Last updated: March 25, 2026
VeriPrompt ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our AI Gateway & Agentic Platform ("Service").
The data controller responsible for your personal data is VeriPrompt, operated by Axel Weber. Contact details are available on our Impressum page.
Data Protection Officer: Axel Weber has been appointed as Data Protection Officer, contactable at data.protection@veriprompt.tech.
We collect the following categories of personal data:
We use your personal data to:
VeriPrompt includes a built-in PII sanitization module that can detect and tokenize personally identifiable information before sending prompts to AI providers. Email addresses are stored using one-way hashing for lookup while personal names are encrypted at rest using AES-256. Companies can configure data protection policies per project, team, or user.
We share data with third parties only as necessary to provide the Service:
The complete, current list of sub-processors — including purpose, location and DPA status for each — is published at /legal/subprocessors. We notify you before a new one takes effect.
We do not sell your personal data to third parties.
We retain your personal data for as long as your account is active or as needed to provide the Service. Usage logs are retained for analytics purposes and are automatically purged after the retention period configured by your company administrator. You may request deletion of your account and associated data at any time.
Under the General Data Protection Regulation (GDPR), you have the following rights:
To exercise these rights, contact us through the information on our Impressum page.
We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising cookies. Analytics data is collected server-side without client-side tracking scripts.
We implement industry-standard security measures including encrypted data transmission (TLS/SSL), encrypted data at rest (AES-256), role-based access controls, and regular security audits. However, no method of transmission over the Internet is 100% secure.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date.
For questions about this Privacy Policy or to exercise your data protection rights, please contact us through the information provided on our Impressum page.