Skip to content
Cited Record
Coverage Method Request access

Contents

  1. 1. Who we are
  2. A.1 What we do, and what we deliberately do not do
  3. A.2 So why do you hold my personal data at all?
  4. A.3 Where the data comes from (Article 14(2)(f))
  5. A.4 What categories we process (Article 14(1)(d))
  6. A.5 Why we process it, and our legal basis (Article 14(1)(c))
  7. A.6 How long we keep it (Article 14(2)(a))
  8. A.7 Who we share it with (Article 14(1)(e))
  9. A.8 Your rights, and how to use them
  10. A.9 Accuracy
  11. B.1 The waitlist
  12. B.2 Analytics, and why there is no cookie banner
  13. B.3 Account data
  14. B.4 Usage data
  15. B.5 Sanctions screening
  16. B.6 Email we send you
  17. B.7 Your rights under Part B

Privacy Notice

Last updated: 06 August 2026

Cited Record is a service operated by Mimmox LLC.

This notice has two parts:

  • Part A covers personal data that appears inside the public regulatory enforcement documents we collect. If you have been named in a regulator's enforcement letter, this is the part that concerns you — and the short version is that we do not display your name.
  • Part B covers personal data of our customers and website visitors.

1. Who we are

Controller: MIMMOX LLC, a limited liability company registered in Wyoming, United States (filing ID 2025-001620797), trading as Cited Record.

Registered address: 30 N Gould St Ste N, Sheridan, WY 82801, United States

Privacy contact: privacy@citedrecord.com

Representative in the European Union (GDPR Article 27): not currently appointed. Cited Record is not yet offering its service to anyone, in the EU or elsewhere. A representative will be appointed, and named here, before the service is offered to customers in the European Union. If you are in the EU and want to raise something with us in the meantime, privacy@citedrecord.com reaches a person and we answer.

Data Protection Officer: we have not appointed one. Having assessed Article 37, we do not believe we are required to, principally because our core activity is processing records about companies rather than large-scale monitoring of individuals. Privacy questions go to privacy@citedrecord.com and are handled by us directly.


Part A — Personal data within regulatory enforcement documents

A.1 What we do, and what we deliberately do not do

We collect enforcement records that regulators publish, normalise them into a consistent structure, verify them against the official source, and make them searchable for business customers doing supplier and counterparty due diligence.

Our service covers companies, not individuals. We made that choice on purpose:

  • The searchable database holds the company, what the regulator said, when, and whether the matter has been resolved.
  • It does not hold the name of the person the letter was addressed to, their job title, or their contact details. These are never displayed, never returned by our API, and never available to any customer at any price.
  • Where an enforcement action concerns an individual rather than a company — a sole trader or an individual practitioner — we do not publish it at all. Those records are set aside and reviewed by a person.

This is enforced in our software rather than promised in a policy. Two independent checks in the code prevent an individual's name from reaching the published database, and our automated tests fail if either is removed.

A.2 So why do you hold my personal data at all?

Because we keep an unmodified copy of the documents the regulator published, and your name is in the regulator's document.

Our central promise to customers is that every fact we publish can be checked against the exact official document it came from, down to the character. That only works if we keep the document as it was issued. Editing it would break the ability to verify our own records, and would also make our copy differ from the official one.

So the position is:

  • The archived source document may contain your name, title, business address, contact details and the regulator's findings. It is stored internally, is not searchable by customers, and is not exposed by any product feature.
  • The published record derived from it contains none of that.

A.3 Where the data comes from (Article 14(2)(f))

Entirely from publicly available official sources. Currently:

  • U.S. Food and Drug Administration — Warning Letters, published at fda.gov.

The full current list, with how often we check each source, is on our sources page.

We do not buy personal data, and we do not collect it from social media, data brokers or any private source.

A.4 What categories we process (Article 14(1)(d))

Published to customers: company name, the regulator's subject line, the issuing office, the dates, the reference number, the current status of the matter, and a link to the official source.

Held in the internal archive only, because the regulator's document contains it: your name, your job title, a business postal address, contact details including email addresses, and the regulator's findings as published.

A.5 Why we process it, and our legal basis (Article 14(1)(c))

Legal basis: legitimate interests, GDPR Article 6(1)(f).

The legitimate interests are:

  • Ours, in operating a regulatory-intelligence service about companies.
  • Our customers', in knowing whether a supplier or counterparty has been subject to regulatory enforcement.
  • The wider public interest in the transparency of regulatory enforcement, which is why regulators publish these documents in the first place.

We have carried out a documented balancing assessment weighing these against your rights. You may request a summary of it by writing to privacy@citedrecord.com.

We do not make automated decisions about you, and we do not score, rank or profile individuals.

A.6 How long we keep it (Article 14(2)(a))

  • The archived source document is kept indefinitely. Regulators remove older records from their public sites — the FDA's public index currently reaches back only to 2021 — and the archive preserves the citable historical record.
  • The published company-level record is kept for as long as the source is covered, subject to our retention policy.
  • If we uphold an objection, we suppress the affected data from everything we serve, and record that we did.

A.7 Who we share it with (Article 14(1)(e))

Your personal data is not shared with our customers, because it is not part of what we publish.

The archive is disclosed to:

  • Service providers who process on our behalf under contract: hosting, within the European Union.
  • Anyone we are legally required to disclose to.

We do not sell personal data. We do not use it for advertising. We do not use it to train AI models, and our AI providers are contractually prohibited from retaining or training on anything we send them.

A.8 Your rights, and how to use them

Under the GDPR you have the right to:

  • Object to our processing (Article 21). Because we rely on legitimate interests, you can object at any time and we will stop unless we can show compelling legitimate grounds that override your interests.
  • Access the personal data we hold about you (Article 15). In practice this means telling you which archived documents mention you and what they contain.
  • Rectify inaccurate data (Article 16). Important: if the regulator's published record is wrong, we cannot alter the official record and we will not misrepresent what it says. What we can and will do is correct any error we introduced, record your position alongside the record, and tell you how to contact the regulator.
  • Erasure in the circumstances set out in Article 17.
  • Restrict processing (Article 18).
  • Lodge a complaint with a supervisory authority.

To exercise any of these, write to privacy@citedrecord.com. We respond within one month, extendable by two further months for complex requests, and we will tell you within the first month if we need the extension.

We do not charge for this, and we will not ask you to justify an objection.

If your concern is that you can be found by name in our search results: you cannot. If you believe otherwise, tell us and we will treat it as a priority, because it would mean something in our system has gone wrong.

A.9 Accuracy

Two commitments, because accuracy is the part of this that can actually cause harm:

  1. We reproduce, we do not rewrite. Every published statement is verifiable against the archived source document at recorded character positions. Anything we cannot verify is withheld rather than published.
  2. We tell you how fresh it is. Every record displays when we last verified it against the official source. If a regulator closes out or withdraws a matter, that is reflected. If our systems fail, records are marked unverified rather than continuing to be presented as current.

If you believe we have published something inaccurate or out of date, tell us at privacy@citedrecord.com.


Part B — Customers and website visitors

This part covers you if you use this website or become a customer. It is separate from Part A, which is about people named inside the regulators' documents.

B.1 The waitlist

If you give us your email address through the form on our home page, we use it for exactly one thing: to write to you once, when access opens.

  • What we collect: your email address and the time you submitted it. Nothing else. Not your name, not your company, not your IP address, and not a record of what you looked at before signing up.
  • Legal basis: your consent, Article 6(1)(a). You typed it in for a stated purpose and we will not stretch it to cover anything else.
  • How long: until we send that message, or 24 months, whichever comes first.
  • Withdrawing: write to privacy@citedrecord.com and we delete it. No form to fill in, no reason required, and no confirmation email designed to talk you out of it.
  • We do not add you to a newsletter, sell or share the address, or use it to find you anywhere else.

B.2 Analytics, and why there is no cookie banner

We count page views so we know whether anyone is reading the site. We do it with Umami, which we run on our own server in the European Union. There is no analytics company involved, so your visit is not shared with anyone.

  • No cookies. No local storage. No advertising identifier. That is why this site has no consent banner, and also why we are not able to recognise you across visits even if we wanted to.
  • What is recorded: the page you viewed, the site that referred you, your approximate country, and your browser and device type.
  • Your IP address is never written to disk. It is combined with your browser identity and a secret that changes every day to produce a short-lived visit identifier. Because that secret rotates, the same person tomorrow is a different, unlinkable identifier.
  • Our web server does not log visitor IP addresses either. We turned that off deliberately, because we had no purpose for them.
  • Legal basis: legitimate interests, Article 6(1)(f), in understanding our own audience. How long: 12 months.

B.3 Account data

When the service opens and you create an account: your name, business email address, company, billing details and authentication data.

  • Legal basis: Article 6(1)(b), performance of a contract.
  • How long: the term of the contract, plus the statutory retention period that applies to accounting records.
  • Shared with: our payment processor, and our email providers for messages we send you.

B.4 Usage data

Records of the searches and API calls made from your account, kept for operating the service, billing, security, and detecting bulk extraction of our database.

  • Legal basis: legitimate interests, Article 6(1)(f), in protecting the service against misuse.
  • Note: this is measurement of an account's activity, not profiling of you as a person, and it produces no automated decision about you.

B.5 Sanctions screening

As a United States entity we are required to screen customers against U.S. sanctions lists before providing the service.

  • Legal basis: Article 6(1)(c), compliance with a legal obligation to which we are subject, together with Article 6(1)(f).
  • How long: the screening result and the date are retained as an audit record for as long as required.

B.6 Email we send you

Transactional messages — account confirmations, password resets, receipts, and the single waitlist notification — are sent through Postmark, a provider in the United States. Marketing email is not something we currently send at all.

B.7 Your rights under Part B

The same rights described in section A.8 apply: access, rectification, erasure, restriction, objection, portability, and complaint to a supervisory authority. Where we rely on consent, you can withdraw it at any time, and withdrawing it does not affect anything we did lawfully before you did.

Write to privacy@citedrecord.com. We answer within one month.


2. International transfers

Our primary data storage is in the European Union (Helsinki, Finland). Backups remain within the EU/EEA.

Two kinds of processing take place in the United States:

  • An AI gateway, used to help extract and verify information from source documents. Personal names are removed from a document before it is sent, and the software refuses to send anything it cannot verify as clean. Providers are contractually restricted from retaining the data or training on it.
  • Transactional email, for the messages described in B.6.

These transfers are made under appropriate safeguards. You may request details of the safeguards at privacy@citedrecord.com.

3. Changes to this notice

Material changes are announced on this page with a dated entry in the change log below. We do not make silent changes.

4. Change log

Version Date Change
2.1 06 August 2026 Initial publication. Controller: Mimmox LLC.

(Version 1.0 was drafted on 2026-08-05 and never published. It described a service that displayed individuals' names. The scope was narrowed before launch and version 2.0 reflects what the service actually does. Version 2.1 completed Part B — waitlist, analytics, accounts, usage, sanctions screening and email — which 2.0 left as an outline, and separated the publication blockers by what each one actually blocks.)

© 2026 Cited Record. All rights reserved.

Coverage Privacy Terms Contact