DE

Legal

Privacy Policy

Version 1.8 · Effective 4 September 2026

Stonewake is a research and evidence platform for banks. It is operated by Stonewake, Inhaber: Luca Diaz Hilterscheid, Märkische Heide 5, 14532 Kleinmachnow, Deutschland ("we", "us"). General and privacy contact: contact@stonewake.ai.

This policy covers the marketing website and the Stonewake product (the dashboard banks log into). It explains what personal data we process, why, for how long, who receives it, and your rights. It is written to be read; where a legal basis is cited, it refers to Regulation (EU) 2016/679 (GDPR).

1. The five situations in which we touch personal data

We act in two different legal roles, and it matters which one applies to you:

  1. You visit this website. We are the controller. Section 2 applies.
  2. You use the Stonewake dashboard as a member of a customer bank. We are the controller for your account and usage data. Section 3 applies.
  3. A public register publishes data about you (for example a commercial register entry naming you as a managing director) and our software mirrors that register. We are the controller for this processing. Section 4 summarizes it; the full transparency notice is the Public Records Notice.
  4. A bank instructs research about you (for example an adverse-media screening as part of its statutory customer due diligence). The bank is the controller; we process on its documented instruction as a processor under Art. 28 GDPR. Section 5 explains what that means for you.
  5. We write to you about Stonewake. You work in export or trade finance and we contact you at your work address about our services, based on public professional data. We are the controller. Section 6 applies.

2. Website visitors

Hosting and server logs. This website is delivered by a specialised hosting provider over a global content delivery network; its server functions run in the United States (Section 8). When you open a page, the hosting infrastructure processes the technical data any web request carries: IP address, requested URL, timestamp, browser and device information (user agent), and the referring page. We use these server logs to deliver the site, keep it secure, and diagnose faults. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in operating a secure, functioning website). Log data is kept for the short rotation window of the hosting provider, at most three days, and is not merged with any other data.

No cookies, no tracking. The marketing website sets no cookies, uses no analytics, no tracking pixels, and no third-party advertising or social-media embeds.

Demo requests. If you submit the demo form, we process the data you enter (name, work email, institution, optional message) solely to respond to your request. The submission is delivered to our mailbox by a transactional email delivery provider operating in the United States (Section 8). We keep demo requests as ordinary business correspondence and delete them on request at any time. Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a contract, taken at your request) and Art. 6(1)(f) GDPR (our interest in answering inquiries). The form is protected by a rate limit that briefly holds request counts per IP address in memory; nothing about this is stored durably.

Email contact. If you email us, we process your address and message to handle the correspondence, on the same legal bases as demo requests.

3. Product users (the dashboard)

If your bank is a customer of Stonewake and gives you access, we process:

  • Account data: name, work email address, your role in the workspace (for example analyst or administrator), your bank (tenant) and team assignment, and authentication events. Authentication is operated through a managed authentication service hosted in the United Kingdom (Section 8); sign-in links can be sent by email. Legal basis: Art. 6(1)(b) GDPR (performance of the usage relationship) in conjunction with the contract with your bank.
  • Strictly necessary session information stored in your browser. The dashboard stores sign-in session information in your browser (first-party cookies set by the sign-in client; the dashboard sends your session token to our API with each request) whose only purpose is to keep you signed in, and a small set of interface preferences (for example that you have completed the product tour). Both serve only the service you requested; no consent is needed for them (Section 25(2) TDDDG). The dashboard sets no tracking cookies and contains no analytics.
  • Audit records. The product keeps an append-only audit ledger of material actions: who started a screening, who confirmed or dismissed a verdict, who exported a report, with timestamps and prior states. This ledger exists so that the work banks do in Stonewake is reviewable by them and by their auditors, and so that security incidents can be investigated. Legal basis: Art. 6(1)(f) GDPR (auditability and security of a tool used for regulated work) and, where applicable, Art. 6(1)(c) GDPR.
  • Support communications: whatever you send us when something breaks, used to fix it.

We do not profile dashboard users, we run no usage analytics on individuals, and we never use product data for advertising.

4. The public-records graph (summary)

Stonewake maintains a database of facts published by official company registers and gazettes: companies, their officers and beneficial owners, insolvency publications, entity identifiers. Where a register publishes data about a natural person acting in a business capacity (directors, authorized representatives, beneficial owners, sole traders), our software stores what the register publishes, with a citation to the register entry for every fact.

For this processing we are the controller, on the legal basis of Art. 6(1)(f) GDPR. The complete transparency notice under Art. 14 GDPR, including every named source, the retention clocks, the objection mechanism, and our no-scoring commitment, is published permanently at /public-records-notice. The short version:

  • We process only what registers themselves publish, in professional capacity.
  • Every fact carries a citation. We add nothing, we infer nothing, and we never compute a score, rating, or ranking about any person.
  • Statutory deletion clocks of the source registers are enforced in code.
  • Objections go to contact@stonewake.ai and are answered within one month.

5. Bank-instructed processing (we act as processor)

When a bank uses Stonewake to run a screening or assemble a research dossier on a named subject, including a natural person in a professional capacity as part of the bank's anti-money-laundering due diligence, the bank determines the purpose and is the controller under Art. 4(7) GDPR. We process on the bank's documented instruction under a data processing agreement per Art. 28 GDPR concluded with each customer bank.

Within that role: screenings run only on the bank's instruction, each with a recorded due-diligence purpose; results are isolated per customer bank; findings are quotes from cited public sources, and no person-level score, rating, ranking, or probability value exists anywhere in the product; a screening can be erased on demand, and every screening has a retention horizon enforced by an automated purge.

If your data was processed in a bank-instructed screening, the bank is your first point of contact for GDPR rights; its own privacy notices govern. If you contact us instead, we will forward your request to the responsible bank and help resolve it within the processor role.

6. Business contact data for outreach

Stonewake is sold to banks, export credit agencies, and advisory firms. To reach the professionals who would use it, we keep a small outreach list of people who work in export and trade finance, and we write to them at their work addresses about our services. We are the controller for this processing (Section 13 has our details). This section is the transparency notice under Art. 14 GDPR for that list; the first message you receive from us refers to it.

What we hold. Name, role or job title, organization, business contact details (work email address, office address), the URL of a public professional profile, and the public evidence for the role, for example a register entry, a conference program, or a trade-press article naming you in that role. We hold no private contact details, no special categories of data, and nothing about you outside your professional function.

Where it comes from. Public company registers, company websites, professional networks such as LinkedIn, press and trade media, conference materials, and B2B data providers.

Purpose and legal basis. The sole purpose is to contact you, in your professional capacity, about Stonewake's services. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in direct marketing to professionals, an interest recital 47 GDPR recognizes). The balancing is short: we hold business-context data only, we approach you strictly in your professional role about a product built for that role, and the volume of our outreach is low.

Recipients. Outreach data is shared only with our delivery providers, acting as processors for us: an email delivery provider operating in the United States (Section 8) and a letter printing and postal delivery provider in Switzerland (Switzerland holds an EU adequacy decision). Section 7 describes them.

Retention. We keep outreach records until you object or until the outreach purpose ends, whichever comes first. After an objection we delete the record and keep only a minimal suppression entry (name and email address) for as long as we run outreach at all, because honoring your objection permanently requires remembering not to contact you again.

Your rights, and how to object. Art. 21(2) GDPR gives you an unconditional right to object to direct marketing at any time. An objection needs no reason and takes immediate, permanent effect: we stop contacting you, and your data is never again processed for outreach. Reply to any message we send, or write to contact@stonewake.ai. You also have the rights of access, rectification, and erasure, and the right to lodge a complaint with a supervisory authority; Section 10 explains them and names the authority responsible for us.

No automated decision-making. Outreach involves no decision within the meaning of Art. 22 GDPR (see Section 11). A person decides whom to contact and a person writes to you.

7. Recipients and subprocessors

We share personal data only with service providers in the categories listed here, under data processing agreements, and with customer banks in the ways described above. We never sell personal data.

  • Hosting and database infrastructure. The product database and backend run on infrastructure in the European Union and the United Kingdom. This website and the dashboard front end are delivered through a global edge network whose server functions run in the United States under the safeguards described in Section 8.
  • Email and postal delivery providers. Used for transactional email (demo requests) and for the outreach messages described in Section 6; the outreach delivery providers are described there. Processing takes place in the United States (EU standard contractual clauses and, where available, EU-US Data Privacy Framework certification, Section 8) and in Switzerland (EU adequacy decision).
  • Business email and correspondence. Our mailbox, through which inquiries, data-subject requests, and notices to customer banks travel, is operated by a business email and productivity suite provider whose processing takes place in the United States under its EU-US Data Privacy Framework certification (Section 8).
  • AI inference providers. Language-model and embedding APIs used for extraction, verification, and drafting over public web text. Processing may occur outside the EEA, including in the United States, Singapore, and the People's Republic of China; Section 8 describes these transfers and the applicable safeguards.
  • Web search and data providers. Search and data-access APIs used by the research engine to query and fetch public web content, primarily in the United States, under the safeguards described in Section 8.
  • Observability. Prompts and model outputs are stored only on our own infrastructure in the European Union.

What actually reaches the AI and search providers: page text fetched from public web sources, search queries, and research prompts. For a bank-instructed person screening, the subject's name necessarily appears in the search queries and the fetched text. Account data, audit records, and the product database never leave our hosting and database infrastructure.

A full, current list of the processors and subprocessors we use is available on request via contact@stonewake.ai.

8. International transfers

Product data at rest (the database, files, audit records) stays in the provider regions named above: Finland (European Union) and the United Kingdom. Transfers to the United Kingdom rest on the European Commission's adequacy decision for the UK (reviewed and renewed 2025), valid to 27 December 2031. Where a provider processes data in the United States, we rely on the provider's EU-US Data Privacy Framework certification where the provider is certified, and on the EU standard contractual clauses where the provider has incorporated them. Search queries naming individuals are routed only to providers with recognised transfer safeguards. Three providers in our search ensemble publish no such safeguards (one of them wired but not yet enabled) and receive company and entity queries only; such a query can incidentally contain a personal name, for example where a business trades under its owner's name. Transfers to Israel (our public-page retrieval provider) rest on the European Commission's adequacy decision for Israel.

We state the exception plainly rather than hiding it in a list: the group behind our current language-model provider is headquartered in the People's Republic of China, and the entity we contract with for the interface we use operates from Singapore and states that it processes the API data there. Neither country has an adequacy decision, and no transfer safeguard framework applies to either. What the provider receives is public web page text, research prompts, and, in bank-instructed screenings, subject names inside queries. An inference endpoint operating from the European Union is the committed replacement, at the latest at the start of the first paid customer relationship; until that replacement is deployed, this policy states the transfer plainly.

9. How long we keep data

DataRetention
Server logs (website)Short provider rotation window, at most three days (Section 2)
Demo requests and email correspondenceUntil handled and as business correspondence; deleted on request
Outreach business contact dataUntil objection or the end of the outreach purpose; after an objection only a minimal suppression entry remains (Section 6)
Dashboard account dataUntil the account is removed and the contract with the bank ends, then deletion subject to statutory retention duties
Audit ledgerDuration of the customer relationship plus statutory retention; identifiers-only entries persist under the append-only design
Bank-instructed screeningsRetention horizon set per screening by the bank, enforced by a daily purge job; erasable on demand at any time
Public-register factsPer the Public Records Notice: while the source register publishes the fact, subject to objection
Insolvency publications naming a personAt most 180 days, inside the source register's own six-month deletion clock (Section 3 InsBekV)
Database backupsEncrypted rolling backups, seven daily full backups, kept for at most seven days

10. Your rights

You have the rights of Art. 15 to 21 GDPR: access, rectification, erasure, restriction, data portability, and objection. Where processing rests on legitimate interest, Art. 21 GDPR gives you the right to object on grounds relating to your particular situation; for the public-records lane, the Public Records Notice describes exactly how we handle objections and how quickly (within one month).

Requests go to contact@stonewake.ai. We answer within one month (Art. 12(3) GDPR). You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence or workplace. The authority responsible for us is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg (LDA Brandenburg), Stahnsdorfer Damm 77, 14532 Kleinmachnow, lda.brandenburg.de.

11. No automated decision-making

We make no decisions producing legal or similarly significant effects on any person by solely automated means (Art. 22 GDPR). The product computes no score, rating, ranking, or probability value about any natural person, and its outputs are drafts that a human analyst must review. Banks are contractually prohibited from using Stonewake output as the sole basis for automated decisions about natural persons.

12. Changes to this policy

We update this policy when the product or our providers change. The version and effective date at the top tell you what you are reading; material changes to how we process personal data are announced to customer banks in advance and, for the public-records lane, reflected in the Public Records Notice.

13. Contact

Stonewake, Inhaber: Luca Diaz Hilterscheid, Märkische Heide 5, 14532 Kleinmachnow, Deutschland.
General and privacy contact: contact@stonewake.ai.