Privacy policy

Scrutinex is operated by Cardinal Point Advisors. This policy covers both the people who order reports and the people and companies those reports are about.

Last updated 1 August 2026

  1. 01What we collect from clients

    When you order a report we collect your name, email address, organisation and country, the subject details and identifiers you supply, and the purpose you state for the report. If you create an account we also store authentication data handled by our authentication provider.

    We collect standard server and analytics data when you use the website, including IP address, browser type and pages viewed.

  2. 02What we collect about report subjects

    To prepare a report we process identifying information about the subject: legal or personal name, registration number, date of birth, nationality, addresses, directorships and shareholdings, sanctions and PEP list entries, offshore database records, litigation records and published media.

    This data comes from public registers, licensed commercial databases and the information you provide. We do not obtain data through pretexting, unauthorised access or any unlawful means.

  3. 03Why we process it

    We process client data to accept, prepare and deliver the report you ordered and to maintain records of the engagement. We process subject data for the legitimate interest of our client in verifying a counterparty before entering a commercial relationship, and for the prevention of fraud and financial crime. We do not use subject data for marketing, and we do not sell data to anyone.

  4. 04Who we share it with

    We share data with service providers who host our infrastructure, process payments and supply screening databases, in each case under contract and only to the extent needed. We disclose data to authorities where legally required. We do not disclose to the subject of a report that a report has been commissioned, except where reference verification with contacts you supplied necessarily involves contacting them.

  5. 05How long we keep it

    Completed reports and the underlying research file are retained for seven years, which reflects the period over which a due diligence decision may need to be evidenced. Order and billing records are retained as required by applicable tax and accounting law. You may ask us to delete your account data at any time, subject to those retention obligations.

  6. 06Security

    Data is encrypted in transit and at rest. Access to research files is restricted to the analysts working on them. Report delivery is by authenticated link rather than open attachment. We do not store payment card details on our systems.

  7. 07Your rights

    Depending on where you live, you may have rights to access, correct, delete, restrict or object to our processing of your personal data, and to receive a copy in portable form. Report subjects in jurisdictions with data protection legislation such as the GDPR may exercise those rights in relation to data we hold about them.

    Submit requests to support@scrutinex.com. We respond within 30 days. Where a request would require us to disclose the identity of a client who commissioned a report, we will consider that request against our confidentiality obligations and applicable exemptions, and explain our position.

  8. 08International transfers

    We operate globally, and data may be processed in countries other than your own, including by our infrastructure providers. Where personal data is transferred out of the European Economic Area or the United Kingdom, we rely on standard contractual clauses or another lawful transfer mechanism.

  9. 09Cookies

    We use only the cookies needed to keep you signed in and to measure aggregate site usage. We do not use advertising cookies and we do not share browsing data with advertising networks.

  10. 10Contact

    Cardinal Point Advisors, data controller and data protection contact

    11468 Marketplace Dr. N., Champlin, MN 55316, United States

    +1 575 418 4408

    support@scrutinex.com