Data transparency
What we have on you and where it came from.
Short answer: public records only, until you choose to tell us more. This page explains exactly what is in the database, which registry it came from, what is not in it, and the specific steps to get removed or suppressed.
For legal questions about your data rights, the applicable frameworks are CASL (Canada), CAN-SPAM (USA), GDPR (UK), and equivalent regulations in Australia, New Zealand, and Ireland.
Database contents
What is in the database about you
Every field below is public record. The right-hand column names the source. You can verify each one yourself by looking up your business in the relevant registry.
| Data field | Source | Notes |
|---|---|---|
| Company legal name | Government corporate filing | Exactly as registered. Not a DBA or trade name unless separately filed. |
| Company registration number | Government corporate filing | The unique identifier assigned by the filing jurisdiction. |
| Business category (NAICS or equivalent) | Government corporate filing or licensing record | May be broad (e.g., 'Business Support Services') or specific (e.g., 'Plumbing, Heating, and Air Conditioning Contractors'). |
| Registered address | Government corporate filing | The address on file with the registry. May be a registered agent address or head office. Not necessarily the operating location. |
| Owner or officer name | Government corporate filing, director registry, or licensing board | Name as it appears in the public record. May be a legal name rather than a preferred name. |
| Business phone number | Government filing or public licensing record, if listed | Only if the number appears in the public registry. We do not source phone numbers from social media or commercial data brokers. |
What is not in the database
Your personal home address.
Your personal mobile or direct phone number (unless you filed it as the registered business number).
Your personal email address.
Revenue, earnings, profit, or any financial data.
Number of employees.
Customer lists or any customer information.
Information from your personal social media profiles (LinkedIn, Facebook, Instagram, etc.).
Credit report or financial history.
Personal background check data.
Anything you have not put into a public government filing.
Sources
Which registries, by market
All of these are public government sources. None are commercial data brokers, purchased lists, or social media scrapers. You can access each of these registries directly and look up what they contain about your business.
Canada
United States
United Kingdom
Australia
New Zealand
Ireland
NDA
What the NDA covers (and does not cover)
Request a copy before any call — we send it immediately, no commitment required. Have an attorney review it before signing. The summary below explains what it covers and what it does not.
Covered by the NDA
Everything you tell us that is not already public record.
Any financial information you share (revenue, EBITDA, margins, customer concentration).
The fact that you are in conversation with Serava, if you ask for that to be covered.
Any description of your operations, team, or business model that goes beyond what is in public filings.
Your identity in any blind marketing to potential buyers (before you consent to a named introduction).
Not covered
Information already in the public registries listed above. We cannot un-know what is public.
Information you choose to make public yourself after signing.
Information we independently develop from other public sources.
Information a buyer already has before the introduction (though the buyer's NDA with Serava covers their conduct going forward).
Opt-out and suppression
How to get removed or suppressed
There are two distinct things you can request. They are different and it matters which one you want.
Opt out of outreach
Serava and every domain we use for outreach will stop contacting you. This covers all future emails from our system. It does not remove your record from the database, because the database is built from public records we are not the sole custodian of.
Timeline: honored within 10 business days.
How to request: submit the form at serava.ai/owners/remove, or reply “No Thanks” to the email you received from us. Both reach a person.
We will stop all outreach from Serava and every domain we use for outreach. Your contact information remains in our research database (the same one our subscribers access), because it is compiled from public government registries. To also suppress your record from subscriber exports, see the suppression section below.
Suppression from subscriber exports
Serava's research database is accessed by buyers (our subscribers). When buyers search the database, your business may appear in their results. Suppression flags your record so it is excluded from exports and searches accessed by subscribers.
This is a manual process. Email sadra@serava.ai with the subject line “Suppression request” and include your company name and registration jurisdiction. We will confirm when the flag is applied.
Note: your business remains in the underlying database because it is built from public government records. Suppression prevents it from appearing in subscriber-accessible searches and exports. If you are later removed from the government registry itself, the record becomes stale and will be removed during routine data maintenance.
Legal frameworks
Applicable regulations
Serava's outreach is subject to the following regulatory frameworks depending on your location. If you believe we have violated any of these, reply directly to any email you received from us. If the issue is not resolved, contact your local authority below.
CASL s.10(9)(b) (Canada's Anti-Spam Legislation)
CanadaRequires a functioning unsubscribe in every commercial email, honored within 10 business days. Where we email a Canadian business we rely on implied consent by conspicuous publication, s.10(9)(b): the business itself published the address, it carried no statement refusing unsolicited commercial messages, and our message relates to the role the address was published for. Where a source does not meet that test we do not email the contact. Opt-out is always free and immediate.
Authority: Canadian Radio-television and Telecommunications Commission (CRTC)
PIPEDA / BC PIPA (Canada data protection)
CanadaPIPEDA (federal) and BC PIPA (provincial) govern the collection, use, and disclosure of personal information in commercial activities. We collect only what appears in public government registries, use it solely for B2B research outreach, and do not sell or share it with third parties outside of our subscriber platform.
Authority: Office of the Privacy Commissioner of Canada (OPC) / BC Office of the Information and Privacy Commissioner (OIPC)
CAN-SPAM Act
United StatesRequires accurate sender identification, non-deceptive subject lines, a physical postal address, and a functioning opt-out honored within 10 business days. We comply with all requirements.
Authority: Federal Trade Commission (FTC)
UK GDPR and PECR
United KingdomUK GDPR Article 6(1)(f) (legitimate interests) is our lawful basis for processing business contact data. PECR permits B2B electronic marketing where the sender is identified and an opt-out is provided. You have an absolute right to object to direct marketing processing under UK GDPR Article 21(2).
Authority: Information Commissioner's Office (ICO)
EU GDPR (Ireland and EU member states)
Ireland / EUEU GDPR Article 6(1)(f) (legitimate interests) is our lawful basis. The ePrivacy Directive permits B2B outreach to business email addresses where the sender is identifiable and opt-out is clear. Data subjects may exercise rights including access, rectification, erasure, and objection to marketing.
Authority: Data Protection Commission (DPC) — Ireland; national DPA in your member state
Spam Act 2003
AustraliaRequires that commercial messages identify the sender and include a functional unsubscribe honored within 5 business days. We comply. Consent is inferred under the conspicuous publication basis where a business's contact information is publicly accessible.
Authority: Australian Communications and Media Authority (ACMA)
Privacy Act 1988 (Australia)
AustraliaWe collect and use personal information (where applicable under the Act) only for the primary purpose of B2B outreach. Data is sourced from ASIC public records and equivalent registries. Australian individuals may request access to or correction of their information.
Authority: Office of the Australian Information Commissioner (OAIC)
Unsolicited Electronic Messages Act 2007
New ZealandPermits commercial messages where the recipient's address has been conspicuously published in a public register and the message relates to a role or capacity in which the recipient appears in that register. An unsubscribe must be included. We comply.
Authority: Department of Internal Affairs (DIA)
Privacy Act 2020 (New Zealand)
New ZealandGoverns collection and use of personal information. We collect only publicly available information from the NZ Companies Register for B2B outreach purposes. New Zealand individuals may request access to their information or request correction.
Authority: Office of the Privacy Commissioner (OPC NZ)
Your rights
How to exercise your data rights
Depending on where you are located, you may have the right to access, correct, delete, or restrict processing of information we hold about you. The mechanism is the same regardless of jurisdiction: reply directly to any email you received from us, or email sadra@serava.ai. We respond within 10 business days.
Right of access
Request a copy of what information we hold about you and where it came from.
Right to rectification
If information we hold is inaccurate, request a correction.
Right to erasure
Request deletion of your information from our active outreach database. We will also flag your record for suppression from subscriber exports.
Right to object (direct marketing)
You may object to us processing your data for direct marketing purposes at any time. We stop immediately.
Right to restrict processing
Request that we limit processing of your data to storage only while a request is being resolved.
Right to data portability
Applicable in the UK and EU: request the information we hold in a structured, machine-readable format.
Right to lodge a complaint
If you believe we have not handled your request properly, you may escalate to the relevant authority listed in the regulatory frameworks above.
No automated decision-making
We do not make automated decisions that produce legal or similarly significant effects about you.
Data retention: We retain outreach records for as long as we operate the platform. Opt-out records are retained indefinitely to prevent re-adding you to outreach lists. Suppression flags are retained until you request removal of the flag. Information shared under NDA is retained per the terms of that NDA. Underlying public registry data may update when we refresh from source registries — opt-out suppression persists across refreshes.