Trust
How we handle data
This page states what data Momentum Terminal holds, what protects it, and which providers process it. It describes the system as it runs today; where a measure arrives with commercial launch, it says so. Questions: hello@momentumterminal.pl.
Last reviewed: 3 Jul 2026
Product
01What Momentum is
Momentum Terminal, operated by Momentum AI sp. z o.o., provides data on Polish registered companies and the people who hold roles in them. The company and officer records are sourced from public registries and filings: the National Court Register (KRS), the Central Register of Beneficial Owners (CRBR), and companies’ own published financial statements. How and why we process registry persons’ data is set out in the Article 14 privacy notice.
Data held
02What we store, and about whom
Two groups of people appear in our systems: customers who create accounts, and registry persons who appear in the public filings we serve.
Customers
Registry persons
Security
03Measures in place today
Defaults
04Private by default
There is no analytics script, no tracking pixel, and no third-party script on any page of the product or this site.
Sub-processors
05Who processes data on our behalf
When you use the AI features, your queries and the company data used to answer them are processed by Anthropic, and your search query text is embedded by OpenAI. Both run on their default United States endpoints today; EU routing for the language model is planned. AI features require a verified email address.
Active today
Anthropic
Large language model (Claude) behind the AI features: chat, question answering, and query interpretation.
Data: user-typed queries and chat messages; company data returned by tools while answering (can include officers' names as filed).
United States (default API endpoint today); EU routing planned
OpenAI
Text embeddings for semantic search and screening (query understanding).
Data: search and screener query text typed by the user.
United States (default API endpoint today)
OAuth sign-in (identity provider) - only for users who choose to sign in with Google.
Data: sign-in identity from the Google profile: email, name, avatar URL.
Per Google account terms (global provider)
Hostinger
Infrastructure hosting for the database server.
Data: all service data at rest (accounts, sessions, audit log, registry data).
EU-based provider; datacenter region of the specific server pending verification
Configured, not active
Integrated in the codebase but holding no data today; listed for transparency. Each begins processing only when the corresponding feature is switched on at launch.
Resend
Transactional email (sign-in links, email verification, team invites, data-request verification). Not active: no email is sent today.
Data: recipient email address; message content including verification links.
United States
Upstash
Redis for rate limiting. Not active: not provisioned; no data is stored there today.
Data: rate-limit counters keyed by IP address or email.
Region selected at provisioning
Stripe
Payment processing and subscription billing. Activates when billing launches; no payment can be made today.
Data: billing details; VAT numbers.
US headquarters; Irish EU entity for EU customers
Register last updated 2026-07-03. We update this list before any new provider begins processing customer data.
Hosting
06Where the data lives
The database is self-managed PostgreSQL on a server with an EU-based hosting provider; we are confirming the datacenter region of that specific server and are moving to managed, region-pinned infrastructure before commercial launch. Separately, AI queries are processed in the United States by the providers listed above.
Rights
07Your rights
Agreements
08Data processing agreement
Our data-processing terms are summarised in the Data Processing Addendum (draft, pending counsel review). To arrange a signed DPA, write to hello@momentumterminal.pl.