Last updated: July 15, 2026

Privacy Policy

Last updated: July 15, 2026

This Privacy Policy explains how ValGuard.ai ("ValGuard," "we," "us," or "our") collects, uses, discloses, and protects personal data in connection with the ValGuard AI Security & Governance Gateway, including the validation proxy, dashboard, APIs, SDKs, documentation, and website (together, the "Service"). It applies to Customers and their authorized users, website visitors, and job applicants. It should be read together with the Terms of Service, Cookie Policy, Data Processing Agreement, and Subprocessors list, which are incorporated by reference. Capitalized terms not defined here have the meaning given in the Terms of Service.

1. Scope and roles: when we are a controller vs. a processor

1.1 We are a controller for "Account Data" — personal data about our own Customers, their authorized users, website visitors, newsletter subscribers, and job applicants, such as registration, billing, support, marketing, and website-analytics data. This Policy describes that processing in full.

1.2 We are a processor (or sub-processor) for "Customer Data" — personal data that a Customer or its own end users submit to or generate through the Service while using it (for example, Prompts and Outputs, where a Customer has enabled payload logging, and any personal data embedded in Playbooks or configuration). For Customer Data, the Customer (or the business it represents) determines the purposes and means of processing and is the controller; ValGuard processes Customer Data only on Customer's documented instructions, as described in the DPA. If you are an end user of one of our Customers and have questions about your data, please contact that Customer directly — ValGuard typically has no direct relationship with, or independent means to identify, a Customer's end users.

2. Definitions

  • "Personal Data" means information relating to an identified or identifiable natural person.
  • "Account Data" means personal data ValGuard controls about Customers, authorized users, website visitors, and applicants, as described in Section 1.1.
  • "Customer Data," "Prompts," "Outputs," "LLM Provider," "Guardrails"/"Validators," "Playbook," "BYOK," "Provider Vault," and "Plan" have the meanings given in the Terms of Service.
  • "End User" means an individual who interacts with a Customer's own product or agent, whose data may be included in Prompts or Outputs that Customer routes through the Service.

3. Personal data we collect

3.1 Account and identity data. Name, email address, organization name, role, authentication events, and password hash (or SSO/OAuth identifiers) when you create an account or are invited to a workspace.

3.2 Billing data. Billing name and address, and tokens/identifiers returned by our payment processor (Stripe) for invoices and subscription management. We do not receive or store full payment card numbers — Stripe handles card data directly.

3.3 Service usage and request metadata (collected on every request, by default). For every call routed through the Service we record operational metadata: timestamps, latency, upstream provider and model name, request status, prompt/completion token counts, estimated cost, retry/reask count, whether the request used a BYOK or Provider Vault credential, and whether payload logging was enabled for that request. We also record, per configured Guardrail, whether it passed or failed and its severity — but not the underlying content, unless payload logging is enabled (see Section 5). This metadata does not include the raw text of Prompts or Outputs by default.

3.4 Prompts and Outputs (only if a Customer explicitly enables payload logging). By default, Prompt and Output content is used only in memory to run validation and is discarded immediately afterward — it is not written to a database. If a Customer opts into payload logging for an Agent, the corresponding Prompts, Outputs, and/or validator detail may be stored as described in Section 5. Where such content includes personal data about a Customer's End Users, ValGuard processes it as a processor under Section 1.2 and the DPA.

3.5 Configuration data. Guardrail/validator configuration, Agent settings, budgets, routing rules, and exported/imported Playbooks (declarative JSON/YAML). This is configuration data describing how the Service should behave, not personal data about individuals, unless a Customer chooses to embed personal data in field names, descriptions, or test fixtures — Customers should avoid doing so.

3.6 Support and communications. Content of support tickets, contact-form submissions, and emails to our support, sales, or security addresses, including any attachments you choose to send us.

3.7 Cookies and similar technologies. As described in the Cookie Policy, including strictly necessary, functional, and (where consented to) analytics cookies on our marketing website and dashboard.

3.8 Automatically collected technical data. IP address, browser/user-agent, device information, and approximate location (derived from IP) collected via server logs and session records for security, fraud prevention, and diagnostics.

4. How we use personal data and our legal bases (GDPR Article 6)

PurposeTypical legal basis
Creating and administering accounts, authenticating sign-in, providing the ServicePerformance of a contract
Processing payments, invoicing, tax complianceContract; legal obligation
Operating Guardrail validation, budgets, analytics, and observability features you configureContract
Securing the Service, preventing fraud/abuse, enforcing rate limits and the Acceptable Use PolicyLegitimate interests
Providing support and responding to inquiriesContract; legitimate interests
Sending service and security noticesContract; legal obligation
Sending marketing communicationsConsent, or legitimate interests for existing customers (opt-out available at any time)
Non-essential cookies and website analyticsConsent, where required by law
Complying with law, audits, and lawful requests from authoritiesLegal obligation

5. No payload storage by default — how this works in practice

5.1 Default: no payload storage. Validation runs in memory as traffic passes through the gateway. Unless a Customer explicitly turns on payload logging for an Agent, ValGuard does not persist the content of Prompts or Outputs; only the request metadata in Section 3.3 is retained.

5.2 Configurable log levels. When a Customer does enable logging, it can choose how much detail is retained for validator findings and, at the most detailed level, raw content:

  • Metadata (recommended, and the default when logging is on): sensitive values (emails, tax IDs, PESEL/NIP, IBAN, card numbers, and similar) are automatically masked before anything is written to storage; field names and pass/fail counts are kept for debugging.
  • Hashed (strict): sensitive strings are reduced to one-way SHA-256 fingerprints; only structural metadata is retained in readable form.
  • Full (debug only): validator messages and, where enabled at the Agent level, Prompt/Output content are stored verbatim. This level is opt-in, intended for short-lived debugging, and is flagged to Customers as not recommended for workloads involving PII or regulated data.

5.3 The payload_logged flag. Every logged request carries a payload_logged attribute recording whether that specific request's content was captured, so Customers (and, on request, ValGuard) can audit exactly when detailed logging was active.

5.4 Customer responsibility. The decision to enable payload logging, and for how long content is retained, rests with the Customer via its Agent and Plan settings; ValGuard does not enable payload logging on a Customer's behalf. Customers that route personal data or regulated content through the Service should carefully consider whether, and at what log level, to enable logging.

6. Retention periods

6.1 Request metadata and (if enabled) payload logs are retained for the log-retention period included in the Customer's Plan, unless a shorter period is configured: 7 days on the Free and Developer plans, 30 days on Growth, 90 days on Production, and 365 days on Enterprise (or as stated in an Order Form). Where payload logging is enabled, a Customer may configure a shorter payload retention period for an Agent, up to its Plan's maximum; after that period, the corresponding records are deleted or irreversibly anonymized on a rolling basis.

6.2 Account Data (registration, billing, and support records) is retained for as long as the account is active, plus a limited period after closure (generally up to 90 days) to handle reactivation, disputes, and fraud prevention, and longer where required — for example, invoices and tax-relevant billing records are retained for the period required by applicable tax law.

6.3 Marketing and cookie data is retained per the consent or preference you provide, as described in the Cookie Policy, and no longer than needed for the stated purpose.

6.4 Backups. Data contained in encrypted backups is retained for a limited additional period for disaster-recovery purposes and is deleted or overwritten on our normal backup-rotation schedule.

7. Disclosure to third parties and sub-processors

7.1 We do not sell personal data. ValGuard does not sell personal data for monetary or other valuable consideration, and does not share personal data for cross-context behavioral advertising.

7.2 Sub-processors. We share personal data with the sub-processors listed at /legal/subprocessors (currently our cloud-hosting provider, which also provides email delivery and monitoring, and our payment processor) strictly to deliver the Service, under written contracts imposing data-protection obligations equivalent to this Policy. Enterprise customers receive advance notice of new sub-processors as described on that page.

7.3 LLM Providers are not our sub-processors. When a Customer routes traffic to an LLM Provider (via BYOK or Provider Vault), that provider processes the Prompts/Outputs Customer chooses to send it, under that provider's own terms and privacy practices — not as a ValGuard sub-processor. Customers should review the applicable LLM Provider's privacy terms before routing personal data to it.

7.4 Other disclosures. We may disclose personal data to professional advisors (auditors, lawyers) under confidentiality obligations, to a successor in a merger, acquisition, or asset sale (with notice as required by law), or where required to comply with a valid legal process, protect our rights, or prevent harm to any person.

8. International data transfers

Where personal data is transferred from the EEA, UK, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and, where applicable, the UK International Data Transfer Addendum), as further described in the DPA. Sub-processor transfer details are available on request to privacy@valguard.neteos.eu.

9. Data security

We apply technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and, for Provider Vault credentials, encryption at rest; role-based access controls and audit logging for administrative access; automatic PII masking/hashing at the Metadata and Hashed log levels described in Section 5.2; and vulnerability management and incident-response procedures described on our Security page. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your rights under GDPR / UK GDPR (EEA, UK, and Swiss individuals)

Subject to applicable law and verification of your identity, you may request to: access a copy of your personal data; rectify inaccurate data; erase data; restrict or object to certain processing (including processing based on legitimate interests or for direct marketing); port data you provided to us in a structured, machine-readable format; and withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing. To exercise these rights, email privacy@valguard.neteos.eu. We will respond within the timeframes required by applicable law (generally one month for GDPR requests, extendable in limited circumstances). If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority — for our EU entity, the lead authority is the Polish Personal Data Protection Office (Urząd Ochrony Danych Osobowych, "UODO"), ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl), or your own country's supervisory authority if you reside elsewhere in the EEA or UK.

We have not appointed a statutory Data Protection Officer because our processing does not meet the mandatory-appointment thresholds under Article 37 GDPR; our privacy team serves as the point of contact for data-protection matters at privacy@valguard.neteos.eu.

11. California and other U.S. state privacy rights (CCPA/CPRA and similar laws)

11.1 Categories collected. In the past 12 months we have collected the categories of personal information described in Section 3, which map to the CCPA categories: identifiers (name, email, IP address); customer records (billing details); commercial information (Plan and billing history); internet/network activity (usage and request metadata, cookies); and, only where a Customer enables payload logging, the content categories reflected in that Customer's own Prompts/Outputs.

11.2 No sale or sharing. We do not sell personal information for monetary or other valuable consideration and do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.

11.3 Your rights. California residents (and residents of other states with comparable laws) may request to know/access the specific pieces and categories of personal information we hold, delete personal information (subject to legal exceptions), correct inaccurate personal information, and limit the use of sensitive personal information. We will not discriminate against you for exercising these rights. You may designate an authorized agent to submit a request on your behalf; we may require proof of the agent's authority and verification of your identity.

11.4 How to exercise your rights. Submit a request to privacy@valguard.neteos.eu or through the Do Not Sell or Share page. We will verify your request using information reasonably available to us (typically matching the email address on your account) before responding.

12. Do Not Sell or Share

Because ValGuard does not sell or share personal information as described in Section 11.2, no opt-out is generally required. If a jurisdiction nonetheless grants you a "Do Not Sell or Share" right, you may still submit a request by emailing privacy@valguard.neteos.eu with the subject line "Do Not Sell Request", and we will honor any applicable opt-out going forward.

13. Children's privacy

The Service is intended for business use and is not directed to individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@valguard.neteos.eu and we will delete it.

14. Automated processing and Guardrail decisions

Guardrail/validator pass-fail-reask decisions are automated checks that Customers configure and control to validate their own Prompts and Outputs; they do not, by themselves, produce legal or similarly significant effects concerning individuals within the meaning of GDPR Article 22, and ValGuard does not use them to make such decisions about Customers or End Users. Customers deploying the Service in contexts involving automated decision-making about their own end users remain responsible for their own compliance obligations, including any human-review safeguards required by law.

15. Intellectual property in data you provide

As between the parties, Customers retain all right, title, and interest in their Prompts, Outputs, Customer Data, and Playbooks; ValGuard does not claim ownership over them and uses them only as needed to provide, secure, and support the Service, or as this Policy and the DPA otherwise describe. ValGuard and its licensors retain all right, title, and interest in the Service itself, including the validation proxy, dashboard, and configuration engine, as further described in the Terms of Service.

16. No warranty regarding detection of personal data

The Service is provided "as is" and "as available." While Guardrails can be configured to detect and mask common categories of personal or sensitive data, ValGuard does not warrant that any Guardrail will identify every instance of personal data, and Customer remains responsible for configuring Guardrails, log levels, and retention settings appropriate to the personal data it processes, and for its own compliance obligations toward its End Users, including with respect to agentic loops or misconfiguration that could unintentionally expose or over-retain data.

17. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, VALGUARD'S TOTAL, AGGREGATE LIABILITY TO A CUSTOMER ARISING OUT OF OR RELATED TO THIS PRIVACY POLICY OR OUR PROCESSING OF PERSONAL DATA — INCLUDING FOR ANY CLAIM RELATING TO A SECURITY INCIDENT — WILL NOT EXCEED THE TOTAL FEES ACTUALLY PAID BY THAT CUSTOMER TO VALGUARD IN THE SIX (6) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, CONSISTENT WITH SECTION 11 (LIMITATION OF LIABILITY) OF THE TERMS OF SERVICE, WHICH GOVERNS AND IS NOT EXPANDED BY THIS POLICY. NOTHING IN THIS SECTION LIMITS ANY LIABILITY THAT CANNOT LAWFULLY BE LIMITED UNDER MANDATORY PROVISIONS OF APPLICABLE DATA PROTECTION LAW, INCLUDING A DATA SUBJECT'S STATUTORY RIGHT TO COMPENSATION UNDER GDPR ARTICLE 82.

18. Governing law

This Privacy Policy is governed by the laws of the Republic of Poland and, as applicable, European Union law, consistent with Section 15 (Governing Law and Dispute Resolution) of the Terms of Service, without prejudice to any mandatory data-protection rights you have under the law of your habitual residence.

19. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in the Service, legal requirements, or our data practices. We will post the updated Policy here with a revised "Last updated" date and, for material changes, provide additional notice (such as email or an in-dashboard notice) at least thirty (30) days before the change takes effect where required by law or where the change materially reduces your rights.

20. Contact us

Questions about this Privacy Policy or your personal data can be sent to: