Privacy notice

How Creditbase handles personal data.

Creditbase is a Solharbor product in development. This privacy notice explains the data Creditbase expects to process for the website, early-access discussions, portfolio monitoring and public-record intelligence.

Status and contact

Creditbase is not yet a generally available public service. The Solharbor DPA identifies Solharbor Management Ltd as the Solharbor entity for processor services. The exact controller details for Creditbase, including registered address, must be confirmed before launch.

Data-protection questions can be sent to privacy@solharbor.com or hello@creditbase.co.uk until Creditbase publishes a dedicated privacy contact.

Website visitors

When you visit the website, the hosting provider may process technical request data such as IP address, browser and device information, pages requested, time of request and diagnostic logs. The application code in this repository does not currently implement analytics cookies or advertising trackers.

If analytics, cookies, forms or tracking tools are added later, this notice and any cookie notice must be updated before they go live.

People who contact us or request early access

If you email Creditbase or request early access, Creditbase may process the information you provide, such as your name, work email address, organisation, role, message content and related communications.

This information is used to respond, manage early-access conversations, arrange demonstrations and keep appropriate business records.

Customer users and portfolio data

For pilots or customer use, Creditbase may process user account details, authentication and permission data, uploaded watchlists, company numbers, customer portfolio records, CRM records, deal records, integration metadata, support communications, logs and operational data supplied or connected by the customer.

Where Creditbase processes this information on a customer's behalf, the Solharbor DPA is expected to apply and the customer is expected to be the controller.

Public-record intelligence

Creditbase is designed to collect, normalise, preserve and interpret public company information. That may include public-register personal data about directors, officers, PSCs, beneficial owners, insolvency practitioners and other individuals appearing in company filings, Gazette notices or other lawful public sources.

Being public does not remove data-protection obligations. Before launch, Creditbase must confirm and document its lawful basis, transparency approach, retention rules and correction process for this processing.

Sources

Creditbase expects to use lawful public and licensed sources relevant to UK commercial-credit intelligence.

  • Companies House company records, filings, officers, PSCs, charges and related events
  • The Gazette statutory notices
  • Public payment-practices reporting where relevant
  • Public procurement data where relevant
  • Corporate judgment information only where lawfully licensed, authorised by the customer or otherwise lawfully available

Lawful bases

The lawful basis depends on the purpose. Likely bases include contract for customer service delivery, legitimate interests for business communications and public-record commercial-credit intelligence, and legal obligation where records must be retained or disclosed by law.

The legitimate-interests basis must be supported by documented assessments before launch, particularly for public-register personal data and any profiling or risk indicators.

Sharing and subprocessors

Creditbase does not intend to sell personal data. Personal data may be shared with Solharbor service providers and subprocessors as necessary to host, secure, support and deliver Creditbase. Customer-directed integrations, such as CRM or workflow systems, may also receive data at the customer's instruction.

The inherited Solharbor DPA contains the current general subprocessor and transfer provisions. A Creditbase-specific subprocessor list must be confirmed before production use.

Retention

Customer personal data should be retained for the customer relationship and deleted or returned under the applicable agreement and DPA, unless legal, security, audit or backup retention is required.

Point-in-time public-record history may need to be retained for research integrity, auditability and historical reconstruction. Exact retention periods must be confirmed before launch.

Your rights

Depending on the processing and lawful basis, individuals may have rights to access, rectification, erasure, restriction, objection and other rights under UK data protection law. Requests can be sent to privacy@solharbor.com or hello@creditbase.co.uk.

Where Creditbase acts only as processor for a customer, Creditbase may refer the request to that customer unless required by law to respond directly.

Open points to confirm before launch

  • Confirm the controller identity, registered address and ICO registration position
  • Complete and record legitimate-interest assessments for public-register intelligence
  • Decide whether a DPIA is required for profiling, graph inference or risk indicators
  • Define retention periods and deletion workflows
  • Finalise the Creditbase-specific subprocessor list and hosting locations
  • Confirm whether analytics, cookies, forms or AI providers are used on the public website or product
  • Confirm the process for Article 14 transparency, corrections, objections and suppression requests