Who We Are and How to Reach Us
PromptHalo Technologies (“PromptHalo”, “we”, “us”) provides AI security testing and runtime protection to business customers. Reach us at security@prompthalo.ai. We have not appointed a Data Protection Officer, the formal privacy role some organizations must designate under European privacy law. Our Security Officer is accountable for privacy alongside security.
Where we operate. We are established in the United States and support customers globally, including in the European Economic Area (EEA) and the United Kingdom. Many carry obligations of their own under the General Data Protection Regulation (GDPR), the EU and UK privacy law; the Health Insurance Portability and Accountability Act (HIPAA), the US law covering health information; US state privacy laws; or comparable regimes.
We support those obligations rather than asking the customer to work around them, and we sign what each requires: a data processing agreement carrying the processor terms GDPR Article 28 sets out; the Standard Contractual Clauses, the transfer contract the European Commission approves, with the UK International Data Transfer Addendum; and a business associate agreement, the contract HIPAA requires, where protected health information is involved.
We keep our own position under the EU and UK GDPR under review at least annually. Where either applies to data we hold as controller, we comply with it and appoint a representative in the EEA or the UK, which GDPR Article 27 requires in some cases, if one is needed. Independently of that, we extend the rights in this Notice to everyone who asks, wherever they live. If you are in the UK or the EEA and are not satisfied with our response, you may complain to your local supervisory authority.
What This Notice Covers
| Our role | For what | Who to contact |
|---|---|---|
| Controller | Website visitors, people who contact us, marketing contacts, customer contacts, our security event records | PromptHalo. This Notice applies |
| Processor service provider under US state law | Everything our services process for a customer: test targets and results, runtime traffic, prompts and responses, traces, findings, derived information | The customer. Their notice applies |
| Business associate under HIPAA | Protected health information present in what our services process for a covered entity | The customer, under the business associate agreement |
This Notice does not cover our own personnel, or third-party sites we link to.
What Our Services See
| Service | What it processes | Controller |
|---|---|---|
| Website | Server-side request records. No analytics tooling. | PromptHalo |
| AI red teaming | The target a customer nominates, the prompts and payloads we send it, and the responses returned. A response can surface personal data the target holds. Findings and evidence. | The customer |
| Runtime protection | Prompts, responses, and tool and Model Context Protocol (MCP) calls passing between a customer application and its model providers, inspected in line. Can include content typed by the customer end users. | The customer |
| Derived information | Classifications, risk scores, evaluation results, embeddings and traces generated from the above. | The customer |
| Operational records | Logs, timestamps, model identifiers, token usage, IP and device data, security events. | PromptHalo |
We do not choose what a customer sends through our services and we do not decide what it is used for. Because testing can surface personal data nobody intended to include, our procedures require us to contain and minimize it rather than retain it, and to notify the customer without undue delay.
What We Collect and Why
As controller we collect the following. Where we rely on legitimate interests, we have weighed them against your rights and you can object at any time.
| What | Why | Legal basis |
|---|---|---|
| Server-side request records: pages, time, IP, browser, device | Keeping the site working and secure | Legitimate interests in security and availability |
| Your name, business email, company, role, and what you write to us | Answering you, arranging meetings, keeping a record | Legitimate interests, and pre-contract steps at your request |
| Business contact details from public sources or introductions | Relevant business contact | Legitimate interests, with an unsubscribe link |
| Contact details and records for individuals at customers | Delivering services, invoicing, record-keeping | Contract, and legal obligation for financial records |
| Security event records, which may include IP addresses | Detecting and responding to security incidents | Legitimate interests, and legal obligation if notifiable |
We do not ask you for special category data and ask that you do not send it. Health information reaching us through a customer service is covered in Health Information and HIPAA.
Cookies and Similar Technologies
We use cookies to run our site and platform, not to advertise. We do not use them to build advertising profiles or to track you across other sites, and we honor Global Privacy Control signals, the browser setting that communicates an opt-out. Blocking them stops you signing in, though public pages remain readable. Our Cookie Policy sets out the categories in use and how to control them.
Who We Share It With
We do not sell personal data and do not share it for cross-context behavioral advertising. We share it only with providers who process it on our instructions, each under written contract:
| Recipient | What they do for us |
|---|---|
| Cloud infrastructure and hosting | Runs our website and services |
| Model and AI service providers | Process prompts and responses where a service requires it |
| Email, collaboration and file storage | Handles correspondence and documents |
| Payment and accounting | Processes invoices and keeps financial records |
| Professional advisers | Legal, insurance and audit services |
A current list of the providers used to deliver customer services is available on request, and customers get notice before a new one starts. We may also disclose where the law requires it, to establish or defend legal claims, or in a sale of the business, in which case we tell affected customers first.
Where Your Data Goes
We operate from the United States and use providers there and in the EEA, so data may be transferred outside the UK or EEA. Where a transfer needs a safeguard we rely on the Standard Contractual Clauses with the UK Addendum, or on an adequacy decision. You can ask which mechanism applies to a specific transfer.
How Long We Keep It
| What | How long |
|---|---|
| Server-side request records | Up to thirteen months, then deleted or aggregated |
| Enquiries that do not become a relationship | Up to twenty-four months from last contact |
| Marketing contact details | Until you unsubscribe, then a minimal suppression record so we do not contact you again |
| Customer contacts and engagement records | The engagement plus six years, for contractual, tax and professional obligations |
| Security event records | Thirteen months, unless an investigation requires longer |
| Customer content, derived information and traces | The term of the engagement, and no longer than the customer agreement allows. Returned or deleted at the customer choice on termination |
When a period ends we delete or irreversibly anonymize the data. Backups are overwritten on their own cycle, so a deleted record may persist briefly in a backup. We do not restore it to active use.
AI, Model Data and Derived Information
We do not use customer content to train or fine-tune general-purpose models, ours or a provider’s, unless the customer agrees in writing.
Where we use a commercial AI service to deliver a service, we use terms that exclude submissions from provider training, and we verify the setting that enforces them.
Prompts, responses, tool calls, traces and logs can contain personal data. We treat them as personal data.
Our systems produce information we derive rather than collect, including classifications, scores and embeddings. Where it can still be linked to a person, we treat it as personal data with the same rights.
We may derive security threat intelligence from what our services process, limited to detecting incidents and protecting against malicious activity, and only after removing customer-identifying information and personal data. Protected health information is excluded entirely.
We do not make decisions about you by automated means alone that produce legal or similarly significant effects.
When We Act for a Customer
Most of what our services process belongs to customers and may include personal data about their staff, their customers, or the end users of their applications. Our data processing agreement commits us to the following, matching GDPR Article 28:
Process only on the customer’s documented instructions, and flag an instruction that appears unlawful.
Bind our personnel to confidentiality and apply security measures appropriate to the risk.
Engage sub-processors only under written terms no less protective, keep a current list, and give notice before a new one starts.
Assist with individual rights requests, breach notification and impact assessments, and notify the customer of a breach affecting their data without undue delay.
Return or delete the data at the customer’s choice at the end of the engagement, including derived information and cached representations, with written confirmation.
Make available the information needed to demonstrate compliance and support audits.
If your personal data is processed by us on a customer’s behalf, contact that organization; they are the controller. If you contact us instead, we pass your request to them promptly and tell you we have done so.
Health Information and HIPAA
We are not a covered entity. Where a customer is a covered entity or business associate and protected health information may be present in what our services process, we act as a business associate and sign a business associate agreement before that processing begins. Without one, our terms require the customer not to route protected health information through our services. Under that agreement we commit to:
Use and disclose protected health information only as the agreement and law permit, never for our own purposes.
Apply the safeguards required by the HIPAA Security Rule, and limit use and disclosure to the minimum necessary.
Bind subcontractors to the same restrictions.
Report security incidents and any breach of unsecured protected health information to the customer without unreasonable delay.
Support the customer’s access, amendment and accounting obligations, and return or destroy the information at termination where feasible.
Exclude protected health information from model training and from threat intelligence.
Your Rights
Depending on where you live, you have some or all of these rights over personal data we hold as controller:
| Right | What it means |
|---|---|
| Access | Ask what we hold about you and get a copy |
| Correction | Ask us to correct data that is wrong or incomplete |
| Deletion | Ask us to delete data we no longer need |
| Restriction | Ask us to pause processing while a question is resolved |
| Portability | Ask for data you gave us in a machine-readable form |
| Objection | Object to processing based on legitimate interests |
| Opt out of marketing | Unsubscribe at any time |
| Withdraw consent | Withdraw any consent you have given us, at any time |
In California and other US states with comparable law, you also have the right to know, delete, correct, opt out of sale or sharing, which does not arise because we do neither, and not to be discriminated against for exercising a right.
To exercise a right, email security@prompthalo.ai. We acknowledge within a few working days and respond within the period the law allows, or tell you if we need longer. We may verify your identity first, and an authorized agent may act for you. If we refuse, we tell you why and how to appeal: reply to our response, or email us with the word appeal in the subject line. We review it and give you the outcome and our reasons, and where your state provides one we tell you how to contact the regulator.
How We Protect It
We encrypt personal data in transit and at rest, grant access on least privilege, require multi-factor authentication, log and review access, separate customer environments logically, and screen the people who work with us. Our program is aligned to the Security criteria of SOC 2, the audit standard for service organizations published by the AICPA; the Security Overview has the detail, and the statements we publish reflect assurance activities actually completed.
No system is perfectly secure. If a breach affects you and is likely to result in a high risk to your rights, we tell you without undue delay and notify the regulator where the law requires. Where we act as processor, we notify the customer without undue delay.
Children
Our website and services are for business use and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
Changes to This Notice
We update this Notice when what we do changes, and at least once a year. The date at the top shows when it was last updated. Where a change materially affects personal data we already hold, we tell affected people directly rather than relying on this page.
Reference
EU and UK General Data Protection Regulation (GDPR), in particular Articles 12 to 22, 28 and 46
California Consumer Privacy Act as amended by the California Privacy Rights Act (CPRA)
Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security and Breach Notification Rules, 45 CFR Parts 160 and 164
SOC 2 Trust Services Criteria, Security category, AICPA