Privacy Policy
Last updated: 14 March 2025
Refute Ltd ("the Company," "we," "us," or "our") (1 Bath Street, London EC1V 9BW) is the data controller for personal data processed through withrefute.com under the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018. This policy explains what data we process, why, and what rights you have.
Refute's core service analyses content submitted by enterprise brand safety teams and newsroom trust desks to score the authenticity of stories and accounts and to detect coordinated inauthentic behaviour. That data-processing reality shapes this policy: we are not a consumer social service. Our clients submit URLs, account identifiers, and content samples; our system returns scored verdicts. This policy covers both the data our clients supply to the platform and the personal data we collect from visitors to this website.
1. Data Controller
Refute Ltd (1 Bath Street, London EC1V 9BW) is the data controller for personal data processed through withrefute.com under the UK GDPR and the Data Protection Act 2018. You can contact us at [email protected].
2. Personal Data We Process
Depending on how you interact with Refute, we process the following categories of personal data:
- Account and identity data: name, work email address, employer name, and job title provided when creating a Refute account or booking a demo.
- Contact and communications data: messages you send via our contact form, email correspondence, and demo-request details.
- Platform usage data: story URLs, account handles, and content samples submitted by authorised users of the Refute scoring service for authenticity analysis. This data is processed solely to generate scored verdicts, network maps, and signal reports for our clients. We do not use submitted content to train our models without explicit written agreement.
- Technical data: IP address, browser type, device identifiers, pages visited, and session identifiers collected automatically when you use the website or platform API.
- Analytics data: aggregated usage metrics collected with your prior consent under the Privacy and Electronic Communications Regulations ("PECR") where a cookie consent has been granted.
3. Lawful Bases (Article 6 UK GDPR)
We process personal data on the following lawful bases:
- Pre-contractual steps and contract performance (Art. 6(1)(b)): processing account data and platform-submitted content to deliver the scoring service to clients.
- Legitimate interests (Art. 6(1)(f)): operating and securing the platform, responding to demo enquiries, fraud prevention, and improving service reliability, where those interests are not overridden by your rights.
- Legal obligation (Art. 6(1)(c)): retaining records to the extent required by applicable UK law.
- Consent (Art. 6(1)(a)): placing non-essential analytics cookies and sending direct marketing, where you have given prior consent that you may withdraw at any time.
4. Recipients and International Transfers
We share personal data only with processors engaged to support the platform (such as cloud infrastructure and analytics providers), under written data-processing agreements complying with Article 28 UK GDPR. Transfers to processors located outside the United Kingdom are protected by the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or an adequacy regulation issued under Section 17A of the Data Protection Act 2018, as applicable. We do not sell personal data to third parties.
5. Retention
We retain personal data only for as long as necessary for the purpose for which it was collected:
- Account and contract data: retained for the duration of the client relationship and for up to 36 months thereafter, to handle post-contract queries and comply with statutory obligations.
- Contact and enquiry data: retained for 24 months from last contact.
- Platform scoring submissions: retained for the period set out in the applicable client agreement; Enterprise clients may request custom data retention terms.
- Access and server logs: retained for 90 days.
- Analytics data: retained for up to 13 months from the date of collection.
6. Your UK GDPR Rights
As a data subject under the UK GDPR, you have the following rights:
- Right of access: to obtain a copy of your personal data and information about how we process it.
- Right to rectification: to have inaccurate personal data corrected.
- Right to erasure: to request deletion of your personal data in certain circumstances.
- Right to restriction of processing: to ask us to limit processing while a dispute is resolved.
- Right to data portability: to receive your data in a structured, commonly used, machine-readable format.
- Right to object: including to direct marketing (which takes effect without conditions), and to processing based on legitimate interests where your particular circumstances warrant it.
- Rights related to automated decision-making: we do not engage in solely automated decisions with legal or similarly significant effects on individuals.
To exercise any of these rights, email [email protected]. We respond within one calendar month, extendable by two further months for complex or multiple requests, and will inform you of any extension.
7. Right to Complain to the ICO
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the UK Information Commissioner's Office ("ICO"), the supervisory authority for data protection in the United Kingdom. The ICO's website is ico.org.uk; helpline 0303 123 1113. We would, however, appreciate the chance to address your concerns before you approach the ICO, so please contact us first.
8. Cookies
See our Cookie Policy for full details. We do not set non-essential cookies (analytics, preferences, or marketing) without your prior consent, as required by PECR. You can manage or withdraw consent at any time via the cookie banner or by clicking "Cookie preferences" in the footer.
9. Security and Changes
We implement technical and organisational measures appropriate to the risks associated with the types of data we process, including encryption in transit, access controls, and regular security assessments. In the event of a personal data breach likely to result in risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay where required. Material changes to this policy are reflected by an updated "Last updated" date.
10. Contact
Refute Ltd1 Bath Street, London EC1V 9BW
Email: [email protected]
Phone: +44 20 3808 7100