Privacy policy — Prometiam

How Prometiam handles personal data, for both customers of the API and individuals whose details appear in official company registers.

Registry data and lawful basis

Prometiam processes company-officer data published by official public registers. That processing rests on GDPR Article 6(1)(c), the legal obligation under which those registers publish, and Article 6(1)(f), the legitimate interest in fraud prevention, anti-money-laundering and counterparty due diligence. Only data already published by the relevant official register is served.

Data residency

Data is hosted in the European Union (Frankfurt).

Your rights

Individuals may request access, rectification, erasure or restriction of their personal data, and may object to processing. Requests are handled through the contact page. Where data originates from an official register, corrections generally need to be made at the source register for the change to persist through daily updates.

Customer account data

Account email, API key hashes and request metadata are retained to operate the service, enforce quotas and produce billing. API keys are stored only as SHA-256 hashes.

See also the terms of service and the trust and security page.