Contact
Get in touch
Write to us
Send a message
Everything here reaches the same mailbox. Nothing is stored in a ticketing system, nothing is scored by a bot, and there is no queue position to check.
What to expect
Response times
| Subject | First reply | Notes |
|---|---|---|
| General support | 3 business days | Usually much sooner. If it is going to take longer we say so. |
| Credits paid for but not delivered | 1 business day | Treated as urgent. See delivery. |
| Refund request | 2 business days | Acknowledgement. Refund initiated within 5–10 business days — see the refund policy. |
| Security report | 3 business days | Acknowledgement, then a triage assessment within 10 business days. |
| Data protection request | 1 month | The statutory deadline, extendable by two months for a genuinely complex request with notice inside the first month. |
We do not run a phone line or a live chat, and we would rather say so than list a number nobody answers. Everything above is email, and email gets read.
Coordinated disclosure
Reporting a security problem
What we ask
- Report privately first and give us 90 days before publishing, or less by agreement if the fix ships sooner.
- Test only against your own account and your own API keys. Do not access, modify or retain another person’s data — if you stumble on some, stop, tell us, and delete it.
- No denial-of-service testing, no volumetric load testing, no spam or social engineering of our people or our providers, and nothing physical.
- Use the smallest proof of concept that demonstrates the issue. Do not run destructive operations, and do not exfiltrate more than the minimum needed to show it is real.
- Respect the third parties in the chain: our subprocessors have their own disclosure programmes, and issues in their platforms should go to them.
What we do
- Acknowledge within 3 business days, from a person, not an autoresponder.
- Give you a triage assessment — severity, and whether we agree — within 10 business days.
- Keep you updated while we fix it, and tell you when it has shipped.
- Notify affected users where the law or basic decency requires it, and a supervisory authority within 72 hours where a personal data breach requires that — the procedure is written down in the data processing addendum.
Things that are not vulnerabilities
To save you the time: missing security headers with no demonstrated impact, rate limits you consider too generous, the absence of a bug bounty, self-XSS, output from an automated scanner with no working proof of concept, and reports that the public data API serves public data.
Legal identity
Who you are dealing with
- Legal entity
- Merieu Private Limited
- Entity type
- private limited company
- Trading as
- worldgovdata
- Registered address
- C-20, G BlockBandra Kurla ComplexMumbai Maharashtra 400 051India
- Website
- worldgovdata.com
- GSTIN
- 27AAOCM5661J1ZW
- Hosting
- Germany
worldgovdata is an independent project. It is not affiliated with, endorsed by, sponsored by, or acting on behalf of any institution whose data it republishes.
For data corrections, please check the original provider on the sources page first — most values trace directly upstream, and the fastest fix is often at the publisher.