Privacy Policy
Regtech Radar
Operated by Series B Limited, trading as Regtech Radar.
Last updated: 5 August 2026 · Version 2.0
1. Who we are
Series B Limited, a company registered in England and Wales (company number 09691789), trading as Regtech Radar ("Regtech Radar", "we", "us", "our"), operates the Regtech Radar directory (the "Service").
We are the controller of the personal data described in this policy. We decide what data is collected and why. We are not a processor acting on any provider's or buyer's instructions.
Contact
Series B Limited, 1 Everest Road, Cheltenham, GL53 9LA, United Kingdom
privacy@theregtechradar.com
2. Which law applies and where
This policy explains how we handle personal data under:
- the UK GDPR and the Data Protection Act 2018, for our processing as a UK-established controller; and
- the EU GDPR, to the extent we offer the Service to people in the European Economic Area or monitor their behaviour there.
We also comply with the Privacy and Electronic Communications Regulations 2003 ("PECR") in relation to cookies and electronic marketing.
3. Who this policy covers
- Providers: people who create an account to list a regtech product.
- Buyers: people who browse the directory. Buyers do not need an account. We still process limited data about buyer activity, described in section 8.
- Listed contacts: individuals named on a provider's listing as a point of contact, who may not have an account themselves.
- Prospects: individuals at regtech companies whose business contact details we hold so that we can invite them to list.
- Website visitors generally.
4. What we collect
Account and provider data. When a provider creates an account and builds a listing: name, job title, work email address, company name, and the content added to the listing (product descriptions, capability tags, case studies, client references, outcome metrics, logos, links and similar). Some of this is company information rather than personal data. Where it identifies an individual, we treat it as personal data.
Listed contact details. Where a listing names an individual as its contact, we hold that person's name, job title, work email address and, where supplied, telephone number.
Buyer enquiry data. When a buyer sends an enquiry to a provider through the Service, we process the content of that enquiry and any details the buyer chooses to include, such as their name, work email address and company.
Payment data. Payment is handled by Stripe. We do not receive or store full card details. We receive limited billing information: billing name, billing country, VAT or tax identification number where supplied, subscription status, and the card type and last four digits.
Usage and event data. We record how the Service is used: pages viewed, searches run and the terms used, listings viewed, providers added to a comparison and which providers are compared together, contact reveals, outbound link clicks, and similar interactions. For buyers without an account, this activity is linked to a session identifier rather than to a named person.
Technical data. IP address, approximate location derived from IP at country and region level only, browser type and version, device type, operating system, referring URL, and timestamps.
Prospect data. Business contact details of individuals at regtech companies: name, job title, work email address, company, and the source we obtained them from.
Communications. Records of correspondence with us, including support and sales enquiries.
We do not knowingly collect special category data (health, race, religion, political opinions, trade union membership, biometric or genetic data, sex life or sexual orientation) or criminal offence data. Please do not include such data in a listing, an enquiry or a message to us.
5. Where we get prospect data, and what we do about it
For business development we obtain business contact details of regtech providers from third-party data providers and from public sources, so that we can invite them to list on the Service.
The categories of source are: business contact-data providers (such as Apollo), public LinkedIn profiles, company websites, and published industry reports.
Where we obtain personal data this way, we tell the individual which categories of source it came from, and why we hold it, no later than our first communication with them, as Article 14 of the UK GDPR requires. Every such communication carries a one-click means of objecting. If you object, we stop and add the minimum necessary details to a suppression list so that we do not contact you again.
6. Why we use your data, and our lawful bases
| Purpose | Personal data used | Lawful basis |
|---|---|---|
| Creating and managing provider accounts and listings | Account and provider data | Contract with the provider organisation; legitimate interests in operating the Service |
| Publishing listings, including named contacts, so buyers can find providers | Account, provider and listed contact data | Legitimate interests in operating a directory that works |
| Enabling buyers to browse, search, compare and reveal contact details | Usage, event and technical data | Legitimate interests in providing a functioning directory |
| Passing a buyer's enquiry to a provider | Buyer enquiry data | Legitimate interests in connecting buyers and providers |
| Taking payment and managing subscriptions | Payment data | Contract; legal obligation for tax and accounting records |
| Producing performance reports for providers | Aggregated usage and event data | Legitimate interests in providing the Service and its features |
| Producing aggregated and anonymised market intelligence | Usage and event data, aggregated and anonymised as described in section 8 | Legitimate interests, until the point of anonymisation; after that, the data is not personal data and data protection law no longer applies to it |
| Inviting regtech providers to list | Prospect data | Legitimate interests, subject to PECR (see section 11) |
| Securing the Service, detecting scraping and preventing misuse | Usage, technical and account data | Legitimate interests; legal obligation |
| Responding to enquiries and providing support | Communications | Contract; legitimate interests |
| Marketing our own services to existing customers | Account data | Legitimate interests, subject to PECR (see section 11) |
| Establishing, exercising or defending legal claims | Any of the above, as relevant | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests do not override your rights and freedoms. You can ask for a summary of any of these assessments, and you can object to legitimate-interests processing under section 17.
7. Named contacts on listings
Where a provider names an individual as the contact on its listing, we rely on the provider's confirmation that it has that person's authority to publish their name, job title and contact details. Our Terms of Service require that confirmation.
If you are named on a listing and you did not agree to it, or you no longer want to be, email privacy@theregtechradar.com. We will remove or replace your details, and we will tell the provider that we have done so. You do not need to go through the provider first.
8. Buyer activity, provider reporting and market intelligence
Recording how buyers use the Service is central to how the Service works and to how we make money. This section sets out exactly what a provider can see and what we do with the rest.
What we record. Searches, filters applied, listings viewed, comparisons run and their composition, contact reveals, and enquiries sent.
What providers can see. Providers receive reports about their own listing. Those reports contain counts and aggregates only. They include figures such as views, reveals, and which other providers their listing is most often compared against. They also include buyer distribution by country and by broad company-size band. Where a report describes the type of organisation showing interest, it does so only in general, non-identifying terms, for example "a large public payments company", and never names an individual buyer or an individual buyer's employer.
Providers cannot see the identity of any individual buyer, the name of any buyer's company, any buyer's IP address or session identifier, or any figure derived from fewer than five distinct sessions in the reporting period. Where a figure would fall below that threshold, we suppress it rather than round it.
The one exception. If a buyer reveals a provider's contact details and then sends an enquiry, the provider receives whatever the buyer chose to put in that enquiry. That is a deliberate act by the buyer. Revealing contact details alone does not tell the provider who did it.
Market intelligence. We aggregate usage and event data across the Service to produce market-intelligence outputs, which we may publish or sell. Before any data enters those outputs we strip direct identifiers, remove the session identifier, and aggregate to a minimum cohort of five distinct sessions. We do not attempt to re-identify anyone from these outputs and we require the same of anyone we license them to. Once anonymised in this way the data is no longer personal data, and we use and share it without restriction.
9. Listings we create before a provider claims them
Some listings are created by us from publicly available information about a provider, before that provider has an account. These listings are marked as unclaimed. They contain company information and product information only. They do not name an individual contact, and they do not contain any personal data beyond what the company itself has published about its own business.
A provider can claim its listing at any time by verifying control of its email domain. A provider can ask us to remove an unclaimed listing entirely by emailing us, and we will do so.
10. Cookies and similar technologies
We use cookies, a session identifier and similar technologies. They fall into two groups.
Strictly necessary. These run without your consent, because the Service does not work without them.
| Purpose | Retention |
|---|---|
| Keeping you signed in | Session, or 30 days if you choose to stay signed in |
| Remembering the providers in your comparison | 30 days |
| Security and cross-site request forgery protection | Session |
| Remembering your cookie choices | 12 months |
Analytics and market intelligence. These run only if you consent. They record the usage and event data described in section 8 and support the reporting and market-intelligence products described there.
| Purpose | Retention |
|---|---|
| Session identifier used for usage analytics | 13 months |
How to control this. We ask for your consent through a banner the first time you visit. You can accept, reject, or choose by category. Rejecting analytics does not restrict your access to any part of the Service. You can change your choice at any time through the "Cookie settings" link in the footer. You can also block or delete cookies in your browser, though blocking strictly necessary cookies will stop parts of the Service from working.
11. Direct marketing
Providers we invite to list. We send business-to-business email inviting regtech companies to list. Where the recipient is a corporate subscriber (a limited company, LLP or equivalent body), PECR permits this without prior consent. Where the recipient is an individual subscriber (a sole trader, or a partnership that is not an LLP), we send marketing email only with consent or where the soft opt-in applies. Every message identifies us and carries a one-click unsubscribe.
Existing customers. We may email existing providers about features, pricing and similar products. Every message carries an unsubscribe link.
Objecting. You can object to direct marketing at any time, for any reason or none, and we will stop. Use the unsubscribe link or email privacy@theregtechradar.com. We keep a minimal suppression record so that we can honour your objection.
12. Who we share your data with
| Recipient | Why | Where |
|---|---|---|
| Vercel | Hosting the Service | United States, with data processing safeguards |
| Supabase | Primary database | Ireland (EU) |
| Stripe | Taking payment, billing | United States, with data processing safeguards |
| Resend | Transactional and marketing email | United States, with data processing safeguards |
Each of these acts on our instructions under a written contract that meets Article 28 of the UK GDPR.
We also share data:
- with providers, where a buyer sends them an enquiry, as described in section 8;
- with our professional advisers, including lawyers and accountants, where needed;
- with authorities or third parties, where required by law, to enforce our Terms, or to protect our rights, our users or the public;
- with an acquirer or successor, in connection with a merger, acquisition or sale of assets, subject to that party being bound to protections no weaker than those in this policy.
We do not sell personal data that identifies you. We do sell aggregated and anonymised data, which does not.
13. International transfers
Our primary database is hosted in the European Union (Ireland). We process data in the United Kingdom and the European Union. Some of our suppliers process data in the United States, as shown in the table in section 12.
Where we transfer personal data outside the UK or the EEA, we rely on one of the following: an adequacy decision or adequacy regulations; the UK Extension to the EU-US Data Privacy Framework, where the recipient is certified; the International Data Transfer Agreement or the Addendum to the EU Standard Contractual Clauses; or the EU Standard Contractual Clauses. We carry out a transfer risk assessment where one is required.
You can ask us for a copy of the safeguards we rely on for any specific transfer by emailing privacy@theregtechradar.com.
14. How we protect your data
We maintain technical and organisational measures appropriate to the risk, including:
- encryption of data in transit using TLS 1.2 or above, and encryption at rest for our primary database;
- role-based access control, with access limited to those who need it, and multi-factor authentication on administrative accounts;
- no storage of full payment card details on our systems;
- written confidentiality obligations on everyone with access.
If a personal data breach occurs, we assess it and, where the legal threshold is met, report it to the ICO within 72 hours of becoming aware of it, and to affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
15. How long we keep your data
| Data | Retention |
|---|---|
| Provider account and listing data | Life of the account, then 12 months after closure |
| Billing and transaction records | 6 years from the end of the accounting period they relate to |
| Buyer enquiry content | 24 months from the date sent |
| Contact reveal records | 24 months |
| Usage and event data linked to a session identifier | 13 months, then aggregated or anonymised |
| Server and access logs, including IP address | 90 days |
| Prospect data | 24 months from the last engagement, then deleted |
| Suppression list entries | Kept indefinitely, minimal data only, so that we can honour your objection |
| Correspondence | 3 years, or 6 years where it relates to a dispute or potential claim |
| Aggregated and anonymised data | Indefinitely; this is not personal data |
Where we are required to keep data longer by law, or need it to establish, exercise or defend a legal claim, we keep it for that purpose and no other.
16. Automated decision-making, profiling and AI
We do not make decisions about you that produce legal effects or similarly significant effects using automated processing alone.
We do not use your personal data to train machine-learning models, and we do not make your personal data available to third parties to train theirs. Where we use AI tools internally, for example to categorise or summarise publicly available company information, we do not input personal data from accounts, enquiries or usage records into those tools.
17. Your rights
Under the UK GDPR and, where it applies, the EU GDPR, you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data in certain circumstances;
- restrict our processing in certain circumstances;
- object to processing based on legitimate interests, including profiling, on grounds relating to your particular situation;
- object to direct marketing at any time, absolutely and without giving a reason;
- data portability, where processing is based on consent or contract and is carried out by automated means;
- withdraw consent where we rely on it, at any time, without affecting processing carried out before you withdrew it.
How to exercise them. Email privacy@theregtechradar.com. We respond within one month. We may extend that by up to two further months where a request is complex or where you have made several requests, and we will tell you within the first month if we do. We do not charge a fee unless a request is manifestly unfounded or excessive.
Identity. We may ask you for information to confirm who you are, and to identify which data relates to you. We ask for the minimum needed.
A limit on what we can do for buyers without accounts. Buyers browse without an account, and the resulting data is linked to a session identifier rather than to a name. Where we cannot identify you from the data we hold, Article 11 of the UK GDPR does not require us to obtain additional data solely to comply with a request. If you can give us the session identifier or other information that lets us locate the data, we will act on it.
18. Account closure and deletion
To close your account, email privacy@theregtechradar.com. We acknowledge within 5 working days and complete closure within 30 days.
On closure we delete or anonymise the personal data associated with your account, subject to the retention periods in section 15 and to any legal obligation to keep it. Your listing is removed from the directory on closure.
Usage and event data that has already been aggregated or anonymised is not reversed and does not identify you.
19. Children
The Service is for business users. It is not directed at children and we do not knowingly collect personal data from anyone under 18. If you believe we hold data about someone under 18, email privacy@theregtechradar.com and we will delete it.
20. Changes to this policy
We may update this policy. The current version is always on the Service with the date and version number at the top.
Where a change materially affects how we use your personal data, we will notify account holders by email at least 14 days before it takes effect.
21. Contact and complaints
Series B Limited, trading as Regtech Radar (company number 09691789)
1 Everest Road, Cheltenham, GL53 9LA, United Kingdom
privacy@theregtechradar.com
If you are unhappy with how we have handled your personal data, please tell us first and give us the chance to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
If you are in the EEA, you may also complain to the supervisory authority in your country of residence, work or the place of the alleged infringement.