Transparent data processing under GDPR

We process only what is necessary, store it in Europe, and delete it when you ask. Contact us for a signed copy.

Previous version. This is the text that applied until 6 October 2026. For customers who signed up before 7 October 2026, it stays in force until 30 days after our notice email about Ask Limitguard. Read the current version. All previous versions.

Processor: Ambulatio Consulting BV, The Netherlands  |  Last updated: 4 October 2026  |  Contact: security@limitguard.ai

Request a signed DPA: Email security@limitguard.ai with subject "DPA Request". We will respond within 5 business days with a countersigned copy.

1. Parties and scope

This Data Processing Agreement ("DPA") applies between Ambulatio Consulting BV ("Processor") and the customer ("Controller") using the Limitguard service. This DPA forms part of the service agreement, is accepted when the Controller signs up, and governs all personal data processed by the Processor on behalf of the Controller in connection with the Limitguard service: the checks, lead lists and requests that the Controller sends through the API, the MCP server, the A2A service or the dashboard.

This DPA does not cover personal data for which Ambulatio Consulting BV is itself the controller: account, billing, signup, security and abuse-prevention data. These are described in the Privacy Policy.

This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

2. Categories of data processed

Category Examples Purpose
Entity identifiers Business name, KVK number, CBE number, VAT number Business registry verification
Business contact data Registered address, domain name Domain intelligence, jurisdiction assessment
Lead list contents Contact names, business email addresses, company names, the last four digits of an IBAN Running the checks the Controller asked for
Financial identifiers IBAN (processed in memory; only the last four digits or a keyed hash are kept), wallet address Financial trust verification, wallet address format validation
Report emails The Controller's check results, sent to the Controller's own account email Delivering the report the Controller asked for
Risk scores Trust score, sanctions match status, risk level Returned to Controller for their own use
API usage data Endpoint called, timestamp, response time, IP address Audit logging, rate limiting, abuse prevention

Data subjects are employees and contacts of the Controller's leads and counterparties, directors and owners of companies as they appear in public registers (limited for sole traders as described in the Privacy Policy), and the Controller's own users.

The Processor does not intentionally process special categories of personal data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR). If the Controller submits such data through the API or a lead list, the Controller is responsible for ensuring an appropriate lawful basis exists.

3. Nature and purpose of processing

The Processor processes data solely to provide the Limitguard service: accepting entity data from the Controller, querying third-party verification sources, computing trust scores, and returning results. Processing is carried out on instructions from the Controller via API calls, lead lists and the dashboard.

The Processor will not process personal data for any purpose other than providing the contracted service, except for the following limited purposes that are compatible with it: security, abuse prevention and rate limiting; and billing. For the data in the Privacy Policy that the Processor handles for its own purposes, it acts as an independent controller. The Processor will not train machine learning models on Controller data, sell it to third parties, or use it for the Processor's own marketing.

4. Data retention

Data Type Default Retention Configurable?
Entity check requests and results (check records) 365 days No
Lead lists and their per-row results Until deleted by the Controller; otherwise removed by the daily purge 30 days after upload Yes, the Controller can delete a list at any time
API usage logs 90 days No
Audit log entries and per-entity reports (hashed entity identifiers, never the name) 7 years No
API key metadata Duration of account + 30 days post-deletion No, required for security
Payment and invoice records (Stripe and x402) 7 years No, Dutch accounting law

Controllers may request immediate deletion of all their data by submitting a GDPR erasure request to security@limitguard.ai. Deletion is processed within 30 days, except where retention is required by law (Article 17(3) GDPR).

5. Data hosting and location

Application data is hosted in the EU: on servers located in the European Union (EU) operated by Contabo GmbH (API and audit logs) and Hetzner Online GmbH (dashboard application and encrypted backups of the API server, kept 35 days), and in a database in Ireland (EU) operated by Supabase, Inc. (dashboard accounts, workspaces, check records and lead lists). Some sub-processors process limited data outside the European Economic Area, as the sub-processor list below shows, each with the transfer tool named there.

6. Sub-processors

Sub-Processor Service Location Data Processed Transfer tool
Contabo GmbH API hosting (VPS) European Union (Contabo data centre) API requests and responses, audit logs, cache None needed (EU)
Hetzner Online GmbH Dashboard hosting; encrypted backups of the API server (kept 35 days) European Union Dashboard requests in processing; encrypted backup archives None needed (EU)
Supabase, Inc. Database and authentication Ireland (EU), AWS eu-west-1 Dashboard accounts and sign-in data, workspaces, check records, lead lists None needed for storage (EU). Supabase, Inc. is a US company: its data processing agreement (Standard Contractual Clauses) covers remote access from the US
Cloudflare, Inc. CDN, WAF, DDoS protection; Turnstile on the sign-up form US (EU-adequate via DPF) Request metadata, IP addresses (not request bodies); sign-up challenge data EU-US Data Privacy Framework
Resend Email delivery EU (sending region Ireland, AWS eu-west-1); Resend, Inc. is a US company Recipient email address and email content: sign-in and confirmation emails, workspace invitations, low-balance notices, sign-in codes and report emails (report emails carry check results) Resend's data processing agreement, with Standard Contractual Clauses for access from the US
OpenSanctions Sanctions matching API Germany (EU); hosted on Google Cloud in Frankfurt, according to the provider Name and country of the entities checked (companies, and persons screened as possible politically exposed persons), for the standard check, the deep check and sign-up screening None needed (EU)
Stripe Payments (card, Bancontact, iDEAL | Wero, SEPA Direct Debit) EU (Stripe Payments Europe, Ltd., Ireland); US group companies Billing contact and payment data of the Controller's workspace. Never lead or check data. For payment, fraud prevention and its own legal duties Stripe acts as an independent controller Stripe's data processing agreement; Standard Contractual Clauses or the Data Privacy Framework
dilisense GmbH Adverse media screening API (extended deep check) Switzerland (EU adequacy decision) Names of the entities screened (company names, and person names if the Controller enters one). dilisense states that it does not store these search requests Adequacy decision of the European Commission for Switzerland
Coinbase (Coinbase Developer Platform) Verification and settlement of x402 payments, on some endpoints United States Paying wallet address and signed payment authorisation, which are published on the public blockchain when the payment settles. Never lead or check data Derogation for the payment the payer requests (Art. 49(1)(b) GDPR)

Better Stack (status page and uptime monitoring) checks only the public health addresses of the API and the dashboard and receives no personal data of the Controller. The Processor's operational telemetry (Langfuse) runs on the Processor's own server and is not a sub-processor. The public registers, company-identifier directories (GLEIF), blockchain indexes and nodes, and sanctions lists that the Processor queries receive only the public identifier listed in section 4 of the Privacy Policy and are not sub-processors.

The Processor will notify the Controller of any intended changes to this sub-processor list (additions or replacements) at least 30 days in advance by updating this page and notifying registered users by email. The Controller has the right to object to new sub-processors in accordance with Article 28(2) GDPR.

7. Security measures (Article 32 GDPR)

The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls: RBAC, API key authentication, audit logging of all access
  • Container hardening: read-only filesystem, capability dropping, non-root process
  • Network isolation: internal Docker network, no direct external database access
  • Continuous security scanning: SAST on every PR, nightly dependency audits, weekly active penetration testing
  • Incident response procedures with documented response times

Full details are available on the Security Architecture page.

8. Data breach notification (Article 33 GDPR)

In the event of a personal data breach, the Processor will:

  • Notify the Controller without undue delay and within 72 hours of becoming aware of the breach
  • Provide details including: nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken or proposed
  • Cooperate fully with the Controller in fulfilling their notification obligations to supervisory authorities and data subjects

Breach notifications will be sent to the email address registered with the Controller's account or API key.

9. Data subject rights

The Processor will assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) within the timescales required by GDPR. Requests should be submitted to security@limitguard.ai.

10. Audit rights

The Controller has the right to audit compliance with this DPA. The Processor will make available all information necessary to demonstrate compliance and will allow for and contribute to audits conducted by the Controller or a third-party auditor mandated by the Controller, subject to reasonable notice (minimum 30 days) and confidentiality obligations. The Processor may satisfy audit rights through provision of current third-party audit reports where available.

11. Termination and return of data

Upon termination of the service agreement, the Processor will, at the Controller's choice, delete or return all personal data processed on behalf of the Controller within 30 days, and certify deletion in writing. Lead lists are deleted when the account closes. Deletion does not apply to data retained under a legal obligation.

Contact for DPA queries: security@limitguard.ai  |  Signed copies: Available on request within 5 business days.