Legal
Privacy Policy
Last updated: July 2026
Who we are
MergeSearch is a service of MBWorkers Vof (“we”, “us”), KvK 96195363, Hollands Hoenlaan 47, 3772 PC Barneveld, Netherlands. We process data under the GDPR. Privacy questions: [email protected].
Data we process about you
For visitors and prospects: minimal contact/inquiry data you send us (name, firm, work email, your brief) and basic, privacy-friendly site data. We don’t run advertising trackers, and we don’t use visitor-identification services: we know that someone from a company visited only if they tell us. Billing is handled by our payment provider. We don’t store full card details. As a processor, we handle any client materials only to deliver the agreed service.
The data in our deliverables (company-level)
Our market maps and Opportunity Monitor pings are company-level intelligence (company names, facts and events, and market analysis) and may include limited, public, professional data about executives: a person’s name and position, and publicly-reported comparable hires. We do not include or sell personal contact details (email, phone) or build private profiles on individuals.
Sources & why this isn’t data-brokering
The professional data we carry is drawn from public and government records (e.g. SEC filings, press releases, company sites, news) and widely-distributed media: publicly available information, which the CCPA treats as outside “personal information”. Because we include only public professional data and sell no contact details or private profiles, we don’t act as a data broker. Under the GDPR this limited, public, professional data is processed on a legitimate-interest basis for B2B intelligence.
Why we use data & who we share it with
Only to respond to you, build your free deliverable, and run the service if you become a client. We never sell your data. We share it only with the processors needed to operate (e.g. hosting, email, CRM/forms, payments, and AI providers used to deliver the service), under appropriate safeguards. Some processors may be outside the EEA, in which case we rely on safeguards such as the EU Standard Contractual Clauses. If you are a client and use our link-sharing feature to send a deliverable to your own leads, we process basic usage analytics on those recipients (e.g. opens, time on page) strictly on your behalf, as your processor — you decide the purpose and are responsible for the lawful basis to share them with us.
Retention
We keep data only as long as needed for the purpose or as legally required, then delete or anonymize it. You can ask us to delete it sooner at any time. We don’t need your data room or your client’s confidential materials, and we’ll sign your NDA on request.
Your rights
Under the GDPR you can access, correct, export, delete or object to the use of your data, and withdraw consent. Email us and we’ll action it promptly. You may also complain to the Dutch DPA (Autoriteit Persoonsgegevens). US-state residents (CCPA/CPRA and similar): the professional data in our deliverables is publicly available information; beyond that we hold only ordinary contact/account data. You have the usual rights (know/access, delete, correct, opt out of any “sale”/“sharing”, though we don’t sell your personal contact data and no third party collects identifiers on our site), with no discrimination for exercising them. If you’re named in a deliverable and want to exercise a right, email [email protected].
Cookies
We use strict-minimum functional cookies and privacy-friendly analytics (on a legitimate-interest basis, with IP anonymization), with no advertising cookies and no third-party identification cookies. See the cookie policy.