SERAVA.AI/For business owners/Data & privacy

Data transparency

What we have on you and where it came from.

Short answer: public records only, until you choose to tell us more. This page explains exactly what is in the database, which registry it came from, what is not in it, and the specific steps to get removed or suppressed.

For legal questions about your data rights, the applicable frameworks are CASL (Canada), CAN-SPAM (USA), GDPR (UK), and equivalent regulations in Australia, New Zealand, and Ireland.

Database contents

What is in the database about you

Every field below is public record. The right-hand column names the source. You can verify each one yourself by looking up your business in the relevant registry.

Data fieldSourceNotes
Company legal nameGovernment corporate filingExactly as registered. Not a DBA or trade name unless separately filed.
Company registration numberGovernment corporate filingThe unique identifier assigned by the filing jurisdiction.
Business category (NAICS or equivalent)Government corporate filing or licensing recordMay be broad (e.g., 'Business Support Services') or specific (e.g., 'Plumbing, Heating, and Air Conditioning Contractors').
Registered addressGovernment corporate filingThe address on file with the registry. May be a registered agent address or head office. Not necessarily the operating location.
Owner or officer nameGovernment corporate filing, director registry, or licensing boardName as it appears in the public record. May be a legal name rather than a preferred name.
Business phone numberGovernment filing or public licensing record, if listedOnly if the number appears in the public registry. We do not source phone numbers from social media or commercial data brokers.

What is not in the database

×

Your personal home address.

×

Your personal mobile or direct phone number (unless you filed it as the registered business number).

×

Your personal email address.

×

Revenue, earnings, profit, or any financial data.

×

Number of employees.

×

Customer lists or any customer information.

×

Information from your personal social media profiles (LinkedIn, Facebook, Instagram, etc.).

×

Credit report or financial history.

×

Personal background check data.

×

Anything you have not put into a public government filing.

Sources

Which registries, by market

All of these are public government sources. None are commercial data brokers, purchased lists, or social media scrapers. You can access each of these registries directly and look up what they contain about your business.

Canada

Alberta Corporate Registry·Alberta-incorporated businesses and registered trade names.
BC OrgBook / BC Registries·BC-incorporated companies, societies, and cooperatives.
Ontario Business Registry·Ontario corporations and business names.
Corporations Canada·Federal (Canada Business Corporations Act) companies.
Provincial licensing boards·Regulated professions and trades (contractors, health, finance, etc.) where owner names appear in public filings.

United States

State Secretary of State databases·State-incorporated LLCs, corporations, and partnerships across all 50 states.
EDGAR (SEC)·Public companies and certain investment vehicles.
NPPES (NPI registry)·Healthcare providers: physicians, dentists, therapists, and clinics.
SAM.gov·Federal government contractors and grant recipients.
SBA SBIR database·Small businesses receiving federal research and development awards.

United Kingdom

Companies House·All registered UK companies, directors, and persons with significant control.

Australia

ASIC (Australian Securities and Investments Commission)·Registered Australian companies and business names.

New Zealand

NZ Companies Office·Registered NZ companies and directors.

Ireland

CRO (Companies Registration Office)·Irish-registered companies and directors.

NDA

What the NDA covers (and does not cover)

Request a copy before any call — we send it immediately, no commitment required. Have an attorney review it before signing. The summary below explains what it covers and what it does not.

Covered by the NDA

Everything you tell us that is not already public record.

Any financial information you share (revenue, EBITDA, margins, customer concentration).

The fact that you are in conversation with Serava, if you ask for that to be covered.

Any description of your operations, team, or business model that goes beyond what is in public filings.

Your identity in any blind marketing to potential buyers (before you consent to a named introduction).

Not covered

×

Information already in the public registries listed above. We cannot un-know what is public.

×

Information you choose to make public yourself after signing.

×

Information we independently develop from other public sources.

×

Information a buyer already has before the introduction (though the buyer's NDA with Serava covers their conduct going forward).

Opt-out and suppression

How to get removed or suppressed

There are two distinct things you can request. They are different and it matters which one you want.

Opt out of outreach

Serava and every domain we use for outreach will stop contacting you. This covers all future emails from our system. It does not remove your record from the database, because the database is built from public records we are not the sole custodian of.

Timeline: honored within 10 business days.

How to request: submit the form at serava.ai/owners/remove, or reply “No Thanks” to the email you received from us. Both reach a person.

We will stop all outreach from Serava and every domain we use for outreach. Your contact information remains in our research database (the same one our subscribers access), because it is compiled from public government registries. To also suppress your record from subscriber exports, see the suppression section below.

Suppression from subscriber exports

Serava's research database is accessed by buyers (our subscribers). When buyers search the database, your business may appear in their results. Suppression flags your record so it is excluded from exports and searches accessed by subscribers.

This is a manual process. Email sadra@serava.ai with the subject line “Suppression request” and include your company name and registration jurisdiction. We will confirm when the flag is applied.

Note: your business remains in the underlying database because it is built from public government records. Suppression prevents it from appearing in subscriber-accessible searches and exports. If you are later removed from the government registry itself, the record becomes stale and will be removed during routine data maintenance.

Legal frameworks

Applicable regulations

Serava's outreach is subject to the following regulatory frameworks depending on your location. If you believe we have violated any of these, reply directly to any email you received from us. If the issue is not resolved, contact your local authority below.

CASL s.10(9)(b) (Canada's Anti-Spam Legislation)

Canada

Requires a functioning unsubscribe in every commercial email, honored within 10 business days. Where we email a Canadian business we rely on implied consent by conspicuous publication, s.10(9)(b): the business itself published the address, it carried no statement refusing unsolicited commercial messages, and our message relates to the role the address was published for. Where a source does not meet that test we do not email the contact. Opt-out is always free and immediate.

Authority: Canadian Radio-television and Telecommunications Commission (CRTC)

PIPEDA / BC PIPA (Canada data protection)

Canada

PIPEDA (federal) and BC PIPA (provincial) govern the collection, use, and disclosure of personal information in commercial activities. We collect only what appears in public government registries, use it solely for B2B research outreach, and do not sell or share it with third parties outside of our subscriber platform.

Authority: Office of the Privacy Commissioner of Canada (OPC) / BC Office of the Information and Privacy Commissioner (OIPC)

CAN-SPAM Act

United States

Requires accurate sender identification, non-deceptive subject lines, a physical postal address, and a functioning opt-out honored within 10 business days. We comply with all requirements.

Authority: Federal Trade Commission (FTC)

UK GDPR and PECR

United Kingdom

UK GDPR Article 6(1)(f) (legitimate interests) is our lawful basis for processing business contact data. PECR permits B2B electronic marketing where the sender is identified and an opt-out is provided. You have an absolute right to object to direct marketing processing under UK GDPR Article 21(2).

Authority: Information Commissioner's Office (ICO)

EU GDPR (Ireland and EU member states)

Ireland / EU

EU GDPR Article 6(1)(f) (legitimate interests) is our lawful basis. The ePrivacy Directive permits B2B outreach to business email addresses where the sender is identifiable and opt-out is clear. Data subjects may exercise rights including access, rectification, erasure, and objection to marketing.

Authority: Data Protection Commission (DPC) — Ireland; national DPA in your member state

Spam Act 2003

Australia

Requires that commercial messages identify the sender and include a functional unsubscribe honored within 5 business days. We comply. Consent is inferred under the conspicuous publication basis where a business's contact information is publicly accessible.

Authority: Australian Communications and Media Authority (ACMA)

Privacy Act 1988 (Australia)

Australia

We collect and use personal information (where applicable under the Act) only for the primary purpose of B2B outreach. Data is sourced from ASIC public records and equivalent registries. Australian individuals may request access to or correction of their information.

Authority: Office of the Australian Information Commissioner (OAIC)

Unsolicited Electronic Messages Act 2007

New Zealand

Permits commercial messages where the recipient's address has been conspicuously published in a public register and the message relates to a role or capacity in which the recipient appears in that register. An unsubscribe must be included. We comply.

Authority: Department of Internal Affairs (DIA)

Privacy Act 2020 (New Zealand)

New Zealand

Governs collection and use of personal information. We collect only publicly available information from the NZ Companies Register for B2B outreach purposes. New Zealand individuals may request access to their information or request correction.

Authority: Office of the Privacy Commissioner (OPC NZ)

Your rights

How to exercise your data rights

Depending on where you are located, you may have the right to access, correct, delete, or restrict processing of information we hold about you. The mechanism is the same regardless of jurisdiction: reply directly to any email you received from us, or email sadra@serava.ai. We respond within 10 business days.

Right of access

Request a copy of what information we hold about you and where it came from.

Right to rectification

If information we hold is inaccurate, request a correction.

Right to erasure

Request deletion of your information from our active outreach database. We will also flag your record for suppression from subscriber exports.

Right to object (direct marketing)

You may object to us processing your data for direct marketing purposes at any time. We stop immediately.

Right to restrict processing

Request that we limit processing of your data to storage only while a request is being resolved.

Right to data portability

Applicable in the UK and EU: request the information we hold in a structured, machine-readable format.

Right to lodge a complaint

If you believe we have not handled your request properly, you may escalate to the relevant authority listed in the regulatory frameworks above.

No automated decision-making

We do not make automated decisions that produce legal or similarly significant effects about you.

Data retention: We retain outreach records for as long as we operate the platform. Opt-out records are retained indefinitely to prevent re-adding you to outreach lists. Suppression flags are retained until you request removal of the flag. Information shared under NDA is retained per the terms of that NDA. Underlying public registry data may update when we refresh from source registries — opt-out suppression persists across refreshes.