Privacy

Privacy is the product, not the paperwork.

We turn public business facts into decisions. We minimize personal data by design, honor your rights promptly, delete on schedule, and show our work on every signal.

Last updated: September 2026.

Company facts first

We collect business-level facts — prices, availability, public filings, company announcements. Personal data fields are blocked unless specifically approved as necessary for a documented product.

One purpose per source

Every source is tied to a specific recurring decision for a defined customer class. We do not collect everything that might one day become valuable.

Your data stays yours

Customer-connected data (CRM, inventory, private documents) is logically separated by tenant and never used for shared training or benchmarking without explicit permission.

Every claim is traceable

Signals carry source links, retrieval time, confidence, and human-review status. Corrections are recorded as history — facts are never silently overwritten.

What we do not collect

Prohibited by default. No exceptions without legal approval and executive sign-off.

  • Data behind logins or access controls, without authorization
  • Health, political, religious, biometric, or sexuality data
  • Criminal-record dossiers or private communications
  • Children's data, precise location, or detailed financial data
  • Credentials, authentication secrets, or re-identified anonymous users

Your rights under GDPR

Where the GDPR applies, we act as the controller for the purposes we define — including data collected through providers on our behalf. A vendor contract never transfers that responsibility away from us. We follow the European Data Protection Board's Guidelines 03/2026 on web scraping wherever personal data is involved.

Access

Ask what personal data we hold about you and where it came from.

Correction

Challenge anything inaccurate and have the correction propagated to every downstream copy.

Deletion

Request erasure. Deletion propagates across ingestion, warehouse, search, exports, and models — with completion records to prove it.

Objection and opt-out

Object to processing or opt out entirely. One opt-out blocks all five surfaces at once.

To exercise any right, email joe@derivativegenius.com with “Privacy request” in the subject. We verify identity proportionately, meet response deadlines, and confirm completion across all systems.

How long we keep data

Conservative defaults, enforced automatically — not by memory.

  • Raw observations — 90 days. Unprocessed retrievals expire first.
  • Canonical records — 24 months. Linked entities and history.
  • Decision signals — 12 months. Delivered answers and scores.

When a source contract ends or you object, expiry is enforced with completion proof — and a named owner is accountable for every deletion.

Collection with consent of the source

We prefer authoritative APIs, open-data portals, and licensed feeds over scraping. Where web collection is used, it is targeted and documented: exact domains and fields, terms and access signals reviewed, rate limits respected, and crawler identity disclosed where appropriate. We do not bypass authentication, CAPTCHAs, or explicit technical opposition to obtain personal data.

Public visibility is not consent. The absence of a robots.txt entry is not consent. Each source carries its own lawful basis, necessity assessment, and review date.