1. Who is the controller?
For personal data we collect about you as the operator of a Promethean workspace (your name, email, billing details, workspace activity), the controller is Promethean B.V. [TBD], [TBD street, postcode, city], Netherlands, KvK [TBD KvK].
For personal data that flows through your Promethean-built product to be processed by an LLM and recorded as a hash in the L12 chain, you are the controller and we are a processor acting on your instructions. That relationship is governed by our Data Processing Agreement.
2. What we collect
We collect three categories of personal data:
- Account data. Your email address, workspace display name, and the SHA-256 hash of your API keys. We do not store raw API keys.
- Billing data. Your company name, billing address, VAT identification number, and payment-method metadata. Payment-method details (card numbers, IBAN) are handled by Stripe and are never stored on our servers.
- Workspace activity. The events your workspace generates: spec creation, key rotation, tier changes, ingested receipt metadata (entry hashes, timestamps, schemaValid flags, reviewer verdicts, fallback flags, model identity). This activity is metadata only — raw LLM inputs and outputs are never written to the L12 chain.
We do not collect or process special categories of personal data (Art. 9 GDPR) as part of operating your account.
2.5 Children's data
The Service is a B2B accountability substrate and is not directed at children. We do not knowingly collect or process personal data of individuals under the age of 18 in connection with operating an account. Downstream data subjects of the operator's AI processing may include children depending on the operator's deployment context (e.g., paediatric clinical decisioning, education-tech, child-protection workflows); responsibility for the lawful basis to process such data, including any obligations under GDPR Art. 8 (conditions applicable to a child's consent) and any national age-of-consent variations, rests with the operator as Controller.
3. Why we collect it (legal basis)
- Contractual necessity (Art. 6(1)(b) GDPR). Account data and workspace activity, to provide the Service you signed up for.
- Legal obligation (Art. 6(1)(c) GDPR). Billing data, to comply with our tax and accounting obligations under Dutch and EU law.
- Legitimate interests (Art. 6(1)(f) GDPR). Security telemetry (failed-login counters, key-rotation alerts) to keep your account safe; aggregated usage statistics to improve the Service. You can object to these uses at any time by emailing privacy@promethean.software.
4. PII-safe by construction
The L12 chain — the central artefact of the Service — never contains raw inputs or outputs of the LLM calls you make through your Promethean-built product. The SDK computes a SHA-256 hash of the input before any network call to our servers; only the hash is recorded. This means personal data you process through your AI feature does not enter our infrastructure.
Whether the upstream model provider (Anthropic, OpenAI, Azure, etc.) sees raw inputs is governed by your direct contract with that provider. We do not proxy LLM calls.
5. Where the data lives
Account data, billing data, and workspace activity are stored on infrastructure provided by Vercel Inc. (frontend hosting) and Upstash Inc. (Redis storage). The primary processing region is the European Union (Frankfurt). We do not transfer your data outside the EU/EEA except as described below.
Stripe (payment processing) and Resend (transactional email) process limited data on our behalf. Both rely on EU Standard Contractual Clauses for any transfer of personal data to the United States. Full sub-processor list is published at /legal/dpa.
6. How long we keep it
- Account data: for the lifetime of your workspace plus 90 days after termination, to allow export of your chain and audit bundle.
- Billing data: seven (7) years, as required by Dutch tax law (Algemene wet inzake rijksbelastingen, Art. 52(4)).
- Workspace activity (L12 chain): for the lifetime of your workspace plus 90 days, unless you have configured a different retention policy in workspace settings. The chain itself is append-only and cannot be partially edited; full deletion is the only modification supported.
- Security logs: 90 days.
7. Your rights
Under the GDPR, you have the right to (a) access the personal data we hold about you, (b) ask us to correct inaccurate data, (c) ask us to erase your data (subject to legal-retention obligations), (d) object to or restrict processing, (e) data portability, and (f) withdraw consent at any time where processing relies on consent.
Exercise any of these rights by emailing privacy@promethean.software. We respond within 30 days; for complex requests we may extend by an additional 60 days in accordance with Art. 12(3) GDPR.
You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens or with the supervisory authority of the EU member state where you reside.
Data Protection Officer. Promethean's processing does not statutorily require designating a Data Protection Officer under GDPR Art. 37: we are not a public authority or body, our core activities do not consist of processing operations that require regular and systematic monitoring of data subjects on a large scale, and we do not process special categories of personal data or data relating to criminal convictions and offences on a large scale. Privacy enquiries are handled by privacy@promethean.software. We will re-assess this position if our processing scale or nature changes.
7.5 California residents — CCPA / CPRA rights
If you are a California resident, the California Consumer Privacy Act of 2018 (as amended by the California Privacy Rights Act of 2020), Cal. Civ. Code §§ 1798.100 et seq. ("CCPA/CPRA"), grants you the rights set out below in respect of personal information ("PI") that Promethean processes about you in your capacity as an operator or workspace user. Capitalised terms used in this section have the meaning given in the CCPA/CPRA.
Categories of PI we collect. Identifiers (email, workspace display name, hashed API key), commercial information (subscription tier, billing transactions, VAT identifiers), internet or other electronic network activity information (request logs, security telemetry), and professional or employment-related information limited to the operator's company role. We collect this PI directly from you, from your authenticated workspace activity, and from our payment processor (Stripe). We use it to provide the Service, to bill, to secure the account, and to comply with legal obligations.
Sensitive PI. We do not knowingly collect or process Sensitive Personal Information as defined at Cal. Civ. Code § 1798.140(ae) (e.g., government identifiers, precise geolocation, racial or ethnic origin, religious beliefs, union membership, contents of mail/email/text messages, genetic data, biometric identifiers, health data, sex life or sexual orientation data). Accordingly, the § 1798.121 right to limit use and disclosure of Sensitive PI does not arise in practice.
No sale or sharing. Promethean does not sell personal information and does not share personal information for cross-context behavioural advertising within the meaning of Cal. Civ. Code §§ 1798.140(ad) and 1798.140(ah). We have not sold or shared PI in the preceding twelve (12) months and have no plans to do so.
Your CCPA/CPRA rights are:
- Right to know (§ 1798.110, § 1798.115) — the categories and specific pieces of PI we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties to whom we disclose PI.
- Right to delete (§ 1798.105) — request deletion of PI we hold about you, subject to the statutory exceptions (e.g., completing a transaction, security, legal compliance, internal use reasonably aligned with the consumer's expectations).
- Right to correct (§ 1798.106) — request correction of inaccurate PI we hold about you.
- Right to opt out of sale or sharing (§ 1798.120) — as stated above, we do not sell or share PI, so this right has no operative effect; we honour any opt-out signal (including Global Privacy Control) we receive.
- Right to limit use of Sensitive PI (§ 1798.121) — as stated above, we do not process Sensitive PI and therefore do not use it for purposes that would trigger the limit-use right.
- Right to non-discrimination (§ 1798.125) — we will not deny the Service, charge a different price, or provide a different quality of service because you exercised a CCPA/CPRA right.
How to submit a request — including a "Do Not Sell or Share My Personal Information" request. Because we do not sell or share PI, no separate "Do Not Sell or Share" webform is provided; CCPA/CPRA requests of any kind may be submitted by emailing privacy@promethean.software from the email address associated with your workspace, or by post to the registered address in Section 11. We will verify your identity using the workspace email-of-record and may request additional information proportionate to the sensitivity of the request. We respond within forty-five (45) days, extendable once by a further forty-five days where reasonably necessary.
Authorised agents. You may designate an authorised agent to submit a request on your behalf under Cal. Civ. Code § 1798.135(c) and 11 CCR § 7063. We will require (i) written authorisation signed by you, (ii) verification of your identity directly with us, and (iii) confirmation that the agent has authority to act for you. An agent registered with the California Secretary of State and acting under a valid power of attorney (Cal. Prob. Code §§ 4000 et seq.) need only satisfy the standard agent-verification requirements.
8. Cookies
We set strictly-necessary cookies for session authentication (the prom_ws_session cookie) and consent storage. We do not use third-party advertising or analytics cookies. Details and management are in the Cookie Policy.
9. Security
API keys are stored as SHA-256 hashes only. Session cookies are HTTP-only and Secure-flagged. All data in transit uses TLS 1.2+. Workspace data is encrypted at rest by the underlying Upstash Redis service. If we become aware of a confirmed personal data breach likely to result in a risk to your rights, we will notify you without undue delay and, where you are a Controller under a Data Processing Agreement with us, within forty-eight (48) hours of our becoming aware of the breach, consistent with Art. 34 GDPR. Report a suspected breach to security@promethean.software.
10. Changes
We may update this Privacy Policy from time to time. Material changes will be announced by email at least 30 days before they take effect.
11. Contact
Privacy questions: privacy@promethean.software. Postal: Promethean B.V. [TBD], [TBD street, postcode, city], Netherlands.