Skip to content
worldgovdata
Sign in

Legal / Privacy

Privacy policy

The full Article 13 and 14 notice: every category we hold, the legal basis for each purpose, how long it survives, who else sees it, and the exact route for each of your eight rights. We stayed cookieless on purpose, which is why you have never been shown a consent banner here.

Version 2026-07-28Effective 2026-07-28

01

Who is responsible for your data

The controller of the personal data described here is Merieu Private Limited, the operator of worldgovdata. That means we decide why and how it is processed, and we are the party you hold to account for it.

Controller
Merieu Private Limited (private limited company), trading as worldgovdata
Registered address
C-20, G BlockBandra Kurla ComplexMumbai Maharashtra 400 051India
Data protection officer
None appointed
EU representative
— to be completed —
Where the service runs
netcup GmbH, Germany (European Union)

We are not required to appoint a data protection officer: we do not carry out large-scale systematic monitoring and we process no special-category data. Where the field above says — to be completed —, the answer is not yet settled and we would rather show the gap than invent one. Privacy questions go to the address above and reach a person, not a queue.

02

What this notice covers

This notice covers the worldgovdata website, the account area, and the metered API at https://api.worldgovdata.com/v1.

It does not cover the statistical data the service publishes. That data is country-level and indicator-level — population, emissions, school enrolment, government effectiveness — aggregated by the institutions that produce it. It contains no personal data, we do not attempt to make it personal, and reading it tells us nothing about you.

You can browse the entire portal without an account. Personal data only starts existing when you create one.

03

What we collect

Four categories, and nothing outside them. We do not buy data about you, we do not enrich your record from third parties, and we do not run advertising or marketing trackers.

Categories of personal data worldgovdata processes, with the fields in each and where they come from.
CategoryWhat is in itWhere it comes from
AccountEmail address, name if you give one, a password hash (argon2id — never the password), self-declared country, marketing opt-in flag and its timestamp, the terms and privacy versions you accepted, and account timestamps.You, at signup and in settings.
AuthenticationSession records (a hash of the session token, a hashed IP, the browser user-agent string, timestamps), login attempts (a hashed email key, a hashed IP, success or failure), and single-use email tokens for verification and password reset.Generated when you sign in or ask for a link.
BillingOrders — pack, currency, amount, credits, receipt and invoice number, billing name and country — the payment provider's order and payment identifiers, and the credit ledger. We never see or store your card number, and no card is kept on file.You, and our payment processor when it confirms a payment.
Usage and technicalPer-request records: the route template (never the raw URL), method, status, credits charged, row count, duration and a hashed IP; the daily rollup derived from them; API key metadata (name, public id, a hash of the secret, last four characters, scopes); an audit log of security-relevant actions; and ordinary server logs.Generated automatically as you use the API and the site.

IP addresses are never stored raw

Wherever this notice says “a hashed IP”, we mean an HMAC-SHA256 digest computed with a server-side secret. It lets us count repeated failures from one source without holding the address itself. The same discipline applies to session tokens and API key secrets: we store a hash, so a copy of our database does not hand anyone a working credential.

Support correspondence

If you email us, we keep the message and our reply for as long as needed to deal with it and to have a record of what was agreed.

05

Is providing it mandatory?

Browsing the portal requires nothing at all. Beyond that:

  • Email and password are required to hold an account. They are a contractual necessity — without them there is no account to authenticate, no way to send you a receipt, and no way to return a key to its owner. If you do not want to provide them, you can still use every free part of the service.
  • Name and country are optional. Country helps us apply the right tax treatment; leaving it blank costs you nothing.
  • Marketing consent is optional and never a condition of anything.
  • Billing name and country become required at the moment you buy credits, because invoicing and tax law require them.
06

Cookies, analytics, and why there is no banner

We set exactly two cookies, both strictly necessary: one holds your signed-in session, one carries a CSRF token that stops another site submitting forms as you. Both are set only after you sign in. A signed-out visitor gets no cookies at all.

Because we set nothing beyond what is strictly necessary, no consent is legally required and no consent banner is shown. That is the entire point of the design, not an oversight. The full list, including the two browser-local preferences that are not cookies, is on the cookie page.

Analytics, in detail

We use PostHog to count page views. It is configured with in-memory persistence, so it writes no cookie and no local storage and holds no identifier that survives the tab. Autocapture, session recording and page-leave tracking are all switched off; only a pageview event with a path is sent. We honour the browser’s Do Not Track signal, and where a deployment has no analytics key configured, nothing is collected at all.

The consequence is that our analytics cannot tell one visitor from another, cannot follow you between visits, and cannot be used to build a profile. We accept less precise numbers in exchange for that.

07

Who else touches it

A small number of processors run parts of the service for us. Each is bound by a written data processing agreement, may act only on our instructions, and is named — with its location and the transfer safeguard that applies — on the subprocessors page, which is the authoritative list.

  • Hosting and infrastructure, in Germany.
  • CDN, DNS and denial-of-service protection.
  • Transactional email delivery.
  • Cookieless product analytics.
  • Payment processing. Our payment processor is also an independent controller of the card and anti-money-laundering data you give it directly — that part is governed by its own privacy notice, not ours, because we never receive it.

Beyond those: our professional advisers where they need to see something, a successor entity if the business is ever transferred (you would be told first), and public authorities where we are legally compelled — in which case we will tell you unless the law forbids it.

08

International transfers

The service runs on infrastructure in Germany, inside the European Union, and that is where account, usage and billing records live.

Two functions involve a transfer outside the EEA: payment processing, which is performed in India, and transactional email delivery, which is performed in the United States. Our CDN operates a global edge network. In each case the transfer is covered by the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) incorporated into that provider’s data processing agreement, together with the technical measures described in clause 11 — in particular that everything is encrypted in transit and that we hash rather than store the identifiers most likely to be sensitive.

The subprocessors page states the mechanism for each named recipient. You may ask us for a copy of the safeguards by emailing queries@worldgovdata.com.

09

How long we keep it

Retention is per category, not one blanket period, and the clocks below are the ones the system actually runs.

Retention period for each category of data, and what happens at the end of it.
WhatKept forThen
Account recordWhile openSoft-deleted the moment you ask; hard-deleted 30 days later.
Sessions90 days maxDeleted. Sliding 30-day expiry with a hard 90-day cap that is never extended.
Per-request usage events90 daysDeleted by a daily job. Only the aggregated daily rollup survives.
Daily usage rollupIndefinitelyKept as an aggregate: a day, an endpoint template and three counts.
Login attempts30 daysDeleted.
Security audit log24 monthsDeleted.
Credit ledgerWhile the account is openKept as long as the account exists — it is the audit trail behind every balance. Entries tied to a purchase follow the 8-year rule below.
Orders and invoices8 yearsRetained because tax and accounting law requires it. This is the one category a deletion request cannot clear.
Verification and reset tokens24h / 1hSingle-use, then expired and cleared.
Support correspondence24 monthsDeleted, unless it relates to a matter still open.

When you delete your account

The account is marked deleted immediately, sessions and keys stop working at once, and the record is purged 30 days later. The delay is deliberate: it is the window in which a mistaken or malicious deletion can be undone. After it, the only thing that remains is the financial record the law obliges us to keep, held in pseudonymised form — order, amount, date, tax details — with the account identifiers stripped.

10

Your rights, and exactly how to use them

You have all eight. Two of them you can exercise yourself, right now, without asking us — which is how it should be.

Each data protection right, and the specific route for exercising it.
RightHow to use it
Access — Art. 15Self-serve. Account settings → export my data produces a machine-readable JSON file of your account, keys, ledger, usage and orders, available on a signed one-time link. Or email us and we will send it.
Portability — Art. 20The same export. It is JSON, structured and commonly used, so it can be handed to another provider directly.
Rectification — Art. 16Self-serve. Change your name, country and marketing preference in settings. To change your email address, or to correct anything you cannot reach, email us.
Erasure — Art. 17Self-serve. Account settings → delete account, confirmed with your password. See clause 09 for what survives and why. If you hold unused credits, ask for a refund before deleting.
Restriction — Art. 18Email queries@worldgovdata.com. We freeze the data in place while a dispute about its accuracy or our basis is resolved.
Objection — Art. 21Email queries@worldgovdata.com, telling us which processing and why. For anything resting on legitimate interests we stop unless we can show compelling grounds that override your interests, and we will explain our reasoning either way. Objection to direct marketing is absolute — we stop, no balancing.
Withdraw consent — Art. 7(3)Self-serve. Turn off the marketing preference in settings, or reply to any marketing email. It takes effect immediately and does not affect the lawfulness of what came before.
Complain to a regulator — Art. 77You may complain to the supervisory authority in the EU or EEA state where you live, where you work, or where you think the problem happened. The European Data Protection Board publishes the directory of national authorities. You do not have to come to us first, though we would like the chance to fix it.

How we handle a request

  • We reply within one month. If a request is genuinely complex we may extend by up to two further months, and we will tell you inside the first month that we are doing so and why (Art. 12(3)).
  • It is free. We charge only for a request that is manifestly unfounded or excessive, and we would explain first.
  • We verify that the request comes from the account holder — normally by requiring you to be signed in, or by writing to the address on the account. We will not ask you for an identity document unless we have real doubt.
  • If we refuse, we say why, and we tell you about your right to complain and to a judicial remedy.
11

No automated decisions, no profiling

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22. We build no profiles, score nobody, and take no automated decision about creditworthiness, eligibility or pricing.

To be complete about it: two controls do run automatically. Rate limits throttle a key or an address that exceeds a documented threshold, and repeated failed logins trigger a temporary lockout. Both are mechanical, time-limited and reversible, neither produces a legal effect, and a human is one email away at queries@worldgovdata.com if one of them catches you unfairly.

12

How we protect it

The measures below are the ones actually in place. We hold no security certification and make no claim to one — no ISO 27001, no SOC 2, no audit report. When we have something to show, we will name it here.

  • Everything travels over HTTPS, with HSTS enforced.
  • Passwords are hashed with argon2id and are never logged, never returned, and never included in an error message.
  • Session tokens and API key secrets are stored only as SHA-256 hashes. We cannot recover either, which is also why a leaked key must be revoked rather than retrieved.
  • IP addresses are stored only as HMAC-SHA256 digests, with a server-side secret.
  • Account, billing and security-relevant actions are written to an append-only audit log.
  • Access to production data is limited to the people who need it to run the service, and the payment path is delegated to a processor so that card data never reaches our systems at all.
  • Automatic backups, with a documented breach procedure in the data processing addendum: notification to a supervisory authority within 72 hours where the law requires it, and to affected users without undue delay where the risk is high.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If you find a weakness, the coordinated disclosure invitation on the contact page is genuine.

13

Children

The service is not directed at children. You must be at least 16, or the age of digital consent where you live if that is higher, to hold an account. We do not knowingly collect data from anyone younger; if you believe a child has created an account, tell us at queries@worldgovdata.com and we will delete it.

14

Changes to this notice

When this notice changes we bump the version stamp at the top of the page and set a new effective date. The version you accepted at signup is recorded against your account, so there is always a record of which text you agreed to.

For a change that materially affects how we use your data, we email account holders at least 30 days before it takes effect. We will not make a material change retroactive.

The statistical data this service publishes is aggregated country-level material from public institutions and contains no personal data. This notice is about the account and billing records that exist because you use the service. Data protection requests: queries@worldgovdata.com.