Last updated 9 October 2026

This notice explains how unbackoffice ("we", "us") handles personal data on Screen Terminal: this website and the screening API at https://screen.unbackoffice.com. We are the controller of the data described here, except where section 3 says otherwise. Contact us by email at privacy@daertho.com, or on WhatsApp at +35797439775.

1. Your account

When you sign in with Google we get and keep:

  • your name, work email address, Google account ID and your company's Google Workspace domain;
  • when you signed in, your IP address and your browser's identifying string;
  • your referral code, who referred you, and how many people you referred;
  • your keys, stored only as a one-way hash, with how many screens each has used and has left;
  • any paid tier or screens we add for you, with the invoice reference.

Why: to run your account and keys, count screens, handle referrals and purchases, and prevent abuse such as fake accounts or going over limits. Legal basis: performing our agreement with you, and our legitimate interest in keeping the service secure and fair.

2. What you screen

For each request we keep a record of what you sent (names, dates of birth, countries, other name forms), the result, the time, your key, your IP address and your browser's identifying string.

Why: to return results, to keep an audit trail of each screen, and to detect misuse. Legal basis: our legitimate interests in providing a reliable, auditable and secure service.

Searches before you sign in: we keep the name and details you searched, the time, your IP address and your browser's identifying string, under the same time limit as other screening records. To enforce the daily limit we also keep a one-way hash of your IP address for two days. Before your first search, Cloudflare Turnstile checks that you are a person.

If a name is written in a non-Latin script (for example Arabic, Chinese or Korean), we send that name to Anthropic, whose Claude model returns its standard Latin spellings. We keep that answer for up to 90 days so the same name is not sent again.

3. Your responsibilities for the people you screen

You decide whom to screen and why. For that, you are the controller of the data you send, and you need a lawful basis to screen each person. We process it to give you the result and keep the record described in section 2. Don't send more than you need: a name, and a date of birth or country if you have them.

4. People in our screening data

Our screening data is about politically exposed persons, their relatives and close associates, and people and entities on sanctions, watch and debarment lists. We collect it from public sources: official government, parliament and regulator publications, published sanctions and enforcement lists, official registers, and open reference data such as Wikidata.

It can include names and other name forms, date of birth, nationality, public positions and their dates, published family or business links, and the source of each fact.

Why: to help businesses meet their anti-money-laundering, counter-terrorist-financing and sanctions obligations. Legal basis: our legitimate interests, and those of our users, in preventing financial crime, as these laws require. If you think we hold data about you, you can ask to see it, correct it, or object, using the contact details above. We review every request and keep a record of the sources we rely on.

5. Who we share data with

We don't sell personal data, show ads, or use analytics or tracking. We use these providers:

  • Google: sign-in.
  • Hetzner: hosts our servers and database in the European Union.
  • Anthropic (USA): reads non-Latin names in signed-in searches, as described in section 2. Anthropic does not use this data to train its models.
  • Cloudflare (USA): Turnstile checks for bots before searches without sign-in. Cloudflare receives your IP address and browser details when the check runs.
  • WhatsApp (Meta): only if you choose to message us there.

We may also disclose data where the law requires it, or to protect our rights or the safety of others.

6. Transfers outside Europe

Google, Anthropic, Cloudflare and Meta may process data in the United States. Those transfers rely on the safeguards each provider offers under data protection law, such as the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.

7. Cookies

We only use cookies needed to sign in, to count free searches and to make referrals work. There are no analytics or advertising cookies.

cookiepurposelasts
st_sessionkeeps you signed in7 days
st_oauthsecures the Google sign-in step10 minutes
st_revealshows a new key to you once, encrypted10 minutes
st_refremembers the referral link you arrived from30 days
st_anoncounts your free searches and remembers the bot check24 hours

8. How long we keep data

  • Account and key records: while your account exists.
  • Screening records, and the IP address and browser details logged at sign-in: 12 months, then deleted automatically. Sooner if you ask.
  • Romanised names: up to 90 days.
  • Hashed IP addresses used for the daily search limit: 2 days.
  • When you ask us to close your account, we delete your account and screening records, except what we must keep by law or to deal with a dispute or abuse.

9. Security

All traffic uses HTTPS. Keys are stored only as one-way hashes. Access to our systems is limited to the people who run the service.

10. Your rights

You can ask to see, correct, delete, restrict or move your data, and you can object to processing based on legitimate interests. Contact us by email at privacy@daertho.com, or on WhatsApp at +35797439775. We will reply within one month. You can also complain to your data protection authority.

11. Changes

We may update this notice. The date above shows the latest version.

Terms·Privacy·API docs