CompanyStack
APISamplesPricingDocs
Explore data

The register

IndustriesIndustries by SIC code: key figures, the largest companies by turnover and the newest.Towns and citiesCompanies registered in each UK town, its main industries and the newest arrivals.New incorporationsThe companies formed each day, newest first, with their industry and town.Company status guidesWhat active, dissolved, liquidation and proposal to strike off mean for you.

Look closer

Search companiesAny UK company by name or number: profile, health score and filed accounts.Financial screenerFilter companies by the figures in their latest filed accounts.Sample outputsReal reports, exports and API responses to look through.
Log inCreate free account
APISamplesPricingDocs

Explore data

IndustriesTowns and citiesNew incorporationsCompany status guidesSearch companies
Log inCreate free account
  1. Home
  2. Legal
  3. Data Processing Addendum

Data Processing Addendum

Version 1 · Effective 2 October 2026

Contents
  1. About this addendum
  2. When we are a controller
  3. When we are your processor
  4. Our processor commitments
  5. Sub-processors
  6. Personal data breaches
  7. End of the service
  8. Full DPA

1. About this addendum

This addendum forms part of our Terms of Service between you and Stuart Wilson trading as CompanyStack. It applies where we process personal data on your behalf, and sets out the terms required by Article 28 of the UK GDPR.

2. When we are a controller

We are the controller, not your processor, for:

  • the public register data we publish, such as directors and people with significant control from Companies House. We decide what is published and why. Once you take that data out of the Service, you are a separate controller of your copy (see clause 16 of the Terms);
  • your account, billing and usage data, which we use to run our business; and
  • our website analytics.

Our Privacy Notice covers this data.

3. When we are your processor

We process the following on your behalf and on your instructions:

  • names and email addresses of team members you add to your account;
  • watchlists, alert rules and other content you create, to the extent they contain personal data; and
  • webhook destinations and the alerts we send to them.

The processing lasts as long as your account. Its purpose is to provide the Service. The data subjects are your staff and contacts, and people named in your watchlists.

4. Our processor commitments

When we act as your processor, we will:

  1. process the data only on your documented instructions, which are these terms and your use of the Service, unless the law requires otherwise (in which case we will tell you unless the law forbids it);
  2. make sure everyone who can access the data is bound by confidentiality;
  3. keep appropriate technical and organisational security measures in place, including encryption in transit, hashed credentials, access controls and backups;
  4. use sub-processors only as described in section 5;
  5. help you respond to requests from individuals exercising their rights;
  6. help you with security, breach notification, data protection impact assessments and consultation with the ICO, taking into account the information available to us;
  7. delete or return the data at the end of the service, as described in section 7; and
  8. give you the information you reasonably need to show compliance with Article 28, and allow reasonable audits on reasonable notice, normally by written questionnaire.

5. Sub-processors

You authorise us to use the sub-processors on our sub-processors page. We will update that page before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. If we cannot address your objection, you may cancel the affected subscription and we will refund any prepaid fees for the rest of the period. We put data protection terms in place with each sub-processor that are no less protective than these, and we remain responsible for them.

6. Personal data breaches

We will tell you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting data we process for you. We will give you the information you need to meet your own obligations, and keep you updated as we learn more.

7. End of the service

Before your account closes, you can ask us for a copy of the personal data we process for you. We then delete it within 30 days of closure, unless the law requires us to keep it.

8. Full DPA

This page summarises our processing terms. A full Data Processing Agreement is available on request through our contact page or at support@companystack.co.uk.

Data from Companies House. Contains public sector information licensed under the Open Government Licence v3.0.

The same data is available through the CompanyStack API (OpenAPI spec). Company status meanings · Data freshness

CompanyStack

The UK company register, made useful. Company profiles, health scores and financials in the web app, and the same data through the CompanyStack API.

Talk to us

CompanyStack web app

  • Dashboard
  • Financial screener
  • Watchlist and alerts
  • Map
  • Web app pricing
  • Create a free account

CompanyStack API

  • UK company data API
  • API documentation
  • API explorer
  • API pricing
  • Signals add-on
  • Get a free API key
  • Enterprise and bulk data

Built for

  • Accountants and bookkeepers
  • Compliance and procurement
  • Lenders and credit
  • Sales and business development
  • Investors and corporate finance
  • Insolvency and business recovery
  • Developers and data teams
  • Recruitment agencies

See the data

  • Sample outputs
  • Data sources
  • Book a 20-minute call
  • Monthly UK company report
  • UK private company data
  • Company status meanings
  • SIC codes list
  • Compare providers

© 2026 CompanyStack.

TermsPrivacyCookiesRefundsLegalBrand and pressAboutHelp centreContactDocs