Your data stays in Europe

We collect only what is necessary, store it in the EU, and give you full control. No tracking, no profiling, no selling.

Previous version. This is the text that applied until 3 October 2026. It stays in force for customers who signed up before 4 October 2026 until 3 November 2026. Read the current version. All previous versions.

Controller: Ambulatio Consulting BV, Ceresstraat 13, 4811 CA Breda, The Netherlands  |  Contact: privacy@limitguard.ai  |  Last updated: October 2026

1. What we collect

Data When Legal Basis (GDPR)
Email address API key registration Contract performance (Art. 6(1)(b))
API request data (entity names, identifiers) Each API call Contract performance (Art. 6(1)(b))
IP address, request timestamp Each API call Legitimate interest: security and abuse prevention (Art. 6(1)(f))
Solana wallet address x402 payment Contract performance (Art. 6(1)(b))
Web analytics (page views, country) Website visit Legitimate interest: service improvement (Art. 6(1)(f))

2. What we do not collect

  • We do not use cookies for tracking or advertising.
  • We do not collect personal data beyond what is listed above.
  • We do not build user profiles or track behaviour across sites.
  • We do not sell, rent, or share your data with third parties for their own purposes.

3. How we use your data

  • Provide the service: Process API requests, return trust scores, manage your account.
  • Security: Detect abuse, enforce rate limits, maintain audit trails.
  • Legal compliance: Retain payment records as required by Dutch accounting law (7 years).
  • Service communication: Send API key notifications, deprecation notices, and security alerts. No marketing emails unless you opt in.
  • Report emails: when you run a company check in the dashboard, we email you, the account holder, your own report. You can turn this off in Settings or with the link in any report email.

People we look up for our customers (Lead Verify)

When a customer checks a business lead, we look up the company in public business registers (the Dutch KVK register, the Belgian KBO register and the EU VAT register) and in public sanctions lists, and we check whether the email domain the customer sent can receive mail. This can include the names of directors or owners as they appear in those registers, and the business email address the customer supplied.

  • Purpose: to tell our customer whether a lead is a real, active company before they contact it.
  • Legal basis: our customer's and our legitimate interest (GDPR Art. 6(1)(f)): avoiding effort on, and fraud by, companies that do not exist or misrepresent themselves. We only use data that a business published for business purposes.
  • Sole traders and partnerships: we return only whether the business is registered and active, the date it stopped, and whether it asked not to receive marketing mail. No other personal register data.
  • How long: as long as the check record of the customer who ran it (see Data Retention).
  • Your right to object: email privacy@limitguard.ai. We stop using your data for these checks unless we have compelling grounds, and we tell you the outcome within one month.

Sole traders and partnerships: public register data

We hold the public records of sole traders and partnerships as the Dutch KVK register and the Belgian KBO register publish them, including the business phone number, email address and website in the KBO register, and we compare names with public sanctions lists. We did not collect this data from you; this section is our notice under GDPR Article 14.

  • Source: KVK (Netherlands) and KBO Open Data (Belgium); OFAC, EU and UN sanctions lists.
  • Purpose: business-to-business lead verification: telling a customer whether a lead is a real, active business.
  • Legal basis: legitimate interest (GDPR Art. 6(1)(f)). We honour the register's own protections: an address KVK shields stays city only, and a wish not to receive marketing mail is always shown to our customer. We never sell contact lists.
  • What we return: see "Sole traders and partnerships" in the Lead Verify section above.
  • How to object: email privacy@limitguard.ai with your KVK or KBO number. We add it to our objection list; from then on we do not screen your names against sanctions lists, stop watching names we screened before for new sanctions listings, read no website and return no contact details. Our answers carry no field or code that says you objected, and reports we built for customers before you objected stop showing your contact details and full register profile. We still return the basic register record we return for every business: the registered name, legal form, founding date and address (city only where the register shields it), whether your business is active, the date it stopped and your mail preference, and for Belgium the main activity, the registered names and the number of establishments.

Lead lists our customers upload

A customer can upload a list of leads as a CSV file and have us check the whole list. A list can contain email addresses, names and partial bank account numbers (IBANs). We never keep a full IBAN: we store only its last four digits.

  • Our role: we process an uploaded list on the customer's behalf, as a processor under our Data Processing Agreement. The customer decides what to upload and why.
  • How long: until the customer deletes the list. A list the customer has not deleted is removed by our daily purge 30 days after upload.
  • No other use: we use a list only to run the checks the customer asked for. We never reuse it for anything else, and we never share it or sell it.

4. Where we store your data

Service Provider Location Purpose
API hosting Contabo GmbH Germany (EU) API, audit logs, cache
Dashboard hosting Hetzner Online GmbH Germany (EU) The dashboard web application at dashboard.limitguard.ai
Database and sign-in Supabase, Inc. Ireland (EU), AWS eu-west-1 Dashboard accounts and sign-in, workspaces, check records
CDN and WAF Cloudflare, Inc. US (EU-adequate via Data Privacy Framework) DDoS protection, request routing. Processes request metadata only, not request bodies.
Web analytics Cloudflare, Inc. US (DPF) Privacy-preserving page view analytics. No cookies, no personal identifiers.
Email delivery Resend EU or US, under Resend's data processing agreement Sending service emails: waitlist confirmations, and the report emails described above. Processes your email address and the email's content.

Application data is stored in the EU: API requests, responses and audit logs on servers in Germany; dashboard accounts, workspaces and check records in a database in Ireland. Data does not leave the EEA in the ordinary course of processing.

5. Data retention

Data Retention Reason
Check records: the company checked, the identifiers you sent (an IBAN only as a keyed hash) and the result 365 days Service provision and your check history
Trust score history 365 days Score history and change monitoring
API usage logs 90 days Usage metering and abuse prevention
Audit trail and per-entity reports: a one-way hash of the entity name (never the name), score and recommendation 7 years Tamper-evident compliance record
Webhook delivery logs 7 days Delivery troubleshooting
Enterprise sales enquiries (name, work email, stated need) 12 months after the last contact Answering your enquiry
Shopping agent waitlist (email, your optional answers, and the record of your consent: when you agreed and confirmed, and from which IP address) 7 days if never confirmed, otherwise 12 months from your latest sign-up. If you unsubscribe, we stop emailing you and delete your answers at once, and keep only your email and the record of your consent and withdrawal until the 12 months end, to show we respect it Emailing you about the waitlist, based on your consent (GDPR Art. 6(1)(a)); withdraw at any time with the link in every email
Account data (email, API key) Account lifetime + 30 days Service provision
Dashboard sign-ups that never joined a workspace (email and sign-in record) 90 days after sign-up, unless you signed in during the last 90 days. If you join or create a workspace, the account data row above applies instead Letting you finish setting up your account, as a step before a contract (GDPR Art. 6(1)(b))
Payment records 7 years Dutch accounting law (Art. 2:10 BW)
Web analytics Aggregated, no personal data retained Service improvement

6. Your rights

Under GDPR, you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data ("right to be forgotten") (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability: receive your data in a structured format (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl

To exercise any right, email privacy@limitguard.ai. We will respond within 30 days.

7. Cookies

This website uses Cloudflare Web Analytics, which does not use cookies and does not collect personal data. No cookie consent banner is required.

We do not use advertising cookies, social media trackers, or any third-party tracking scripts beyond Cloudflare Web Analytics.

8. Children

Limitguard is a B2B service. We do not knowingly collect data from anyone under 16. If you believe we have inadvertently collected such data, contact privacy@limitguard.ai and we will delete it promptly.

9. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified via email to registered API key holders at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

Privacy questions? Contact privacy@limitguard.ai  |  Supervisory authority: Autoriteit Persoonsgegevens