CompanyDelta
Privacy notice
How Global Data Intelligence Limited handles information provided through the CompanyDelta website and authenticated service.
Updated 15 September 2026. This notice distinguishes public-site, account, enquiry, workspace and optional analytics information.
Who is responsible
Global Data Intelligence Limited, registered in England and Wales, company number 09410808. Registered office: Artisans’ House, 7 Queensbridge, Northampton, NN4 7BF, United Kingdom.
Contact the privacy team about your personal data.
Information you provide
Enquiry forms collect your name, business email, company, request type, message and optional portfolio size and countries. Account setup also requires your company name and phone number. Support conversations record messages, replies and ticket status. We also record submission time and the version of the privacy acknowledgement. Avoid sending sensitive personal data or confidential documents.
Why enquiries and account details are processed
We use this information to assess and respond to requests, provide and administer the service, maintain support history and protect account access. The relevant basis is responding to a request before a contract where applicable, performing or administering a service, or our legitimate interest in handling business enquiries and protecting the service. Submitting these details does not enrol you in marketing.
Storage, providers and CRM
CompanyDelta stores application records in its hosted database. Restricted administrators can access the enquiry and operations inboxes. WorkOS provides customer authentication, Stripe provides checkout and subscription management, Resend handles service email, and Google provides optional website analytics only after consent. Enquiry and signup details are queued for HubSpot only when the production HubSpot private-app credential is configured. Delivery states and provider references are retained to diagnose failures. Hosting and security providers may process technical information needed to operate and protect the service.
Workspace and provider data
CompanyDelta stores authorised users, portfolios, saved companies, review activity and configuration. Workspace records originate from users, imports and configured sources. They may include names and business roles of directors or shareholders from company filings and licensed records. A configured source, webhook destination or AI connection receives only the records needed for the action you request. Customer agreements and applicable provider terms must establish the permitted data scope and processing responsibilities.
Homepage company assistant
Question text is sent to the Regis company-data AI service to retrieve relevant records and generate an answer. We save your current conversation, returned records and unfinished question so you can continue after registration or a reload. Conversations expire after 30 days without a save. A secure browser cookie connects a guest conversation to the account that signs in; after that, access requires that account. Recent messages may be sent with a follow-up question to retain context. Starting a new conversation clears the current saved conversation. A selected company can be carried through registration in a signed link that expires after 24 hours. Confirming “Save to watchlist” stores the company details and source in your workspace; automatic recurring monitoring requires an active paid plan.
To enforce monthly allowances, we retain a hashed account or network identifier, a hashed request identifier, the UTC month and submission time. We do not store the underlying IP address in this table. Automated maintenance removes these usage records after 90 days. Provider processing and retention are governed by the applicable service arrangements.
Optional analytics
If you choose “Allow analytics,” CompanyDelta creates a pseudonymous first-party attribution identifier. It records the first public landing path, an approved referring-host category, approved campaign values when configured, and a limited set of conversion or product milestones such as a pricing view, checkout start, signup, saved company or first investigation. First acquisition is not overwritten by later visits. CompanyDelta’s first-party analytics excludes IP addresses, user-agent strings, question text, answers, enquiry messages and provider payloads. Its identifier, attribution and events expire after 90 days.
The same choice also loads Google Analytics 4 on public marketing pages. Google Analytics receives the page path and title, referrer and campaign context, standard browser or device information, approximate location, and enabled interaction events. CompanyDelta does not send form values, assistant question text, answers, enquiry messages, account details or provider payloads to Google Analytics. Google uses an IP address at collection time to determine approximate location and states that it is discarded before the data is logged. Advertising storage, advertising user data, ad personalisation and Google Signals are disabled by CompanyDelta’s tag configuration.
If you choose “Essential only,” the Google Analytics tag does not load and CompanyDelta does not create the optional analytics cookie or send optional analytics events. Use “Privacy choices” in the website footer to change your selection. Withdrawing consent expires CompanyDelta’s cookie and deletes its linked attribution and event rows; it also disables Google Analytics and attempts to remove its first-party cookies from this site. See the cookies and browser-storage notice and Google’s explanation of regional data collection.
Retention and cleanup
Expired sign-in transactions, sessions and checkout-browser links are removed automatically. Unclaimed local checkout workspaces with no members, saved companies or active subscription are removed after eight days; this does not automatically delete a separate provider-side customer record. Search-allowance and CompanyDelta first-party analytics records are removed after 90 days. Google Analytics uses its property-level retention settings and the configured first-party analytics cookies expire after no more than 90 days. Completed service-delivery records are pruned after 90 days, while failed delivery diagnostics are pruned sooner. Enquiries, support history, workspace evidence, billing records and audit history follow their operational, contractual and legal retention requirements and may be removed on a verified request where appropriate.
Automated processing
The enquiry form does not make decisions with legal or similarly significant effects about you. AI investigation output supports human review and is not an automated decision about an individual.
Your rights
Depending on applicable law, you may request access, correction, erasure, restriction, portability or object to processing. You may object to processing based on legitimate interests. Contact the privacy team above. We may need proportionate information to verify your identity. You may also raise concerns with the UK Information Commissioner’s Office.
Related notices
Find other website notices in the legal centre. For the data provider’s broader services, see its website privacy notice and database privacy notice.