Duceus
  • Documentation
  • Coverage
  • Pricing
  • Get started
  • Login

Privacy policy

Last updated 4 October 2026

This policy explains what personal data we process when you use the Duceus website and API, and what personal data is contained in the regulatory disclosures we aggregate.

1. Controller

The controller is Duceus ("we"). Contact: support@duceusapi.com.

2. Data we process about customers

  • Account data: email address, password (stored only as a bcrypt hash), optional name, email-verification status and account creation time. Legal basis: performance of the contract with you.
  • Subscription and billing data: your plan, billing period and renewal state. Payment card details are handled by our payment provider (Stripe) and never reach our servers. Legal basis: contract, and our legal obligation to keep accounting records.
  • API usage: the key used, request counts per hour and timestamps, kept to enforce plan limits and to bill correctly. Legal basis: contract and our legitimate interest in running the service.
  • Server logs: IP address, user agent, requested URL and response status, kept for security and troubleshooting for up to 30 days. Legal basis: legitimate interest in keeping the service secure.
  • Where you signed up from: the page on this site where you clicked the signup link, or the campaign tags in the link that brought you to the signup page. Kept with your account to learn which pages bring new users. No cookie is used for this. Legal basis: legitimate interest in improving the site.
  • Emails we send you: account verification, password reset and service notices. We do not send marketing email without your consent.

3. Cookies

We use a single, strictly necessary session cookie (access_token) to keep you logged in. It contains a signed token, not your password, and expires after a short period of inactivity. We do not use analytics or advertising cookies, so there is no cookie banner.

4. Personal data in the disclosures

The data set itself contains personal data: the names and roles of company insiders (persons discharging managerial responsibilities and persons closely associated with them) and of natural persons who cross major shareholding thresholds. These details are published by the individuals' companies and by national regulators because EU and UK law (Art. 19 MAR and the Transparency Directive) requires them to be public.

We process this data on the basis of our legitimate interest in providing a market-transparency service, and in the public interest served by the disclosure regime. We do not enrich it with data from other sources, we do not profile the individuals, and where a source publishes a filing anonymously we keep it anonymous.

If you are named in the data and believe a record is inaccurate, the correction has to be made at the regulatory source; tell us and we will re-import the filing. Requests to remove a record are assessed against the public-disclosure purpose of the underlying regulation; we will remove records that the regulator has withdrawn.

5. Who we share data with

  • Processors acting on our instructions: hosting (Hetzner Online GmbH, Germany), transactional email (Resend, United States) and payments (Stripe Payments Europe, Ireland). Each is bound by a data-processing agreement.
  • Authorities, where we are legally required to.
  • A successor, if the business is transferred; you would be told beforehand.

We do not sell personal data.

6. International transfers

We host in the EU/EEA. Where a processor is outside the EEA, transfers rely on an adequacy decision or the EU Standard Contractual Clauses.

7. Retention

  • Account data: for as long as your account exists, then deleted within 30 days of closure.
  • Billing records: as long as tax and accounting law requires (typically 5–10 years).
  • API usage counters: rolling, purged automatically once the rate-limit window has passed.
  • Server logs: up to 30 days.
  • Disclosure data: indefinitely. The archive is the product, and several national registers purge filings after 12 months.

8. Your rights

Under the GDPR (and the UK GDPR) you can ask us for access to your data, correction, erasure, restriction, portability, and you can object to processing based on legitimate interest. Write to support@duceusapi.com; we reply within one month. You can also complain to your data protection authority.

9. Security

Passwords are hashed with bcrypt, API keys are stored only as hashes, all traffic is encrypted in transit and access to production systems is restricted. No system is perfectly secure; if we learn of a breach that affects you we will notify you and the authorities as the law requires.

10. Changes

We will post updates here and, for material changes, email account holders. See also our terms of service.

Duceus

Insider transactions and major shareholdings across Europe's public registers, in one API.

Product

  • Documentation
  • Coverage
  • Companies
  • Pricing
  • Blog

Contact

  • Get in touch

Legal

  • Terms of service
  • Privacy policy
© 2026 Duceus. All rights reserved.Source data is public regulatory disclosure under MAR and the Transparency Directive; Duceus is not a regulated entity.