TrustedFirms

Privacy

What we collect, why, and how to make us stop. Written to describe what the software actually does rather than to cover us — if you find something here that does not match what happens, that is a correction and we want it.

Last updated 7 August 2026

Who we are

TrustedFirms is operated by [legal entity name], [registered address], company number [company number]. For anything in this document, write to [privacy@ contact address].

What we collect, and when

WhatWhenWhyKept
Name, work email, company, budget band, your messageYou request an introduction to a firmTo make the introduction and follow up once24 months
Company name, website, your name and email, declared figures, evidence URLsYou apply to be listedTo assess the application against our published rule and tell you the outcome36 months, so a re-application can be read against the last decision
Name, role, email, and a hash of a verification tokenYou claim a firm’s profileTo prove you control the domain before we hand you a right of replyWhile the claim stands, then 24 months
Subject, message, emailYou report a correctionTo investigate it and tell you what we did36 months — corrections are part of the record of what we published
A one-way hash of your IP address, and your browser’s user-agent stringAny form submissionAbuse handling only12 months

We do not store raw IP addresses from forms. They are hashed on arrival. A hash is enough to see that one source submitted four hundred applications overnight, and not enough to be worth stealing.

Information about companies

Most of this site is factual information about businesses, gathered from public record — their own websites, their case studies, public registries, public review profiles. Where that information identifies a person (a named founder, an author of a published methodology), we hold it because it is already public and because a directory that could not name who does the work would be useless.

If you are named on this site and would rather not be, tell us. Where the name is not load-bearing for what we are establishing, we will remove it. Where it is — a named individual holding a certification is the evidence — we will say so and explain why, rather than quietly refusing.

Lawful basis for the company research is legitimate interest: publishing checkable information about businesses that sell to other businesses. You can object, and we will weigh it rather than reciting the phrase back at you.

Who else sees it

There is no advertising network, no analytics that follows you between sites, and no data broker. If that changes, it changes here first.

Cookies

The public directory sets none. There is no consent banner because there is nothing to consent to — a banner that appears when a site sets no cookies is theatre. Signing in to a dashboard sets a session cookie, because that is what signing in is.

Your rights

Depending on where you live you can ask for a copy of what we hold, ask us to correct or delete it, object to our processing it, or complain to a regulator. Ask at [privacy@ contact address] and we will answer within 30 days.

In the UK the regulator is the ICO; in the EU it is your national data protection authority. You do not have to come to us first, though it is usually faster.