Privacy Policy
How we handle your data — and why we see so little of it.
Dot-0, Dijk 25, 1721 AA Broek op Langedijk, Netherlands (KVK 34268249) is the data controller for personal data processed through Guarrix. Contact: hello@guarrix.com.
We process only the minimum data necessary to operate the service. For account holders: your email address, encrypted API keys, and billing-related metadata. For each API request: timestamps, token counts, detection outcome labels (e.g. “PII detected”, “injection attempt”), and your tenant identifier. We never store the content of prompts or LLM responses — they are processed in RAM and discarded after each request. No prompt text, personal names, addresses, or other values detected inside prompts are ever written to disk or retained.
Processing your email and account data is necessary to perform our contract with you (Article 6(1)(b) GDPR). Security and abuse-prevention logging is based on legitimate interest (Article 6(1)(f) GDPR). You may object to legitimate-interest processing at any time by emailing hello@guarrix.com. If you choose optional analytics cookies, that processing is based on your consent (Article 6(1)(a) GDPR), which you can withdraw at any time. Data is not used for any purpose other than delivering and billing the service.
Guarrix operates as an automated AI guardrail. It makes per-request decisions — blocking or passing prompts and responses — without human review. Under Article 22 GDPR, if you are a natural person whose data is processed as part of an API call routed through Guarrix, you have the right to request human review of any automated decision that produces legal or similarly significant effects. Contact hello@guarrix.com with the relevant request ID. In most integrations, Guarrix processes data on behalf of its tenants (businesses), not directly on behalf of end-users. We do not carry out profiling in the sense of Article 4(4) GDPR. If you are an end-user of a product built on Guarrix, direct your Art. 22 review requests to the operator of that product — Dot-0 cannot identify individual end-users from tenant traffic.
Audit log metadata (timestamps, detection labels, token counts, tenant ID) is retained for 90 days and then deleted automatically. Account data (email, encrypted API keys) is retained until you delete your account. Billing records are retained for 7 years as required by Dutch tax law. You can request account deletion at any time by emailing hello@guarrix.com. We will process your request within 30 days.
Under GDPR you have the right to: access your data (Art. 15), correct inaccurate data (Art. 16), request erasure (Art. 17), restrict processing (Art. 18), receive your data in a portable format (Art. 20), object to processing (Art. 21), and not be subject to automated decisions with significant effects without the option of human review (Art. 22). To exercise any right, email hello@guarrix.com. We respond within 30 days.
Hetzner Online GmbH (Germany, EU) provides server infrastructure. Paddle.com Market Limited (UK) provides payment processing. We do not transfer personal data outside the EU/EEA. Our sub-processor list is updated when changes are made and is available in full on request at hello@guarrix.com.
All data in transit is protected with TLS 1.3. Tenant LLM API keys are stored encrypted with AES-256-GCM; Dot-0 staff cannot access them in plaintext. Swap is disabled on all production servers so no RAM content can be paged to disk. Access to production infrastructure is restricted via TOTP-protected accounts and private networking. We follow responsible disclosure for security vulnerabilities.
Guarrix is a probabilistic system. It detects common patterns of PII, prompt injection, and policy violations but does not guarantee detection of all instances. False positives (blocking valid content) and false negatives (missing harmful content) do occur. Guarrix is not designed or validated for use in safety-critical contexts such as medical diagnosis, legal determinations, child safeguarding systems, or critical infrastructure. Tenants are responsible for determining whether Guarrix is appropriate for their specific use case and for testing its performance against their requirements.
For privacy questions, contact hello@guarrix.com. You have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl or by calling +31 (0)70 888 85 00. EU residents may also use the European Commission online dispute platform at ec.europa.eu/consumers/odr.