Privacy notice: bgroup demo
Last updated 5 October 2026
This notice explains how the bgroup demo app and its website handle personal information. It is written for testers and for anyone whose name is typed into the demo.
Who we are
- Controller
- World3 Corporation, a Delaware corporation. It is the company responsible for this demo.
- Questions about this notice
- Contact the World3 team through the person who invited you to the demo.
- UK representative
- Not required for this demo.
What this demo is
bgroup is a prototype. A tester types a name. The demo compares that name with public sanctions lists and public politically exposed person (PEP) lists. It can store the result, open a case, and record a two-person approval and an audit trail.
The demo tenant is for the trial. It is not a live customer system. Do not type customer names into it, and do not upload customer files.
Information we use
We use only the following.
- The names that testers type, and the screening results against the public lists.
- The cases, the approval decisions, and the audit trail of who did what in the demo tenant.
- Your sign-in details. These are a shared site password and, if you choose to set one up, a passkey. A passkey is a public key, which we store on our server. The private key stays on your device.
- If you have a personal account: your first name, your surname, your email address, a salted hash of your password (we never store the password itself), the times you signed in and out, and a record of each sign-in session. Your full name is recorded on the work you do in the demo, including screenings, cases, decisions and the audit trail.
- Server logs. The server logs the internet (IP) address behind a failed sign-in attempt and behind a passkey sign-in, and sign-in events such as a personal account being set up. We use these logs for security, to spot and stop attempts to guess passwords.
- Login cookies, and a short-lived cookie used only when you sign in with a passkey or set one up, all described below.
- Face ID or Touch ID, only on your device, as described below.
We do not use analytics. We do not use advertising. We do not use tracking cookies, pixels, or similar tools. We do not buy data. We do not sell data.
Why we use it
We use this information to run the demo, to show sanctions and PEP screening on public lists, to require two people for an approval, and to keep an audit trail. If you have a personal account, we also use your name and email address to sign you in and to show who did what.
The lawful basis under UK GDPR is legitimate interests. The interest is running a secure internal demonstration and keeping a record of what the testers did. You can object to this. Our contact is below.
A PEP result can indicate a public political role. We do not use the demo to make a decision that has a legal effect, or a similar significant effect, on anyone. A person reviews every case. Two people have to approve it.
Face ID, Touch ID and passkeys
If you set up a passkey, your device unlocks it with Face ID, Touch ID or its own screen lock. That check is done on your device, through Apple's framework or your platform's own. We do not receive a picture of your face or fingerprint, a template, or any other biometric information. Nothing biometric reaches our server.
The server keeps the passkey's public key, a name for the device, and the dates it was set up and last used. You can remove a passkey at any time from Passkeys on this site, in the console's session menu.
Cookies
We set a cookie so that you stay signed in. If you sign in with a personal account, we set a sign-in cookie for that account too. While you sign in with a passkey or set one up, we also set a cookie that lasts only a few minutes.
| Name | Purpose | How long it lasts |
|---|---|---|
| __Host-bgroup_site | Keeps you signed in to the demo | 12 hours |
| __Host-bgroup_session | Keeps you signed in to your personal account | 12 hours |
| bgroup_wa | A short-lived cookie used only during passkey sign-in or set-up | 5 minutes |
The two sign-in cookies start with __Host-, which tells your browser to keep them to this one site, over a secure connection only. These cookies are strictly necessary for the demo you asked to use. We do not use them to track you across other sites. We do not set any other cookies.
Who we share it with
We share demo information with the staff and suppliers who run the demo tenant, under instructions from the controller.
Our host for the demo tenant is Amazon Web Services, in Frankfurt (eu-central-1), Germany.
We share information if the law requires it. We do not share it with advertisers or data brokers.
Where it is kept
The demo tenant is hosted in the EU, in Frankfurt, Germany. For people in the UK, this is covered by the UK adequacy regulations for the European Economic Area (EEA).
How long we keep it
We keep screening results, cases, the audit trail, and the details of personal accounts for the life of the demo tenant. We delete them when the demo ends, or within 30 days of a valid request to delete them, whichever comes first.
We keep a short record of a deletion request so we can show that we handled it.
Your rights
If UK GDPR applies to you, you can ask us to:
- tell you what we hold about you
- correct it
- delete it
- limit how we use it
- give you a copy in a portable form, where the law provides that right
- object to use based on legitimate interests
We reply within one month. We may ask you to confirm who you are.
You can complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, at ico.org.uk, or on 0303 123 1113. We would like to hear from you first, using the contact below.
Children
This demo is for adult testers. It is not aimed at children.
Changes
If we change this notice, we will put the new date at the top and publish the new version at this URL.
Contact
Contact the World3 team through the person who invited you to the demo.
Prototype. Public list data; no live customer processing.