Transparent data processing under GDPR

We process only what is necessary, store it in Europe, and delete it when you ask. Contact us for a signed copy.

Previous version. This is the text that applied until 3 October 2026. It stays in force for customers who signed up before 4 October 2026 until 3 November 2026. Read the current version. All previous versions.

Processor: Ambulatio Consulting BV, The Netherlands  |  Effective Date: February 2026  |  Contact: security@limitguard.ai

Request a signed DPA: Email security@limitguard.ai with subject "DPA Request". We will respond within 5 business days with a countersigned copy.

1. Parties and scope

This Data Processing Agreement ("DPA") applies between Ambulatio Consulting BV ("Processor") and the customer ("Controller") using the Limitguard Trust Intelligence API. This DPA forms part of the service agreement and governs all personal data processed by the Processor on behalf of the Controller in connection with the Limitguard service.

This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

2. Categories of data processed

Category Examples Purpose
Entity identifiers Business name, KVK number, CBE number, VAT number Business registry verification
Business contact data Registered address, domain name Domain intelligence, jurisdiction assessment
Financial identifiers IBAN, wallet address Financial trust verification, wallet address format validation
Risk scores Trust score, sanctions match status, risk level Returned to Controller for their own use
API usage data Endpoint called, timestamp, response time, IP address Audit logging, rate limiting, abuse prevention

The Processor does not intentionally process special categories of personal data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR). If the Controller submits such data through the API, the Controller is responsible for ensuring an appropriate lawful basis exists.

3. Nature and purpose of processing

The Processor processes data solely to provide the Limitguard Trust Intelligence service: accepting entity data from the Controller, querying third-party verification sources, computing trust scores, and returning results. Processing is carried out on instructions from the Controller via API calls.

The Processor will not process personal data for any purpose other than providing the contracted service, including training machine learning models on Controller data, selling data to third parties, or using data for Processor's own marketing or analytics.

4. Data retention

Data Type Default Retention Configurable?
Entity check requests and results (check records) 365 days No
API usage logs 90 days No
Audit log entries and per-entity reports (hashed entity identifiers, never the name) 7 years No
API key metadata Duration of account + 30 days post-deletion No, required for security
Payment records (x402) 7 years No, Dutch accounting law

Controllers may request immediate deletion of all their data by submitting a GDPR erasure request to security@limitguard.ai. Deletion is processed within 30 days, except where retention is required by law (Article 17(3) GDPR).

5. Data hosting and location

All personal data is hosted in the EU: on servers located in Germany (EU) operated by Contabo GmbH (API and audit logs) and Hetzner Online GmbH (dashboard application), and in a database in Ireland (EU) operated by Supabase, Inc. (dashboard accounts, workspaces and check records). Data does not leave the European Economic Area in the ordinary course of processing. Cloudflare CDN/WAF processes request metadata at the network edge; see sub-processor list below for details.

6. Sub-processors

Sub-Processor Service Location Data Processed
Contabo GmbH API hosting (VPS) Germany (EU) API requests and responses, audit logs, cache
Hetzner Online GmbH Dashboard hosting Germany (EU) Dashboard requests in processing
Supabase, Inc. Database and authentication Ireland (EU), AWS eu-west-1 Dashboard accounts and sign-in data, workspaces, check records
Cloudflare, Inc. CDN, WAF, DDoS protection US (EU-adequate via DPF) Request metadata, IP addresses (not request bodies)

The Processor will notify the Controller of any intended changes to this sub-processor list (additions or replacements) at least 30 days in advance by updating this page and notifying registered users by email. The Controller has the right to object to new sub-processors in accordance with Article 28(2) GDPR.

7. Security measures (Article 32 GDPR)

The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls: RBAC, API key authentication, audit logging of all access
  • Container hardening: read-only filesystem, capability dropping, non-root process
  • Network isolation: internal Docker network, no direct external database access
  • Continuous security scanning: SAST on every PR, nightly dependency audits, weekly active penetration testing
  • Incident response procedures with documented response times

Full details are available on the Security Architecture page.

8. Data breach notification (Article 33 GDPR)

In the event of a personal data breach, the Processor will:

  • Notify the Controller without undue delay and within 72 hours of becoming aware of the breach
  • Provide details including: nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken or proposed
  • Cooperate fully with the Controller in fulfilling their notification obligations to supervisory authorities and data subjects

Breach notifications will be sent to the email address registered with the Controller's API key.

9. Data subject rights

The Processor will assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) within the timescales required by GDPR. Requests should be submitted to security@limitguard.ai.

10. Audit rights

The Controller has the right to audit compliance with this DPA. The Processor will make available all information necessary to demonstrate compliance and will allow for and contribute to audits conducted by the Controller or a third-party auditor mandated by the Controller, subject to reasonable notice (minimum 30 days) and confidentiality obligations. The Processor may satisfy audit rights through provision of current third-party audit reports where available.

11. Termination and return of data

Upon termination of the service agreement, the Processor will, at the Controller's choice, delete or return all personal data processed on behalf of the Controller within 30 days, and certify deletion in writing. Deletion does not apply to data retained under a legal obligation.

Contact for DPA queries: security@limitguard.ai  |  Signed copies: Available on request within 5 business days.