CheckDNC
Sign in

Privacy Policy

Last updated: August 23, 2026

1. About this Privacy Policy

This Privacy Policy explains how NEBS-IT SOLUTION LTD (“CheckDNC,” “we,” “us,” or “our”) collects, uses, stores, and shares personal data when people visit the CheckDNC website, create an account, purchase or use the Service, contact support, or otherwise interact with us.

CheckDNC is a business-to-business compliance-screening software platform.

2. Our data-protection roles

For account, website, support, security, and business-administration information, NEBS-IT SOLUTION LTD generally acts as the data controller.

When a business customer submits telephone-number records or other personal data for screening, the customer generally acts as the data controller and CheckDNC acts as its data processor or service provider.

Customers are responsible for establishing a lawful basis for collecting, submitting, screening, and using their records.

3. Information we collect

Depending on how you use CheckDNC, we may collect:

Account information

  • Name;
  • Business name;
  • Business email address;
  • Telephone number;
  • Username and account identifiers;
  • Account preferences; and
  • Authorised-user information.

Customer-submitted data

  • Telephone numbers;
  • Fields contained in uploaded CSV, TXT, or supported files;
  • Suppression or screening instructions;
  • Processing results;
  • Upload and export history; and
  • Related metadata.

Customers should submit only the information necessary for screening.

Transaction information

  • Products, credits, or subscriptions purchased;
  • Transaction identifiers;
  • Payment status;
  • Billing country;
  • Tax-related information;
  • Refund and dispute information; and
  • Paddle customer or transaction references.

Complete payment-card information for Paddle transactions is collected and processed by Paddle, not CheckDNC.

Technical and usage information

  • IP address;
  • Browser and device information;
  • Operating system;
  • Login and access records;
  • Pages and features used;
  • API requests;
  • Error and security logs;
  • Cookie identifiers; and
  • Date and time of activity.

Communications

  • Support requests;
  • Contact-form submissions;
  • Email correspondence;
  • Feedback; and
  • Records of communications with our team.

4. How we use personal data

We use personal data to:

  • Create and administer accounts;
  • Authenticate users and secure the Service;
  • Process submitted records and generate screening results;
  • Provide reports, exports, APIs, and requested functionality;
  • Administer credits, subscriptions, and purchases;
  • Provide customer service and technical support;
  • Diagnose errors and maintain Service availability;
  • Prevent fraud, abuse, and unauthorised access;
  • Monitor compliance with our Terms;
  • Improve the Service and understand feature usage;
  • Maintain appropriate business and transaction records;
  • Communicate service-related information;
  • Respond to lawful requests and meet legal obligations; and
  • Establish, exercise, or defend legal claims.

We do not sell customer-uploaded telephone-number lists.

We do not use submitted lists to place calls or send marketing messages.

5. Legal bases

Where the UK GDPR or EU GDPR applies, we rely on one or more of the following legal bases:

  • Contract: Processing necessary to provide the Service or take requested pre-contractual steps;
  • Legitimate interests: Securing, operating, supporting, and improving the Service; preventing fraud and abuse; and managing our business;
  • Legal obligation: Processing necessary to comply with tax, accounting, regulatory, sanctions, or other legal requirements;
  • Consent: Where consent is legally required, including for certain cookies or optional communications; and
  • Legal claims: Processing necessary to establish, exercise, or defend legal rights.

Where we process customer-submitted data as a processor, the business customer determines the applicable legal basis.

6. Customer responsibilities

Customers must ensure that:

  • Submitted personal data was collected lawfully;
  • A valid legal basis exists for processing;
  • Required privacy notices have been provided;
  • Consent, where required, is valid and documented;
  • Opt-outs and do-not-contact requests are respected;
  • Only necessary information is submitted;
  • Data is not used for unlawful telemarketing, spam, harassment, or discrimination; and
  • Screening results are used in accordance with applicable laws.

CheckDNC results do not replace the customer’s legal responsibilities.

7. Payment processing through Paddle

Paddle acts as the Merchant of Record for purchases completed through Paddle.

Paddle independently processes payment, transaction, billing, tax, fraud-prevention, refund, and buyer-support information under its own privacy notice.

Paddle’s Privacy Notice is available at:
https://www.paddle.com/legal/privacy

We may receive limited transaction information from Paddle to activate purchases, manage customer accounts, prevent fraud, provide support, and reconcile payments.

8. Service providers

We may use vetted service providers for:

  • Cloud hosting and infrastructure;
  • Database and file storage;
  • Security and fraud prevention;
  • Authentication;
  • Email delivery;
  • Error monitoring and analytics;
  • Customer support;
  • Payment and transaction administration; and
  • Professional legal, accounting, or compliance services.

Service providers may process personal data only as necessary to provide contracted services and subject to applicable confidentiality and data-protection obligations.

We may also disclose information when required by law, court order, regulatory request, or to protect legal rights and system security.

9. International transfers

Personal data may be processed in countries outside the user’s country of residence.

Where required, we use appropriate safeguards for international transfers, which may include adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum, Standard Contractual Clauses, or another lawful transfer mechanism.

10. Data retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing the Service, maintaining security and audit records, resolving disputes, and satisfying legal, tax, accounting, or regulatory requirements.

Customer-submitted files and screening results should be retained according to a documented operational retention schedule. Customers may request deletion where applicable, subject to technical and legal limitations.

Backups and security records may remain for a limited period after deletion before being overwritten through ordinary retention cycles.

11. Data security

We use reasonable technical and organisational safeguards intended to protect personal data. These may include:

  • Encryption in transit;
  • Appropriate access controls;
  • Authentication and credential protections;
  • Infrastructure monitoring;
  • Logging and abuse prevention;
  • Restricted staff access; and
  • Backup and recovery procedures.

No system is completely secure. Customers are responsible for protecting their credentials and using secure methods when uploading, accessing, and exporting data.

12. Cookies

The CheckDNC website and application may use:

  • Essential cookies required for login, security, and Service operation;
  • Preference cookies;
  • Analytics cookies; and
  • Other optional technologies where permitted.

Where required by law, non-essential cookies will be used only after consent. Users may manage applicable preferences through the cookie banner or browser settings.

13. Marketing communications

We may send product or service communications where legally permitted.

Recipients may unsubscribe from optional marketing communications using the link in the message or by contacting us.

Service, security, billing, and account-related notices may still be sent when necessary to provide the Service.

We do not use customer-uploaded telephone-number lists for CheckDNC’s own marketing.

14. Data-protection rights

Depending on location and applicable law, individuals may have the right to:

  • Access personal data;
  • Correct inaccurate information;
  • Request deletion;
  • Restrict processing;
  • Object to certain processing;
  • Receive portable data;
  • Withdraw consent;
  • Opt out of certain communications; and
  • Complain to a data-protection authority.

These rights may be subject to legal limitations.

Where CheckDNC processes data on behalf of a business customer, an individual should ordinarily direct the request to that customer. We will provide reasonable assistance to the customer where required.

15. UK complaints

Individuals in the United Kingdom may complain to the Information Commissioner’s Office:
https://ico.org.uk/make-a-complaint/

We encourage individuals to contact us first so we can attempt to address the concern.

16. Children

CheckDNC is a business service and is not intended for children. We do not knowingly offer accounts to children or intentionally collect children’s information through the Service.

17. Business transfers

If NEBS-IT SOLUTION LTD is involved in a merger, acquisition, reorganisation, financing, or sale of business assets, relevant information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.

18. Changes to this Policy

We may update this Privacy Policy to reflect changes in the Service, legal requirements, security practices, or processing activities.

The updated policy will be posted on this page with a revised “Last updated” date. Material changes will be communicated where required by law.

19. Contact

CheckDNC is operated by:

NEBS-IT SOLUTION LTD
Registered in England and Wales
Email: contact@checkdnc.net
Website: https://checkdnc.net

For data-protection questions or requests, use the email address above with the subject “Privacy Request.”

See also our Terms of Service and Refund Policy.

© NEBS-IT SOLUTION LTD · CheckDNC