Re:ta — Operated by Chil7 Ltd
Chil7 Ltd is a company registered in England and Wales (company number 15595409) and registered with the Information Commissioner’s Office (ICO) under number ZC149536. We operate Re:ta and are the data controller for the personal data described in this notice.
Questions about this notice or how we handle your personal data: info@chil7.com
This notice explains how Chil7 Ltd collects, uses, and stores personal data in operating Re:ta. It applies to individuals whose personal data may appear in Re:ta’s database and to individuals who interact with our service.
Re:ta is a KYC screening tool used by regulated financial institutions — including banks, law firms, and accounting firms — to search for information about individuals and companies that appear in government enforcement records, sanctions lists, wanted persons publications, and similar official sources. Re:ta aggregates and makes searchable the contents of these official publications. It does not add editorial commentary beyond what those authorities have formally stated.
Personal data appears in Re:ta’s database where public-domain official publications by government authorities and public bodies contain information relevant to compliance screening. This includes individuals who:
Your name may also appear in Re:ta’s activity logs if it was entered as a search term by a user of the Re:ta portal. This does not mean you are recorded as having done anything wrong.
| Category | Examples | Source |
|---|---|---|
| Identity information | Name, aliases, date of birth, nationality | Official publications by government authorities and public bodies |
| Address | Where published as part of the official record (e.g. where required for identification) | As above |
| Enforcement or sanctions details | Nature of finding, penalty, designation basis, order made | As above |
| Political office | Parliamentary role, constituency or peerage | UK Parliament website |
| Search log entries | Names entered as search terms; date and time; searching organisation | Re:ta activity logs |
| Portal access records | Which client organisations retrieved a record; when | Re:ta portal access logs |
We process personal data under Article 6(1)(f) UK GDPR on the basis of legitimate interests — our own and those of our clients. Our clients are regulated institutions required by law to conduct customer due diligence and identify financial crime risks. Re:ta provides reliable, government-sourced information that directly supports those legal obligations. We have assessed that this interest is not overridden by your rights and interests, given that all data is sourced from official publications already in the public domain.
Some records relate to criminal offences, criminal proceedings, or findings engaging criminal or quasi-criminal sanctions. This data is processed under Article 10 UK GDPR, on the basis of substantial public interest conditions in the Data Protection Act 2018 — specifically the prevention and detection of unlawful acts, protection of the public against dishonesty or malpractice, and compliance with anti-money laundering legislation. We do not seek your consent for this processing; the applicable legal conditions authorise processing without consent.
Re:ta’s database is accessed by regulated client organisations. When a client user retrieves a record about you, that client receives the data in that record. Our clients act as independent data controllers and are responsible for how they use data retrieved from Re:ta.
We use a small number of third-party service providers who process personal data solely to provide infrastructure services on our behalf. These include cloud infrastructure and database hosting providers, AI processing providers, client relationship management software, and website hosting providers. They do not use Re:ta data for any purpose other than providing services to us.
We do not sell your personal data.
Some of our service providers operate outside the United Kingdom. All transfers of personal data outside the UK are made with an appropriate safeguard in place: transfers to the European Economic Area are covered by the UK Adequacy Regulations 2021; transfers to other countries (including the United States) are made under the UK International Data Transfer Agreement incorporating Standard Contractual Clauses.
We apply technical and organisational security measures appropriate to the sensitivity of the data we hold. These include encryption of data at rest and in transit, access controls and authentication requirements for all users, and contractual security obligations imposed on all service providers. We keep our security measures under review.
Records remain in Re:ta’s database for as long as they are relevant to compliance screening. Where a government authority publishes a status change — such as the lifting of a sanctions designation, the discharge of an individual from insolvency proceedings, a change in political status, or the closure of an enforcement action — we update the record to reflect the current position. The record history is retained because prior adverse history remains relevant to financial crime screening under applicable anti-money laundering legislation and international standards.
Search and portal access logs are retained for six years.
We do not use automated decision-making processes that produce legal effects or similarly significant effects concerning you. Re:ta provides information to its clients; all decisions about individuals are made by the client’s own compliance personnel, not by Re:ta.
Under UK data protection law, you have the right to: request access to the personal data we hold about you; request correction of inaccurate data; request erasure of your data (subject to overriding legitimate grounds — see below); restrict our processing while a dispute is pending; and object to our processing on legitimate interests grounds.
Where a record is sourced from an official government publication, we may be entitled to decline an erasure request on public interest grounds. In such cases, we will explain our decision in writing and direct you to the issuing authority if you wish to challenge the underlying finding.
To exercise any of these rights, email info@chil7.com with the subject line ‘Data Rights Request’, including your full name and, where relevant, your date of birth. We will respond within 30 calendar days.
You have the right to lodge a complaint with the Information Commissioner’s Office (ico.org.uk/make-a-complaint, telephone 0303 123 1113). We would appreciate the opportunity to address your concern directly first — please contact us at info@chil7.com before contacting the ICO.
We may update this notice from time to time. The current version will always be available at chil7.com. This notice was last updated in May 2026 (Version 1.0).