1. Who we are
fernandes.media limited (trading as inc:tdy, incorporated:today and incorporated.today) is the data controller for your account information, subscription metadata, platform logs, and the UK Companies House registry data we cache and index on our systems.
- Company number: 17256342
- Registered office: 66 Dulverton Road, Leicester, LE3 0SA, England
- Privacy & data subject requests: info@incorporated.today
- ICO registration: We are not currently registered with the Information Commissioner's Office (ICO).
2. Controller and processor roles (enrichment)
To understand your privacy rights on our platform, you need to distinguish between two separate processing roles:
We act as a data controller for:
- Account management (name, email, settings, watchlists, contacted flags, encrypted company notes, saved searches)
- Subscription and billing metadata held in our application database
- Platform usage and security logs (see section 3)
- Public corporate records from Companies House that we ingest, cache, and index — including officer and signatory names derived from statutory filings
We act as a data processor (Pro and Executive tiers only) for:
Contact enrichment via licensed third-party data providers when you explicitly click Get contact details for a company. We fetch on your instruction and return results to your active browser session. By default we do not write emails or telephone numbers to Postgres or our Typesense search index. If you click Save in the Inspector Contacts tab, those contact fields are stored encrypted in Postgres, scoped to your account — see our DPA. A fresh lookup requires a new action.
The subscribing customer (or their organisation) is the data controller for any outbound use of that contact data — including cold outreach, marketing sequences, and compliance with PECR and the TPS/CTPS registers. See our Data Processing Agreement for processor terms on enrichment.
3. Personal data we collect
Personal data means information about an identifiable individual. We collect and process the following categories:
| Category | Examples | Where stored |
|---|---|---|
| Identity | Name (optional display name on sign-up) | Postgres — users table |
| Contact | Email address | Postgres — users table |
| Account & preferences | Colour palette choice, watchlist entries, contacted flags, encrypted company notes, saved search queries, team member invitations (Executive plan only), and optionally saved enrichment contacts you explicitly save (encrypted) | Postgres |
| Saved enrichment contacts (opt-in) | When you click Save on an enrichment result: person name, role, company context, contact fields (email/phone), save timestamp, and data provider source. Encrypted at rest; strictly per-user; export and delete available; removed on account deletion. | Postgres — saved_contacts (encrypted) |
| Billing & subscription | Stripe customer ID, subscription ID, product/plan name, payment status. Card numbers and billing addresses are handled by Stripe and are not stored on our servers. | Postgres (teams) and Stripe |
| Security & activity | Sign-in and account events with IP address where available | Postgres — activity_logs |
| API usage (admin telemetry) | Endpoint kind, status code, duration, company number and fetch flags in metadata — no enrichment payloads | Postgres — admin_request_log |
| Public registry data | Company filings, financial metrics, and officer/signatory names from Companies House | Postgres, Typesense (VPS), and transient API responses |
We do not collect job titles, corporate roles, or billing addresses in our application database. During private beta, access may be restricted to authorised email addresses.
Our hosting provider (Vercel) may process standard web server metadata such as IP addresses and request headers as part of delivering the service. We do not store browser fingerprints or device types in our application database.
4. Subprocessors and data sources
| Purpose | Provider | Notes |
|---|---|---|
| Hosting & serverless API | Vercel | EU/US regions — subject to provider DPA |
| Application database | Neon Postgres | Managed cloud database |
| Search index | Typesense (self-hosted) | Dedicated VPS — UK/EU data centre (IONOS) |
| Authentication | Google OAuth | Sign-in via Google (UK/Ireland) |
| Payments | Stripe | PCI-compliant payment processing |
| Contact enrichment | Third-party enrichment API | Pass-through API only — no persistence on our systems |
| Public registry source | Companies House | Official UK company register — open data/API under Companies House terms |
Registry data on incorporated.today (trading as inc:tdy, incorporated:today and incorporated.today) is sourced from UK Companies House. We display attribution on our marketing pages and process public records under our legitimate interests (see section 5).
5. Lawful bases
Performance of a contract (Article 6(1)(b))
We process your name, email, account settings, and subscription data to provide the service you signed up for, including paid tier features and Stripe billing.
Legitimate interests (Article 6(1)(f)) — public registry caching
We ingest, cache, and index public corporate records from Companies House to operate a fast UK company intelligence console for professional researchers and B2B operators. Officer and signatory names in public filings remain personal data; we rely on legitimate interests balanced against individual rights, and security controls limit how that data is exposed. Because this information is already on the public statutory register, providing individual Article 14 notices to every officer may involve disproportionate effort — we assess this position periodically. This section is not legal advice; seek independent counsel if you rely on it for compliance decisions.
Consent (Article 6(1)(a)) — non-essential cookies
Theme preference cookies are set only after you opt in via our cookie banner. See our Cookie policy.
Processor role — third-party contact enrichment
When you trigger contact enrichment, we process data on your documented instructions as a processor. The lawful basis for outbound use of that data is your responsibility as controller.
7. Retention
We retain personal data only for as long as necessary for the purposes described in this policy. The table below sets out our current target retention periods. We are implementing automated deletion routines; until those are fully operational, we will honour erasure requests manually within the statutory response window.
| Data type | Target retention | Notes |
|---|---|---|
| Account (email, name, settings) | Until deletion request, or 24 months after last login | Soft-delete or anonymisation on expiry |
| Watchlists, contacted flags, notes & saved searches | Linked to account lifespan | Removed when account is deleted |
| admin_request_log | 90 days | Company numbers and endpoint metadata only |
| activity_logs & admin_audit_log | 12 months | Security and admin audit trail |
| Stripe payment records | Per Stripe and tax law | Maintained in Stripe |
| Third-party enrichment contacts | 0 days (pass-through) | Never written to our databases |
If you cancel a paid Stripe subscription, your account is not automatically deleted. Paid entitlements end at the close of the billing period (or after Stripe's payment retry window if a charge fails). Your account reverts to the Free tier unless you delete it.
8. Account deletion
- Password accounts: Self-serve soft-delete in Settings. Your email is mangled and the account is flagged with a deletion timestamp, removing it from active use.
- Google sign-in accounts: Self-serve deletion is not yet available in the UI. Email info@incorporated.today and we will process deletion within 30 days.
9. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, or object to certain processing, and to data portability where applicable. To exercise these rights, email info@incorporated.today. We aim to respond within one calendar month at no charge.
Third-party enrichment data: If you are asking us to erase contact details shown during a subscriber's session, we cannot comply from stored records because we do not persist that data. Direct your request to the subscriber who initiated the lookup, or to the relevant upstream third-party enrichment provider.
You may lodge a complaint with the ICO at ico.org.uk. We would appreciate the chance to address your concern first.
10. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Material changes may be notified by email or an in-app notice where appropriate.