and correspondence for as long as needed to respond and for a reasonable follow-up period, typically no longer than 24 months from the last interaction. Purchase and billing records are retained as required by applicable tax and accounting law (typically 6–8 years in India). Issued access tokens are retained for the duration of the product's access window plus a reasonable buffer for support purposes. You may request earlier deletion — see Section 11.
We apply reasonable technical and organizational safeguards appropriate to the data involved: encrypted transport (HTTPS) on all Sites, secrets stored in Cloudflare's managed secret store rather than in code, and payment data handled exclusively by our PCI-DSS-compliant payment processor rather than passing through our own systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
refdatum operates from India. Our service providers (Cloudflare, Resend, Razorpay, Google) may process data on servers located outside India, including in the United States and the European Union. Where required, we rely on those providers' own compliance mechanisms (such as standard contractual clauses) for cross-border transfers.
Depending on your location, you may have the right to:
To exercise any of these rights, email connect@refdatum.com. We will respond within a reasonable time and, in any event, within the timeframe required by applicable law.
Under India's Digital Personal Data Protection Act, 2023, refdatum acts as a Data Fiduciary for the personal data described in Section 3 (contact-form and purchase data). We process this data only for the purposes stated in this policy, with your consent or another valid legal basis under the Act, and we do not retain it longer than necessary for those purposes. You may exercise the rights available to you as a Data Principal under the Act — including the right to access a summary of your personal data and the processing activities carried out, the right to correction and erasure, and the right to grievance redressal — by contacting our grievance officer (Section 17).
If you are located in the European Economic Area or the United Kingdom, you have the rights described in Section 11 under the EU/UK GDPR, and the right to lodge a complaint with your local supervisory authority. refdatum's EU-sourced product (EU Procurement Intelligence, built from TED/SIMAP notices) processes organizational bidder/contracting-authority data, not individual data, consistent with GDPR Recital 14 — see Section 15.
The Sites are intended for business use and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
refdatum's data products are reference datasets sourced from public government and regulatory registries (e.g. DGFT trade statistics, OFAC/UN/EU sanctions lists, GeM/CPPP procurement records, TED/SIMAP EU procurement notices). These datasets are predominantly organizational — company names, identifiers, trade flows, contract awards — not individual personal data. Where a dataset does include identifiable individuals, it is limited to cases like public-registry corporate officer/director names or publicly designated sanctioned individuals, which are treated as low-risk under the DPDPA public-data pathway and, for EU-sourced data, excluded from scope by GDPR Recital 14 where organizational. This governance is documented internally in docs/legal-compliance.md and reviewed per product before release. This policy's Sections 3–14 govern data you give us directly (contact/purchase data) — not the third-party registry data contained within a purchased dataset itself.
We may update this policy from time to time to reflect changes in our practices or legal requirements. We will update the "Last updated" date at the top of this page when we do. Material changes will be reflected here before they take effect.
For any question about this policy, to exercise a data-subject/data-principal right, or to raise a grievance under the DPDPA 2023:
We aim to acknowledge privacy inquiries within 5 business days and resolve them within the timeframe required by applicable law.