Privacy policy
Last updated: August 27, 2026.
Who we are
Acuris Holding GmbH (“we”, “us”) operates the address validation and geocoding APIs at api.acuris-geo.com (international) and paf.acuris-geo.com (UK, under licence from Royal Mail), and the related websites. Registered office: Hammanstraße 1, 67549 Worms, Germany. Contact: support@acuris-geo.com.
Data we process
- Account data: registration details you submit (e.g. email, name) and credentials.
- API traffic: the address, email, and phone-number data and parameters you send to the API for validation, geocoding, or lookup — see what we log, and for how long below.
- Technical data: IP address, browser/device information, timestamps, and logs needed for security, rate limits, and troubleshooting.
What we log when you call the API, and why
This section covers every request that reaches our validation and geocoding engine — address validation, geocoding, and reverse geocoding, as well as our email-address and phone-number validation tools. It applies the same way whether the request is a single call, a batch submitted via /validate/batch, an asynchronous job, or a row run through our online demo tool or the Excel add-in: every address (or email, or phone number) in a batch is logged individually, exactly like a standalone call. The same underlying log, for the same purposes and retention, is also used for our other verification tools (for example business, sanctions-screening, IBAN, and identity checks, and postcode lookup/autocomplete).
Each logged request can include:
- What you submitted. The address, email, or phone number, plus the call's parameters (e.g. country). Every input shape carries its own length cap: a single free-text address line (for example, typed into a search box, or sent as one plain-text string to
/validate) is capped at 240 characters; a submitted email address is capped at 128 characters; a submitted phone number is capped at 48 characters. Structured address fields (street, house number, city, state, postcode) sent to/validate, and every field sent to our geocoding endpoints, are logged in full — there is no length cap on those. Inputs to our other verification tools (for example, a name checked against sanctions lists, or a search term typed into postcode autocomplete) carry their own, similarly modest caps. - The result. Match status (matched / no match / error), match score, accuracy level (e.g. rooftop vs. street vs. postcode-level), the resulting postcode, locality, country, and coordinates, the reason for a failed match, and how long the request took us to process.
- Who called us. Your IP address; the API key used, if any, and its account tier; the endpoint called; your browser or app's User-Agent string; a device-type classification we derive from it (e.g. desktop, mobile, bot); a session identifier that groups requests from the same visit; a self-declared integration/client identifier some callers send in the
X-Acuris-Clientheader (capped at 200 characters); and, for internal automated jobs only, a shard/job label sent in anX-Acuris-Shard,X-Acuris-Job, orX-Acuris-Internal-Idheader (capped at 96 characters). - Where the request appears to come from. We resolve your IP address against a third-party geolocation/network lookup and store the result on the same row: approximate country, city, and region; approximate, city-level coordinates (not your device's actual location); the owning organisation/ISP name and network (AS) name; and whether the IP looks like a mobile carrier or a hosting/datacentre network.
We use this log for two purposes:
- Improving the service. Real-world submissions that fail to match, or match poorly, are our best signal for finding gaps in our matching logic and reference data. Permanent fixes are recorded separately as curated corrections to the reference data.
- Detecting and preventing abuse. We use the same log to detect systematic extraction, scraping, or other misuse of the service (see Anti-scraping & bulk extraction in our Terms of service). Some of our reference data is licensed from third parties — for example, under the UK Royal Mail PAF® licence — and our obligation to protect it against unauthorised extraction depends on being able to review what was queried.
The lawful basis for both purposes is our legitimate interest (Art. 6(1)(f) GDPR) in operating and improving an accurate service and in protecting our own and our licensors’ data. You have the right to object to this processing under Art. 21 GDPR — contact support@acuris-geo.com.
This log is kept for up to 90 days (see Retention below for the one exception) and is never sold, published, or supplied to third parties as a dataset or feed.
Acuris Validate for Excel (Office Add-in)
Acuris Validate for Excel is a Microsoft Office task-pane add-in that lets you clean, verify, and geocode addresses (plus emails and phone numbers) without leaving Excel. This section describes how the add-in itself handles data; the same processing, retention, and rights described elsewhere in this policy apply.
- What it sends: only the cell values in the range you select and click Validate on — e.g. address, email, or phone columns — are sent to our API (
api.acuris-geo.com) for processing. The add-in does not read, scan, or transmit any other cells, sheets, or workbooks. - What it writes back: results (validated address, coordinates, verdict, etc.) are written into the same worksheet, at the columns and rows you direct. Nothing is sent anywhere else.
- Account data: using the add-in without an account (the “Try free” option) only requires an email address, used solely to issue and rate-limit a trial API key. Pasting an existing API key requires no personal data at all.
- No other Office data: the add-in does not access your calendar, mailbox, files outside the active workbook, or any other Microsoft 365 service.
Purposes & legal bases (EEA-style summary)
We process data to deliver the service, authenticate users, enforce rate limits and abuse prevention, improve reliability, and comply with law. The legal bases under the GDPR are: contract (Art. 6(1)(b)) for service delivery to account holders, legitimate interests (Art. 6(1)(f)) for security, abuse prevention, and operational reliability, and legal obligation (Art. 6(1)(c)) for tax and accounting records.
Retention
We retain account data for five (5) years after subscription cancellation, except where law requires a longer retention period (for example, German tax and commercial-code obligations may require up to 10 years for invoicing records). Operational request logs (including the API request log described under What we log above) and rate-limit counters are retained for up to 90 days unless a security incident or audit requires longer. Backup snapshots are rotated on a 30-day cycle.
One exception: the IP→location/network lookup we use to populate the “where the request appears to come from” fields is kept in a separate cache, keyed by IP address, so that we don't have to re-query our geolocation provider every time. That cache entry is refreshed whenever we see the same IP address again, but — unlike the 90-day request log — it is not deleted on a fixed schedule. So the cached approximate location and network data for a given IP address can persist for longer than 90 days, and for an IP address we never see again, indefinitely.
Processors & transfers
Hosting and infrastructure are provided by Hetzner Online GmbH (Germany) on EU-located servers. Payment processing is handled by Stripe Payments Europe Ltd. (Ireland) with sub-processing in the United States under standard contractual clauses. Transactional email is delivered via Hetzner Mail. IP geolocation and network lookups — used to populate the “where the request appears to come from” fields described under What we log above — are performed by ip-api.com, with IPinfo.io used as a fallback when ip-api.com does not return a usable organisation/network signal; both receive the visitor's IP address for this purpose. Enterprise customers may request a Data Processing Agreement and an up-to-date sub-processor list.
Your rights
Under the GDPR you may have rights to access, rectify, delete, restrict, or object to processing, to data portability, and to lodge a complaint with a supervisory authority (in Germany, the data-protection authority of Rhineland-Palatinate). Contact support@acuris-geo.com to exercise these rights.