Privacy Policy & Consent Notice
Last updated: May 2025 · Effective: May 2025
1. Who We Are
SafePrompt is operated by SG2 Technologies ("we", "our", "us"). We provide an AI Data Loss Prevention (DLP) service that protects organisations from data leaks through AI tools such as ChatGPT, Claude, Gemini, and Copilot.
Contact: sales@safeprompt.pro
2. Data We Collect
| Category | Data | Legal Basis | Retention |
|---|---|---|---|
| Account | Name, email, company name | Contract performance | Duration of account |
| Authentication | Password hash (Argon2), Firebase UID | Contract performance | Duration of account |
| DLP Scan Logs | Redacted text snippet, category, action, confidence | Legitimate interest (security) | 7–90 days (plan-dependent) |
| Usage Analytics | Page views, feature usage (anonymised) | Consent | 12 months |
| Technical | IP address, browser type, timestamps | Legitimate interest | 30 days |
Important: SafePrompt does NOT store the original sensitive content that triggers a DLP scan. Only a redacted snippet (with PII replaced by [REDACTED_TYPE] placeholders) is retained for audit purposes.
3. How We Use Your Data
- Providing and operating the SafePrompt DLP service
- Authenticating your access and maintaining session security
- Generating compliance audit logs for your organisation
- Detecting and preventing abuse of the service
- Sending transactional emails (account creation, security alerts)
- With your consent: product updates and security tip newsletters
4. Cookie Policy
| Type | Purpose | Required | Duration |
|---|---|---|---|
| Necessary | Authentication token, CSRF protection, session state | Yes | Session / 30 days |
| Analytics | Anonymous usage statistics (page views, feature adoption) | No | 12 months |
| Marketing | Conversion tracking, referral attribution | No | 90 days |
| Personalisation | Dashboard layout preferences, theme settings | No | 12 months |
You can manage cookie preferences at any time using the cookie banner or by clearing your browser's local storage.
5. Data Sharing
We share data with the following third parties:
- Google Firebase — Authentication service (Firebase Auth). Firebase Privacy
- MongoDB Atlas — Database hosting for audit logs and policies (EU region available)
- Upstream LLM Providers — When you use the API gateway, sanitised (redacted) prompts are forwarded to OpenAI/Anthropic/Google per your request
We do not sell your personal data to third parties.
6. Your Rights (GDPR)
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your account and data
- Portability: Export your audit logs in CSV format
- Objection: Object to processing based on legitimate interest
- Withdraw Consent: Unsubscribe from marketing emails at any time
To exercise any right, email sales@safeprompt.pro. We respond within 30 days.
7. Data Security
We implement industry-standard security measures including:
- Argon2id password hashing (not bcrypt) for maximum resistance to GPU attacks
- TLS 1.3 in transit, AES-256 at rest
- JWT tokens with short expiry (configurable)
- SHA-256 prompt hashing for zero-knowledge audit logs
- Role-based access control with tenant isolation
8. Children's Privacy
SafePrompt is a B2B enterprise service and is not intended for use by individuals under 16 years of age. We do not knowingly collect data from minors.
9. Changes to This Policy
We may update this policy periodically. Material changes will be communicated via email or a prominent notice in the dashboard. Continued use after the effective date constitutes acceptance.
Questions about this policy? We're happy to help.
Contact Privacy Team →