merkleset
documents juridiques

version: 2026-08-12en vigueur: 2026-08-12informatif

Ce document est publié en anglais uniquement. Le texte anglais est la version qui fait foi : l'acceptation est enregistrée sur un SHA-256 de la source anglaise, donc une traduction ne pourrait pas être le texte que vous avez accepté.

Copyright, Takedown and Complaints Policy

Version 2026-08-12. Effective 2026-08-12.

There are three different complaints this policy handles, and they need different routes:

If you areGo toSection
A rights holder who believes material we publish infringes your copyrightdmca@merkleset.com2 and 3
A source operator who wants us to stop collecting from your site or serviceabuse@merkleset.com4
A person who believes personal data about you is in one of our datasetsprivacy@merkleset.com5

Before anything else, the one constraint we cannot engineer around. A release we have already delivered to a customer exists on that customer's systems. We cannot reach into it and delete it. So our remedy is always: remove from future releases, delete from our internal store, and require our customers to remove the identified records from their own copies. Section 6 explains exactly what that means and what we can and cannot promise. We would rather state the limit up front than describe a recall we cannot perform.

1. What we publish, and why copyright complaints should be rare

1.1 Our shipping datasets are built from official public United States federal government sources. Works of the US government are not subject to copyright in the United States, which is the whole reason these two corpora were chosen first.

1.2 We collect logged out, never create or use accounts on source sites, honour robots.txt and machine-readable text-and-data-mining reservations, and keep request rates modest.

1.3 We do not republish full text from commercial publishers, news organisations or user-generated-content platforms.

1.4 None of that makes us immune to error. If we got something wrong, tell us and we will fix it.

2. Copyright complaint (DMCA-style notice)

We follow the notice-and-counter-notice procedure of the US Digital Millennium Copyright Act, 17 U.S.C. §512, as our own policy, because it is a well-understood process and most of our source material is US-hosted. Using it is a policy choice: merkleset is operated by an individual established in Spain and this agreement is governed by Spanish law (see section 8). Nothing here implies a US legal entity or a US presence.

2.1 Send your notice to dmca@merkleset.com, addressed to our designated agent {{DMCA_AGENT}}, {{DMCA_AGENT_ADDRESS}}.

2.2 Include all of the following, or we may not be able to act:

  1. your physical or electronic signature;
  2. identification of the copyrighted work you say is infringed;
  3. identification of the material you say is infringing, precise enough for us to locate it — for a dataset, that means the dataset slug, the release version, and the record identifier or source_url where possible;
  4. your name, postal address, telephone number and email address;
  5. a statement that you have a good-faith belief the use is not authorised by the rights holder, its agent, or the law;
  6. a statement that the information in the notice is accurate and, under penalty of perjury, that you are the rights holder or authorised to act for them.

2.3 What we do on receipt:

  1. acknowledge within 3 business days;
  2. assess the notice, and ask you for clarification if identification is not precise enough;
  3. where the complaint is well-founded or genuinely arguable, remove the material from future releases and stop collecting the affected source material;
  4. delete the corresponding internal raw evidence;
  5. notify affected customers under the flow-down obligation in section 6 and tell them which records to remove;
  6. record the decision and the date.

2.4 We do not host user-uploaded content, so there is no third-party uploader to notify. Where the material came from an identifiable upstream source, we may tell that source that a complaint was made.

2.5 Sending a notice in bad faith, or materially misrepresenting that material is infringing, can make you liable for costs and damages. Please do not use this route as a general objection to being included in a public-records dataset — section 4 or 5 is the right route for that.

3. Counter-notice

3.1 If your material was removed and you believe that was a mistake or a misidentification, send a counter-notice to dmca@merkleset.com containing: your signature; identification of the removed material and where it appeared; a statement under penalty of perjury that you have a good-faith belief it was removed by mistake or misidentification; and your name, address, telephone number and email address.

3.2 We will forward the counter-notice to the complainant, and — unless they tell us within 10 business days that they have started proceedings — we may restore the material to future releases.

3.3 We will not restore material where doing so would breach data protection law, whatever the copyright position. Personal data removed under section 5 stays removed.

4. Source operator: asking us to stop collecting

If you operate a website, API or data service and you do not want us collecting from it, this is the fastest route. You do not need a lawyer and you do not need to allege infringement.

4.1 Write to abuse@merkleset.com from a domain-associated address, or by post to the address in the Legal Notice, identifying the source and what you want stopped.

4.2 We stop. Our internal engineering rules make a credible demand to stop collecting a hard stop, not a negotiation. Concretely, on receipt we:

  1. acknowledge within 3 business days;
  2. disable the connector for that source, so no further collection occurs;
  3. stop publishing new releases derived from that source;
  4. delete the internal raw evidence collected from it;
  5. tell you what we had collected, and over what period, if you ask.

4.3 We also honour machine-readable signals without being asked: robots.txt directives and text-and-data-mining reservations. If you would rather express the objection that way, that is enough — you do not need to email us. Tell us anyway if you want confirmation.

4.4 Continuing to collect after a demand to stop is exactly the conduct that turns a weak dispute into a serious one. We have no interest in it.

4.5 If you believe we breached your terms of access, say what those terms are and when. We collect logged out and accept no account terms, so this is usually a misunderstanding we can resolve quickly with the provenance records we keep — the source URL, the timestamp and the HTTP status of every fetch.

5. Personal data about you in a dataset

5.1 Write to privacy@merkleset.com. Tell us what you found, and where, as precisely as you can — the dataset, the release version, and the text or record identifier if you have it. You do not have to prove your identity beyond what is needed to locate the data and confirm it concerns you, and we will ask for no more than that.

5.2 Our datasets are built to contain no personal data, and screening runs in the pipeline before any published hash is computed. That screening is deliberately narrow in scope, and we publish its gaps: an official named in running prose without a contact label is not removed, and neither are postal addresses or obfuscated contact details. So finding something is possible, and reporting it is genuinely useful to us.

5.3 What we do:

  1. acknowledge within 3 business days;
  2. locate the records and confirm the finding;
  3. remove the data from future releases — either by redaction or by dropping the record;
  4. delete the corresponding internal raw evidence, which is the unscreened copy;
  5. where the pattern is general rather than a one-off, extend the screening rules so the class of value stops appearing, and tell you we have;
  6. notify affected customers under section 6 and require them to remove the identified records;
  7. answer you within one month, as the GDPR requires, and tell you if we need longer.

5.4 This is also the route for a GDPR erasure request about dataset content. Requests about your customer account — access, correction, deletion, portability, objection — go to the same address and are described in section 8 of the Privacy Policy.

5.5 We will not charge you, and we will not require you to explain why.

6. What removal does and does not reach — the flow-down

6.1 Future releases: fully. The affected records are removed or redacted, so every release published after we act is clean.

6.2 Our internal evidence store: deleted. The unscreened snapshot behind the affected records is deleted. Note honestly: a retention period of 90 days is configured for that store but nothing enforces it automatically yet, so deletion in response to a complaint is performed manually, as a specific act, and we log it.

6.3 Releases already downloaded by customers: we cannot recall them. A file on someone else's system is beyond our technical reach, and any vendor claiming otherwise is describing something they cannot do.

6.4 What we do instead. Our Data Licence obliges customers to remove data we identify from their own copies and indexes on our reasonable request (clause 7.4). On acting under sections 2, 4 or 5 we will:

  1. notify each customer who received an affected release;
  2. tell them exactly which records to remove, by record identifier;
  3. require confirmation of removal;
  4. treat refusal as a material breach of the licence, which lets us terminate and, under clause 3.3 of the Data Licence, revoke that customer's licence.

6.5 We keep a log of every complaint, what we did and when. If you asked for the removal, you can ask for a copy of the entry that concerns you.

7. Repeat complaints and abuse of these routes

7.1 We will act on repeated well-founded complaints about a source by retiring the source rather than patching case by case.

7.2 We may decline to process a complaint that is manifestly unfounded or excessive, or that is plainly an attempt to remove public-record facts about an organisation's dealings with a government. We will explain the refusal in writing, and it does not affect your right to complain to a supervisory authority or to go to court.

8. Legal framework and contact

8.1 merkleset is operated by Andrii Sukhanov, a natural person trading as an independent professional (autónomo) registered in Spain, NIE Z2338955K. Full identification data is in the Legal Notice.

8.2 The DMCA procedure in sections 2 and 3 is adopted as our own operating policy for handling copyright complaints. It sits inside an agreement governed by the laws of the Kingdom of Spain, with the exclusive jurisdiction of the courts of Santa Cruz de Tenerife (Canary Islands, Spain). Adopting the procedure is not a submission to US jurisdiction and does not create a US establishment.

8.3 Nothing in this policy limits your statutory rights, including your right to complain to the Agencia Española de Protección de Datos (www.aepd.es) or the supervisory authority where you live or work.

8.4 Addresses:

PurposeAddress
Copyright notices and counter-noticesdmca@merkleset.com, for the attention of {{DMCA_AGENT}}
Source operator demands, abuse, securityabuse@merkleset.com
Personal data, data subject requestsprivacy@merkleset.com
Anything elsecontact@merkleset.com
PostAndrii Sukhanov, Av. Marítima 2, puerta 05c, {{POSTAL_CODE}} Los Silos, Santa Cruz de Tenerife, Spain

sha256 10391491a53d…f16a9dd00a1f