Privacy Policy
Who we are
Intesta is operated by DC ESCRYPT SL, Calle Torre Bermeja 2, Urb. Marbella Views, Villa 8, 29679 Benahavís (Málaga), Spain — VAT ES B55413975. DC ESCRYPT SL is the data controller. Contact for anything in this policy: hello@intesta.io.
What Intesta is
Intesta is a public registry of business fact passports. Organisations register an entity (a domain), prove control of that domain, and publish facts about themselves. Those facts are served to people on this site and to AI agents through our API and MCP endpoint. Published passports are public by design — that is the purpose of the registry.
What we store and why
| Data | Why | How long |
|---|---|---|
| Account email address, one-time sign-in codes, session tokens | To let entity owners sign in and manage their passports (legitimate interest / performance of the service) | Account: until you ask us to delete it. Codes and sessions: short-lived, expire automatically |
| Entity data (organisation name, domain, category) and the facts you publish, with their attestation status and source | The registry itself. Published entities and public facts are visible to anyone | Kept while the entity exists. Revoked facts are kept as history in an append-only ledger so that the registry's past statements remain auditable |
| Verification and change events (method used, timestamp, the IP address the request came from) | Proof of how a trust level was earned and who changed what — the integrity of the registry depends on this record | Kept as part of the append-only ledger |
| Question log: the question text sent to the ask endpoint, the channel (human/agent), an optional agent identifier, timestamp | Abuse prevention, rate limiting and improving the passports (unanswered questions are shown to the entity owner as a to-do) | Up to 12 months, then deleted automatically |
| Payment records (Stripe checkout session id, status, amount) — only if you request a paid verification level | To upgrade an entity's trust level after a completed payment | Kept as part of the verification record. We never see or store card numbers — payment details are handled by Stripe |
| Server logs (IP address, request path, status, user agent) | Security and operations | Rotated within 30 days |
Where data is processed
- Servers: hosted in the European Union (OVH, Germany). Encrypted backups are stored in France.
- Email delivery (sign-in codes, notifications): Resend, sent from EU infrastructure.
- Payments (paid verification levels only): Stripe. Stripe's own privacy policy applies to the checkout page.
We do not sell personal data and we do not use advertising trackers. The site sets no third-party cookies; the owner cabinet keeps your session token in your browser's local storage only.
AI agents and public data
Public passports are meant to be read by software, including AI agents, through our MCP endpoint and API. Every response carries a version identifier and a cryptographic signature so that the registry's statements can be verified. If you publish a fact, expect it to be read and quoted by machines.
Usage logs and API keys
To keep single lookups free and meter programmatic access we record, per request to the ask/search/bulk/watchlist endpoints: the IP address (anonymous calls) or the API key identifier (keyed calls), the endpoint and a unit count. These records are kept for up to 13 months for quota accounting and then deleted. API keys are stored only as a hash; the key value is shown once at creation.
Question matching
To find the attested facts that answer a question, the text of the question (and the passport facts) is converted into a numeric representation by a third-party model provider (NVIDIA API; Google Gemini as fallback) and compared inside Intesta. The provider receives only the question text, never your account data. For visitors (human channel) a language model (Ollama cloud) may compose a short answer from the selected facts; it receives only those facts and the question, and its output is accepted only if every statement is verifiably present in the facts — otherwise the facts are shown verbatim. Do not include personal data in questions. Answers are still built exclusively from attested facts; the model never generates content.
Your rights
Under the GDPR you can ask us for access to, correction of, or deletion of your personal data, object to processing, or ask for a copy of your data. Entity owners can revoke their own facts at any time from the cabinet. To exercise any right, write to hello@intesta.io from the email address on your account. You may also lodge a complaint with the Spanish data protection authority (AEPD) or the supervisory authority in your country.
Changes
When this policy changes, the new version is published here with a new effective date.