Your data stays in Europe

We collect only what is necessary, store application data in the EU, and give you control. No advertising tracking, no selling.

Previous version. This is the text that applied until Ask Limitguard was added on 7 October 2026. For customers who signed up before 7 October 2026, it stays in force until 30 days after our notice email about Ask Limitguard. Read the current version. All previous versions.

Controller: Ambulatio Consulting BV, Ceresstraat 13, 4811 CA Breda, The Netherlands  |  Contact: privacy@limitguard.ai  |  Last updated: 7 October 2026

We have not appointed a data protection officer. Privacy questions go to privacy@limitguard.ai.

1. What we collect

Data When Legal basis (GDPR)
Email address Account or API key registration Contract performance (Art. 6(1)(b))
Company and signup details: country, company registration number (KVK, KBO or VAT number), company name, address and legal form as held in the official register, your answers about how you plan to use Limitguard (main use, expected leads per month, how you heard about us), and the record that you accepted the Terms and confirmed you sign up as a business (time and version) Dashboard signup Contract or steps before a contract (Art. 6(1)(b)). For a sole trader the company details can be personal data; the same basis applies
Optional short note ("What goes wrong today?", at most 200 characters). Do not enter personal data in it Dashboard signup Legitimate interest: understanding what customers need (Art. 6(1)(f))
Campaign, source, medium, term and content of the signup link you followed (utm parameters), the website that referred you to us (its domain name only) and the first page you visited on our website. They are read from the links you followed (the referring website, if the link does not carry it, from the address your browser sends when you open the signup page) and stored with your signup details when you sign up. No cookie is set and nothing is stored in your browser for this Dashboard signup Legitimate interest: understanding which channels bring customers (Art. 6(1)(f))
Sanctions screening of your company's name at signup, and the result Dashboard signup Legal obligation not to make funds or economic resources available to listed parties (Art. 6(1)(c)); legitimate interest in preventing fraud and abuse (Art. 6(1)(f))
Free-check record: that your company received its 5 free lead checks, with its registration number Dashboard signup Legitimate interest: stopping repeat claims of the free checks (Art. 6(1)(f))
Signup abuse signals: whether your email domain is a disposable domain and can receive mail, a hashed IP address for rate limits, and the Cloudflare Turnstile challenge result Dashboard signup Legitimate interest: security and abuse prevention (Art. 6(1)(f))
Billing details: billing name, address, VAT number, invoices, payment status and payment method type. Card and bank details are held by Stripe, not by us Top-up or plan Contract performance (Art. 6(1)(b)); retention of invoices: legal obligation (Art. 6(1)(c))
API request data (entity names, identifiers) Each API call Contract performance (Art. 6(1)(b))
IP address, request timestamp Each API call Legitimate interest: security and abuse prevention (Art. 6(1)(f))
Wallet address (x402 payment, on Base or Solana) x402 payment Contract performance (Art. 6(1)(b))
Web analytics (page views, country) Website visit Legitimate interest: service improvement (Art. 6(1)(f))

2. What we do not collect

  • We do not use advertising or cross-site tracking cookies. See section 7.
  • We do not collect personal data beyond what is listed above.
  • We do not build advertising profiles or track behaviour across sites.
  • We do not sell, rent, or share your data with third parties for their own purposes. The one exception is described in section 4: Stripe handles payment data for its own payment, fraud and legal duties.

3. How we use your data

  • Provide the service: Process API requests, return trust scores, manage your account.
  • Billing: Take payments through Stripe, issue invoices, handle refunds, disputes and failed payments.
  • Security: Detect abuse, enforce rate limits, maintain audit trails.
  • Legal compliance: Retain payment and invoice records as required by Dutch accounting law (7 years), and screen new customers against sanctions lists.
  • Service communication: Send API key notifications, deprecation notices, and security alerts. No marketing emails unless you opt in.
  • Report emails: when you run a company check in the dashboard, we email you, the account holder, your own report. You can turn this off in Settings or with the link in any report email.

Signing up and your free checks

When you sign up we ask for your country, your company number and a few answers about how you plan to use Limitguard. For Dutch and Belgian companies we fill in your company's name and address from the official register (KVK or KBO), and we take the register's answer over what you typed. Before we give your 5 free lead checks we look your company up in the register (or in VIES for a VAT-only number), screen its name against sanctions lists, and check that your email address is confirmed and not from a disposable domain. We keep a record that your company received the free checks, so it cannot claim them twice. If the sanctions screening finds a possible match, we hold the free checks and may review the case by hand; we tell you only that the checks are on hold.

  • Purpose: to open your account, check that your company is real and not on a sanctions list, give you your free checks and prevent abuse.
  • Legal basis: contract or steps before a contract (Art. 6(1)(b)); legal obligation for sanctions screening (Art. 6(1)(c)); legitimate interest for abuse prevention and for understanding what customers need (Art. 6(1)(f)).
  • Who sees it: our hosting and database providers, Cloudflare Turnstile and the sanctions data provider (section 4). The registers receive your company number or name when we look it up. We do not sell it.
  • If you are a sole trader: your company details can be your personal data. We then handle them as personal data, and your rights in section 6 apply.

People we look up for our customers (Lead Verify)

When a customer checks a company or a business lead, we look up the company in public business registers (the Dutch KVK register, the Belgian KBO register and the EU VAT register) and in public sanctions lists, and we check whether the email domain the customer sent can receive mail. We also read the company's own website (its home page and up to three company-details, contact or about pages) for the business phone numbers and the register or VAT number it publishes there, with the page each was found on. This can include the names of directors or owners as they appear in those registers, and the business email address the customer supplied.

  • Purpose: to tell our customer whether a lead is a real, active company before they contact it.
  • Legal basis: our customer's and our legitimate interest (GDPR Art. 6(1)(f)): avoiding effort on, and fraud by, companies that do not exist or misrepresent themselves. We only use data that a business published for business purposes.
  • Sole traders and partnerships: as for companies, we return the business details the registers publish: for the Netherlands the trade names, the activity, the number of employees, websites, the date the business stopped and whether it asked not to receive marketing mail; for Belgium the registered names, the activity and the number of establishments. We also compare the registered names with public sanctions lists and return only whether there was a possible match, with the dates of the lists. We never return an owner's name, a private address the register shields, a date of birth or a national number. You can object at any time: see "Sole traders and partnerships: public register data" below.
  • How long: as long as the check record of the customer who ran it (see Data Retention). Phone numbers found on a website are also kept in a cache for 30 days, then deleted.
  • Your right to object: email privacy@limitguard.ai. We stop using your data for these checks unless we have compelling grounds, and we tell you the outcome within one month.

Sole traders and partnerships: public register data

We hold the public records of sole traders and partnerships as the Dutch KVK register and the Belgian KBO register publish them, including the business phone number, email address and website in the KBO register, and we compare names with public sanctions lists. We did not collect this data from you; this section is our notice under GDPR Article 14.

  • Source: KVK (Netherlands) and KBO Open Data (Belgium); OFAC, EU and UN sanctions lists.
  • Purpose: business-to-business lead verification: telling a customer whether a lead is a real, active business.
  • Legal basis: legitimate interest (GDPR Art. 6(1)(f)). We honour the register's own protections: an address KVK shields stays city only, and a wish not to receive marketing mail is always shown to our customer. We never sell contact lists.
  • What we return: see "Sole traders and partnerships" in the Lead Verify section above.
  • How to object: email privacy@limitguard.ai with your KVK or KBO number. We add it to our objection list; from then on we do not screen your names against sanctions lists, stop watching names we screened before for new sanctions listings, read no website and return no contact details. Our answers carry no field or code that says you objected, and reports we built for customers before you objected stop showing your contact details and full register profile. We still return the basic register record we return for every business: the registered name, legal form, founding date and address (city only where the register shields it), whether your business is active, the date it stopped and your mail preference, and for Belgium the main activity, the registered names and the number of establishments.

Lead lists our customers upload

A customer can upload a list of leads as a CSV file and have us check the whole list. A list can contain email addresses, names and partial bank account numbers (IBANs). We never keep a full IBAN: we store only its last four digits.

  • Our role: we process an uploaded list on the customer's behalf, as a processor under our Data Processing Agreement. The customer decides what to upload and why.
  • How long: until the customer deletes the list. A list the customer has not deleted is removed by our daily purge 30 days after upload.
  • No other use: we use a list only to run the checks the customer asked for. We never reuse it for anything else, and we never share it or sell it.

4. Where we store your data

Service Provider Location Purpose
API hosting Contabo GmbH European Union (Contabo data centre) API, audit logs, cache
Dashboard hosting Hetzner Online GmbH European Union The dashboard web application at dashboard.limitguard.ai, and encrypted backups of the API server (kept 35 days)
Database and sign-in Supabase, Inc. Ireland (EU), AWS eu-west-1. Supabase, Inc. is a US company, so remote access from the US falls under its data processing agreement (Standard Contractual Clauses) Dashboard accounts and sign-in, workspaces, check records
CDN and WAF Cloudflare, Inc. US (EU-adequate via Data Privacy Framework) DDoS protection, request routing. Processes request metadata only, not request bodies.
Sign-up protection Cloudflare, Inc. (Turnstile) US (DPF) Tells people from bots on the sign-up form. Processes your IP address and browser signals.
Web analytics Cloudflare, Inc. US (DPF) Privacy-preserving page view analytics. No cookies, no personal identifiers.
Payments Stripe EU (Stripe Payments Europe, Ltd., Ireland); Stripe group companies in the US under Standard Contractual Clauses or the Data Privacy Framework Card, Bancontact, iDEAL | Wero and SEPA Direct Debit payments, plans, invoices and the customer portal. Stripe holds card and bank details; we hold opaque ids and payment status. Stripe is an independent controller for payment, fraud prevention and its own legal duties, and our processor for the rest.
Sanctions data OpenSanctions Germany (EU); hosted on Google Cloud in Frankfurt, according to the provider The name and country of the entity checked (a company, or a person when a possible politically exposed person is screened) are sent to its matching API in the standard check, the deep check and the screening of your company at sign-up. The OFAC, EU and UN sanctions lists themselves are downloaded and matched on our own servers.
Email delivery Resend EU (sending region Ireland, AWS eu-west-1). Resend, Inc. is a US company, so remote access from the US falls under its data processing agreement (Standard Contractual Clauses) Sending service emails: sign-up confirmation and sign-in emails, workspace invitations, low-balance notices, sign-in codes, waitlist confirmations, and the report emails described above. Processes your email address and the email's content.
Adverse media screening dilisense GmbH Switzerland (EU adequacy decision) The name of the entity checked (a company, or a person if you enter one) is sent for the extended deep check. dilisense states that it does not store these search requests.
x402 payments Coinbase (Coinbase Developer Platform) United States. The paying wallet address and signed payment are published on a public blockchain anyway; we rely on the derogation for the payment you request (Art. 49(1)(b) GDPR) On some endpoints (today the compliance readiness endpoints) Coinbase verifies and settles an anonymous pay-per-call payment. It receives the paying wallet address and the signed payment authorisation. No company, lead or check data is sent.
Sign-in with Google (optional) Google Ireland Limited (Google LLC, US) EU and US, under Google's own terms Only if you choose Sign in with Google: Google signs you in and sends us your email address and name. Google is an independent controller of your Google account. We send Google no lead, check or company data.
Operational telemetry Langfuse, run by us on our own server (not a third party) Same server as the API hosting Records per request the endpoint, status, timing, a one-way hash of your API key and of your IP address, the country and, for x402 payments, the paying wallet address. It records no company names, identifiers, email addresses or request bodies.

Application data is stored in the EU: API requests, responses and audit logs on servers in the European Union (Contabo data centre); dashboard accounts, workspaces and check records in a database in Ireland. A few providers process limited data in the United States: Cloudflare (request metadata, the sign-up challenge and cookie-free analytics, under the EU-US Data Privacy Framework), Stripe (payments), Coinbase (x402 payments) and Google (optional sign-in). Resend and Supabase are US companies that run their service for us in Ireland, so only remote access can come from the US. dilisense is in Switzerland, which has an EU adequacy decision. Each transfer is under the transfer tool named in the table or in the provider's data processing agreement. Apart from these, data does not leave the EEA in the ordinary course of processing.

To run checks we also query public sources with the identifiers a check needs. Each receives only what the table shows, decides for itself how to handle it, and is not our processor.

Source What we send When
Dutch Chamber of Commerce (KVK) Company name or KVK number Company checks and sign-up
Dutch insolvency register (Rechtspraak) Company name or KVK number Deep check
EU VAT register (VIES) VAT number VAT checks and sign-up
GLEIF (legal entity identifiers) Company registration number, or the exact legal name, and the country Group structure in reports
National Bank of Belgium (Central Balance Sheet Office) Belgian company number Annual accounts in Belgian company checks and reports
Domain registries (RDAP, through rdap.org) Domain name Domain age checks
Blockscout (blockchain index) Wallet address Wallet checks
Base and Solana public nodes Wallet address, and the settlement transactions of x402 payments Wallet checks and payment settlement

The Belgian KBO Open Data and the OFAC, EU and UN sanctions lists are downloaded in bulk and read from our own servers, so nothing about your checks is sent to them. Our status page (status.limitguard.ai) is run by Better Stack. Its uptime monitoring only requests the public health addresses of our API and dashboard. When you open the status page your browser connects to Better Stack, which sees your IP address; the status page has no accounts or subscriptions.

5. Data retention

Data Retention Reason
Check records: the company checked, the identifiers you sent (an IBAN only as a keyed hash) and the result 365 days Service provision and your check history
Trust score history 365 days Score history and change monitoring
API usage logs 90 days Usage metering and abuse prevention
Audit trail and per-entity reports: a one-way hash of the entity name (never the name), score and recommendation 7 years Tamper-evident compliance record
Operational telemetry in Langfuse (endpoint, status, timing, one-way hashes of the API key and IP address, country, and for x402 payments the paying wallet address) 90 days Operating the service, security and abuse prevention
Webhook delivery logs 7 days Delivery troubleshooting
Enterprise sales enquiries (name, work email, stated need) 12 months after the last contact Answering your enquiry
Shopping agent waitlist (email, your optional answers, and the record of your consent: when you agreed and confirmed, and from which IP address) 7 days if never confirmed, otherwise 12 months from your latest sign-up. If you unsubscribe, we stop emailing you and delete your answers at once, and keep only your email and the record of your consent and withdrawal until the 12 months end, to show we respect it Emailing you about the waitlist, based on your consent (GDPR Art. 6(1)(a)); withdraw at any time with the link in every email
Account data (email, API key) Account lifetime + 30 days Service provision
Signup and company details, including the campaign of the signup link and the record that you accepted the Terms and confirmed business status Account lifetime + 30 days Service provision and evidence that we sell to businesses only
Optional short note at signup Deleted 365 days after it was last written, or with the workspace if sooner Understanding what customers need
Signup step events (which step you reached, an answer token, timings; never free text or a company number) 90 days Improving the signup flow
Free-check record (that a company received its free checks, with its registration number) 12 months after the account is deleted, then deleted Stopping repeat claims of the free checks
Dashboard sign-ups that never joined a workspace (email and sign-in record) 90 days after sign-up, unless you signed in during the last 90 days. If you join or create a workspace, the account data row above applies instead Letting you finish setting up your account, as a step before a contract (GDPR Art. 6(1)(b))
Payment and invoice records (Stripe and x402) 7 years Dutch accounting law (Art. 2:10 BW)
Web analytics Aggregated, no personal data retained Service improvement

6. Your rights

Under GDPR, you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data ("right to be forgotten") (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability: receive your data in a structured format (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl, or with the data protection authority of your own EU country (in Belgium: the Gegevensbeschermingsautoriteit / Autorité de protection des données)

To exercise any right, email privacy@limitguard.ai. We will respond within one month; where a request is complex we may extend that period as the GDPR allows, and we will tell you.

7. Cookies

Our website uses Cloudflare Web Analytics, which does not use cookies and does not collect personal data. The website stores your colour-theme choice in your browser; it stays on your device.

The dashboard sets only the cookies that are strictly necessary to keep you signed in. They do not need your consent. We do not set tracking, advertising or campaign cookies: the campaign of a signup link is read from the link itself when you sign up. The sign-up form uses Cloudflare Turnstile to tell people from bots; it is needed for security. We do not use advertising cookies, social media trackers, or any third-party tracking scripts beyond Cloudflare Web Analytics. No cookie consent banner is required.

8. Children

Limitguard is a B2B service. We do not knowingly collect data from anyone under 16. If you believe we have inadvertently collected such data, contact privacy@limitguard.ai and we will delete it promptly.

9. Changes to this policy

We may update this Privacy Policy from time to time. For customers who already have an account, we notify material changes by email to workspace owners and registered API key holders, and in the dashboard, at least 30 days before they take effect. A new version applies immediately to anyone who signs up after it is published. The "Last updated" date at the top of this page reflects the most recent revision, and earlier versions stay available in the archive of previous versions.

Privacy questions? Contact privacy@limitguard.ai  |  Supervisory authority: Autoriteit Persoonsgegevens