Skip to main content
AdverseSearch
PlaygroundAPIPricing
Sign inPlayground
Privacy

Privacy that matches the sensitivity of screening.

This notice explains how Mentorsko Ltd. handles account, contact, security, and adverse media screening data through AdverseSearch.

Last updated 25 August 2026Mentorsko Ltd.
Legal centrePrivacyTermsCookies
On this page
01Scope and controller02Our privacy roles03Data we process04Purposes and legal bases05Sensitive and offence data06Sharing and transfers07Retention and deletion08Your rights09Security10Contact and complaints
Questions or requests?

Use our secure contact form. Do not include screening subjects or evidence in your first message.

Contact Mentorsko Ltd.
Anonymous access24 hours
Screening accessUp to 30 days
Optional advertising cookiesNone
The short version

Customers must have a lawful basis before submitting a person for screening. AdverseSearch supports research and review, but it must not make the final decision about a person.

1. Scope and controller

This Privacy Policy applies to AdverseSearch websites, accounts, APIs, the signed-in playground, contact forms, and related support. The service is operated by Mentorsko Ltd., company registration number 207211334 and VAT number BG207211334, with registered office at 1797 Sofia, Mladost district, Musagenitsa residential complex, block 89, entrance 7, apartment 126, Bulgaria.

Mentorsko Ltd. is the controller for account administration, enquiries, service security, abuse prevention, usage records, and its own legal obligations. The role for screening subject data depends on how the service is used, as explained below.

2. Our privacy roles

When a business customer decides why a person is screened and submits the identifiers, that customer normally acts as controller and Mentorsko Ltd. acts as processor on the customer's documented instructions. The customer remains responsible for its lawful basis, notices, rights handling, decision process, and any sector rules that apply.

Mentorsko Ltd. may act as an independent controller for limited operational data needed to authenticate users, secure the service, prevent abuse, enforce limits, maintain audit records, respond to requests, establish legal claims, and meet legal duties.

An order form or separate data processing agreement may add terms for production use. If those terms conflict with this notice, the more specific privacy term governs the relevant processing.

3. Data we process

Screening inputs and results

A screening requires a first and last name. A customer may also submit a middle name, date of birth, country, state, city, postal code, gender, phone number, email address, and an internal reference. Results may include public source links, excerpts, dates, identity indicators, event details, confidence, and coverage.

Search and AI-assisted source review providers receive data needed for their role. The search provider receives the submitted name and only the optional query inputs enabled by the platform administrator, together with market, language, and page controls. Those optional inputs can include middle name, country, state, city, postal code, date of birth, gender, email, and phone. It stores readable query text in its service account for usage history, security, support, and service operation. Search result previews may also be held in its configured short cache and are not part of the readable query-history record.

Tool-enabled AI source scouts receive the submitted name, mechanically generated name variants, and every optional identity field supplied for that screening, including date of birth, location, postal code, gender, phone, and email. They may place those supplied fields into provider-hosted web queries for source discovery and identity resolution. Exact email addresses and phone numbers may be searched separately. The same submitted subject payload is used if a scout switches to its configured fallback provider. These scout queries are separate from GSearch, so the GSearch optional-input choices do not limit them.

A separate tool-free General Web selector receives only the submitted name, name variants, and bounded public search packets containing exact URLs, titles, and previews, then passes only selected URLs to the web-enabled scout. Limited follow-up discovery receives bounded previously discovered candidate URLs and strict rejection codes. For each candidate, a target-free retrieval request receives one public URL and uses hosted web search to return bounded source text. A separate tool-free verifier receives that text with the submitted name and optional date of birth, country, state, and city. A screening can run up to 24 candidate pipelines and 48 evidence-phase AI calls, with no more than 8 candidate pipelines active at once. Separate bounded scout and selector calls can also run.

AI screening requests are configured not to store generated response objects for later application retrieval. Provider-hosted query records, security records, contract terms, account controls, and limited security or legal retention may still apply independently. Disabling generated response storage does not remove those separate records.

Account, contact, and usage data

We process account identity and workspace details, sign-in and session records, API key metadata, request and credit usage, plan and rate-limit information, role information, contact form details, support correspondence, and limited delivery status data. API key secrets are shown once and are not stored in readable form.

Billing data

For credit purchases and optional automatic top-up, we process pack choice, amount, currency, payment status, transaction identifiers, customer and payment-method references, billing contact details, automatic top-up settings, consent or withdrawal time, and limited failure information. Full payment card numbers and card security codes are collected by our payment service provider and are not stored by AdverseSearch.

Security and device data

We process IP-derived security signals, device and network fingerprints in protected form, request identifiers, timestamps, browser and request metadata, authentication events, audit events, and security challenge results. Routine AdverseSearch application logs are designed to exclude raw screening subjects, search phrases, evidence excerpts, credentials, and authentication cookies. This does not include separate query and security records held by search or AI source-review providers as described above.

Sources

Data comes from customers and users, their identity provider, public online material selected for review, technical interactions with the service, and communications sent to us. Public availability does not remove the customer's duty to use the information lawfully and fairly.

4. Purposes and legal bases

Provide the service

To create accounts, take payment, manage credits and automatic top-up, accept requests, run screenings, return evidence, support deletion, and manage contracted access. We rely on contract necessity or the customer's documented instructions.

Keep the service secure

To authenticate users, prevent fraud and abuse, enforce limits, investigate incidents, and protect customers. We rely on legitimate interests and, where required, legal obligations.

Communicate

To answer sales, support, privacy, legal, and security enquiries. We rely on steps requested before a contract, contract necessity, or legitimate interests.

Meet legal duties

To comply with law, respond to lawful requests, maintain necessary records, and establish or defend legal claims.

Where consent is the proper legal basis, it can be withdrawn for future processing. Withdrawal does not affect processing that was lawful before withdrawal.

5. Sensitive data and criminal offence information

Customer responsibility

Adverse media can reveal allegations, convictions, political views, health information, or other sensitive facts. Customers must not submit or use this data unless applicable law permits it and suitable safeguards are in place.

Information about criminal convictions and offences is subject to Article 10 GDPR and national law. A customer must identify and document the legal authority for that processing before using AdverseSearch for such information. Access to the service does not create that authority.

AdverseSearch does not make solely automated decisions with legal or similarly significant effects. Outputs are research signals. A qualified human must review the identity evidence, source, context, recency, disputes, acquittals, dismissals, coverage, and applicable law before action is taken.

6. Sharing and international transfers

We disclose data only as needed to operate the service, follow customer instructions, protect rights and security, or comply with law. Recipient categories may include hosting and database providers, payment and billing providers, search and AI-assisted source review services, identity and anti-abuse services, email delivery providers, professional advisers, authorities, and a buyer in a lawful corporate transaction.

Providers are limited by contract and access controls appropriate to their role. Screening data is not sold and is not shared for third-party advertising.

Some providers may process data outside the European Economic Area. Where required, we use an adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism, together with supplementary safeguards where appropriate.

7. Retention and deletion

  • Free search allowance: the service records searches against your signed-in account to enforce 3 free attempts in each rolling 24-hour period. Deleting a result does not restore an attempt.
  • Authenticated screenings: access expires no later than 30 days after creation. Authorized workspace members may delete completed records sooner.
  • Provider processing records: GSearch discovery queries are stored in the configured search-provider account under its retention and access settings. AI source-review providers may separately keep hosted-query and security records under approved contract, account, security, and legal settings even though generated response storage is disabled where supported. Deleting an AdverseSearch screening does not necessarily remove those separate provider records.
  • Pending email delivery: recipient and encrypted payload data expire within 24 hours. Successful or permanently rejected message details are cleared earlier where the delivery state permits.
  • Delivery metadata: after recipient and message content are cleared, a limited record of message type, delivery state, attempts, relevant timestamps, and an internal user or screening identifier used to prevent duplicate sends becomes eligible for scheduled deletion after 30 days.
  • Sessions: the browser cookie may last up to 30 days, but server access can expire after 12 hours of inactivity or earlier on sign-out or revocation.
  • Billing records: transaction, invoice, tax, consent, and accounting records are retained for the period required by tax, accounting, fraud-prevention, and legal-claims rules. Saved payment-method references remain while automatic top-up is enabled or while otherwise needed for the billing relationship.
  • Security and audit records: retained only for a proportionate period needed for security, accountability, disputes, and legal duties. They are designed not to contain the raw screening subject.

Independent scheduled maintenance performs physical cleanup. A short operational delay can occur after an access deadline while the next cleanup cycle completes or a temporary lock clears. Backups, legal holds, and records required by law may follow a separate, limited schedule.

8. Your rights

Depending on the law and our role, you may have rights to information, access, correction, deletion, restriction, portability, objection, and withdrawal of consent. You may also complain to a supervisory authority.

If a customer controls the screening record, we may direct your request to that customer or help it respond. We may ask for proportionate proof of identity and enough context to locate the relevant record. Do not send identity documents, screening subjects, or evidence through the first contact message unless we specifically request them through a secure channel.

Authorized workspace users can delete eligible screenings in the account interface. Cookie choices are described in our Cookie Policy.

9. Security

We use technical and organizational measures designed for the sensitivity of screening data. These include encryption of sensitive stored screening fields, transport protection, role-based access, tenant-scoped controls, short access windows, protected API keys and sessions, audit events, rate limits, security challenges, restricted operational logging, and independent retention maintenance.

No online service can guarantee absolute security. Customers must protect their credentials, limit submitted data to what is needed, configure access carefully, and notify us promptly of a suspected incident.

10. Contact, complaints, and changes

For a privacy request or question, use the AdverseSearch contact form and write “Privacy request” at the start of the message. Do not include screening subject data in the initial form.

You can complain to the Bulgarian Commission for Personal Data Protection or the supervisory authority where you live or work. The Bulgarian authority provides current complaint instructions on its official website.

We may update this policy when the service, law, or our processing changes. Material changes will be highlighted through an appropriate service or account notice. The date at the top shows the latest revision.

Mentorsko Ltd.

Company registration number 207211334 · VAT number BG207211334 · Sofia, Bulgaria

Contact us
AdverseSearch

Adverse media screening and negative news search with source links for business teams.

Product

PlaygroundAPI docsPricing

Trust

SecurityPrivacyTermsCookies

Company

ContactAccount
© 2026 Mentorsko Ltd. AdverseSearch is a service of Mentorsko Ltd.