Privacy Policy
How we collect, use, share, and protect information — and your rights.
Last Updated: August 10, 2026
Document Version: 2026-08-10
This version replaces the Privacy Policy last updated June 19, 2026.
Summary: We collect the information needed to run and protect a business screening service: account sign-in data (Google, Microsoft, or email codes), billing data (handled by Stripe), the addresses and watchlists you submit for screening, communications, and website and security logs. On selected public pages, we use Cloudflare Web Analytics to understand page use and performance and the LinkedIn Insight Tag to measure LinkedIn advertising, receive aggregate audience insights, and support website retargeting. We do not sell personal information. We do not send screening submissions, watchlists, or report contents to these website-measurement tools. Separately, the product republishes public-source compliance data (sanctions lists, on-chain company actions, public names and labels) — see Data We Publish for that, including how non-customers can reach us. Our subprocessors are listed at /subprocessors, and a Data Processing Addendum is available to all customers.
1. Who We Are and What This Policy Covers
Eagle Virtual LLC, a Florida limited liability company ("Eagle Virtual," "we," "us"), operates eaglevirtual.com and related services (the "Service"). This policy explains how we process personal data when you visit our websites, create an account, use the Service, or otherwise interact with us — and the rights you have under applicable law, including the EU and UK General Data Protection Regulation ("GDPR"), Brazil's Lei Geral de Proteção de Dados ("LGPD"), and U.S. state privacy laws such as the California Consumer Privacy Act ("CCPA").
For personal data contained in the public-source compliance data we publish (for example, names on government sanctions lists or public blockchain name registrations), the dedicated notice at Data We Publish applies in addition to this policy.
2. Our Roles: Controller and Processor
- Controller. We act as the data controller for account, billing, website, support, security, and marketing data, and for the public-source compliance data we compile and publish.
- Processor. Where you submit data to the Service for screening (for example, blockchain addresses, watchlists, labels, and notes — "Customer Data") and that data contains personal data subject to the GDPR, UK GDPR, or LGPD, we process it on your documented instructions as a processor (LGPD: operador). Our Data Processing Addendum governs that processing.
3. Information We Collect
3.1 Information you provide or authorize us to receive
- Account and sign-in data. You sign in with Google, Microsoft, or an email one-time code. From Google or Microsoft we receive your email address and basic profile information (such as name and account identifier). With email sign-in we process your email address and the one-time codes we send. We do not store a separate Eagle Virtual password.
- Billing data. Paid subscriptions are processed by Stripe, which collects your payment details. We do not store full card numbers; we receive limited billing metadata (plan, status, invoices, last digits/brand of the card).
- Customer screening submissions. Blockchain addresses you screen, watchlists you maintain, and labels or notes you attach. Blockchain addresses are pseudonymous, but an address can constitute personal data where it can be linked to an identifiable person; we treat Customer Data accordingly (see Section 2).
- Communications. If you contact us (email, contact form), we receive your name, contact details, organization, and the content of your message.
3.2 Information collected automatically
- Website, log, and security data. IP address, country, user agent, requested pages/endpoints, response status, timestamps, and referrer. We omit query strings from our recorded page paths and reduce external referrers to the referring domain. For signed-in users, we may associate a page view with the account and session. We use this information for security, abuse prevention, debugging, capacity planning, and website measurement. Our bot-protection provider (Cloudflare Turnstile) processes connection and device signals to distinguish humans from bots.
- Cloudflare Web Analytics. On selected public website pages, Cloudflare's browser beacon processes page-view, referral, device/browser, approximate country, and page performance information so we can understand use and improve website performance. Cloudflare states that Web Analytics does not use cookies or local storage for usage measurement and does not track individuals across its customers' sites.
- LinkedIn Insight Tag. On selected public website pages, including public token pages, LinkedIn receives the page URL, referrer, IP address, browser and device characteristics, and timestamp. Depending on region, browser settings, LinkedIn settings, and our LinkedIn configuration, LinkedIn may use cookies or other identifiers. The tag can support advertising measurement, aggregate professional audience insights, website retargeting, and limited interaction reporting such as page visits, button actions, and form submissions. We receive aggregate reports, not the identities of individual LinkedIn members. Our current site code does not enable enhanced matching or send email addresses through the tag.
- Session and authentication data. Sign-in timestamps, session identifiers, and the IP/user agent associated with authenticated sessions.
- Usage data. Features used, API key usage (for authentication, rate limiting, and billing), and screening query volumes. Where usage accounting can be performed on hashed or aggregated values, we do that rather than retaining raw inputs.
3.3 Public-source compliance data
We collect compliance data from public sources — official government sanctions lists, public blockchain networks (issuer enforcement events), public name registries such as ENS, and public abuse-report databases — and republish some of it. Community abuse-report labels (such as ChainAbuse reports) are collected but are not published on our public pages; if introduced, they would appear only in authenticated customer screening output, identified by source. This can include personal data of people who are not our customers. What we publish, our legal bases, and the rights and review process available to anyone (customer or not) are described in Data We Publish.
3.4 Cookies and Similar Technologies
We use essential session cookies (ev_session and related, HttpOnly/Secure) to keep
you signed in, plus the cookies or state required by Cloudflare Turnstile. Your theme and view
preferences are stored locally in your browser. Cloudflare Web Analytics uses a browser beacon;
Cloudflare states that this analytics product does not use cookies or local storage for usage
measurement. The LinkedIn Insight Tag is non-essential advertising and analytics technology
and may use LinkedIn cookies or other identifiers for the purposes described above. Current
provider details and choices are available through the provider documentation linked from our
Subprocessors and Service Providers page.
4. How We Use Information and Our Lawful Bases
Where the GDPR or LGPD applies, we rely on the following lawful bases. We do not rely on consent except where stated (and where we do, you can withdraw it at any time without affecting prior processing).
- To provide the Service (accounts, sign-in, screening, watchlists, reports, API, support) — performance of a contract (GDPR Art. 6(1)(b); LGPD Art. 7 V).
- To process payments and maintain business records — performance of a contract, and compliance with legal obligations such as tax and accounting rules (GDPR Art. 6(1)(c); LGPD Art. 7 II).
- To secure the Service (logs, abuse and fraud prevention, bot protection, incident response) — legitimate interests (GDPR Art. 6(1)(f); LGPD Art. 7 IX) in protecting our Service, customers, and data; and fraud prevention (GDPR Recital 47; LGPD Art. 10 II).
- To operate, analyze, and improve the Service (website measurement, aggregate usage analysis, debugging, performance, and capacity planning) — legitimate interests in running and improving a business service, using aggregated or de-identified data where feasible.
- To measure and improve our LinkedIn advertising (conversion measurement, aggregate audience insights, and website retargeting) — our legitimate interests in understanding and improving our business-to-business marketing where permitted by law. Applicable law may instead require consent or provide an opt-out right.
- To communicate with you (service notices, billing and security alerts, responses to your requests) — performance of a contract and legitimate interests. Optional product news is sent only with your consent or as otherwise permitted, and you can opt out at any time.
- To compile and publish public-source compliance data — legitimate interests in supporting sanctions and AML/CFT compliance, as explained in detail (including the balancing considerations) in Data We Publish.
- To comply with law (responding to lawful requests, sanctions compliance, enforcing terms, establishing or defending legal claims) — legal obligation and legitimate interests (GDPR Art. 6(1)(c)/(f); LGPD Art. 7 II, VI, IX).
5. How We Share Information
We do not sell personal information. We disclose personal data in the circumstances described below:
- With service providers and subprocessors that help us run the Service (hosting and CDN/security, website analytics, payments, sign-in identity, and transactional email delivery), under applicable contracts and provider terms. The current list, with purposes, locations, and links to each provider's privacy documentation, is maintained at eaglevirtual.com/subprocessors.
- With LinkedIn for public-site advertising measurement. Tagged-page visit information is disclosed to LinkedIn for advertising measurement, aggregate audience insights, website retargeting, and related service improvement. LinkedIn processes that information under its privacy and advertising terms. We receive aggregate reports rather than individual LinkedIn member identities.
- With professional advisers (lawyers, accountants, auditors, insurers) under confidentiality obligations.
- For legal reasons — to comply with law, regulation, legal process, or enforceable governmental requests; to enforce our agreements; or to protect the rights, property, security, or safety of Eagle Virtual, our customers, or others.
- In business transfers. If Eagle Virtual is involved in a merger, acquisition, financing, corporate reorganization, sale of equity or assets, bankruptcy, or other change of control or business transition, personal data may be disclosed during diligence under confidentiality obligations and transferred to the successor or acquirer as part of the transaction. Any successor will be bound to handle the transferred personal data consistently with this policy (or will provide notice and any legally required choices before materially changing how it is handled). This policy does not restrict Eagle Virtual's ability to undertake such a transaction.
Sign-in providers (Google, Microsoft) and our payment processor (Stripe) also act as independent controllers of the data they process in their own right; their privacy notices apply to that processing (links at /subprocessors).
6. International Data Transfers
We are a U.S. company. Personal data is processed in the United States and in the European Union (our primary servers are hosted with Hetzner in Finland). Cloudflare operates a global edge network, and LinkedIn and its providers process Insight Tag information in the United States and other locations described in LinkedIn's privacy documentation. Depending on where you are, your data may therefore be transferred to countries other than your own, in both directions (for example, EU→US and US→EU).
- From the EEA, UK, or Switzerland: where personal data is transferred to the United States or other countries without an adequacy decision, we rely on appropriate safeguards — the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA and Swiss adaptations, as applicable), which are incorporated into our Data Processing Addendum for Customer Data, and/or the EU–U.S. Data Privacy Framework where the receiving provider is certified (several of our subprocessors are; see /subprocessors).
- From Brazil: we rely on the transfer mechanisms recognized by the LGPD and the ANPD's international transfer regulation, including standard contractual clauses, as reflected in our Data Processing Addendum.
You can request a copy of the relevant safeguards via privacy@eaglevirtual.com.
7. Data Retention
- Account data: for the life of your account. Account deletion is handled on request (there is no self-service deletion control); when you request it, we delete or de-identify your account personal data within 30 days, except where retention is legally required.
- Customer Data (screening submissions, watchlists): until you delete it or your account is closed, then deleted or de-identified per the Data Processing Addendum.
- Billing and transaction records: as required by tax, accounting, and audit obligations (typically up to 7 years).
- Server, security, and access logs: short rolling windows sized to security and debugging needs, after which they are deleted or aggregated.
- Website analytics and advertising measurement data: our providers retain information under their own terms. LinkedIn currently states that it removes direct member identifiers from Insight Tag data within 7 days and deletes the remaining pseudonymized data within 180 days. Provider practices may change; current documentation is linked from /subprocessors.
- Issued Certified Report artifacts and their issuance records: retained to operate the public verification service, as described in the Certified Report Terms.
- Published public-source compliance data: for as long as the compliance purpose and source basis persist; source corrections and de-listings propagate on refresh (see Data We Publish).
8. Security
We apply technical and organizational measures appropriate to the risk, including encryption in transit (TLS), HttpOnly/Secure session cookies, server-side access controls and least-privilege administration, isolation of production systems, signed and integrity-checked data publication, logging and monitoring, and vendor due diligence. A summary of our security practices and our vulnerability disclosure policy is at eaglevirtual.com/security. No method of transmission or storage is 100% secure; if we learn of a personal data breach that affects you, we will notify you and the relevant authorities as required by law.
9. Your Rights (EEA, UK, and Similar Jurisdictions)
Where the GDPR or UK GDPR applies to our processing, you have the right to:
- Access the personal data we hold about you, and receive a copy;
- Rectify inaccurate or incomplete data;
- Erase data ("right to be forgotten"), subject to legal exceptions;
- Restrict processing in certain circumstances;
- Object to processing based on legitimate interests, including an absolute right to object to direct marketing;
- Data portability for data you provided to us, in a structured, machine-readable format;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with your national supervisory authority.
To exercise these rights, email privacy@eaglevirtual.com. We respond within one month (extendable as the law allows for complex requests). If your request concerns data we process as a processor on behalf of a customer, we will refer you to that customer and assist them as required. If your request concerns the public-source compliance data we publish, see the dedicated process in Data We Publish — it applies whether or not you are a customer.
10. Brazil (LGPD)
Where the LGPD applies, you have the rights set out in LGPD Article 18, including confirmation of processing, access, correction, anonymization or deletion of unnecessary or noncompliant data, portability, information about sharing and about the consequences of refusing consent, and revocation of consent. Requests go to privacy@eaglevirtual.com, which also serves as our communication channel for LGPD purposes (Art. 41); you may also petition the ANPD. Our lawful bases are listed in Section 4, and our international transfer safeguards in Section 6.
11. California and Other U.S. States
Eagle Virtual is a small business-to-business service and may not meet the thresholds that make the CCPA (as amended by the CPRA) or similar state laws applicable. To the extent such a law applies to you, we provide the following disclosures and will honor the corresponding rights:
- Categories collected (see Section 3): identifiers (name, email, IP), commercial information (subscription and transaction records), internet/network activity (log and usage data), professional information (organization), and customer-submitted content. We do not collect biometric, health, or precise-geolocation data, and we do not use or disclose sensitive personal information for purposes requiring a right to limit.
- Advertising-related disclosures. We do not sell personal information. The LinkedIn Insight Tag discloses tagged-page visit information to LinkedIn for the purposes in Sections 3–5. Privacy laws define terms such as "sale," "sharing," and "targeted advertising" differently. If applicable law gives you a right to opt out of this processing, contact privacy@eaglevirtual.com. LinkedIn members can also manage advertising-data choices in their LinkedIn settings.
- Your rights: to know/access, correct, delete, and to not receive discriminatory treatment for exercising rights. Submit requests to privacy@eaglevirtual.com; authorized agents may submit requests with proof of authorization. We verify requests using your account email.
- Retention is described in Section 7.
12. Non-Customer Data Subjects
If you are not an Eagle Virtual customer but believe the Service displays or includes data about you — for example, a sanctions-list record or a public blockchain name — you have a direct route to us: see Data We Publish for what we publish, our legal bases, and the review/correction process, or simply email privacy@eaglevirtual.com.
13. Children
The Service is a business tool intended for users 18 and older. We do not knowingly collect personal data from children. If we learn that we have, we will delete it promptly.
14. Changes to This Policy
We may update this policy from time to time. We will post the updated policy here and update the "Last Updated" date; for material changes we will provide additional notice (for example, by email to account holders or a notice in the Service) before the changes take effect.
15. Contact Us
- Privacy requests (all jurisdictions, customers and non-customers): privacy@eaglevirtual.com
- EU, UK, and Swiss data subjects: you can reach us at privacy@eaglevirtual.com. If and where we are required to designate a representative under GDPR or UK GDPR Article 27, we will do so and identify the representative here.
- Legal: legal@eaglevirtual.com
- Security disclosures: eaglevirtual.com/security or security@eaglevirtual.com
- Address: Eagle Virtual LLC, 8586 Potter Park Dr, Sarasota, FL 34238, United States