Legal / Privacy
Privacy policy
Version 2026-07-28Effective 2026-07-28
Who is responsible for your data
The controller of the personal data described here is Merieu Private Limited, the operator of worldgovdata. That means we decide why and how it is processed, and we are the party you hold to account for it.
- Controller
- Merieu Private Limited (private limited company), trading as worldgovdata
- Registered address
- C-20, G BlockBandra Kurla ComplexMumbai Maharashtra 400 051India
- Privacy contact
- queries@worldgovdata.com
- Data protection officer
- None appointed
- EU representative
- — to be completed —
- Where the service runs
- netcup GmbH, Germany (European Union)
We are not required to appoint a data protection officer: we do not carry out large-scale systematic monitoring and we process no special-category data. Where the field above says — to be completed —, the answer is not yet settled and we would rather show the gap than invent one. Privacy questions go to the address above and reach a person, not a queue.
What this notice covers
This notice covers the worldgovdata website, the account area, and the metered API at https://api.worldgovdata.com/v1.
It does not cover the statistical data the service publishes. That data is country-level and indicator-level — population, emissions, school enrolment, government effectiveness — aggregated by the institutions that produce it. It contains no personal data, we do not attempt to make it personal, and reading it tells us nothing about you.
You can browse the entire portal without an account. Personal data only starts existing when you create one.
What we collect
Four categories, and nothing outside them. We do not buy data about you, we do not enrich your record from third parties, and we do not run advertising or marketing trackers.
| Category | What is in it | Where it comes from |
|---|---|---|
| Account | Email address, name if you give one, a password hash (argon2id — never the password), self-declared country, marketing opt-in flag and its timestamp, the terms and privacy versions you accepted, and account timestamps. | You, at signup and in settings. |
| Authentication | Session records (a hash of the session token, a hashed IP, the browser user-agent string, timestamps), login attempts (a hashed email key, a hashed IP, success or failure), and single-use email tokens for verification and password reset. | Generated when you sign in or ask for a link. |
| Billing | Orders — pack, currency, amount, credits, receipt and invoice number, billing name and country — the payment provider's order and payment identifiers, and the credit ledger. We never see or store your card number, and no card is kept on file. | You, and our payment processor when it confirms a payment. |
| Usage and technical | Per-request records: the route template (never the raw URL), method, status, credits charged, row count, duration and a hashed IP; the daily rollup derived from them; API key metadata (name, public id, a hash of the secret, last four characters, scopes); an audit log of security-relevant actions; and ordinary server logs. | Generated automatically as you use the API and the site. |
IP addresses are never stored raw
Wherever this notice says “a hashed IP”, we mean an HMAC-SHA256 digest computed with a server-side secret. It lets us count repeated failures from one source without holding the address itself. The same discipline applies to session tokens and API key secrets: we store a hash, so a copy of our database does not hand anyone a working credential.
Support correspondence
If you email us, we keep the message and our reply for as long as needed to deal with it and to have a record of what was agreed.
Why we process it, and on what legal basis
Every purpose below has one named basis under Article 6 of the GDPR. Nothing rests on “legitimate interests” as a catch-all, and where it is the basis we say what the interest is and what we did to keep it proportionate.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and run your account and give you API access | Account, authentication, API key metadata | Art. 6(1)(b) — performance of a contract with you. |
| Meter usage, charge credits, maintain the ledger and show you your usage | Usage, credit ledger | Art. 6(1)(b) — performance of a contract with you. |
| Take payment, issue receipts and invoices | Billing | Art. 6(1)(b) — performance of a contract with you. |
| Keep accounting and tax records | Billing, invoices | Art. 6(1)(c) — compliance with a legal obligation. |
| Send service email: verification, password reset, receipts, security notices, breaking-change warnings | Account | Art. 6(1)(b) — performance of a contract. These are not marketing and you cannot unsubscribe from them while you hold an account. |
| Prevent abuse: brute-force lockout, rate limiting, fraud and payment-reversal checks, keeping the service available | Authentication, usage, audit log | Art. 6(1)(f) — legitimate interests. Our interest is a secure and available service, which is also your interest. Kept proportionate by hashing IPs, storing route templates rather than URLs, and deleting login attempts after 30 days. |
| Count page views so we can see which parts of the portal are useful | Cookieless, identifier-free pageview counts | Art. 6(1)(f) — legitimate interests in understanding aggregate use. No cookie, no persistent identifier, no profile, and no ability to single you out. See clause 06. |
| Send product or marketing email | Account email, consent flag | Art. 6(1)(a) — consent, given by opting in and withdrawable at any moment in settings or by one reply. Withdrawal does not affect what was lawful before it. |
| Handle your data protection requests and keep a record of them | Account, request record, audit log | Art. 6(1)(c) — compliance with a legal obligation. |
| Establish, exercise or defend legal claims | Whatever is relevant to the claim | Art. 6(1)(f) — legitimate interests in defending ourselves, limited to what the specific matter needs. |
You can object to anything resting on legitimate interests. Clause 09 explains how, and what happens next.
Is providing it mandatory?
Browsing the portal requires nothing at all. Beyond that:
- Email and password are required to hold an account. They are a contractual necessity — without them there is no account to authenticate, no way to send you a receipt, and no way to return a key to its owner. If you do not want to provide them, you can still use every free part of the service.
- Name and country are optional. Country helps us apply the right tax treatment; leaving it blank costs you nothing.
- Marketing consent is optional and never a condition of anything.
- Billing name and country become required at the moment you buy credits, because invoicing and tax law require them.
Who else touches it
A small number of processors run parts of the service for us. Each is bound by a written data processing agreement, may act only on our instructions, and is named — with its location and the transfer safeguard that applies — on the subprocessors page, which is the authoritative list.
- Hosting and infrastructure, in Germany.
- CDN, DNS and denial-of-service protection.
- Transactional email delivery.
- Cookieless product analytics.
- Payment processing. Our payment processor is also an independent controller of the card and anti-money-laundering data you give it directly — that part is governed by its own privacy notice, not ours, because we never receive it.
Beyond those: our professional advisers where they need to see something, a successor entity if the business is ever transferred (you would be told first), and public authorities where we are legally compelled — in which case we will tell you unless the law forbids it.
International transfers
The service runs on infrastructure in Germany, inside the European Union, and that is where account, usage and billing records live.
Two functions involve a transfer outside the EEA: payment processing, which is performed in India, and transactional email delivery, which is performed in the United States. Our CDN operates a global edge network. In each case the transfer is covered by the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) incorporated into that provider’s data processing agreement, together with the technical measures described in clause 11 — in particular that everything is encrypted in transit and that we hash rather than store the identifiers most likely to be sensitive.
The subprocessors page states the mechanism for each named recipient. You may ask us for a copy of the safeguards by emailing queries@worldgovdata.com.
How long we keep it
Retention is per category, not one blanket period, and the clocks below are the ones the system actually runs.
| What | Kept for | Then |
|---|---|---|
| Account record | While open | Soft-deleted the moment you ask; hard-deleted 30 days later. |
| Sessions | 90 days max | Deleted. Sliding 30-day expiry with a hard 90-day cap that is never extended. |
| Per-request usage events | 90 days | Deleted by a daily job. Only the aggregated daily rollup survives. |
| Daily usage rollup | Indefinitely | Kept as an aggregate: a day, an endpoint template and three counts. |
| Login attempts | 30 days | Deleted. |
| Security audit log | 24 months | Deleted. |
| Credit ledger | While the account is open | Kept as long as the account exists — it is the audit trail behind every balance. Entries tied to a purchase follow the 8-year rule below. |
| Orders and invoices | 8 years | Retained because tax and accounting law requires it. This is the one category a deletion request cannot clear. |
| Verification and reset tokens | 24h / 1h | Single-use, then expired and cleared. |
| Support correspondence | 24 months | Deleted, unless it relates to a matter still open. |
When you delete your account
The account is marked deleted immediately, sessions and keys stop working at once, and the record is purged 30 days later. The delay is deliberate: it is the window in which a mistaken or malicious deletion can be undone. After it, the only thing that remains is the financial record the law obliges us to keep, held in pseudonymised form — order, amount, date, tax details — with the account identifiers stripped.
Your rights, and exactly how to use them
You have all eight. Two of them you can exercise yourself, right now, without asking us — which is how it should be.
| Right | How to use it |
|---|---|
| Access — Art. 15 | Self-serve. Account settings → export my data produces a machine-readable JSON file of your account, keys, ledger, usage and orders, available on a signed one-time link. Or email us and we will send it. |
| Portability — Art. 20 | The same export. It is JSON, structured and commonly used, so it can be handed to another provider directly. |
| Rectification — Art. 16 | Self-serve. Change your name, country and marketing preference in settings. To change your email address, or to correct anything you cannot reach, email us. |
| Erasure — Art. 17 | Self-serve. Account settings → delete account, confirmed with your password. See clause 09 for what survives and why. If you hold unused credits, ask for a refund before deleting. |
| Restriction — Art. 18 | Email queries@worldgovdata.com. We freeze the data in place while a dispute about its accuracy or our basis is resolved. |
| Objection — Art. 21 | Email queries@worldgovdata.com, telling us which processing and why. For anything resting on legitimate interests we stop unless we can show compelling grounds that override your interests, and we will explain our reasoning either way. Objection to direct marketing is absolute — we stop, no balancing. |
| Withdraw consent — Art. 7(3) | Self-serve. Turn off the marketing preference in settings, or reply to any marketing email. It takes effect immediately and does not affect the lawfulness of what came before. |
| Complain to a regulator — Art. 77 | You may complain to the supervisory authority in the EU or EEA state where you live, where you work, or where you think the problem happened. The European Data Protection Board publishes the directory of national authorities. You do not have to come to us first, though we would like the chance to fix it. |
How we handle a request
- We reply within one month. If a request is genuinely complex we may extend by up to two further months, and we will tell you inside the first month that we are doing so and why (Art. 12(3)).
- It is free. We charge only for a request that is manifestly unfounded or excessive, and we would explain first.
- We verify that the request comes from the account holder — normally by requiring you to be signed in, or by writing to the address on the account. We will not ask you for an identity document unless we have real doubt.
- If we refuse, we say why, and we tell you about your right to complain and to a judicial remedy.
No automated decisions, no profiling
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22. We build no profiles, score nobody, and take no automated decision about creditworthiness, eligibility or pricing.
To be complete about it: two controls do run automatically. Rate limits throttle a key or an address that exceeds a documented threshold, and repeated failed logins trigger a temporary lockout. Both are mechanical, time-limited and reversible, neither produces a legal effect, and a human is one email away at queries@worldgovdata.com if one of them catches you unfairly.
How we protect it
The measures below are the ones actually in place. We hold no security certification and make no claim to one — no ISO 27001, no SOC 2, no audit report. When we have something to show, we will name it here.
- Everything travels over HTTPS, with HSTS enforced.
- Passwords are hashed with argon2id and are never logged, never returned, and never included in an error message.
- Session tokens and API key secrets are stored only as SHA-256 hashes. We cannot recover either, which is also why a leaked key must be revoked rather than retrieved.
- IP addresses are stored only as HMAC-SHA256 digests, with a server-side secret.
- Account, billing and security-relevant actions are written to an append-only audit log.
- Access to production data is limited to the people who need it to run the service, and the payment path is delegated to a processor so that card data never reaches our systems at all.
- Automatic backups, with a documented breach procedure in the data processing addendum: notification to a supervisory authority within 72 hours where the law requires it, and to affected users without undue delay where the risk is high.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If you find a weakness, the coordinated disclosure invitation on the contact page is genuine.
Children
The service is not directed at children. You must be at least 16, or the age of digital consent where you live if that is higher, to hold an account. We do not knowingly collect data from anyone younger; if you believe a child has created an account, tell us at queries@worldgovdata.com and we will delete it.
Changes to this notice
When this notice changes we bump the version stamp at the top of the page and set a new effective date. The version you accepted at signup is recorded against your account, so there is always a record of which text you agreed to.
For a change that materially affects how we use your data, we email account holders at least 30 days before it takes effect. We will not make a material change retroactive.
The statistical data this service publishes is aggregated country-level material from public institutions and contains no personal data. This notice is about the account and billing records that exist because you use the service. Data protection requests: queries@worldgovdata.com.