Privacy Notice
How entyrix.com processes personal data, as required by Art. 13 and 14 GDPR.
The Slovak version is the original. Other language versions are translations of it; in case of conflict the Slovak version prevails.
1. Controller
The controller of this processing is:
- Inger s.r.o., limited liability company (s.r.o.), company ID (IČO) 50178831, Azalková 6524/10, 974 01 Banská Bystrica, Slovak Republic; Commercial Register of the District Court Banská Bystrica, section Sro, file no. 29266/S
- Contact: [email protected]
- Website: entyrix.com
The controller has not appointed a Data Protection Officer, as it does not meet the criteria of Art. 37 GDPR.
Competent supervisory authority. The controller is established in Slovakia, so for cross-border processing the lead supervisory authority under Art. 56(1) GDPR is the Slovak Office for Personal Data Protection. You may also lodge a complaint with the supervisory authority of your own country of residence, which will handle it in cooperation with the lead authority (Art. 60 GDPR).
2. Purposes of processing
We process personal data for the following purposes:
- Providing the Service — a REST API over public register data for KYC/KYB, compliance, credit scoring, sales prospecting and academic research.
- Managing user accounts — API-key authentication, communication, billing (on paid plans).
- Security and operations — rate-limit monitoring, abuse detection, incident diagnostics.
3. Legal basis for processing
| Category | Legal basis (GDPR) | Note |
|---|---|---|
| Contract data (email, API key, billing) | Art. 6(1)(b) — performance of a contract | necessary to provide the Service |
| Public register data (directors, beneficial owners, sanctions) | Art. 6(1)(f) — legitimate interest | see the next section |
| Access logs (IP, request id, timestamps) | Art. 6(1)(f) — legitimate interest (security) | 90-day retention |
| Accounting data | Art. 6(1)(c) — legal obligation | Act No. 431/2002 Coll., 10 years |
4. Legitimate interest — balancing test
For public register data (name, role, term of office of a director or beneficial owner, sanctions, tax arrears) we rely on legitimate interest under Art. 6(1)(f) GDPR.
- Legitimate interest of the controller and of users: KYC/KYB compliance (obligations under Slovak Act No. 297/2008 Coll. on AML, Act No. 366/2024 Coll. on cybersecurity, EU sanctions regimes), fraud prevention, credit risk management, B2B trade.
- Necessity: these purposes cannot be achieved in a less intrusive way — aggregating public registers is the only practical way to obtain a compliance signal across several countries.
- Balancing against the rights of data subjects: the data is published in official public registers and sanctions lists. We publish a strict subset of what the law permits the register itself to publish — name and role, without the date of birth, address or nationality of directors. Records of sole traders are not available on the public web at all.
We keep documented legitimate-interest assessments per purpose and per country. You have the right to object to this processing under Art. 21 GDPR — see the section on your rights below.
5. Categories of personal data and their sources (Art. 14 GDPR)
We process the following categories of data obtained from public registers:
| Category of data | Source | Licence |
|---|---|---|
| Director identification data (name, role, term) | RPO (Statistical Office SK), ARES (CZ Ministry of Finance) | CC-BY 4.0 |
| Officers and traders — Romania | ONRC (Oficiul Naţional al Registrului Comerţului) | public register |
| Officers and traders — Cyprus | DRCOR (Department of Registrar of Companies and Intellectual Property) | public register |
| Officers and traders — Greece | ΓΕΜΗ / GEMH (General Commercial Registry) | ODC-BY 1.0 |
| Beneficial ownership data | RPVS (SK Ministry of Justice), UK Companies House PSC | public database |
| Tax and insolvency records | Slovak Financial Administration, Commercial Bulletin | CC-BY 4.0 |
| Social / health insurance debtors | Sociálna poisťovňa, VšZP | CC-BY 4.0 |
| Sanctions, crime and debarment lists | EU FSF, OFAC, UN, UK HMT/OFSI | OFAC public domain · EU FSF (2011/833/EU) · UN · UK OGL v3.0 |
| LEI (Legal Entity Identifier) | GLEIF | CC0 1.0 |
The full catalogue, with refresh cadence and licence terms, is published at /data-sources.
Statutory basis for the public character of these sources: processing of public register data rests on the publicity principles of company registers — in particular § 27 of the Slovak Commercial Code (Act No. 513/1991 Coll.), Act No. 211/2000 Coll. on free access to information, Act No. 297/2008 Coll. (AML), Act No. 315/2016 Coll. on the register of public-sector partners, Act No. 366/2024 Coll. on cybersecurity and Act No. 18/2018 Coll. on personal data protection. At EU level, publicity of officer data is mandated by Directive (EU) 2017/1132.
What we do not rely on: an open-data licence (such as ODC-BY for ΓΕΜΗ) and Directive (EU) 2019/1024 on open data are not a legal basis for processing personal data — they govern copyright and database rights and expressly leave data protection law untouched (Art. 1(4) of Directive 2019/1024).
6. Information for data subjects in Romania, Cyprus and Greece (Art. 14(5)(b))
Data on officers and traders from the Romanian ONRC, Cypriot DRCOR and Greek ΓΕΜΗ registers was not obtained from you but from those public registers. This section is the information required by Art. 14 GDPR and is also published in Romanian and Greek.
Why we do not notify you individually. We hold no electronic contact detail for these records — the registers do not publish email addresses of natural persons. Only a postal address is available, and not for every record. Individual written notification at the scale of these registers would not be proportionate. We therefore make this information publicly available, as the second sentence of Art. 14(5)(b) GDPR envisages.
What we process about you:
- Officers of legal entities: given name and surname, role and its term, and the link to the company. We do not process date or place of birth, residential address, nationality or a personal identification number — even though, for example, Romanian Act No. 265/2022 Art. 13(1) permits the register to publish date and place of birth.
- Sole traders (RO: PFA, II, PF, AF, IF · CY: business name “B” · GR: ατομική επιχείρηση): business identification and registration data including the registered address. These records are not available on the public web — the subject page returns
410 Gone, and the data is released only to contracted subscribers within the scope their contract allows.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest (KYC/KYB, fraud prevention, credit risk management). Recipients: authenticated B2B subscribers and the processors listed below. Retention: see the retention section.
Your rights and how to exercise them. You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18) and, in particular, the right to object to the processing on grounds relating to your particular situation (Art. 21 GDPR). We accept an objection, or any other request:
- through the data-subject request form — also available in Romanian and Greek,
- or by email to [email protected].
We accept submissions in Romanian, Greek, English and Slovak and reply within 30 days of receipt (Art. 12(3) GDPR). If we do not accede to an objection we will state our reasons and tell you how to complain to a supervisory authority.
Supervisory authorities: the lead authority is the Slovak Office for Personal Data Protection; you may also complain to ANSPDCP (Romania), the HDPA (Greece) or the Commissioner for Personal Data Protection (Cyprus).
Is the register entry wrong? The register is the source of truth. Corrections are made by ONRC, DRCOR or ΓΕΜΗ and we pick them up at the next refresh. If you need it corrected sooner, write to us and we will correct it on our side immediately.
7. Politically exposed persons and linking the records of one person
Politically exposed person (PEP) screening. For obliged entities under anti-money-laundering law we offer a check whether a name matches a politically exposed person within the meaning of Art. 3(9) of Directive (EU) 2015/849. Sources: Wikidata (CC0 1.0), the European Parliament list of Members (CC BY 4.0) and the open data of the Chamber of Deputies of the Czech Parliament. We process the name, year of birth (where the source gives it), public functions with their period and a link to the source. We do not process political affiliation, date of birth, address or media reports. The scope is limited to living persons whose function is ongoing or ended less than five years ago; anyone who falls out of scope is deleted at the next update. This data is not on the public website — it is available only through an API key to companies that have accepted the personal-data addendum, and the result is a candidate to verify, not a verdict. Legal basis: Art. 6(1)(f) GDPR.
Linking the records of one person. Where the register publishes a person's date of birth (the Czech public register via ARES, the Slovak register of public-sector partners), we link records into one person by name and date of birth, so that namesakes are not merged. For the Czech register the date of birth is used only to compute a pseudonymous key (a one-way keyed hash) and is not stored. Records of the Slovak register of public-sector partners are kept as the register publishes them, including the date of birth; we release at most the year of birth of an adult. A person page never displays a date of birth. Two different people with the same name and date of birth may be merged into one person — if that concerns you, ask for rectification (Art. 16 GDPR) through the same form. Person pages are not indexed by search engines and show only roles in legal entities, never a natural person's own business.
Objection. You may object to both under Art. 21 GDPR through the data-subject request form or at [email protected]. An accepted objection removes you from screening and from future updates, or removes the view of you on every company respectively. We answer within 30 days.
8. Recipients of the data
- Users of the Service — B2B customers with a valid API key, within their KYC/KYB and compliance processes.
- Processors (sub-processors):
- Hetzner Online GmbH (DE) — hosting and infrastructure, EU data centre. DPA.
- Cloudflare, Inc. (US/EU edge) — CDN, DDoS protection, TLS termination, edge cache; R2 offsite backups (encrypted on our side before upload); Turnstile (human verification in forms); Web Analytics; Email Routing. Cloudflare EU Data Boundary + SCCs (DPA).
- Functional Software, Inc. (dba Sentry, US) — error report aggregation. EU ingest region (Frankfurt) + SCCs (DPA).
- GitHub, Inc. (US) — git repository mirror, no user-facing personal data. DPA + SCCs.
- jsDelivr (Prospect One) (global CDN) — static Swagger UI assets on the single page
/api/v1/public/swagger; the visitor's browser fetches them directly, so the CDN sees their IP address and user agent. No data-subject data; all other pages, including web fonts, are served from our own origin. - Resend, Inc. (US; sending from the EU region – Ireland) — transactional e-mail (account sign-in links, monitoring alerts); sees the recipient's e-mail address and the message content. SCCs (DPA).
- Stripe (Stripe Payments Europe, Ltd., IE / US) — payments and subscriptions via Stripe Checkout. For payments under Managed Payments, Stripe is the merchant of record. Card details are entered directly on Stripe's page and never reach us. SCCs (DPA).
- What is deliberately NOT here. Telegram (operational alerts) and Anthropic (AI due-diligence reports) appear in our internal documentation as possible processing channels, but are not configured in production — they have no credentials, so no data reaches them. Listing them would assert that data leaves the EU where it does not. If either is switched on, it appears here before it starts, not after. Consistent with the sub-processor register.
- Public authorities — only to the extent of statutory obligations.
We do not transfer personal data to third countries outside the EU/EEA beyond the processors listed above, which are bound by standard contractual clauses (SCCs).
9. Retention periods
| Category | Retention |
|---|---|
| Public register data | continuously refreshed from the upstream source; archival copies for at most 7 years for auditability |
| User accounts and API keys | for the term of the contract + 7 years (accounting obligation) |
| Access logs | 90 days |
| Security incidents (breach log) | 5 years |
Records of dissolved entities and ended mandates are not deleted but marked historical — they are needed to verify whether a subject was previously active (KYC), to trace legal successors, and for sanctions history.
10. Your rights as a data subject
Under the GDPR you have the following rights:
- Right of access (Art. 15) — confirmation whether we process your data, and a copy of it;
- Right to rectification (Art. 16) — correction of inaccurate data (the primary sources are public registers, whose content is corrected by the competent state authorities; we will still correct our own copy);
- Right to erasure (Art. 17) — the “right to be forgotten”, subject to the exceptions in Art. 17(3);
- Right to restriction of processing (Art. 18);
- Right to data portability (Art. 20) — in JSON/CSV, for data processed on the basis of a contract or consent;
- Right to object (Art. 21) — you may object at any time to processing based on legitimate interest, on grounds relating to your particular situation. We will stop the processing unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms.
You can exercise these rights through the online request form or by email to [email protected]. We respond within 30 days of receipt. We accept submissions in English, Slovak, Romanian and Greek.
Lodging a complaint: you have the right to lodge a complaint with a supervisory authority — the Slovak Office for Personal Data Protection, Hraničná 12, 820 07 Bratislava, or the supervisory authority of your country of residence.
11. Cookies and tracking
The Service uses no marketing or tracking cookies. We use only functional cookies necessary for operation (language choice, theme, dashboard session). Analytics is server-side, with no cross-site tracking.
12. Automated decision-making and profiling (Art. 22 GDPR)
The aggregate indicators credit score (0-100 plus an A-F grade), NIS2 scoping and risk tier are informational decision-support metrics, not automated individual decisions producing legal effects within the meaning of Art. 22(1) GDPR. The final decision (granting credit, selecting a supplier, placing an entity in compliance scope) must be the result of human judgement by the user of the Service.
Scope of profiling: all three indicators are computed over data about legal entities. The exception is records of sole traders, where the business identifier identifies a natural person — there the output is an informational indicator, and the user of the Service must ensure that any subsequent decision is not based solely on it.
Logic of the computation (disclosure in line with the CJEU judgment in C-203/22 Dun & Bradstreet Austria, 27 February 2025):
- Input categories: financial indicators from filed accounts, tax and social-contribution compliance, insolvency, sanctions status, company age, public-contract history, antitrust history.
- Direction of influence: positive signals (profit, active contracts, long history) raise the score; negative ones (debts, sanctions, insolvency) lower it. Hard cap: sanctions / bankruptcy / liquidation → ≤ 10.
- Method: a deterministic sum of bonuses and penalties from a fixed rule set; no machine learning and no black-box models.
- Consequences: the score is shown only to authenticated B2B users. No legal effect on a data subject follows directly from the output of the Service.
Rights: sole traders have the right under Art. 22(3) GDPR to obtain human intervention, to express their point of view and to contest the outcome. Send such requests to [email protected].
13. Security
We apply appropriate technical and organisational measures in line with Art. 32 GDPR:
- TLS 1.2+ on all endpoints, HSTS (1 year + includeSubDomains);
- API keys stored hashed (SHA-256), no plaintext in the database;
- IP addresses in audit logs are stored only as a salted hash, with the salt rotating daily;
- Rate limiting, fail2ban, SSH password authentication disabled;
- Daily database backups, offsite copy encrypted before upload;
- Monitoring and error tracking hosted in the EU region.
14. Crawling and AI model training
Pages carrying data about individual subjects (/firma/…) are disallowed in robots.txt for crawlers that collect content into model training corpora (among others GPTBot, ClaudeBot, CCBot, Google-Extended, Applebot-Extended, Bytespider). Marketing pages and API documentation are not disallowed.
Why. The Regional Court of Kiel (LG Kiel, case no. 12 O 64/24, judgment of September 2024) ruled against an operator that continued to publish data taken from official registers after that data had changed at the source. The point that matters to us is a single one: whoever republishes register data is responsible for making a correction or an erasure take effect on their own surface — pointing at the register does not discharge that responsibility.
Data that once enters the training set of a language model can no longer be corrected or erased. If we let training crawlers walk pages containing the names of natural persons, we would ourselves be stripping your right to rectification (Art. 16) and erasure (Art. 17) of its effect — we would comply on our side while the data lived on elsewhere. Blocking training crawlers is therefore a measure under Art. 25 GDPR (data protection by design), not a commercial decision about who may read our pages.
This is not a claim about effectiveness: robots.txt is an instruction, not a technical barrier, and only those who choose to obey it do. It is a measure available to us, so we took it.
15. Changes to this notice
We announce material changes at least 30 days in advance by email or on the status page.
16. Contact
Address any data protection question to [email protected]. Related documents: sub-processor register · security · DSA notice-and-action.