Privacy Notice

Sonde Data · Last updated 15 July 2026

Who we are. Sonde Data (“the Service”) is operated by Syndicate Room Ltd (“SyndicateRoom”, “we”, “us”). SyndicateRoom is the data controller for the personal data described in this notice and is registered with the UK Information Commissioner’s Office (ICO). This notice is specific to the Service. It sits under SyndicateRoom’s wider privacy framework; for company-level matters please also see our main privacy policy.

Who this notice is for. This notice explains how we handle personal data in two situations: (1) information about company directors and individual shareholders that the Service draws from public sources; and (2) information about the people who register for and use the Service. The two are explained separately below.

At a glance

  • We show information about companies and the people connected to them, taken largely from the public Companies House register.
  • For individuals in our data, we hold names and (for shareholders) their shareholding, plus an indicative estimated value we calculate. For directors we also hold the month and year of birth exactly as published on the Companies House register, which we use to tell apart different people who share a name. We do not hold full dates of birth or addresses.
  • Our paid users can also search for an individual by name and see their holdings combined across companies, with estimated values and returns. That is profiling, and we explain it in Part A — you can object to it.
  • Our lawful basis for this is legitimate interests.
  • You can ask us to remove you. Contact privacy@sondedata.com and we will deal with your request.

Part A — Information about directors and shareholders

The Service helps users research UK companies and the people connected to them. To do this we process limited personal data about company directors and individual shareholders.

What we collect and where it comes from

Information Source Notes
Director names Companies House public register (officer appointments) Business-capacity information already on the public record.
Director month and year of birth Companies House public register (officer appointments) Month and year only — the register withholds the day and we never infer it. Used to distinguish directors who share a name.
Individual shareholder names and their shareholding (number and class of shares) Companies House CS01 confirmation statements Applies to individual shareholders. Corporate shareholders are not personal data.
An indicative, estimated value of a shareholding Calculated by us using share prices from SH01 filings This figure is produced by us, not taken from the register, and is an estimate only. It may not reflect later funding rounds, dilution, different share classes, or buy-backs.
Company website and a short business description Retrieved via a third-party service (Serper.dev) Company-level information; any personal data is incidental.

What we do not collect: we do not ingest full dates of birth, residential or service addresses, signatures, or any special category data.

Source attribution. The Service contains public sector information licensed under the Open Government Licence v3.0. Source: Companies House.

Why we process it (purpose) and our lawful basis

Purpose. We make public-register information more useful for legitimate business research — investment screening, due diligence and market mapping — by our users (typically angel investors, small funds, founders and advisers).

Lawful basis: legitimate interests (Article 6(1)(f) UK GDPR). Our legitimate interests, and those of our users and the wider interest in corporate-register transparency, are in providing and using this research tool. We have weighed these interests against your rights in a documented Legitimate Interests Assessment, and have minimised what we hold (names and holdings only) and how it can be used. That assessment covers not just the company-by-company record but also combining an individual’s holdings across companies — see “Searching for an individual” below, which explains that processing and how to object to it. You can ask us for a summary of the assessment.

Searching for an individual, and combining their holdings across companies

The Service is not only a company-by-company record. A user can search for a person by name and see the holdings we have matched to them across every company we cover, brought together in one view. Two features do this, and we describe them here because they go further than simply republishing a filing:

  • Investor search. The same person is often written differently from one filing to the next, so we match names rather than compare them literally: we normalise the name and match on nicknames (for example “Bill” and “William”), initials, reordered or middle names, common misspellings, and how a surname sounds. A search can therefore return holdings filed under name forms other than the one searched for.
  • Portfolio analysis. Where a user confirms that matched holdings belong to the same person, we combine them into a portfolio view: which companies they hold, when they first appeared and how the holding changed over time, an indicative estimated value for each, an estimated total invested, and estimated return measures (MOIC and IRR). These are our estimates, derived by correlating cap-table changes with share prices from SH01 filings. They are not figures from the register, and they are not verified with the individual.

This is profiling, and we treat it as such. Taken together, these features build a picture of an individual — their investment activity, and an indicative estimate of what their holdings are worth — out of information that is published company by company. We recognise that someone filing a statutory form at Companies House would not necessarily expect it to be combined this way, and that the combined picture says more than any single filing does. That expectation gap is a factor we have weighed in our Legitimate Interests Assessment, and it is why the safeguards below matter.

Safeguards. Name matching is a best-effort estimate and can be wrong — two different people with the same or a similar name can be matched to each other — so a user is asked to confirm matches rather than being handed a portfolio as established fact. These features are available only to signed-in users on a paid plan; they are not on our public pages and are not available to anonymous visitors. Our terms prohibit using them for unsolicited marketing, bulk extraction, or to build a competing dataset. No automated decision is made about you: nothing in the Service produces a legal or similarly significant effect, so there is no automated decision-making of the kind Article 22 UK GDPR restricts.

Your right to object. Because we rely on legitimate interests, you can object to this processing — including asking us to exclude you from investor search and portfolio analysis specifically, rather than from the Service altogether. Email privacy@sondedata.com; see “Your rights” below.

How we use and share it

  • We combine the information into a searchable tool available to registered users of the Service. Free accounts can view a small, fixed number of companies in full; wider access requires a paid subscription.
  • Users cannot bulk-download records. Exports are limited to individual company pages, and our terms prohibit users from using the data to re-identify individuals, extract data in bulk, share it onward as a product, or send unsolicited marketing.
  • We use a third-party processor (Serper.dev) for the company enrichment step. We do not sell your personal data.

How long we keep it

We keep the information for as long as it remains relevant to the Service and refresh it against Companies House filings so it reflects the current public record. Superseded records are removed or updated in line with our retention policy. If you ask us to remove you, we will suppress your data promptly.

Why we haven’t contacted you individually

Because this information comes from public sources rather than from you directly, the law requires us to make this notice available to you (rather than, in most cases, to contact each person individually). Given the number of individuals on the public register, contacting everyone would involve disproportionate effort. Instead we publish this notice prominently and make it easy for you to exercise your rights, including asking us to remove you.

Part B — Information about users of the Service

If you register for or use the Service, we also process personal data about you as a user.

What we collect

  • Account information: your name, email address, organisation, and login credentials.
  • Plan and billing information: your plan (free or paid), subscription status and billing period, your free-lookup usage (which companies you have unlocked), and a customer reference issued by our payment provider, Stripe. We never receive or store your full card details — see Payments below.
  • Sign in with Google: if you choose to sign in with Google, we receive from Google your email address (as verified by Google) and a unique Google account identifier, which we store to link your Google account to your Service account. We do not receive or store your Google password, contacts, or other Google data.
  • Usage information: records of how you use the Service — for example searches run, pages viewed, and technical logs such as IP address and device/browser information — used for security, to operate and improve the Service, and to keep audit records. This includes a record of sign-in attempts (successful and failed) with the associated IP address, kept for security and abuse prevention; for failed attempts we store a cryptographic hash of the submitted email address rather than the address itself.

Payments

Subscription payments are handled by Stripe (Stripe Payments Europe, Ltd. and its affiliates, including Stripe, Inc. in the United States). When you subscribe or manage your billing, you do so on Stripe-hosted pages: your card details are entered directly with Stripe and are never received or stored by us. Stripe tells us the information we need to run your subscription — such as whether a payment succeeded and when your billing period ends — and processes your payment data in accordance with its own privacy policy. Stripe also acts as an independent controller for some of its processing, such as fraud prevention and complying with its own legal obligations.

Why we process it and our lawful basis

  • To provide the Service under our terms with you, including managing your plan, subscription and payments — lawful basis: performance of a contract, and our legitimate interests in operating the Service.
  • To keep billing and transaction records — lawful basis: legal obligation (tax and accounting law) and legitimate interests.
  • For security, fraud-prevention and audit logging — lawful basis: legitimate interests and, where applicable, legal obligation.
  • For product analytics (understanding how the Service is used so we can improve it) — see the Cookies and analytics section below for how this works and how consent applies.

How long we keep it

How long we hold each kind of information, and what decides it:

Information How long What determines it
Account information (name, email, organisation, credentials, sign-in method) While your account is open, and until any outstanding billing, support or legal matter is resolved after you close it We need it to give you an account and let you sign in. Once the account is closed and nothing is outstanding, it is deleted or anonymised — except records we must keep for the reasons below.
Your record of which companies you have unlocked on the free plan For the life of the account The free allowance is a lifetime one and the companies you unlock stay viewable, so we have to remember which they were. Deleting it would either re-grant the allowance or take away access you already have.
Plan and subscription status While your account is open; the underlying payment records follow the billing row below Needed to give you the access you are paying for.
Sign-in attempts and usage/audit logs (including IP address) While they remain useful for the purpose they were collected for Security and abuse-prevention (spotting repeated failed sign-ins and account takeover) and keeping an audit trail of who accessed what. We review these and remove them once they are no longer needed for that purpose. Failed sign-ins hold a hash of the submitted email, not the address itself.
Billing and transaction records At least six years after the end of the tax year they relate to Required by tax and accounting law. This applies even after you close your account, and we cannot delete these on request within that period.

Where a period is not fixed by law, we decide it against these criteria: whether we still need the information to provide the Service or run your account; whether we are required to keep it; whether it is needed to establish, exercise or defend legal claims; and the risk to you of our keeping it. If you want to know what we hold about you specifically, or how long we expect to keep it, ask us at privacy@sondedata.com.

Emails we send you

Transactional emails — such as email-address verification and password-reset messages — are delivered on our behalf by Customer.io Inc., a United States company. Customer.io processes your email address and the message content for this purpose only, under the UK Extension to the EU–US Data Privacy Framework (see International transfers below). Payment receipts and billing notifications may be sent by Stripe. We do not use your account email address for marketing without your consent.

Cookies and analytics

We use a single, strictly necessary cookie, set by us, to keep you signed in and to protect forms against cross-site request forgery. It lasts up to 7 days, refreshing while you stay active, and your sign-in is cleared when you sign out. It is essential to providing the Service you have asked for and is exempt from consent requirements under UK PECR, so there is no cookie banner. If you block this cookie you will not be able to sign in. We do not use any advertising, profiling, or cross-site tracking cookies.

Stripe-hosted pages. Checkout and billing-management pages are hosted by Stripe on its own domain. Stripe sets cookies on those pages for security and fraud prevention under its own cookie policy; those cookies are not set on our site.

Analytics. To understand how the Service is used — which features people use, where they get stuck — we use Plausible Analytics, a privacy-focused analytics tool hosted in the European Union. Plausible is cookieless, sets no persistent identifiers, does not track you across sites, and does not retain personal data about visitors. What we receive is anonymous, aggregate usage statistics (for example, how many people viewed a page or used a feature).

Lawful basis and your rights. Because Plausible is cookieless and does not collect personal data about you individually, no consent is required under UK PECR. We rely on legitimate interests for this aggregate analytics. You can use browser settings (such as Do Not Track or content blockers) if you prefer not to be counted in our statistics.

Server logs. We also keep server logs (including IP address, request URL, timestamps and basic device/browser information) for security, abuse-prevention and audit purposes. These are strictly necessary to operate the Service and are not used for analytics or marketing.

Note on our main website. Our main SyndicateRoom website uses advertising and analytics cookies and a cookie-consent banner (CookieHub). That is managed separately; the Service’s privacy posture (no tracking cookies, no banner — only the essential sign-in cookie above) is deliberately different.

Your rights

Whether you are an individual in our data or a user of the Service, you have rights under UK data protection law. These include the right to:

  • be informed about how we use your personal data (this notice);
  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • object to our processing where we rely on legitimate interests — including asking us to stop including you in the Service;
  • have your data erased in certain circumstances;
  • restrict our processing in certain circumstances; and
  • withdraw consent (where we rely on consent, such as for certain analytics) at any time.

How to exercise your rights. Contact us at privacy@sondedata.com. We will respond without undue delay and within one month. There is usually no charge. To protect your data we may need to verify your identity.

Right to object — quick route. If you simply want us to remove you from the Service, email privacy@sondedata.com and we will deal with it. (A self-service option is planned for the future.)

Other information

International transfers

Some of our service providers are based outside the UK. For example, the company-enrichment provider (Serper.dev) is based in the United States; our transactional email provider (Customer.io Inc.) is a United States company certified under the EU–US Data Privacy Framework, including the UK Extension; and our payment provider, Stripe, includes United States entities. Where personal data is transferred to a country without a UK adequacy decision, we use an appropriate safeguard recognised under UK data protection law, such as the UK Extension to the EU–US Data Privacy Framework, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. Our analytics provider (Plausible) is hosted in the European Union, which is covered by a UK adequacy decision, so no separate transfer mechanism is required there.

How to complain

If you have concerns about how we handle your personal data, please contact us first at privacy@sondedata.com so we can try to resolve them. You also have the right to complain to the ICO (ico.org.uk).

Changes to this notice

We may update this notice from time to time. Where changes are significant we will take reasonable steps to bring them to your attention. The date at the top shows when it was last updated.

Contact

Controller: Syndicate Room Ltd. Privacy contact for the Service: privacy@sondedata.com. For company-level matters, see our main privacy policy.