You send us your most sensitive content so we can find the PII in it — we protect that content with the highest standards of security and privacy. Our entire infrastructure operates within the European Union, fully compliant with GDPR.
All servers and data storage are located exclusively in Germany and Finland. Your data never leaves the European Union.
We follow all requirements of the EU General Data Protection Regulation (GDPR) across every aspect of our operations.
Data submitted via our API is processed in real time and immediately discarded. We do not store, log, or retain your content.
For maximum privacy, we offer fully local on-premise deployment where no data ever leaves your own infrastructure.
This Data Privacy Statement explains how PII Detection API (operated by Alpha Quantum, Munich, Germany) handles data when you use our PII detection services. We designed our platform with privacy at its core — the content you submit for scanning is processed in-memory, never persisted, and never shared with third parties beyond the processing pipeline described below.
When you submit data to our API for PII detection, the following principles apply:
Our standard cloud API service utilizes external Large Language Model (LLM) providers as part of the detection pipeline. This means that during processing, your data may be sent to third-party LLM APIs (e.g., for advanced entity recognition and context-aware classification). These providers process data transiently and are contractually bound not to store or use your data for training purposes. However, if your data privacy requirements prohibit any external processing, we recommend our Local Deployment option (see Section 3 below).
When you send a request to our cloud API, your content is processed through our pipeline — which may include external LLM calls — the detected entities (with offsets and confidence scores) are returned, and the original data is discarded. No provider in the chain retains your content.
We offer two deployment models to accommodate different data privacy requirements:
Our standard service where PII detection is performed via our cloud infrastructure, leveraging external LLM providers for advanced AI-powered entity recognition.
A fully self-contained deployment running entirely on our EU-based servers with local AI models. No data ever leaves our infrastructure — zero third-party API calls.
For most use cases, our Cloud API provides excellent privacy with fast, accurate PII detection. If your compliance or regulatory framework requires that data must not be processed by any third-party service — even transiently — our Local Deployment ensures complete data isolation within our EU infrastructure. Contact us at [email protected] to discuss your requirements.
All of our own infrastructure is hosted exclusively within the European Union. For the Cloud API, external LLM providers may process data outside the EU transiently; for the Local Deployment option, all processing remains strictly within EU borders.
Primary processing and application servers are located in German data centers, operating under strict German and EU data protection laws.
Additional infrastructure is hosted in Finnish data centers, ensuring redundancy and high availability — all within the EU.
We fully adhere to the EU General Data Protection Regulation (GDPR). Our commitment includes:
Separately from API content data, we collect limited account information to manage your subscription:
This account and billing data is stored within the EU and retained only for as long as your account is active or as required by applicable tax and commercial law.
We implement comprehensive technical and organizational measures to protect your data:
We do not sell or share your data for marketing, analytics, or any purpose unrelated to delivering the PII detection service. Our sub-processors include:
If you require a deployment where no data is processed by any third party, our Local Deployment option eliminates all external sub-processors from the data pipeline.
As a data subject under GDPR, you have the following rights regarding your personal data:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
Our team is here to discuss your specific data protection requirements. We also provide Data Processing Agreements (DPAs) for enterprise customers.