Data Protection Policy

All of our metrics are created using public, open data, whether this is sourced from databases such as Companies House and the Charity Commission Register, or collected by visiting public- facing company websites. Our data refers exclusively to companies, VCSEs and other organisations, and not to individual persons, and hence does not come under the remit of regulations covering personally identifiable information (such as the GDPR/ UK GDPR or Data Protection Act).

We apply the following principles when accessing and processing data from the open web and from publicly available datasets:

 We only access data from public-facing company websites, and information maintained in the public domain by responsible bodies (e.g. Office for National Statistics, Companies House).

• We seek to use recognised and supported APIs where available.

• We minimise the burden we place on company websites by limiting the depth to which we read them.

• We pledge to honour any policies requesting that we refrain from collecting data from particular websites, as well as to uphold the right of any organisation to retroactively opt out of our data.

• We do not provide our customers or any other party with personally identifiable information, even when that data is available on the public sites or databases we consult.

• We commit to monitoring the legal and regulatory situation with regards to data collection and data sharing, and to update our policies as appropriate.