Sonde Data · Last updated 15 July 2026
Who we are. Sonde Data (“the Service”) is operated by Syndicate Room Ltd (“SyndicateRoom”, “we”, “us”). SyndicateRoom is the data controller for the personal data described in this notice and is registered with the UK Information Commissioner’s Office (ICO). This notice is specific to the Service. It sits under SyndicateRoom’s wider privacy framework; for company-level matters please also see our main privacy policy.
Who this notice is for. This notice explains how we handle personal data in two situations: (1) information about company directors and individual shareholders that the Service draws from public sources; and (2) information about the people who register for and use the Service. The two are explained separately below.
The Service helps users research UK companies and the people connected to them. To do this we process limited personal data about company directors and individual shareholders.
| Information | Source | Notes |
|---|---|---|
| Director names | Companies House public register (officer appointments) | Business-capacity information already on the public record. |
| Director month and year of birth | Companies House public register (officer appointments) | Month and year only — the register withholds the day and we never infer it. Used to distinguish directors who share a name. |
| Individual shareholder names and their shareholding (number and class of shares) | Companies House CS01 confirmation statements | Applies to individual shareholders. Corporate shareholders are not personal data. |
| An indicative, estimated value of a shareholding | Calculated by us using share prices from SH01 filings | This figure is produced by us, not taken from the register, and is an estimate only. It may not reflect later funding rounds, dilution, different share classes, or buy-backs. |
| Company website and a short business description | Retrieved via a third-party service (Serper.dev) | Company-level information; any personal data is incidental. |
What we do not collect: we do not ingest full dates of birth, residential or service addresses, signatures, or any special category data.
Source attribution. The Service contains public sector information licensed under the Open Government Licence v3.0. Source: Companies House.
Purpose. We make public-register information more useful for legitimate business research — investment screening, due diligence and market mapping — by our users (typically angel investors, small funds, founders and advisers).
Lawful basis: legitimate interests (Article 6(1)(f) UK GDPR). Our legitimate interests, and those of our users and the wider interest in corporate-register transparency, are in providing and using this research tool. We have weighed these interests against your rights in a documented Legitimate Interests Assessment, and have minimised what we hold (names and holdings only) and how it can be used. That assessment covers not just the company-by-company record but also combining an individual’s holdings across companies — see “Searching for an individual” below, which explains that processing and how to object to it. You can ask us for a summary of the assessment.
The Service is not only a company-by-company record. A user can search for a person by name and see the holdings we have matched to them across every company we cover, brought together in one view. Two features do this, and we describe them here because they go further than simply republishing a filing:
This is profiling, and we treat it as such. Taken together, these features build a picture of an individual — their investment activity, and an indicative estimate of what their holdings are worth — out of information that is published company by company. We recognise that someone filing a statutory form at Companies House would not necessarily expect it to be combined this way, and that the combined picture says more than any single filing does. That expectation gap is a factor we have weighed in our Legitimate Interests Assessment, and it is why the safeguards below matter.
Safeguards. Name matching is a best-effort estimate and can be wrong — two different people with the same or a similar name can be matched to each other — so a user is asked to confirm matches rather than being handed a portfolio as established fact. These features are available only to signed-in users on a paid plan; they are not on our public pages and are not available to anonymous visitors. Our terms prohibit using them for unsolicited marketing, bulk extraction, or to build a competing dataset. No automated decision is made about you: nothing in the Service produces a legal or similarly significant effect, so there is no automated decision-making of the kind Article 22 UK GDPR restricts.
Your right to object. Because we rely on legitimate interests, you can object to this processing — including asking us to exclude you from investor search and portfolio analysis specifically, rather than from the Service altogether. Email privacy@sondedata.com; see “Your rights” below.
We keep the information for as long as it remains relevant to the Service and refresh it against Companies House filings so it reflects the current public record. Superseded records are removed or updated in line with our retention policy. If you ask us to remove you, we will suppress your data promptly.
Because this information comes from public sources rather than from you directly, the law requires us to make this notice available to you (rather than, in most cases, to contact each person individually). Given the number of individuals on the public register, contacting everyone would involve disproportionate effort. Instead we publish this notice prominently and make it easy for you to exercise your rights, including asking us to remove you.
If you register for or use the Service, we also process personal data about you as a user.
Subscription payments are handled by Stripe (Stripe Payments Europe, Ltd. and its affiliates, including Stripe, Inc. in the United States). When you subscribe or manage your billing, you do so on Stripe-hosted pages: your card details are entered directly with Stripe and are never received or stored by us. Stripe tells us the information we need to run your subscription — such as whether a payment succeeded and when your billing period ends — and processes your payment data in accordance with its own privacy policy. Stripe also acts as an independent controller for some of its processing, such as fraud prevention and complying with its own legal obligations.
How long we hold each kind of information, and what decides it:
| Information | How long | What determines it |
|---|---|---|
| Account information (name, email, organisation, credentials, sign-in method) | While your account is open, and until any outstanding billing, support or legal matter is resolved after you close it | We need it to give you an account and let you sign in. Once the account is closed and nothing is outstanding, it is deleted or anonymised — except records we must keep for the reasons below. |
| Your record of which companies you have unlocked on the free plan | For the life of the account | The free allowance is a lifetime one and the companies you unlock stay viewable, so we have to remember which they were. Deleting it would either re-grant the allowance or take away access you already have. |
| Plan and subscription status | While your account is open; the underlying payment records follow the billing row below | Needed to give you the access you are paying for. |
| Sign-in attempts and usage/audit logs (including IP address) | While they remain useful for the purpose they were collected for | Security and abuse-prevention (spotting repeated failed sign-ins and account takeover) and keeping an audit trail of who accessed what. We review these and remove them once they are no longer needed for that purpose. Failed sign-ins hold a hash of the submitted email, not the address itself. |
| Billing and transaction records | At least six years after the end of the tax year they relate to | Required by tax and accounting law. This applies even after you close your account, and we cannot delete these on request within that period. |
Where a period is not fixed by law, we decide it against these criteria: whether we still need the information to provide the Service or run your account; whether we are required to keep it; whether it is needed to establish, exercise or defend legal claims; and the risk to you of our keeping it. If you want to know what we hold about you specifically, or how long we expect to keep it, ask us at privacy@sondedata.com.
Transactional emails — such as email-address verification and password-reset messages — are delivered on our behalf by Customer.io Inc., a United States company. Customer.io processes your email address and the message content for this purpose only, under the UK Extension to the EU–US Data Privacy Framework (see International transfers below). Payment receipts and billing notifications may be sent by Stripe. We do not use your account email address for marketing without your consent.
We use a single, strictly necessary cookie, set by us, to keep you signed in and to protect forms against cross-site request forgery. It lasts up to 7 days, refreshing while you stay active, and your sign-in is cleared when you sign out. It is essential to providing the Service you have asked for and is exempt from consent requirements under UK PECR, so there is no cookie banner. If you block this cookie you will not be able to sign in. We do not use any advertising, profiling, or cross-site tracking cookies.
Stripe-hosted pages. Checkout and billing-management pages are hosted by Stripe on its own domain. Stripe sets cookies on those pages for security and fraud prevention under its own cookie policy; those cookies are not set on our site.
Analytics. To understand how the Service is used — which features people use, where they get stuck — we use Plausible Analytics, a privacy-focused analytics tool hosted in the European Union. Plausible is cookieless, sets no persistent identifiers, does not track you across sites, and does not retain personal data about visitors. What we receive is anonymous, aggregate usage statistics (for example, how many people viewed a page or used a feature).
Lawful basis and your rights. Because Plausible is cookieless and does not collect personal data about you individually, no consent is required under UK PECR. We rely on legitimate interests for this aggregate analytics. You can use browser settings (such as Do Not Track or content blockers) if you prefer not to be counted in our statistics.
Server logs. We also keep server logs (including IP address, request URL, timestamps and basic device/browser information) for security, abuse-prevention and audit purposes. These are strictly necessary to operate the Service and are not used for analytics or marketing.
Note on our main website. Our main SyndicateRoom website uses advertising and analytics cookies and a cookie-consent banner (CookieHub). That is managed separately; the Service’s privacy posture (no tracking cookies, no banner — only the essential sign-in cookie above) is deliberately different.
Whether you are an individual in our data or a user of the Service, you have rights under UK data protection law. These include the right to:
How to exercise your rights. Contact us at privacy@sondedata.com. We will respond without undue delay and within one month. There is usually no charge. To protect your data we may need to verify your identity.
Right to object — quick route. If you simply want us to remove you from the Service, email privacy@sondedata.com and we will deal with it. (A self-service option is planned for the future.)
Some of our service providers are based outside the UK. For example, the company-enrichment provider (Serper.dev) is based in the United States; our transactional email provider (Customer.io Inc.) is a United States company certified under the EU–US Data Privacy Framework, including the UK Extension; and our payment provider, Stripe, includes United States entities. Where personal data is transferred to a country without a UK adequacy decision, we use an appropriate safeguard recognised under UK data protection law, such as the UK Extension to the EU–US Data Privacy Framework, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. Our analytics provider (Plausible) is hosted in the European Union, which is covered by a UK adequacy decision, so no separate transfer mechanism is required there.
If you have concerns about how we handle your personal data, please contact us first at privacy@sondedata.com so we can try to resolve them. You also have the right to complain to the ICO (ico.org.uk).
We may update this notice from time to time. Where changes are significant we will take reasonable steps to bring them to your attention. The date at the top shows when it was last updated.
Controller: Syndicate Room Ltd. Privacy contact for the Service: privacy@sondedata.com. For company-level matters, see our main privacy policy.