Previous version. This is the text that applied until 3 October 2026. It stays in force for customers who signed up before 4 October 2026 until 3 November 2026. Read the current version. All previous versions.
Processor: Ambulatio Consulting BV, The Netherlands | Effective Date: February 2026 | Contact: security@limitguard.ai
1. Parties and scope
This Data Processing Agreement ("DPA") applies between Ambulatio Consulting BV ("Processor") and the customer ("Controller") using the Limitguard Trust Intelligence API. This DPA forms part of the service agreement and governs all personal data processed by the Processor on behalf of the Controller in connection with the Limitguard service.
This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
2. Categories of data processed
| Category | Examples | Purpose |
|---|---|---|
| Entity identifiers | Business name, KVK number, CBE number, VAT number | Business registry verification |
| Business contact data | Registered address, domain name | Domain intelligence, jurisdiction assessment |
| Financial identifiers | IBAN, wallet address | Financial trust verification, wallet address format validation |
| Risk scores | Trust score, sanctions match status, risk level | Returned to Controller for their own use |
| API usage data | Endpoint called, timestamp, response time, IP address | Audit logging, rate limiting, abuse prevention |
The Processor does not intentionally process special categories of personal data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR). If the Controller submits such data through the API, the Controller is responsible for ensuring an appropriate lawful basis exists.
3. Nature and purpose of processing
The Processor processes data solely to provide the Limitguard Trust Intelligence service: accepting entity data from the Controller, querying third-party verification sources, computing trust scores, and returning results. Processing is carried out on instructions from the Controller via API calls.
The Processor will not process personal data for any purpose other than providing the contracted service, including training machine learning models on Controller data, selling data to third parties, or using data for Processor's own marketing or analytics.
4. Data retention
| Data Type | Default Retention | Configurable? |
|---|---|---|
| Entity check requests and results (check records) | 365 days | No |
| API usage logs | 90 days | No |
| Audit log entries and per-entity reports (hashed entity identifiers, never the name) | 7 years | No |
| API key metadata | Duration of account + 30 days post-deletion | No, required for security |
| Payment records (x402) | 7 years | No, Dutch accounting law |
Controllers may request immediate deletion of all their data by submitting a GDPR erasure request to security@limitguard.ai. Deletion is processed within 30 days, except where retention is required by law (Article 17(3) GDPR).
5. Data hosting and location
All personal data is hosted in the EU: on servers located in Germany (EU) operated by Contabo GmbH (API and audit logs) and Hetzner Online GmbH (dashboard application), and in a database in Ireland (EU) operated by Supabase, Inc. (dashboard accounts, workspaces and check records). Data does not leave the European Economic Area in the ordinary course of processing. Cloudflare CDN/WAF processes request metadata at the network edge; see sub-processor list below for details.
6. Sub-processors
| Sub-Processor | Service | Location | Data Processed |
|---|---|---|---|
| Contabo GmbH | API hosting (VPS) | Germany (EU) | API requests and responses, audit logs, cache |
| Hetzner Online GmbH | Dashboard hosting | Germany (EU) | Dashboard requests in processing |
| Supabase, Inc. | Database and authentication | Ireland (EU), AWS eu-west-1 | Dashboard accounts and sign-in data, workspaces, check records |
| Cloudflare, Inc. | CDN, WAF, DDoS protection | US (EU-adequate via DPF) | Request metadata, IP addresses (not request bodies) |
The Processor will notify the Controller of any intended changes to this sub-processor list (additions or replacements) at least 30 days in advance by updating this page and notifying registered users by email. The Controller has the right to object to new sub-processors in accordance with Article 28(2) GDPR.
7. Security measures (Article 32 GDPR)
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Access controls: RBAC, API key authentication, audit logging of all access
- Container hardening: read-only filesystem, capability dropping, non-root process
- Network isolation: internal Docker network, no direct external database access
- Continuous security scanning: SAST on every PR, nightly dependency audits, weekly active penetration testing
- Incident response procedures with documented response times
Full details are available on the Security Architecture page.
8. Data breach notification (Article 33 GDPR)
In the event of a personal data breach, the Processor will:
- Notify the Controller without undue delay and within 72 hours of becoming aware of the breach
- Provide details including: nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken or proposed
- Cooperate fully with the Controller in fulfilling their notification obligations to supervisory authorities and data subjects
Breach notifications will be sent to the email address registered with the Controller's API key.
9. Data subject rights
The Processor will assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) within the timescales required by GDPR. Requests should be submitted to security@limitguard.ai.
10. Audit rights
The Controller has the right to audit compliance with this DPA. The Processor will make available all information necessary to demonstrate compliance and will allow for and contribute to audits conducted by the Controller or a third-party auditor mandated by the Controller, subject to reasonable notice (minimum 30 days) and confidentiality obligations. The Processor may satisfy audit rights through provision of current third-party audit reports where available.
11. Termination and return of data
Upon termination of the service agreement, the Processor will, at the Controller's choice, delete or return all personal data processed on behalf of the Controller within 30 days, and certify deletion in writing. Deletion does not apply to data retained under a legal obligation.
Contact for DPA queries: security@limitguard.ai | Signed copies: Available on request within 5 business days.