Our commitment to EU data protection standards
The General Data Protection Regulation (GDPR) sets the standard for data privacy in the European Union. AgentAIShield is committed to full compliance with GDPR requirements. This page describes how we implement those requirements in practice — as both a data controller for our own customers and a data processor when handling data on behalf of our customers' end users.
If you are accessing AgentAIShield from the EU, EEA, or Switzerland, all provisions of this page apply to you in full. You may exercise your rights at any time by contacting [email protected] or our DPO at [email protected].
For the purposes of GDPR, the data controller responsible for your personal data is:
When you use AgentAIShield to monitor your own AI agents, you are the data controller for your end users' data, and AgentAIShield acts as your data processor. Our Data Processing Agreement governs that relationship.
We process personal data only when we have a lawful basis under GDPR Article 6. The basis depends on the type of processing:
Processing necessary to deliver the Service you've signed up for, including:
Processing necessary for our legitimate interests, which don't override your rights, including:
Processing based on your explicit, freely given consent, including:
We process the minimum data necessary to deliver the Service. Here is exactly what we collect and why:
When your AI agents route requests through AgentAIShield, we log metadata only by default — not raw prompts or completions. Metadata includes: timestamp, model provider, model name, API key ID, latency, token counts (prompt/completion), HTTP status code, and request ID. Raw content is processed in-memory for inspection and immediately discarded unless you opt in to full logging.
Our PII detection engine identifies sensitive data in request/response content. We store the result of that detection — entity types found (e.g., "email address," "phone number"), confidence scores, and actions taken (allowed/redacted/blocked) — not the PII values themselves. Your users' actual PII never persists in our systems under the default configuration.
Agent Trust Scores™ are computed from aggregated behavioral signals per API key: PII leak rates, injection attempt rates, response consistency, and data handling patterns. These scores are associated with your API keys and organization — not with any individual end user.
We may collect anonymized dashboard usage data (pages visited, features used, session duration) to improve the product. This data is not linked to your request traffic or monitoring data, and is processed under legitimate interests.
Name, email address, hashed password, organization name, team member names and emails, billing contact information (Stripe customer ID; no full card numbers), and communication preferences.
Under GDPR, you have the following rights regarding your personal data. We respond to all requests within 30 days (or 72 hours for breach notifications). Complex requests may be extended by up to 60 additional days with notification.
Request a full copy of all personal data we hold about you. Available via Settings → Data Export in the dashboard, or email us at [email protected].
Correct inaccurate or incomplete personal data. Update your name, email, and org details directly in Settings → Profile, or contact us to correct any other data.
Request deletion of your personal data ("right to be forgotten"). Delete your account via Settings → Account → Delete Account, or email us. Processing completes within 30 days.
Receive your data in a structured, machine-readable format (JSON or CSV). Available via Settings → Data Export on all paid plans, or request via email.
Request that we restrict processing of your data (e.g., while contesting accuracy or pending an objection). Email us with the specific restriction requested.
Object to processing based on legitimate interests (e.g., analytics). Email us at [email protected] with "GDPR Objection" in the subject line. We will stop unless we have compelling legitimate grounds.
Email [email protected] or [email protected] with subject "GDPR Rights Request — [Right Type]." We will verify your identity (typically by confirming from your registered email) and respond within 30 days. Requests are free of charge.
When you use AgentAIShield to process data on behalf of your own users or customers, you are the data controller and we are your data processor under GDPR Article 28. A Data Processing Agreement (DPA) is required for this relationship.
We keep our sub-processor list minimal to reduce data exposure risk. Current sub-processors who may access personal data:
We do not use advertising networks, data brokers, or analytics platforms that process personal data from your agent traffic. A complete and up-to-date sub-processor list is included in the DPA and available upon request.
AgentAIShield is based in the United States. When personal data is transferred from the EU/EEA to the US, we ensure appropriate safeguards are in place:
We retain personal data for the minimum period necessary, consistent with our contractual and legal obligations:
Given the nature of our business — processing data about AI agent behavior, including potential PII detection — we have designated a Data Protection Officer to ensure ongoing GDPR compliance.
In the event of a personal data breach, we are committed to the following timeline and process:
If you believe there has been unauthorized access to data you process through AgentAIShield, contact our security team immediately at [email protected] and our DPO at [email protected]. We operate 24/7 incident response.
Our DPO and privacy team are here to help.
DPO: [email protected]
Privacy: [email protected]
AgentAIShield by You! Ventures LLC
Austin, TX, United States