Privacy
Privacy policy
What OpenBase USA processes, why, and how to exercise your privacy rights.
Last updated: September 19, 2026. This notice describes this version of OpenBase USA. It applies to visitors and people who contact us about published information.
Who is responsible
Quentin Lainé — entrepreneur individuel, 80 boulevard Saint-Marcel, 75005 Paris, France. Contact for privacy: contact@openbaseusa.com. No Data Protection Officer designation is claimed.
What information is processed
| Category | Purpose | Source / recipients |
|---|---|---|
| Company names, CIK, published EIN, incorporation state, business locality, SIC and filing links | Business reference and source verification | SEC public records; displayed on company profiles |
| Network and security data necessary to deliver a page, such as IP address and request metadata | Deliver the site and prevent abuse | Your device; hosting infrastructure |
| Your reply email and information you choose to include in a form or email request | Respond, verify authority proportionately, and handle corrections, rights and appeals | You or your authorized agent; the operator and its email provider |
| Privacy preference stored on your device | Remember a choice you expressly make | Your browser; not transmitted by the preference tool |
The directory does not include people-search profiles, dates of birth, SSNs, personal phone numbers, street addresses, criminal histories or personal credit scores. A business name or locality can still relate to an individual; we do not assume that every public record is exempt from privacy law.
No advertising or tracking sale
This version has no behavioral advertising, analytics pixels, advertising cookies or sale of visitor data. It does not sell or share personal information for cross-context behavioral advertising, or use it for targeted advertising. No sensitive personal information is used to infer characteristics. Essential page delivery still discloses your IP address to the server.
Cookies, preferences and Global Privacy Control
No analytics or advertising cookies are set by this application. If you choose “Save privacy preference”, the application stores that preference locally in your browser. It does not create an advertising identifier. Global Privacy Control is recognized by the privacy choices interface; because sale, sharing and targeted advertising are disabled for everyone, those practices remain disabled whether or not the signal is present. We do not track browsing across third-party sites in response to Do Not Track or otherwise.
Purposes and legal bases where GDPR applies
Our purposes are to provide sourced business reference, operate and secure the service, and answer requests. Where personal data is involved, we rely on legitimate interests for proportionate business-reference publication and security, subject to necessity, balancing of rights and your right to object. Handling legally required rights requests is based on legal obligations. We do not rely on public availability as a legal basis in itself.
Recipients and international processing
Published company records can be read by visitors and, once indexing is enabled, search engines. We do not publish private request correspondence. Our infrastructure providers are DigitalOcean, LLC (public website in the United States), OVH SAS (restricted administration in France), and Infomaniak Network SA (email in Switzerland). They receive only data needed for their respective services; we do not sell visitor or request data to them. U.S. hosting involves international processing. DigitalOcean’s published data-processing terms describe its transfer framework and fallback standard contractual clauses. You may contact us for information about the safeguards applicable to your data.
When online submission is available, form messages are transmitted through the U.S. web server to the operator’s restricted administration database in France. The operator uses your reply email and message to handle the request. A reference confirms database receipt; it does not mean an email was sent or the request has been resolved. Email correspondence sent directly to our contact address is handled through Infomaniak. Abuse prevention retains a keyed network identifier and a counter for approximately one hour; the original IP address is not stored in that rate-limit table. Request messages are not published or written to application logs.
Retention
Company reference records are maintained while relevant, subject to correction and restrictions. Suppression identifiers are retained to prevent re-publication. Web access logs omit visitor IP addresses, requested URLs and search terms. They are rotated daily and retained for no more than 14 days. Request correspondence is retained only as needed to handle the request, document compliance and resolve disputes, with a planned review after 12 months. A specific legal preservation duty can require longer retention.
Your choices and rights
Everyone may request access, correction, deletion or restricted publication, and raise an objection. Where applicable law provides them, you may also request portability, opt out of sale, sharing, targeted advertising or qualifying profiling, limit sensitive-data use, and appeal a refusal. Rights depend on the law, scope and exemptions; we explain any refusal and do not deny requests automatically merely because a source is public.
Your privacy choices provides a submission form and direct email contact. A form error means sending was not confirmed; use the direct email alternative. A receipt reference confirms that your request was recorded, not that an email was delivered or a rights request completed. You may use an authorized agent. We ask for only proportionate verification and do not ask for an SSN or identity document by default. Exercising rights will not result in unlawful discrimination.
Our handling target is within 20 days of receipt, with any shorter applicable deadline controlling. Under GDPR, the initial deadline is one calendar month. Extensions, when permitted, must be explained within the applicable initial period. You may appeal by replying with “Privacy appeal”. Statutory appeal deadlines and complaint rights are preserved.
State-specific rights and complaints
See State privacy rights. California residents may contact the California Privacy Protection Agency or Attorney General. Other residents may contact their state privacy regulator or Attorney General. Where GDPR applies, you may complain to the CNIL or your competent supervisory authority.
Children
This business-reference service is not directed to children under 13. We do not knowingly collect their personal information or provide personal profiles of minors. Contact us if you believe such information was included.
External sites and changes
Official-source links take you to separately operated sites with their own privacy practices. Material changes to our practices require an updated notice and any consent or opt-out mechanism required by law before implementation.