Privacy policy
Checked works with data the Belgian authorities publish, plus the minimum we need to make your account work. Below is exactly what that is, why we do it, who we share it with and how you can change it.
Version of 9 August 2026.
1. Who is responsible
The controller for everything on this page is:
- Company
- WhileLoop BV
- Registered seat
- Hundelgemsesteenweg 722B, 9820 Merelbeke-Melle, Belgium
- Enterprise number
- 0716.802.779
- Privacy questions and requests
- privacy@checked.be
- General contact
- contact@checked.be
We are not required to appoint a data protection officer and do not have one. Your requests reach the people who build the product directly, and they answer them themselves.
2. Public-register data
Most of Checked is about companies, and company data is not personal data. But those publications also contain people's names, and those are. We did not obtain those names from you: we take them from registers the authorities publish. That is why you also read here exactly where they come from.
What data
- Name, role and term of directors, managers, permanent representatives and liquidators, with the publication they come from.
- Names of curators, interim administrators, court-appointed officers and notaries in insolvency and property publications.
- Name and date of birth of persons subject to a professional ban, as published in the Belgisch Staatsblad. We show that data only to paying, signed-in users, and the pages are hidden from search engines.
- Data from protection orders (interim administration), with the same shielding.
- Company data that coincides with a person, as with a sole trader: enterprise number, activity, registered address.
What we deliberately do not process: national register numbers, private addresses not published as a registered seat, and data on health, political opinions, religion, trade-union membership, sex life or ethnic origin. On address pages we show businesses that are a natural person with a neutral label, without a name.
Where it comes from
- Crossroads Bank for Enterprises (KBO/CBE), open data from the FPS Economy.
- Belgisch Staatsblad, via the publications on ejustice.just.fgov.be.
- National Bank of Belgium, filed annual accounts.
- Public property, cadastre, permit and public-procurement sources from the federal and regional authorities.
Every page shows the source alongside, with the Numac number of the publication or the link to the register, so you can check for yourself where a data point comes from.
Why, and on what legal basis
Legal basis: our legitimate interest and that of our users (article 6.1.f GDPR). The purpose is plain: anyone doing business with a Belgian company should be able to check who is behind it, whether a bankruptcy or professional ban is in play, and whether the figures add up. That is exactly what company publicity exists for: the register is public so that third parties can rely on it.
We weighed those interests against your privacy, and this is what that balancing exercise concretely produces:
- We process your data solely in your professional capacity: which role you held in which company, and when. Never your private life.
- We add nothing that has not been published. No scores about people, no advertising profiles, no resale of data, no ad networks.
- The most sensitive categories, professional bans and protection orders, sit behind a sign-in and a paid plan, and we keep those pages out of the sitemap and out of search engines.
- Person pages are hidden from search engines, so your name does not surface in general search results through Checked.
- Every data point carries its source, so you immediately see where to ask for a correction.
- You can always object. How that works and what we then do is explained further down.
3. Your account data
If you create an account, we process the data you provide yourself and the data your use of the service produces:
- Your email address and, if you fill it in, your name. Your email address is also your username.
- Your password, which we store only as an irreversible hash. We cannot read it and cannot give it back to you; if you lose it, you set a new one through a reset email.
- Your watchlist, your alert rules, your notifications and your digest frequency.
- Your plan, your Stripe customer id and your Stripe subscription id. Card details never reach our servers.
- The time your account was created, and the failed-sign-in counter that drives the lockout.
- If you sign up for the newsletter, we keep your email address, your language and the page where you signed up.
Legal basis: performance of the contract between you and us (article 6.1.b GDPR) for your account, your watchlist and your subscription. For the newsletter it is your consent (article 6.1.a), which you can withdraw at any time. For account security, such as the lockout after failed attempts, it is our legitimate interest (article 6.1.f).
Email we send you
Two kinds. Messages about your account and subscription, such as a welcome mail, an address confirmation, a password reset or a failed-payment notice: those belong to the contract and to your account's security, and they carry no unsubscribe link, because silencing "your payment failed" is not a preference. And your alerts and digests, which you switch on and off yourself; every digest and alert carries an unsubscribe link that works without signing in, plus the unsubscribe button your mail client shows.
For delivery we use Microsoft 365. Your email address and the content of the message therefore pass through Microsoft's mail infrastructure, which acts as our processor. If a send fails, we keep the address, the subject and the error message in a small failure table, so we can see what went wrong and try again.
What we do not do: we keep no IP addresses, no browser data and no profile of your browsing, and we do not track you across websites. IP addresses are used only briefly in memory to apply rate limits; they are not stored and not logged. There are no analytics cookies and no third-party trackers.
What we measure in aggregate
To know whether the service works and what it is missing, we count a handful of things at the level of the whole site: how many accounts are created per day, how many subscriptions start and stop, how many companies are followed, how many dossiers are viewed, how many searches happen and how many of those return nothing, how many API calls there are, how many emails go out or fail, and which errors visitors run into.
Only as daily totals. No user id, no session id, no IP address and no browser data is attached: those columns do not exist in the tables, so the link cannot be made afterwards either. A row says "this dossier was opened twelve times that day", never by whom.
For searches we also keep the searched text itself, because the searches that return nothing are the clearest signal of what the service is missing. That text is likewise fully detached from whoever typed it, and it is filtered first: if a term looks like an email address, a web address or a long run of digits, it is refused and not kept at all. These totals with search text are deleted after ninety days.
Legal basis: to the extent this involves personal data at all, our legitimate interest in seeing whether the service works and in improving it (article 6.1.f GDPR). Because there is no link to a person and no cookie or tracker is involved, the impact on your privacy is negligible.
4. Checked AI
In a few places you can use Checked AI: ask a question about a dossier, have a due-diligence brief drafted, or have a business idea assessed. Those features do not run on our own servers. Here is what happens:
- We send your question or the text you typed, together with the public data of the dossier you are viewing, to Anthropic PBC in the United States, which runs a language model over it and returns the answer.
- That dossier data includes the names and mandates of directors as they appear in the registers. For paying, signed-in users it also includes the name and date of birth of persons subject to a professional ban; for all other visitors we strip those out beforehand.
- We send no data that identifies you: no email address, no account id, no IP address. Anthropic therefore does not know who asked.
- We keep neither the answer nor your question: no row in our database and no line in our logs. On Anthropic's side the dossier part of the request is held for at most five minutes in a temporary cache to make repeat questions cheaper.
- Anthropic acts as our processor and, under our agreement, may not use this data to train its models.
You do not have to use Checked AI: the whole rest of the dossier works without it. Do not type confidential or sensitive information into it. And because a language model can be wrong, an AI answer is a reading aid for the dossier, not advice.
5. Who we share data with
We never sell data and we do not share it for advertising. This is the complete list of parties that see data about you because they perform part of the service:
| Recipient | Role | Which data | Where |
|---|---|---|---|
| Stripe | Payment provider | Email address, payment details you enter on the payment page, subscription status | Ireland and United States |
| Anthropic | Processor for Checked AI | Your question or typed text plus the public dossier data; no data identifying you | United States |
| Microsoft 365 | Processor for email delivery | Your email address and the content of the messages we send you | European Union, with possible support from the United States |
| Google Fonts | Font delivery | Your IP address and browser type, because your browser fetches the fonts from Google | Ireland and United States |
| Our own servers | Hosting | All the data above | Belgium |
The entire application runs on hardware we manage ourselves in Belgium. We use no external cloud provider for the database or the website. Google Fonts is the only external resource your browser reaches; no Google cookie is set on our site. If you want to avoid it, block fonts.googleapis.com in your browser; the site keeps working, with a different typeface.
In addition we may have to disclose data to an authority or a court where the law requires it. We only do that on the basis of a valid request and never more broadly than asked.
6. Transfers outside the EEA
- Anthropic PBC, United States. The transfer takes place under Anthropic's data processing addendum, which incorporates the European Commission's standard contractual clauses (implementing decision (EU) 2021/914, module 2).
- Stripe. Our contracting party is Stripe Payments Europe in Ireland; onward transfer to the US group entity relies on the EU-US Data Privacy Framework and on the standard contractual clauses.
- Google, for the fonts. Google LLC is certified under the EU-US Data Privacy Framework.
- Microsoft, for email delivery. Our contracting party is Microsoft Ireland Operations Limited; the mail data stays in the European Union, and for any onward transfer to Microsoft Corporation in the US we rely on the EU-US Data Privacy Framework and on the standard contractual clauses.
A copy of the standard contractual clauses that apply to our transfers can be requested via privacy@checked.be.
7. How long we keep data
| Category | Retention |
|---|---|
| Account data, watchlist, alert rules, notifications | For as long as your account exists. After a deletion request: gone within thirty days. |
| Newsletter sign-up | Until you unsubscribe. After that we keep only the fact of the unsubscribe, so we do not contact you again. |
| Failed email sends (address, subject, error) | Ninety days at most, then deleted. |
| Daily usage totals including search text | Ninety days, then deleted. The totals without search text (plain numbers, with no key at all) are kept longer as history. |
| Billing and accounting records | Seven years, as Belgian accounting law requires. That data largely sits at Stripe. |
| Public-register data | For as long as they are in the source or remain relevant to a company's history. If a data point disappears at the source, our display follows. |
| Checked AI questions and answers | We do not keep them. At Anthropic: a temporary cache of at most five minutes, plus what Anthropic itself needs against misuse. |
| Server technical logs | No longer than twelve months. They contain no IP addresses, no browser data and no search queries. |
9. Your rights
- Access. You receive a copy of the personal data we process about you, with its origin.
- Rectification. If a data point is wrong, we correct it, or we show you where it has to be put right at the source.
- Erasure. We delete your account and everything attached to it on request. For register data it depends on the balancing set out below.
- Objection. You can object, on grounds relating to your situation, to anything we do on legitimate interest. We then stop, unless we can demonstrate compelling legitimate grounds that override yours. We always explain our reasoning.
- Restriction. If you contest the accuracy of a data point, we pause processing it while we check.
- Portability. The data you supplied yourself or that came from your use, we deliver in a common machine-readable format.
- Withdraw consent. For the newsletter you can withdraw consent at any time, with the link in every email or by one message to us.
Send your request to privacy@checked.be. We answer within one month; if your request is complex we may extend that by two months and will tell you within the first month. It costs you nothing. We ask for extra identification only when we genuinely doubt who you are, and then as little as possible.
If you feel we are not handling your request properly, you can lodge a complaint with the Belgian supervisory authority:
Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels. Phone 02 274 48 00, contact@apd-gba.be, gegevensbeschermingsautoriteit.be.
You can also go to court. Feel free to tell us first, in most cases we simply fix it.
10. Are you named in a dossier?
If you find your own name as a director, curator, notary or in an insolvency publication, that data point comes from an official register. Here is what we can and cannot do.
- What we cannot do: change the register itself. The KBO, the Belgisch Staatsblad and the National Bank manage their own data. We take it over, we do not write it.
- What we do about a reading error on our side: part of the gazette publications are machine-read, and that can go wrong. If the error is ours, we usually correct it within a few working days and remove the wrong data point.
- For a source error: we show you where to have it put right (the business counter for the KBO, the competent court registry for the gazette, the National Bank for annual accounts) and we mark the data point as disputed in the meantime. Once the source is corrected, our page follows automatically.
- If you simply no longer want to appear on Checked: object via privacy@checked.be with your name and the enterprise number. We weigh your situation against third parties' interest in knowing who runs a company. Where there are special circumstances, for example a safety risk, those weigh heavily and we shield your data. If it concerns a mandate that is still running at an active company, that third-party interest usually prevails; we always explain that assessment in writing and you can challenge it.
- Regardless of that assessment, we remove your name from Checked's search indexes immediately when you ask, and person pages are in any case already noindex for external search engines.
11. Scores and automated decisions
Checked computes scores, signals and an indicative credit limit. They are about companies, not people: they are computed from filed annual accounts and published company facts, using fixed rules we describe publicly in our methodology. We build no profiles of natural persons, and a name appearing in a dossier does not get a score of its own.
We ourselves take no automated decision with legal or similarly significant effects for you within the meaning of article 22 GDPR. We do not decide on credit, hiring, tenancy or insurance. Our users make their own decisions, and our terms forbid them from using one of our scores as the sole basis for such a decision.
One honest nuance: with a sole trader the business coincides with a natural person. Even then the score remains an estimate based on published company facts, and the decision remains the user's. If you think a score about your sole trader business is unjustified, tell us at privacy@checked.be; we check the underlying facts and explain how the score came about.
12. Security
All traffic runs over HTTPS. Passwords are stored only as an irreversible hash. Sign-in attempts are limited and an account locks temporarily after five failures. The session cookie is HttpOnly and encrypted. The database runs on our own hardware in Belgium, not at an external cloud provider. The read connection to the source database has read rights only on restricted views, never on the underlying tables. Card and payment details never reach our servers.
If despite everything a data breach occurs that poses a risk to you, we notify the Data Protection Authority within 72 hours and, where the risk is high, you directly as well. If you find a vulnerability, report it via contact@checked.be; we treat such a report with thanks.
13. Changes
If what we process, who we share it with or how long we keep it changes, we update this page and put the new date on it. For a material change we notify account holders in advance through the contact details on their account. Also read the terms of service and the methodology, which explains how our scores work.