• Search
  • About
  • Free API

Privacy Policy

Updated: October 2026

|View as Markdown|Agent setup

General information on our use of personal data

In this privacy notice (the "Notice") we describe how we collect, use, and share your personal data when using our website (companyregistryapi.com), our free JSON API and our MCP server, when you communicate with us, and when an official company register names you in a record we show. The website, the API and the MCP server are below named the "Service".

Personal data means any information that, directly or indirectly, identifies you, for example, your name or your IP address.

We are committed to your privacy. We take measures to ensure that your personal data is protected and that our use of personal data complies with applicable regulations and laws and our internal procedures and routines.

1. WHO IS COVERED BY THIS NOTICE?

This Notice covers:

  • Visitors and users of the website, the API and the MCP server, including people who let an AI assistant read the Service for them.
  • Persons named in official company registers whose records the Service shows, for example a company's officers ("Registry Data").
  • External persons who contact or otherwise communicate with us, for example by email or through the support chat.

2. WHO IS RESPONSIBLE FOR THE USE OF YOUR PERSONAL DATA?

Upperformance Oy ("we", "our" and "us"), the company behind Coragrid, source-linked company data infrastructure, and CompanyRegistryAPI.com, which is built on it, is responsible, as data controller, for the use of your personal data as described in this Notice. Please see section 11 below for contact information.

This Notice does not cover the Coragrid API and the cgd command line, which are governed by the Coragrid Privacy Policy, data you process in your own products after retrieving it from the Service, or third-party services through which you access the Service, whose own privacy policies apply.

3. WHICH PERSONAL DATA DO WE COLLECT?

We only collect the personal data that we need. Which personal data we collect about you depends on how you interact with us:

  • Technical information. Technical information about the device you use when using the Service, for example your IP address, user agent and browser metadata, the pages and API endpoints you request and the request timing, and the result of the human verification described in section 8.
  • Cookies. The content of the few cookies the site sets, described in section 8.
  • Communication. Contents of communication with us, for example an email, a correction request or a support chat message, and the email address you leave so we can answer.
  • Registry Data. What an official company register publishes about a company: its name, identifiers, status, legal form, activity, addresses, and the names and roles of its current officers. We do not knowingly collect or index data related to private life, health, religious beliefs or political opinions.
  • Support chat. When you use support chat, we collect your messages, the page you send them from and any email address you provide so our team can respond. A cookie and local storage keep the chat working between visits.

4. FROM WHERE DO WE COLLECT PERSONAL DATA?

We collect personal data from the following sources:

  • Yourself. When you use the Service, contact us or communicate with us, we collect the personal data that you provide to us and the technical information your device sends.
  • Official company registers. Registry Data is retrieved live from Coragrid, source-linked company data infrastructure we operate, which collects company facts from official company registers and keeps the source and observation time of each fact. This site stores no Registry Data of its own beyond the MCP server's short-lived cache of answers described in section 5.
  • Service providers. Cloudflare tells us whether a request passed its human verification; where analytics is configured, Google reports aggregated measurements (section 8).
  • AI assistant platforms. When you use the Service through an AI assistant, its platform sends an opaque subject identifier for you, which we use only to apply the per-user allowance.

5. WHY DO WE USE YOUR PERSONAL DATA?

Below we explain the purposes of our use of personal data, the legal basis under the GDPR that we rely on for each purpose and for how long we store the personal data. Not all processing activities may apply to you.

  • Provide the Service. We use technical information to answer your searches and serve company records, and Registry Data to show what the register publishes. Legal basis: our legitimate interest (Article 6(1)(f)) in operating the Service and in facilitating B2B commerce and market transparency.
  • Ensure technical functionality and security. We use technical information to apply the per-client rate limit, tell people from automated clients, and for security logging, error handling and backups. Legal basis: legitimate interest (Article 6(1)(f)). Request logs are kept for up to 90 days. Client addresses used for rate limiting on the website and the API are held in memory only: the table is lost on restart, idle entries are dropped when the limiter reaches its capacity, and nothing is written to a database. The MCP server counts calls in our cache store instead, by client address for 2 minutes and by the subject identifier an AI assistant platform sends for up to 32 days, and keeps a copy of recent answers there for at most 15 minutes to answer repeated questions.
  • Respond to questions. If you contact us, for example by email or through the support chat, we use the personal data you share with us to respond to you. Legal basis: legitimate interest (Article 6(1)(f)). Emails stay in our mailboxes for as long as handling your request needs them. A support chat conversation is deleted 30 days after you last write in the chat, leave your address or reply to one of our emails; the cra_chat cookie expires 30 days after you last write in the chat or leave your address in the browser, so a conversation continued by email can outlive its cookie.
  • Follow up and analyse the use of the Service. Where analytics is configured, we collect and analyse visitor statistics on an aggregated level to understand how the Service is used and to improve it. Legal basis: your consent (Article 6(1)(a)), which you can withdraw at any time on the About page.
  • Manage and defend legal claims and fulfil legal obligations. If needed, we use your personal data to manage and defend legal claims, for example in a dispute, and to fulfil our legal obligations, for example accounting or data protection obligations. Legal basis: legitimate interest (Article 6(1)(f)) and legal obligation (Article 6(1)(c)).

Information where personal data is not obtained directly (Article 14). Registry Data is collected from official company registers, not from the data subject. Providing individual notice to every person named in a register would involve a disproportionate effort given the scale, volume and continuous nature of the processing, so in accordance with Article 14(5)(b) of the GDPR this Notice serves as our public information on the categories of personal data processed, the purposes and legal bases, the sources and your rights. We limit processing to what a register publishes about a person's public role in a company, show each fact with its source and observation time, refresh data from the register and provide clear means to object (section 7).

Registry Data is retained by Coragrid for as long as it remains relevant to the public role it describes, including facts that are no longer current so that a record's history can be told apart from its present state, and is refreshed from the register; the Service shows current facts and marks removed or restricted records as such. The Coragrid Privacy Policy describes that retention.

6. WHICH RECIPIENTS DO WE SHARE PERSONAL DATA WITH?

Below we describe which recipients we share your personal data with. Unless we have stated otherwise, the recipient is responsible (data controller) for its own use of your personal data.

  • Users of the Service. Registry Data is shown to anyone who looks up the company, in the browser, through the API and through the MCP server, as the register publishes it. This is the Service. Those who process it further are independent controllers under our Terms of Service.
  • Service providers. To process personal data for the purposes described in this Notice, we share personal data with service providers that we have engaged: cloud hosting in the European Union, the Cloudflare edge network that protects the Service, runs the human verification and routes support chat replies, Amazon Web Services for sending support chat email, and Google for our mailboxes and, where configured, Google Analytics in Consent Mode. When they process personal data on our behalf, they act as data processors for us, must not use your personal data for their own purposes, and are contractually and legally obliged to protect it.
  • Other recipients. If needed, we share your personal data with other recipients to manage a merger or sale of the business, to manage and defend legal claims and rights, to fulfil legal obligations, and to respond to a request by a public authority. Examples of recipients are external advisors, public authorities, courts, law enforcement, and potential buyers of the business.

7. YOUR RIGHTS

We normally reply to your request within one month following the date that we received it, as Article 12(3) of the GDPR requires. If your request is complex or you have submitted several requests at the same time, we may extend that time by up to two further months and will tell you why within the first month. If we cannot, wholly or partly, act on your request, we will tell you that and why within the same time. If you submit your request electronically, we respond electronically unless you ask otherwise, and we charge nothing for a reasonable request.

When you submit a request to exercise your rights, we need to confirm your identity so that we do not disclose personal data to an unauthorised person or erase personal data in error. We only request the information that is reasonable and necessary to do so.

Below we describe the rights that you have in relation to your personal data.

  • Right to access (Article 15). You have the right to request confirmation of whether we handle your personal data and, if so, a copy of it together with additional information on our use of it.
  • Right to rectification (Article 16). You have the right to request that we rectify or supplement your personal data if you consider it incorrect, incomplete or misleading. For Registry Data, the register of the company's home country is the authoritative source and the durable fix: a correction made there flows into the Service, whereas a value changed anywhere else would return on the next refresh. Tell us too, with the company's page address, the register and identifier and the field concerned, and we will act on a substantiated request within what the source data allows.
  • Right to withdraw your consent (Article 7). Where we use your personal data based on your consent, for example analytics cookies, you have the right to withdraw it at any time, on the About page or by contacting us.
  • Right to erasure (Article 17). You have in certain situations the right to request erasure of your personal data, for example if we no longer need it for the purposes for which it was collected, if you withdraw your consent or if you object and we cannot show a compelling reason to continue. The right does not apply where we must keep the data by law or need it to exercise, manage or defend legal claims.
  • Right to object (Article 21). Where we rely on a legitimate interest, including for Registry Data, you have the right to object for reasons relating to your particular situation. If we cannot show compelling legitimate grounds to continue, we will stop using your personal data for the relevant purpose. You always have an unconditional right to object to direct marketing, which we do not do.
  • Right to restriction (Article 18). In certain situations you have the right to request that we restrict the use of your personal data, for example while we verify its accuracy or your objection; we may then store it but not use it for any other purpose than to manage, defend or exercise legal claims.
  • Right to data portability (Article 20). For personal data you have provided to us that we handle based on your consent or a contract with you, you have the right to receive a copy in a structured, commonly used and machine-readable format and, where technically feasible, to have it transferred directly to another recipient.
  • Right to lodge a complaint. You have the right to lodge a complaint with your supervisory authority. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman (tietosuoja.fi).

Automated individual decision-making. We do not carry out any automated individual decision-making which has legal effects or similarly significant effects on you. The rate limit and the human verification are automated and can reject a request or ask you to show you are a person; if you believe that happened wrongly, contact us and a person will review it. We do not use your personal data to train machine-learning models.

California residents. If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the right to know what personal data we collect, to request its deletion and to opt out of its "sale". We do not sell personal data in the conventional sense, but under the CCPA's broad definition our search functionality may be considered a sale of Registry Data, which you may opt out of by contacting us. We will not discriminate against you for exercising these rights.

8. COOKIES AND OTHER TECHNOLOGIES

The site sets a signed, HTTP-only cookie named cra_human holding only an expiry time when you pass the human verification, a cookie named cra_consent holding granted or denied for 180 days when you answer the cookie notice, and a cookie named cra_chat holding a random conversation number for 30 days when you write in the support chat. They are used for nothing else, and the site uses no other tracking technologies.

Every page loads Google Tag Manager, which runs Google Analytics 4 in Google's Consent Mode. Until you accept, Google Analytics sets no cookies and receives only cookieless measurements of page views, searches and the links you follow, such as the page address, the search term, the time and your browser, with no identifier that links one visit to the next. After you accept, it sets its _ga cookies to recognise returning visits; choosing necessary cookies only removes them. Advertising storage, ad personalisation and ad data stay off either way.

The cookie section of our About page lists every cookie the site sets and lets you change your choice at any time.

The browser search is protected by Cloudflare Turnstile for bot detection. Turnstile evaluates signals from your browser to tell people from automated clients; the site receives only the result. The API and the MCP server do not use Turnstile. For more information, see Cloudflare's privacy policy.

9. WHERE WE PROCESS PERSONAL DATA

We store your personal data within the EU. However, we use service providers, which also may use sub-contractors, that are established in third countries outside the EU/EEA. To ensure an essentially equivalent level of protection for your personal data when transferred to such providers, we rely on the European Commission's adequacy decisions, including the EU-U.S. Data Privacy Framework for certified providers, or on the standard contractual clauses for international transfers adopted by Commission Decision (EU) 2021/914, together with supplementary measures where needed. For more information on the safeguards that we have taken, please contact us.

We protect personal data with technical and organisational measures, including encryption in transit and strict access controls, and will notify you and the supervisory authority of a breach that is likely to result in a high risk to your rights, as Articles 33 and 34 of the GDPR require.

10. UPDATES TO THIS NOTICE

We regularly update this Notice to ensure that it reflects our use of personal data from time to time, for example if we decide to collect additional categories of personal data or to use personal data for additional purposes. We will in such case notify you by appropriate means, for example by a message on this website. The latest version of the Notice is always available on this page, and the date it was last updated is stated above.

11. ANY QUESTIONS?

If you have questions about this Notice, our use of your personal data or if you wish to exercise your rights, please contact us at [email protected].

If you are not satisfied with our response, you have the right to lodge a complaint with the data protection authority in your country. In Finland, the Office of the Data Protection Ombudsman (tietosuoja.fi) is the data protection authority.

Upperformance Oy, Business ID 3282334-3, VAT ID FI32823343, registered in the Finnish Trade Register kept by the Finnish Patent and Registration Office. Registered address: Lapinlahdenkatu 16, 00180 Helsinki, Finland.

How the Service may be used is described in our Terms of Service.

Free company lookup and JSON API. Company data powered by Coragrid.

Product

  • Search companies
  • Free API
  • Company Data API
  • Get API key
  • About
  • Support

Data

  • Coragrid
  • Full API access

Legal

  • Privacy
  • Cookies
  • Terms
© 2026 CompanyRegistryAPI.com

Essential cookies keep the site working. Optional cookies help with performance. Cookie details

CompanyRegistryAPI.com support

CompanyRegistryAPI.com support

  1. Is there something on this page you don’t like, or do you need a hand? Let us know. We offer human support only.

If you wish to receive the response via email:

We won’t use your email for anything other than responding.