PromptHalo logo
PromptHaloTrust Center
← Trust Center Security overview
Published policy

Privacy Notice

How PromptHalo collects, uses, shares and protects personal data, and the rights available over it

Version 1.0Effective September 4, 2026Next review September 4, 2027Classification PublicDistribution PublicReview Annual, or upon material change
About this Notice. It tells you how PromptHalo handles personal information: what we collect and why, how we use it including through AI, who we share it with, how long we keep it, and what privacy rights you have.

Who We Are and How to Reach Us

PromptHalo Technologies (“PromptHalo”, “we”, “us”) provides AI security testing and runtime protection to business customers. Reach us at security@prompthalo.ai. We have not appointed a Data Protection Officer, the formal privacy role some organizations must designate under European privacy law. Our Security Officer is accountable for privacy alongside security.

Where we operate. We are established in the United States and support customers globally, including in the European Economic Area (EEA) and the United Kingdom. Many carry obligations of their own under the General Data Protection Regulation (GDPR), the EU and UK privacy law; the Health Insurance Portability and Accountability Act (HIPAA), the US law covering health information; US state privacy laws; or comparable regimes.

We support those obligations rather than asking the customer to work around them, and we sign what each requires: a data processing agreement carrying the processor terms GDPR Article 28 sets out; the Standard Contractual Clauses, the transfer contract the European Commission approves, with the UK International Data Transfer Addendum; and a business associate agreement, the contract HIPAA requires, where protected health information is involved.

We keep our own position under the EU and UK GDPR under review at least annually. Where either applies to data we hold as controller, we comply with it and appoint a representative in the EEA or the UK, which GDPR Article 27 requires in some cases, if one is needed. Independently of that, we extend the rights in this Notice to everyone who asks, wherever they live. If you are in the UK or the EEA and are not satisfied with our response, you may complain to your local supervisory authority.

What This Notice Covers

PromptHalo is both a controller and a processor. For a small set of personal data we decide why and how it is handled, so this Notice applies. For most of what our services process the customer decides, so their notice applies.
Which role PromptHalo holds for each kind of personal data
Our roleFor whatWho to contact
ControllerWebsite visitors, people who contact us, marketing contacts, customer contacts, our security event recordsPromptHalo. This Notice applies
Processor
service provider under US state law
Everything our services process for a customer: test targets and results, runtime traffic, prompts and responses, traces, findings, derived informationThe customer. Their notice applies
Business associate
under HIPAA
Protected health information present in what our services process for a covered entityThe customer, under the business associate agreement

This Notice does not cover our own personnel, or third-party sites we link to.

What Our Services See

What each service processes and who controls it
ServiceWhat it processesController
WebsiteServer-side request records. No analytics tooling.PromptHalo
AI red teamingThe target a customer nominates, the prompts and payloads we send it, and the responses returned. A response can surface personal data the target holds. Findings and evidence.The customer
Runtime protectionPrompts, responses, and tool and Model Context Protocol (MCP) calls passing between a customer application and its model providers, inspected in line. Can include content typed by the customer end users.The customer
Derived informationClassifications, risk scores, evaluation results, embeddings and traces generated from the above.The customer
Operational recordsLogs, timestamps, model identifiers, token usage, IP and device data, security events.PromptHalo

We do not choose what a customer sends through our services and we do not decide what it is used for. Because testing can surface personal data nobody intended to include, our procedures require us to contain and minimize it rather than retain it, and to notify the customer without undue delay.

What We Collect and Why

As controller we collect the following. Where we rely on legitimate interests, we have weighed them against your rights and you can object at any time.

Personal data PromptHalo collects as controller, why, and the legal basis
WhatWhyLegal basis
Server-side request records: pages, time, IP, browser, deviceKeeping the site working and secureLegitimate interests in security and availability
Your name, business email, company, role, and what you write to usAnswering you, arranging meetings, keeping a recordLegitimate interests, and pre-contract steps at your request
Business contact details from public sources or introductionsRelevant business contactLegitimate interests, with an unsubscribe link
Contact details and records for individuals at customersDelivering services, invoicing, record-keepingContract, and legal obligation for financial records
Security event records, which may include IP addressesDetecting and responding to security incidentsLegitimate interests, and legal obligation if notifiable

We do not ask you for special category data and ask that you do not send it. Health information reaching us through a customer service is covered in Health Information and HIPAA.

Cookies and Similar Technologies

We use cookies to run our site and platform, not to advertise. We do not use them to build advertising profiles or to track you across other sites, and we honor Global Privacy Control signals, the browser setting that communicates an opt-out. Blocking them stops you signing in, though public pages remain readable. Our Cookie Policy sets out the categories in use and how to control them.

Who We Share It With

We do not sell personal data and do not share it for cross-context behavioral advertising. We share it only with providers who process it on our instructions, each under written contract:

Categories of recipient
RecipientWhat they do for us
Cloud infrastructure and hostingRuns our website and services
Model and AI service providersProcess prompts and responses where a service requires it
Email, collaboration and file storageHandles correspondence and documents
Payment and accountingProcesses invoices and keeps financial records
Professional advisersLegal, insurance and audit services

A current list of the providers used to deliver customer services is available on request, and customers get notice before a new one starts. We may also disclose where the law requires it, to establish or defend legal claims, or in a sale of the business, in which case we tell affected customers first.

Where Your Data Goes

We operate from the United States and use providers there and in the EEA, so data may be transferred outside the UK or EEA. Where a transfer needs a safeguard we rely on the Standard Contractual Clauses with the UK Addendum, or on an adequacy decision. You can ask which mechanism applies to a specific transfer.

How Long We Keep It

Retention periods
WhatHow long
Server-side request recordsUp to thirteen months, then deleted or aggregated
Enquiries that do not become a relationshipUp to twenty-four months from last contact
Marketing contact detailsUntil you unsubscribe, then a minimal suppression record so we do not contact you again
Customer contacts and engagement recordsThe engagement plus six years, for contractual, tax and professional obligations
Security event recordsThirteen months, unless an investigation requires longer
Customer content, derived information and tracesThe term of the engagement, and no longer than the customer agreement allows. Returned or deleted at the customer choice on termination

When a period ends we delete or irreversibly anonymize the data. Backups are overwritten on their own cycle, so a deleted record may persist briefly in a backup. We do not restore it to active use.

AI, Model Data and Derived Information

  • We do not use customer content to train or fine-tune general-purpose models, ours or a provider’s, unless the customer agrees in writing.

  • Where we use a commercial AI service to deliver a service, we use terms that exclude submissions from provider training, and we verify the setting that enforces them.

  • Prompts, responses, tool calls, traces and logs can contain personal data. We treat them as personal data.

  • Our systems produce information we derive rather than collect, including classifications, scores and embeddings. Where it can still be linked to a person, we treat it as personal data with the same rights.

  • We may derive security threat intelligence from what our services process, limited to detecting incidents and protecting against malicious activity, and only after removing customer-identifying information and personal data. Protected health information is excluded entirely.

  • We do not make decisions about you by automated means alone that produce legal or similarly significant effects.

When We Act for a Customer

Most of what our services process belongs to customers and may include personal data about their staff, their customers, or the end users of their applications. Our data processing agreement commits us to the following, matching GDPR Article 28:

  • Process only on the customer’s documented instructions, and flag an instruction that appears unlawful.

  • Bind our personnel to confidentiality and apply security measures appropriate to the risk.

  • Engage sub-processors only under written terms no less protective, keep a current list, and give notice before a new one starts.

  • Assist with individual rights requests, breach notification and impact assessments, and notify the customer of a breach affecting their data without undue delay.

  • Return or delete the data at the customer’s choice at the end of the engagement, including derived information and cached representations, with written confirmation.

  • Make available the information needed to demonstrate compliance and support audits.

If your personal data is processed by us on a customer’s behalf, contact that organization; they are the controller. If you contact us instead, we pass your request to them promptly and tell you we have done so.

Health Information and HIPAA

We are not a covered entity. Where a customer is a covered entity or business associate and protected health information may be present in what our services process, we act as a business associate and sign a business associate agreement before that processing begins. Without one, our terms require the customer not to route protected health information through our services. Under that agreement we commit to:

  • Use and disclose protected health information only as the agreement and law permit, never for our own purposes.

  • Apply the safeguards required by the HIPAA Security Rule, and limit use and disclosure to the minimum necessary.

  • Bind subcontractors to the same restrictions.

  • Report security incidents and any breach of unsecured protected health information to the customer without unreasonable delay.

  • Support the customer’s access, amendment and accounting obligations, and return or destroy the information at termination where feasible.

  • Exclude protected health information from model training and from threat intelligence.

Your Rights

Depending on where you live, you have some or all of these rights over personal data we hold as controller:

Rights available over personal data PromptHalo holds as controller
RightWhat it means
AccessAsk what we hold about you and get a copy
CorrectionAsk us to correct data that is wrong or incomplete
DeletionAsk us to delete data we no longer need
RestrictionAsk us to pause processing while a question is resolved
PortabilityAsk for data you gave us in a machine-readable form
ObjectionObject to processing based on legitimate interests
Opt out of marketingUnsubscribe at any time
Withdraw consentWithdraw any consent you have given us, at any time

In California and other US states with comparable law, you also have the right to know, delete, correct, opt out of sale or sharing, which does not arise because we do neither, and not to be discriminated against for exercising a right.

To exercise a right, email security@prompthalo.ai. We acknowledge within a few working days and respond within the period the law allows, or tell you if we need longer. We may verify your identity first, and an authorized agent may act for you. If we refuse, we tell you why and how to appeal: reply to our response, or email us with the word appeal in the subject line. We review it and give you the outcome and our reasons, and where your state provides one we tell you how to contact the regulator.

How We Protect It

We encrypt personal data in transit and at rest, grant access on least privilege, require multi-factor authentication, log and review access, separate customer environments logically, and screen the people who work with us. Our program is aligned to the Security criteria of SOC 2, the audit standard for service organizations published by the AICPA; the Security Overview has the detail, and the statements we publish reflect assurance activities actually completed.

No system is perfectly secure. If a breach affects you and is likely to result in a high risk to your rights, we tell you without undue delay and notify the regulator where the law requires. Where we act as processor, we notify the customer without undue delay.

Children

Our website and services are for business use and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

Changes to This Notice

We update this Notice when what we do changes, and at least once a year. The date at the top shows when it was last updated. Where a change materially affects personal data we already hold, we tell affected people directly rather than relying on this page.

Reference

  • Security Overview and Cookie Policy

  • EU and UK General Data Protection Regulation (GDPR), in particular Articles 12 to 22, 28 and 46

  • California Consumer Privacy Act as amended by the California Privacy Rights Act (CPRA)

  • Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security and Breach Notification Rules, 45 CFR Parts 160 and 164

  • SOC 2 Trust Services Criteria, Security category, AICPA