Privacy Policy
Last updated: 23 August 2026 · Effective: 21 September 2026
1. Who we are
Embargo is a trading name of Pintu Holdings Ltd, a company registered in England and Wales (“we”, “us”, “our”). We operate the export control compliance intelligence service available at getembargo.com (the “Service”).
For questions about this policy or your personal data, contact us at privacy@getembargo.com.
2. Data we collect
Name, email address, and organisation name collected at registration. Authentication is managed by Clerk. Google Sign-In users: we receive name and email from Google via Clerk only — no Google password or other account data is accessed.
Entity names, company names, and identifiers submitted for screening — individually, via bulk CSV, or added to your counterparty watchlist. Screening sessions, matched outcomes, and your compliance audit trail are stored in your account.
ECCN classifications and product descriptions entered in Settings (Products You Ship). Used to generate product-specific screening context. Stored in your account only.
Jurisdiction preferences, watchlist entries, keyword alert terms, Slack webhook URL (if configured), and email delivery settings.
Payment card details are processed directly by Stripe and never stored on our servers. We retain only a Stripe customer ID and subscription status.
Standard server logs: IP address, browser type, pages visited, and timestamps. Retention depends on the log purpose, applicable obligations, and the relevant managed provider.
Embargo indexes information from public regulatory, sanctions, export-control, corporate, and news-source records. For identifiable people this may include names and aliases, nationality, dates or places of birth, public identifiers, designation grounds, list history, relationships recorded by a source, and links or headlines used for adverse-media review. Entity pages identify the supporting source where available.
3. How we use your data
- ▸Providing the Service: Delivering regulatory alerts, email digests, and The Embargo Brief based on your jurisdiction preferences; running entity screening checks on names you submit; re-screening your counterparty watchlist after registry updates; generating source-grounded entity intelligence using configured Google Gemini services; and surfacing ownership evidence from public corporate and regulatory sources where available. Unresolved or inferred ownership is not treated as a legal conclusion.
- ▸Compliance audit trail: Recording screening sessions, bulk upload outcomes, and watchlist re-screen results in your compliance journal so you can generate evidence reports.
- ▸Billing: Processing subscription payments and managing your plan via Stripe.
- ▸Communications: Sending service notifications, account alerts, and product updates. You may opt out of marketing emails at any time.
- ▸Security & fraud prevention: Detecting and preventing unauthorised access and abuse.
- ▸Legal compliance: Meeting our obligations under applicable law.
4. Legal basis for processing (UK GDPR)
We process your personal data under the following legal bases:
- ▸Contract (Article 6(1)(b)): Processing necessary to deliver the Service you have subscribed to.
- ▸Legitimate interests (Article 6(1)(f)): Security monitoring, fraud prevention, and product improvement.
- ▸Legal obligation (Article 6(1)(c)): Where required by law.
5. Sub-processors and third parties
We use the following service providers to deliver the Service. Provider roles and locations are listed below; contact us for the current contractual and international-transfer documentation relevant to your use.
| Provider | Purpose | Location |
|---|---|---|
| Clerk | User authentication, session management, and Google OAuth sign-in | United States |
| OAuth identity provider for Google Sign-In via Clerk, and Google Gemini for source-grounded enrichment, classification, drafting, and evaluation tasks. Google Sign-In provides name and email only. Public regulatory or entity evidence may be sent separately to configured Google AI services. | United States | |
| Supabase | Database hosting, storage, and row-level-secure data access | United States |
| Stripe | Payment processing and subscription management | United States |
| Resend | Transactional and digest email delivery | United States |
| GLEIF | Legal Entity Identifier (LEI) data for ownership chain resolution We query publicly available corporate registry data only. No personal data is sent to GLEIF. | Switzerland |
| Vercel | Application hosting, CDN, and edge functions | United States |
Where UK GDPR requires an international-transfer safeguard, the applicable mechanism depends on the provider contract and transfer. Contact us for the documentation currently available for your procurement review.
6. Data retention
We retain personal data only for as long as it is needed to provide the Service, protect its security and evidence integrity, meet legal or accounting obligations, and establish or defend legal claims. The applicable period depends on the data category, the reason it was collected, provider dependencies, and any lawful retention exception.
- ▸Account closure starts review and deletion or anonymisation of account and preference data that is no longer required.
- ▸Screening, monitoring, and audit-evidence records may need to be preserved where deletion would compromise an applicable legal obligation, security investigation, or the integrity of compliance evidence.
- ▸Billing and transaction records are retained only for the period required by applicable financial, tax, and legal obligations.
- ▸Infrastructure and security-log retention depends partly on the relevant managed provider and the purpose of the log.
Contact us at privacy@getembargo.com for the retention criteria that apply to a particular data category or to request deletion. We assess each request under applicable law and will explain any data we must retain and why.
7. Your rights under UK GDPR
As a UK data subject you have the right to:
Request a copy of the personal data we hold about you.
Ask us to correct inaccurate or incomplete data.
Request deletion of your personal data ("right to be forgotten").
Receive your data in a structured, machine-readable format.
Ask us to limit how we process your data in certain circumstances.
Object to processing based on legitimate interests.
To exercise any of these rights, email privacy@getembargo.com. We normally respond within one month, subject to any lawful extension. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
8. Cookies and analytics
We use cookies for authentication sessions (via Clerk) and security. We do not use advertising cookies. These cookies support access to and protection of the Service. If our use changes, we will update this notice and request consent where the law requires it.
We use Vercel Web Analytics to understand aggregate page usage. Vercel states that this service does not use cookies and records anonymised, aggregated data. We do not send names, email addresses, screening queries, or customer-entered data as custom analytics events.
9. Data security
We use TLS for data in transit and managed infrastructure providers that publish their own storage-encryption assurances. At the database layer, a recurring service-role-only census verifies that row-level security is enabled on every application-owned table in the public schema. Bulk registry tables also grant no privileges to public application roles and are accessed server-side using service credentials. Application access is authenticated and organization-scoped. These measures reduce risk but cannot eliminate every security threat.
10. Data-protection complaints
If you believe Embargo has handled personal data incorrectly, email privacy@getembargo.com with the subject “Data protection complaint”. Include enough information for us to identify the relevant account, record, or processing activity, but do not send passwords, payment-card details, or unnecessary identity documents.
We will acknowledge a data-protection complaint within 30 days, investigate it, keep you informed where the investigation remains open, and communicate the outcome without undue delay. This route does not affect your right to complain to the ICO.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email to registered users at least 14 days before taking effect. Continued use of the Service after that date constitutes acceptance of the updated policy.
12. Contact
Pintu Holdings Ltd (trading as Embargo)
Data privacy enquiries: privacy@getembargo.com
Registered in England and Wales