Privacy Policy
Screengood — sanctions, PEP and watchlist screening service
Effective date: 25 August 2026 · Version 1.0
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
Zentrolink UG (haftungsbeschränkt)
Schwesterstraße 64a, 42285 Wuppertal, Germany
Registered office (Sitz): Düsseldorf
Commercial register: HRB 106228, Amtsgericht Düsseldorf
Managing Directors: Ivan Zhukov, Anda Vitola
VAT ID: DE450306134
Email: [email protected] · Phone: +49 15510 704455
For all data protection matters, including the exercise of your rights, please write to [email protected].
2. Overview
Screengood processes personal data in two distinct roles, and it is important to keep them apart:
(a) Data about our users. People who register and use the Service — account data, usage data, billing data.
(b) Data about listed persons. Screengood indexes sanctions lists, politically exposed person (PEP) records and comparable watchlists published by authorities and international organisations. These contain personal data about individuals who are not our users and who did not provide their data to us. Section 6 deals with this category and with the rights of those individuals.
3. Data about our users
3.1 Account data
What: name, email address, and — where you register via Google Sign-In — the profile identifier and, if provided by Google, your profile picture. We request only your name and email address; we do not request access to your Gmail, Drive, Calendar or other Google services.
Purpose: creation and administration of your account, authentication, communication about the Service.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract with you or with the organisation you act for.
3.2 Search queries and uploaded content
What: the names and identifiers you search for, files you upload for batch screening, saved searches and monitoring lists.
Purpose: delivering the search result, providing saved searches and ongoing monitoring, and — in aggregated form — detecting faults and improving matching quality.
Legal basis: Art. 6(1)(b) GDPR for delivering the Service; Art. 6(1)(f) GDPR (our legitimate interest in a functioning, reliable and secure service) for fault analysis and quality improvement.
Please note: the names you submit are themselves personal data of third parties. You are the controller for that submission and are responsible for having a lawful basis for it. We process such data on your behalf and do not use it to expand our own indexed data set.
3.3 Usage and log data
What: IP address, date and time, pages and endpoints accessed, status codes, referrer, browser and operating system identifiers, and the identifier of your session.
Purpose: delivering the website, ensuring stability and security, detecting and investigating misuse, and troubleshooting.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in the secure and stable operation of the Service.
Retention: server log data is deleted or anonymised after 30 days, unless a specific entry is required for the investigation of a security incident.
3.4 Billing data
What: the data required to invoice and collect payment — company name, address, VAT identification number, plan, invoice history. Card and account details are collected and held by our payment service provider, not by us.
Legal basis: Art. 6(1)(b) GDPR for performance of the contract; Art. 6(1)(c) GDPR for compliance with our legal retention and accounting obligations.
Retention: invoices and accounting records are retained for the statutory periods under German commercial and tax law (as a rule ten years, § 147 AO, § 257 HGB).
3.5 Communication
Where you write to us, we process your message and contact details in order to respond, on the basis of Art. 6(1)(b) or Art. 6(1)(f) GDPR.
4. Google Sign-In
If you choose to sign in with Google, your browser establishes a connection with Google and Google authenticates you. Google transmits to us your name, email address and a stable account identifier. We use these solely to create and identify your account.
We request only non-sensitive scopes (name and email address). We do not receive, request or store access to the content of your Google account.
Your use of Google Sign-In is subject to Google's own privacy terms. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
You may instead register with an email address and password, without using Google.
5. Cookies and local storage
We use cookies and comparable browser storage only where technically necessary — to keep you signed in, to maintain your session and to protect against cross-site request forgery. These are placed on the basis of § 25(2) TDDDG (strictly necessary storage) and Art. 6(1)(f) GDPR.
We do not use advertising cookies and do not track you across other websites. If we introduce analytics or comparable non-essential technologies, we will obtain your consent beforehand and update this policy.
6. Data about listed persons
This section concerns individuals whose data appears in the sanctions, PEP and watchlist material we index. If you have been told that you appear in Screengood, this section is addressed to you.
6.1 Where the data comes from
The data originates exclusively from official and publicly accessible sources — sanctions lists and consolidated measures published by governments, supervisory and enforcement authorities, international organisations, official registers, parliamentary and public-office registers, and comparable published sources. We do not create entries ourselves and we do not add our own assessment of any person. We index and make searchable what those sources publish, and we record which source an entry came from and when it was retrieved.
6.2 Purpose and legal basis
Purpose: enabling obliged entities — banks, payment institutions, and other businesses subject to anti-money-laundering, sanctions and due-diligence obligations — to carry out the screening required of them by law.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest, and the legitimate interest of the recipients, lies in enabling compliance with statutory anti-money-laundering and sanctions obligations (in particular under the German Geldwäschegesetz and directly applicable EU sanctions regulations) and in preventing financial crime. Those interests are not overridden by the interests of the data subject, because the data is already lawfully published by public authorities for precisely that purpose, is limited to what those authorities publish, and is made available only to identified business customers for that purpose.
Insofar as entries relate to criminal convictions or offences within the meaning of Art. 10 GDPR, they are processed only where they have been published by a competent public authority and are made available exclusively to recipients acting under a statutory obligation to perform such checks.
6.3 Information under Art. 14 GDPR
Because this data does not come from you, Art. 14 GDPR applies. Providing individual notice to every listed person would involve disproportionate effort within the meaning of Art. 14(5)(b) GDPR — the number of records is in the millions and we hold no contact details for the persons concerned. This policy therefore serves as the public information measure required by that provision. The categories of data are those published by the source: name and known aliases, date and place of birth where published, nationality, function or office, the measure or listing reason as stated by the source, and identifiers such as passport or register numbers where the source publishes them.
6.4 Recipients
Entries are disclosed only to registered business customers who query them within the Service, in accordance with section 7.
6.5 Retention
An entry is retained for as long as it appears in the source. When a source removes or amends an entry, the change is reflected on our side at the next synchronisation of that source. We also retain a record that an entry previously existed, where this is necessary to substantiate a screening result our customer relied on at a given time.
6.6 Your rights as a listed person
You have the rights set out in section 10, and in particular:
- Access (Art. 15 GDPR) — you may ask what we hold about you and from which source.
- Rectification (Art. 16 GDPR) — if what we display does not correspond to the source, write to us and we will correct it.
- Objection (Art. 21 GDPR) — you may object to the processing on grounds relating to your particular situation.
- Erasure (Art. 17 GDPR) — subject to the conditions of that provision.
Important: where the entry accurately reproduces what the source publishes, we cannot remove you from that source. A correction of the underlying listing must be sought from the authority or organisation that published it; the applicable remedy is stated by that body. What we can and will do is correct any discrepancy between the source and our reproduction of it, re-synchronise the source, and record your objection.
To make a request, write to [email protected]. We may ask for information reasonably necessary to confirm your identity, in order to avoid disclosing data to the wrong person.
7. Recipients and processors
We disclose personal data only where necessary and lawful:
- Hosting and infrastructure providers, which operate the servers on which the Service runs;
- Payment service providers, for the processing of payments;
- Email and communication providers, for transactional messages;
- Tax advisers and auditors, within the scope of statutory obligations;
- Public authorities and courts, where we are legally required to disclose.
Where such providers process personal data on our behalf, we conclude a data processing agreement under Art. 28 GDPR.
We do not sell personal data and do not disclose it for advertising purposes.
8. Transfers to third countries
We process data within the European Union and the European Economic Area wherever possible. Where a provider processes data outside that area, the transfer takes place on the basis of an adequacy decision of the European Commission or of standard contractual clauses under Art. 46(2)(c) GDPR, together with such additional safeguards as are appropriate. We will provide a copy of the relevant safeguards on request.
9. Security
We apply technical and organisational measures appropriate to the risk, including transport encryption (TLS), encryption of data at rest, access control on a need-to-know basis, logging of administrative access, and regular review of our infrastructure. No system can be made absolutely secure, but we take the state of the art into account and review our measures as it develops.
10. Your rights
You have the right:
- to obtain access to your personal data (Art. 15 GDPR);
- to obtain rectification of inaccurate data (Art. 16 GDPR);
- to obtain erasure (Art. 17 GDPR);
- to obtain restriction of processing (Art. 18 GDPR);
- to data portability (Art. 20 GDPR);
- to object to processing based on Art. 6(1)(f) GDPR, on grounds relating to your particular situation (Art. 21 GDPR);
- to withdraw consent at any time with effect for the future, where processing is based on consent (Art. 7(3) GDPR);
- to lodge a complaint with a supervisory authority (Art. 77 GDPR).
To exercise any of these rights, write to [email protected]. We respond without undue delay and in any event within one month of receipt; where a request is complex we may extend that period by two further months and will inform you of the extension and the reasons for it.
Competent supervisory authority for us:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
[email protected] · ldi.nrw.de
You may also complain to the supervisory authority of your habitual residence or place of work.
11. Obligation to provide data
Providing account and billing data is necessary for the conclusion and performance of the contract. Without it we cannot provide the Service. There is no statutory obligation on you to provide it; the consequence of not doing so is simply that no contract can be performed.
12. Automated decision-making
We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22 GDPR.
The matching performed by Screengood is an automated comparison that returns candidate matches to our customer. It is not a decision. Any decision — for instance whether to enter into or continue a business relationship — is taken by our customer, who is required by section 8 of our Terms of Service to review results before acting on them. Where a customer relies on such results, they are the controller for that decision and their own privacy notice applies.
13. Changes to this policy
We update this policy where the Service or the legal framework changes. The current version is always available at screengood.com/privacy, with the effective date shown at the top. Where changes are material, we will inform registered users in advance.
Questions about this policy: [email protected]