piidetectionapi.com
Home
Solutions - Fundamentals
What Is PII Detection? NER vs Regex vs Rules Accuracy, Precision & Recall PII in Test Data
Solutions - Compliance
GDPR Personal Data HIPAA PHI Detection CCPA / CPRA PCI DSS Card Data
Solutions - AI & LLM Safety
LLM Guardrails Chatbot PII Filtering RAG Pipelines
Solutions - Data Discovery & DLP
Data Loss Prevention Log File Scanning Support Tickets Email Scanning Documents & PDFs Database Discovery ETL & Streaming Pipelines
Industries - Financial
Banking Fintech Insurance
Industries - Healthcare
Healthcare Pharma & Clinical Trials Telehealth
Industries - Public Sector & Legal
Government & FOIA Law Enforcement Law Firms & eDiscovery Education (FERPA)
Industries - Technology
SaaS Platforms Cybersecurity & IR Telecommunications Gaming & Platforms
Industries - Other
HR & Recruiting Retail & E-commerce Call Centers & BPO Real Estate Travel & Hospitality Marketing & AdTech
How-to Guides - Identity & Contact
Detect Names Detect Email Addresses Detect Phone Numbers Detect Physical Addresses Detect Dates of Birth
How-to Guides - IDs & Financial
Detect SSNs Detect Passport Numbers Detect Drivers Licenses Detect Credit Card Numbers Detect Bank Accounts & IBAN
How-to Guides - Technical & Health
Detect IP & Device IDs Detect Medical Records & PHI
Resources
Pricing API Docs Supported Entities Languages About Contact Sign In Try the Live Demo Get Started
Enterprise Data Privacy

Data Privacy Statement

You send us your most sensitive content so we can find the PII in it — we protect that content with the highest standards of security and privacy. Our entire infrastructure operates within the European Union, fully compliant with GDPR.

Last updated: March 2026
EU-based infrastructure
GDPR compliant

100% EU-Hosted

All servers and data storage are located exclusively in Germany and Finland. Your data never leaves the European Union.

GDPR Compliant

We follow all requirements of the EU General Data Protection Regulation (GDPR) across every aspect of our operations.

No Data Retention

Data submitted via our API is processed in real time and immediately discarded. We do not store, log, or retain your content.

Local Deployment Option

For maximum privacy, we offer fully local on-premise deployment where no data ever leaves your own infrastructure.

1

Overview

This Data Privacy Statement explains how PII Detection API (operated by Alpha Quantum, Munich, Germany) handles data when you use our PII detection services. We designed our platform with privacy at its core — the content you submit for scanning is processed in-memory, never persisted, and never shared with third parties beyond the processing pipeline described below.

2

Data Processing & Storage

When you submit data to our API for PII detection, the following principles apply:

  • Transient processing only — All content submitted to our API is processed in real time. Once the detection results (and any optional masked output) are returned, the original content is immediately and permanently discarded from our systems.
  • No persistent storage of customer content — We do not write your submitted text, documents, images, audio, or video data to any disk, database, or long-term storage system.
  • No logging of content — We do not log the content of API requests or responses. Only metadata necessary for billing and service reliability (e.g., timestamps, request counts, response codes) is recorded.
  • No use of your data for model training — Your data is never used to train, improve, or fine-tune any machine learning models.

Third-Party LLM Processing

Our standard cloud API service utilizes external Large Language Model (LLM) providers as part of the detection pipeline. This means that during processing, your data may be sent to third-party LLM APIs (e.g., for advanced entity recognition and context-aware classification). These providers process data transiently and are contractually bound not to store or use your data for training purposes. However, if your data privacy requirements prohibit any external processing, we recommend our Local Deployment option (see Section 3 below).

In Practice

When you send a request to our cloud API, your content is processed through our pipeline — which may include external LLM calls — the detected entities (with offsets and confidence scores) are returned, and the original data is discarded. No provider in the chain retains your content.

3

Deployment Options

We offer two deployment models to accommodate different data privacy requirements:

Standard

Cloud API

Our standard service where PII detection is performed via our cloud infrastructure, leveraging external LLM providers for advanced AI-powered entity recognition.

  • Instant access — sign up and start immediately
  • Auto-scaling for any volume of requests
  • Leverages state-of-the-art LLM models for highest accuracy
  • Data processed transiently, not stored or logged
  • LLM providers contractually prohibited from retaining data
  • Standard and volume-based pricing plans
Available on all standard pricing plans

Which Option Is Right for You?

For most use cases, our Cloud API provides excellent privacy with fast, accurate PII detection. If your compliance or regulatory framework requires that data must not be processed by any third-party service — even transiently — our Local Deployment ensures complete data isolation within our EU infrastructure. Contact us at [email protected] to discuss your requirements.

4

Infrastructure & Data Residency

All of our own infrastructure is hosted exclusively within the European Union. For the Cloud API, external LLM providers may process data outside the EU transiently; for the Local Deployment option, all processing remains strictly within EU borders.

🇩🇪

Germany

Primary processing and application servers are located in German data centers, operating under strict German and EU data protection laws.

🇫🇮

Finland

Additional infrastructure is hosted in Finnish data centers, ensuring redundancy and high availability — all within the EU.

  • EU-first data processing — Our own infrastructure keeps your data within EU borders. With the Cloud API, external LLM calls may be routed through providers with global infrastructure; with the Local Deployment option, all processing remains strictly within the EU.
  • EU-governed data centers — Our hosting providers operate Tier III+ certified facilities compliant with EU regulations.
  • Encrypted in transit — All API communication is encrypted using TLS 1.2+ (HTTPS). Data in transit cannot be intercepted or read by any intermediary.
5

GDPR Compliance

We fully adhere to the EU General Data Protection Regulation (GDPR). Our commitment includes:

  • Lawful basis for processing — We process data solely based on the contractual necessity of providing our PII detection service to you (Article 6(1)(b) GDPR).
  • Data minimization — We collect and process only the minimum data necessary to deliver the service.
  • Purpose limitation — Your data is used exclusively for the purpose of returning detection results. No secondary use, no profiling, no analytics on your content.
  • Right to information — This statement provides full transparency into how your data is handled.
  • Data Protection Officer — We have designated a data protection officer who can be reached at [email protected].
  • Data Processing Agreements (DPA) — We provide DPAs to enterprise customers upon request to formalize our data protection commitments.
6

Account & Billing Data

Separately from API content data, we collect limited account information to manage your subscription:

  • Account information — Email address, company name, and contact details provided during registration.
  • Billing records — Transaction history and payment metadata. We do not store full credit card numbers; payment processing is handled by PCI-DSS compliant third-party processors.
  • Usage metrics — API call counts, timestamps, and response codes for billing and reliability monitoring. These records contain no customer content.

This account and billing data is stored within the EU and retained only for as long as your account is active or as required by applicable tax and commercial law.

7

Security Measures

We implement comprehensive technical and organizational measures to protect your data:

  • Encryption in transit — All communications are secured via TLS 1.2+ (HTTPS).
  • Network isolation — Processing servers operate in isolated virtual private networks with strict firewall rules and no public access beyond the API endpoints.
  • Access controls — Internal access is restricted on a need-to-know basis with multi-factor authentication and audit logging.
  • Regular security assessments — We conduct periodic vulnerability assessments and penetration testing of our infrastructure.
  • Incident response — We maintain a documented incident response plan and will notify affected customers within 72 hours in the event of a data breach, in accordance with GDPR Article 33.
8

Sub-processors & Third Parties

We do not sell or share your data for marketing, analytics, or any purpose unrelated to delivering the PII detection service. Our sub-processors include:

  • EU-based hosting providers — Infrastructure providers operating data centers in Germany and Finland, bound by DPAs and GDPR obligations.
  • LLM providers (Cloud API only) — External Large Language Model providers used for advanced AI-powered entity detection and classification. These providers process data transiently via their APIs and are contractually prohibited from storing, logging, or using your data for model training. This applies only to the Cloud API deployment; the Local Deployment option does not use any external LLM providers.
  • Payment processor — PCI-DSS compliant payment provider for subscription billing (no content data is shared).

If you require a deployment where no data is processed by any third party, our Local Deployment option eliminates all external sub-processors from the data pipeline.

9

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights regarding your personal data:

  • Right of access — Request a copy of the personal data we hold about you.
  • Right to rectification — Request correction of inaccurate personal data.
  • Right to erasure — Request deletion of your personal data ("right to be forgotten").
  • Right to restrict processing — Request limitation of how we process your data.
  • Right to data portability — Receive your data in a structured, machine-readable format.
  • Right to object — Object to specific types of processing.
  • Right to lodge a complaint — File a complaint with your local EU data protection supervisory authority.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

Questions About Data Privacy?

Our team is here to discuss your specific data protection requirements. We also provide Data Processing Agreements (DPAs) for enterprise customers.