Previous version. This is the text that applied until 6 October 2026. For customers who signed up before 7 October 2026, it stays in force until 30 days after our notice email about Ask Limitguard. Read the current version. All previous versions.
Processor: Ambulatio Consulting BV, The Netherlands | Last updated: 4 October 2026 | Contact: security@limitguard.ai
1. Parties and scope
This Data Processing Agreement ("DPA") applies between Ambulatio Consulting BV ("Processor") and the customer ("Controller") using the Limitguard service. This DPA forms part of the service agreement, is accepted when the Controller signs up, and governs all personal data processed by the Processor on behalf of the Controller in connection with the Limitguard service: the checks, lead lists and requests that the Controller sends through the API, the MCP server, the A2A service or the dashboard.
This DPA does not cover personal data for which Ambulatio Consulting BV is itself the controller: account, billing, signup, security and abuse-prevention data. These are described in the Privacy Policy.
This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
2. Categories of data processed
| Category | Examples | Purpose |
|---|---|---|
| Entity identifiers | Business name, KVK number, CBE number, VAT number | Business registry verification |
| Business contact data | Registered address, domain name | Domain intelligence, jurisdiction assessment |
| Lead list contents | Contact names, business email addresses, company names, the last four digits of an IBAN | Running the checks the Controller asked for |
| Financial identifiers | IBAN (processed in memory; only the last four digits or a keyed hash are kept), wallet address | Financial trust verification, wallet address format validation |
| Report emails | The Controller's check results, sent to the Controller's own account email | Delivering the report the Controller asked for |
| Risk scores | Trust score, sanctions match status, risk level | Returned to Controller for their own use |
| API usage data | Endpoint called, timestamp, response time, IP address | Audit logging, rate limiting, abuse prevention |
Data subjects are employees and contacts of the Controller's leads and counterparties, directors and owners of companies as they appear in public registers (limited for sole traders as described in the Privacy Policy), and the Controller's own users.
The Processor does not intentionally process special categories of personal data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR). If the Controller submits such data through the API or a lead list, the Controller is responsible for ensuring an appropriate lawful basis exists.
3. Nature and purpose of processing
The Processor processes data solely to provide the Limitguard service: accepting entity data from the Controller, querying third-party verification sources, computing trust scores, and returning results. Processing is carried out on instructions from the Controller via API calls, lead lists and the dashboard.
The Processor will not process personal data for any purpose other than providing the contracted service, except for the following limited purposes that are compatible with it: security, abuse prevention and rate limiting; and billing. For the data in the Privacy Policy that the Processor handles for its own purposes, it acts as an independent controller. The Processor will not train machine learning models on Controller data, sell it to third parties, or use it for the Processor's own marketing.
4. Data retention
| Data Type | Default Retention | Configurable? |
|---|---|---|
| Entity check requests and results (check records) | 365 days | No |
| Lead lists and their per-row results | Until deleted by the Controller; otherwise removed by the daily purge 30 days after upload | Yes, the Controller can delete a list at any time |
| API usage logs | 90 days | No |
| Audit log entries and per-entity reports (hashed entity identifiers, never the name) | 7 years | No |
| API key metadata | Duration of account + 30 days post-deletion | No, required for security |
| Payment and invoice records (Stripe and x402) | 7 years | No, Dutch accounting law |
Controllers may request immediate deletion of all their data by submitting a GDPR erasure request to security@limitguard.ai. Deletion is processed within 30 days, except where retention is required by law (Article 17(3) GDPR).
5. Data hosting and location
Application data is hosted in the EU: on servers located in the European Union (EU) operated by Contabo GmbH (API and audit logs) and Hetzner Online GmbH (dashboard application and encrypted backups of the API server, kept 35 days), and in a database in Ireland (EU) operated by Supabase, Inc. (dashboard accounts, workspaces, check records and lead lists). Some sub-processors process limited data outside the European Economic Area, as the sub-processor list below shows, each with the transfer tool named there.
6. Sub-processors
| Sub-Processor | Service | Location | Data Processed | Transfer tool |
|---|---|---|---|---|
| Contabo GmbH | API hosting (VPS) | European Union (Contabo data centre) | API requests and responses, audit logs, cache | None needed (EU) |
| Hetzner Online GmbH | Dashboard hosting; encrypted backups of the API server (kept 35 days) | European Union | Dashboard requests in processing; encrypted backup archives | None needed (EU) |
| Supabase, Inc. | Database and authentication | Ireland (EU), AWS eu-west-1 | Dashboard accounts and sign-in data, workspaces, check records, lead lists | None needed for storage (EU). Supabase, Inc. is a US company: its data processing agreement (Standard Contractual Clauses) covers remote access from the US |
| Cloudflare, Inc. | CDN, WAF, DDoS protection; Turnstile on the sign-up form | US (EU-adequate via DPF) | Request metadata, IP addresses (not request bodies); sign-up challenge data | EU-US Data Privacy Framework |
| Resend | Email delivery | EU (sending region Ireland, AWS eu-west-1); Resend, Inc. is a US company | Recipient email address and email content: sign-in and confirmation emails, workspace invitations, low-balance notices, sign-in codes and report emails (report emails carry check results) | Resend's data processing agreement, with Standard Contractual Clauses for access from the US |
| OpenSanctions | Sanctions matching API | Germany (EU); hosted on Google Cloud in Frankfurt, according to the provider | Name and country of the entities checked (companies, and persons screened as possible politically exposed persons), for the standard check, the deep check and sign-up screening | None needed (EU) |
| Stripe | Payments (card, Bancontact, iDEAL | Wero, SEPA Direct Debit) | EU (Stripe Payments Europe, Ltd., Ireland); US group companies | Billing contact and payment data of the Controller's workspace. Never lead or check data. For payment, fraud prevention and its own legal duties Stripe acts as an independent controller | Stripe's data processing agreement; Standard Contractual Clauses or the Data Privacy Framework |
| dilisense GmbH | Adverse media screening API (extended deep check) | Switzerland (EU adequacy decision) | Names of the entities screened (company names, and person names if the Controller enters one). dilisense states that it does not store these search requests | Adequacy decision of the European Commission for Switzerland |
| Coinbase (Coinbase Developer Platform) | Verification and settlement of x402 payments, on some endpoints | United States | Paying wallet address and signed payment authorisation, which are published on the public blockchain when the payment settles. Never lead or check data | Derogation for the payment the payer requests (Art. 49(1)(b) GDPR) |
Better Stack (status page and uptime monitoring) checks only the public health addresses of the API and the dashboard and receives no personal data of the Controller. The Processor's operational telemetry (Langfuse) runs on the Processor's own server and is not a sub-processor. The public registers, company-identifier directories (GLEIF), blockchain indexes and nodes, and sanctions lists that the Processor queries receive only the public identifier listed in section 4 of the Privacy Policy and are not sub-processors.
The Processor will notify the Controller of any intended changes to this sub-processor list (additions or replacements) at least 30 days in advance by updating this page and notifying registered users by email. The Controller has the right to object to new sub-processors in accordance with Article 28(2) GDPR.
7. Security measures (Article 32 GDPR)
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Access controls: RBAC, API key authentication, audit logging of all access
- Container hardening: read-only filesystem, capability dropping, non-root process
- Network isolation: internal Docker network, no direct external database access
- Continuous security scanning: SAST on every PR, nightly dependency audits, weekly active penetration testing
- Incident response procedures with documented response times
Full details are available on the Security Architecture page.
8. Data breach notification (Article 33 GDPR)
In the event of a personal data breach, the Processor will:
- Notify the Controller without undue delay and within 72 hours of becoming aware of the breach
- Provide details including: nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken or proposed
- Cooperate fully with the Controller in fulfilling their notification obligations to supervisory authorities and data subjects
Breach notifications will be sent to the email address registered with the Controller's account or API key.
9. Data subject rights
The Processor will assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) within the timescales required by GDPR. Requests should be submitted to security@limitguard.ai.
10. Audit rights
The Controller has the right to audit compliance with this DPA. The Processor will make available all information necessary to demonstrate compliance and will allow for and contribute to audits conducted by the Controller or a third-party auditor mandated by the Controller, subject to reasonable notice (minimum 30 days) and confidentiality obligations. The Processor may satisfy audit rights through provision of current third-party audit reports where available.
11. Termination and return of data
Upon termination of the service agreement, the Processor will, at the Controller's choice, delete or return all personal data processed on behalf of the Controller within 30 days, and certify deletion in writing. Lead lists are deleted when the account closes. Deletion does not apply to data retained under a legal obligation.
Contact for DPA queries: security@limitguard.ai | Signed copies: Available on request within 5 business days.