Last updated August 29, 2026

Privacy Policy (EU/UK)

For users in the EU/UK, GTN SYSTEMS S.R.L. is the data controller. This notice describes our processing under the GDPR and UK GDPR.

Legal bases

  • Contract: to provide the Service you request.
  • Legitimate interests: to secure the Service, prevent fraud, and improve it (balanced against your rights).
  • Consent: for analytics/marketing cookies and marketing email, off until you opt in.
  • Legal obligation: to comply with applicable law.

Your rights

You have the right to access, rectify, erase, restrict, and port your data, to object to processing, and to withdraw consent. You may exercise these in your settings or by contacting us. You also have the right to lodge a complaint with your supervisory authority (e.g. the ICO in the UK).

International transfers

Where we transfer data outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses.

If you are not a customer

Most people whose information appears in a FindWho report have never used FindWho. You hold the same rights as our customers, and you do not need an account to use them.

Use our privacy request form at findwho.net/privacy-request to ask what we hold, object to how it is used, or have it erased. For an email address we can act immediately once you confirm the address is yours. For a phone number we will ask you to confirm your identity another way first. An emailed code does not show who holds a number, and acting without that check would let anyone erase or extract data about someone else's number.

When we erase an identifier we also add a one-way fingerprint of it to a suppression list. That is what stops it reappearing when one of our data sources refreshes. The fingerprint cannot be reversed to recover the original.

What we hold about a person who was looked up

Article 14 requires us to tell you this even though you did not give us the information yourself. What we hold depends entirely on what you are searched by, and we never hold more than the search itself produced.

  • Phone number searches: the number, and what public and licensed sources say about it: whether it is valid and reachable, its line type, its carrier, its region and time zone. It also includes, where those sources hold them, the name people have saved the number under, social profiles and a profile photo linked to it, addresses and relatives on public record (United States numbers), and whether the number appears in leaked databases. We show which source each item came from and never show passwords or credentials from a leak.
  • Email address searches: the address, whether it can receive mail, whether its domain is disposable, any profile the person has themselves published against it (for example a Gravatar), and whether it appears in publicly reported data breaches.
  • We do not process special category data. No biometric or facial recognition, no health, political, religious or sexual-orientation data, and no criminal conviction or offence data.

Where the information comes from

Article 14(2)(f) requires us to name our sources, and we would rather do it plainly than in the abstract. Every finding in a report carries its source on the face of it.

  • Public technical records: the global telephone numbering plan, and public DNS records for an email domain.
  • Information the person published themselves, for example a public Gravatar profile attached to their own email address.
  • Crowd-sourced caller-ID directories: the name, photo and social handles that other users of caller-ID apps have saved a number under. These are contact labels, and the report says so.
  • Public-record aggregators for United States numbers: name, age, address history, other numbers and relatives compiled from public records.
  • Leaked-database records: whether a number appears in a known data breach or leak, and the non-secret fields found alongside it (an email address, a name, an address). We never show passwords or password hashes, and we discard them before anything is stored.
  • Sex-offender registries, which are public only in the United States, searched by the name found for a United States number.
  • A language model (Google Gemini) writes the plain-language summary at the top of a report from those findings only. It receives the findings and the reason you gave for searching, and nothing it writes is stored anywhere but your report.
  • Publicly reported data breaches, via a breach-notification service. We deliberately exclude data taken from infostealer malware logs.
  • Licensed commercial data providers, where connected. These compile information from public records and other lawful sources.

Who we share it with, and where it goes

We do not sell personal data, and we do not share reports with anyone other than the customer who ran the search.

The providers named above receive the identifier being searched, because that is how a lookup works. Our infrastructure suppliers (hosting, database, email delivery, payment processing and the language model that writes report summaries) process data on our instructions under Article 28 contracts. Where any of them is outside the EEA or UK, the transfer is covered by Standard Contractual Clauses.

How long we keep it

A report is kept while the customer who paid for it retains access to it, and is deleted when they delete it or close their account. Payment records are kept for as long as accounting and tax law requires, which is longer, and which is why deleting a customer's data leaves the financial record intact but stripped of the personal detail.

If you ask to be erased, the report is deleted and the identifier goes onto our suppression list permanently. The suppression entry is the one thing we keep indefinitely, and deliberately: it is a one-way fingerprint with no readable identifier in it, and it exists solely so you stay erased when a data source sends the same information back to us later.

Why we are allowed to do this at all

For people who are looked up, our legal basis is Article 6(1)(f), legitimate interests. The interest is in letting someone identify an unknown caller, check who they are dealing with before sending money, or find out whether their own details have been exposed, all of which are recognised, everyday reasons to want this information.

That basis is conditional, not automatic: it only holds where our interest is not overridden by your rights. We have carried out and retained a written balancing assessment, and it is what the safeguards on this page come from: no special category data, sources and confidence shown on every finding, an unauthenticated route to object or be erased, and a suppression list that makes erasure stick.

You can object at any time under Article 21, and you do not have to give a reason.

Data subject requests

Customers can export or delete their account data from their settings. Anyone can use findwho.net/privacy-request, with or without an account. We respond within one month, free of charge, as Article 12 requires.

Contact

Questions? Email support@findwho.net.

Essential cookies only. Analytics and marketing need your consent. Cookie Policy

Privacy Policy (EU/UK) · FindWho