Privacy
What we collect, why, and how to make us stop. Written to describe what the software actually does rather than to cover us — if you find something here that does not match what happens, that is a correction and we want it.
Last updated 7 August 2026
Who we are
TrustedFirms is operated by [legal entity name], [registered address], company number [company number]. For anything in this document, write to [privacy@ contact address].
What we collect, and when
| What | When | Why | Kept |
|---|---|---|---|
| Name, work email, company, budget band, your message | You request an introduction to a firm | To make the introduction and follow up once | 24 months |
| Company name, website, your name and email, declared figures, evidence URLs | You apply to be listed | To assess the application against our published rule and tell you the outcome | 36 months, so a re-application can be read against the last decision |
| Name, role, email, and a hash of a verification token | You claim a firm’s profile | To prove you control the domain before we hand you a right of reply | While the claim stands, then 24 months |
| Subject, message, email | You report a correction | To investigate it and tell you what we did | 36 months — corrections are part of the record of what we published |
| A one-way hash of your IP address, and your browser’s user-agent string | Any form submission | Abuse handling only | 12 months |
We do not store raw IP addresses from forms. They are hashed on arrival. A hash is enough to see that one source submitted four hundred applications overnight, and not enough to be worth stealing.
Information about companies
Most of this site is factual information about businesses, gathered from public record — their own websites, their case studies, public registries, public review profiles. Where that information identifies a person (a named founder, an author of a published methodology), we hold it because it is already public and because a directory that could not name who does the work would be useless.
If you are named on this site and would rather not be, tell us. Where the name is not load-bearing for what we are establishing, we will remove it. Where it is — a named individual holding a certification is the evidence — we will say so and explain why, rather than quietly refusing.
Lawful basis for the company research is legitimate interest: publishing checkable information about businesses that sell to other businesses. You can object, and we will weigh it rather than reciting the phrase back at you.
Who else sees it
- The firm you asked to be introduced to — that is the point of the form, and we say so on it. Nobody else. We do not sell the request on and we do not send it to four of their competitors at the same time.
- Hetzner Online GmbH — the servers this runs on, in Ashburn, Virginia.
- ZeptoMail (Zoho) — sends the mail we send you.
- Dodo Payments — if you buy something. They are the merchant of record; we never see or store a card number.
There is no advertising network, no analytics that follows you between sites, and no data broker. If that changes, it changes here first.
Cookies
The public directory sets none. There is no consent banner because there is nothing to consent to — a banner that appears when a site sets no cookies is theatre. Signing in to a dashboard sets a session cookie, because that is what signing in is.
Your rights
Depending on where you live you can ask for a copy of what we hold, ask us to correct or delete it, object to our processing it, or complain to a regulator. Ask at [privacy@ contact address] and we will answer within 30 days.
In the UK the regulator is the ICO; in the EU it is your national data protection authority. You do not have to come to us first, though it is usually faster.