🇪🇺 GDPR Compliant ยท EU AI Act Aligned

Privacy Policy

Last updated: March 2025 ยท Next review: June 2025 ยท Version 1.0
๐Ÿ‡ช๐Ÿ‡บ
EU Data Protection Commitment
PromptWall is built and operated by NullVector Ltd, registered in Cork, Ireland. We are subject to the General Data Protection Regulation (GDPR) and the EU AI Act. Your data is processed lawfully, fairly, and transparently. We do not sell your data. We do not share it with advertisers. We collect only what we need to provide the service.

01 Who We Are

PromptWall is an AI agent security platform operated by NullVector Ltd, Cork, Ireland. We provide AI-powered security scanning, red team testing, and permission auditing for AI agents.

For data protection purposes, NullVector Ltd is the Data Controller. Contact us at: [email protected]

02 What Data We Collect

Data TypeWhat It IsWhy We Collect ItLegal Basis
Email addressYour email when you sign up or join the waitlistAccount creation, product updates, security alertsContract performance / Legitimate interest
Name & companyOptional fields on signupPersonalisation of your dashboardConsent
Scan contentAgent system prompts you submit for scanningPerforming the security analysis you requestedContract performance
Scan resultsVulnerability findings generated by PromptWallDisplaying results in your dashboardContract performance
Usage dataNumber of scans run, features used, timestampsProduct improvement, plan enforcementLegitimate interest
Technical dataBrowser type, IP address, device typeSecurity monitoring, fraud preventionLegitimate interest
Important: We do not store the full content of your AI agent system prompts beyond the duration of your scan session unless you explicitly save them to your account. Scan results are stored in your browser's local storage by default.

03 What We Do NOT Collect

04 How We Use Your Data

We use your data solely to provide and improve the PromptWall service:

05 EU AI Act Compliance

PromptWall uses AI to analyse AI agent system prompts and identify security vulnerabilities. Under the EU AI Act, our system is classified as a limited risk AI system. We comply with all applicable transparency, documentation, and human oversight requirements.

Specifically under the EU AI Act we:

06 Data Sharing

We share your data only in the following limited circumstances:

RecipientPurposeLocation
AnthropicAI analysis processing (your scan content is sent to the Claude API)United States โ€” Standard Contractual Clauses apply
NetlifyWebsite hosting and deliveryEU region selected
RailwayBackend server hostingEU region selected
Legal authoritiesIf required by law or court orderIreland / EU
Note on Anthropic: When you run a scan, your agent's system prompt is sent to Anthropic's Claude API for analysis. This transfer is covered by Standard Contractual Clauses. Anthropic's privacy policy applies to this processing. We recommend you do not submit system prompts containing personal data of third parties.

07 Data Retention

We retain your data for the following periods:

08 Your Rights Under GDPR

As an EU resident you have the following rights regarding your personal data:

Right of Access
Request a copy of all personal data we hold about you at any time.
Right to Rectification
Correct any inaccurate or incomplete personal data we hold.
Right to Erasure
Request deletion of your personal data โ€” "right to be forgotten."
Right to Portability
Receive your data in a machine-readable format to transfer elsewhere.
Right to Object
Object to processing based on legitimate interests at any time.
Right to Restrict
Request we limit how we process your data in certain circumstances.

To exercise any of these rights email us at [email protected] with the subject line "GDPR Request". We will respond within 30 days.

You also have the right to lodge a complaint with the Data Protection Commission Ireland at dataprotection.ie if you believe we have handled your data improperly.

09 Cookies

We use only essential cookies required to operate the service:

We do not use advertising cookies, tracking pixels, or third-party analytics that share data with advertisers. We use privacy-focused analytics only.

10 Security

We take the security of your data seriously โ€” it is literally our business. We implement:

11 Changes To This Policy

We may update this Privacy Policy from time to time. When we make significant changes we will notify you by email and update the "Last updated" date at the top of this page. Continued use of PromptWall after changes constitutes acceptance of the updated policy.

Questions about your privacy?
Contact our Data Protection team โ€” we aim to respond within 48 hours.
Contact Us