Privacy notice
This notice describes how R-53 OÜ processes personal data on arikratt.ee and on the MCP server. The website is free and does not require an account.
Last updated: 2026-09-26
Controller
The controller is R-53 OÜ, registry code 12351041. Questions about data: arikratt@r-53.com.
No accounts
The public explorer does not create a user account. Sign-in with Google or Apple is not used. Sign-in addresses and the account API do not work on the public site. The explorer API and the MCP server do.
MCP access is an API key. A trial lasts 14 days from key creation and covers 50 successful calls. Prices are published on the MCP page. Payments are not taken yet.
Data in your browser
The watchlist, comparison and theme stay only in your browser. They do not create a user profile.
The localStorage key ak:watch holds up to 50 eight-digit registry codes. ak:watch:seen holds the id of the data snapshot you last viewed. ak:compare holds up to 4 registry codes. ak:theme holds light or dark. The sessionStorage key ak:compare:names holds a company name next to a registry code for that browser tab. Clearing site data removes these entries.
Older screens are still on the site, including sign-in, my company and invoices. They can also write other values in the browser, such as a registry code you pick or an IBAN you type yourself. The account server for those screens does not work on the public site, so the server does not receive those values.
Published data about companies
The explorer shows public data about legal persons: name, registry code, status, address, field of activity, annual-report and tax figures, grants, licences, announcement metadata, and ownership links to other legal persons. Sole proprietors (FIE) are not included. Board members, beneficial owners and identifiers of natural persons are not shown. A credit score is not given. The composite signal is a derived figure about a company, not a decision about a natural person.
A company page may show an email, phone and website from Business Register open data. A value is left out when the text contains an Estonian personal identification code. Email and phone are removed from MCP replies. Source files can contain personal data. This service does not return those fields, apart from the company-page contact described above. That contact can still belong to a natural person when the register published it that way and the text does not contain a personal identification code.
Logs and cookies
Traffic passes through Cloudflare and reaches an OVHcloud VPS in Warsaw, Poland (European Union). The page does not run its own analytics script and does not set its own cookie. A check of the public home-page response on 2026-09-26 found no Set-Cookie header. Cloudflare sends the browser a network-error report policy (NEL). That policy does not collect successful page views.
The Caddy configuration does not write a separate access log. The API process writes a default access line to the system journal. The line can include the IP address, the request path and the status code, because the proxy forwards the visitor address. The published configuration does not set a retention period for the journal. Next.js telemetry is turned off for the web process.
Service providers
OVHcloud hosts the server in Warsaw. The website, the API and the MCP database run there. Cloudflare is the edge network and sees the IP address and technical request data in order to deliver traffic. The controller reads mail sent to arikratt@r-53.com. This notice does not name a technical host for that mailbox. Personal data is not sold.
MCP API key
To get a key, write to arikratt@r-53.com. The message and your address arrive in that mailbox. When a key is created, the server database stores the email address, a label, the plan, the creation time, a prefix of the key, and a SHA-256 hash of the secret. The secret itself is not stored.
Usage rows store the time, the tool name, whether the call succeeded, a row count, the duration and an overage flag. A separate table stores registry codes that were in the request or the reply, up to 500 distinct codes per day. The text of a chat between you and an AI assistant is not written there. Other tool arguments, apart from registry codes, are not stored either. Revoking a key marks it revoked and does not delete the email or the usage rows. Browser sign-in for MCP does not work on the public site.
Legal basis
Showing register data rests on the fact that the data has already been published for reuse. Server logs are kept for the legitimate interest of operating and securing the service (GDPR Article 6(1)(f)). An MCP key request and key administration are steps prior to a contract (Article 6(1)(b)). Where a company contact is the email or phone of a natural person, that basis needs a separate confirmation.
Retention
Browser entries stay until you delete them. The software does not automatically delete the email or usage rows of a revoked API key. No retention period is set for the mailbox or the server journal.
Your rights
You can request access, correction or deletion, restriction of processing, object to processing, and ask for portability where it applies. Send the request to arikratt@r-53.com. We reply within one month. You can complain to the Estonian Data Protection Inspectorate at aki.ee.
Contact
R-53 OÜ, registry code 12351041, arikratt@r-53.com.