Skip to content
heySec heySec
HomeProductEnterpriseBlogAbout
Join Waitlist

Legal

Privacy Policy

Last updated: 30 May 2026

On this page

Overview Data we collect How we protect your data How we use it Storage & retention Sharing & disclosure Your rights Cookies Contact & DPO

Overview

Prompt Firewall is an AI security firewall built by heySec. It sits between your AI and the untrusted content it reads, such as customer emails, documents, web pages, and uploaded files. It scans that content for hidden attacks like prompt injection, then wraps it in a secure boundary your AI treats as data rather than instructions, so even an attack it does not catch cannot give orders to your model. This policy covers the cloud (hosted) version of Prompt Firewall, and explains what data we collect, how we handle it, and the rights you have under the GDPR.

Prompt Firewall is run under the heySec brand by Kempu OÜ (registry code 14643339), a company registered in Estonia. The service runs and is hosted entirely within the European Union, and our supervisory authority is the Estonian Data Protection Inspectorate. If anything here conflicts with a signed agreement or Data Processing Agreement (DPA) between us and your organisation, that agreement takes precedence.

We don’t send your content to third-party AI providers. Prompt Firewall does not forward or proxy your content to OpenAI, Anthropic, Google, or anyone else. It is checked only by our own systems inside the EU. You call your own AI model yourself, and we never see your model’s responses.

Data we collect

Account and billing

When you sign up we collect your name and email address, your password (stored only as a secured hash that cannot be reversed), your organisation, your team’s membership and roles, and your subscription and billing details. If you turn on multi-factor authentication, those secrets are stored encrypted. Card payments are handled by our payment provider, and we do not store full card numbers.

Content you submit

When you send content to the API, we receive the text or files you submit, some technical details about the request (such as a request ID, a timestamp, and the network address of the server that called us), and the result of the check. If you send us feedback about a result, it is stored encrypted.

Website visitors

When you visit our website we collect standard server logs, such as your IP address, browser type, and the pages you view. For website analytics we use Plausible, a privacy-focused service hosted in the EU. Plausible does not use cookies, does not collect personal data, and does not track you across websites or devices; it only gives us aggregate figures such as page views and referrers. We do not use advertising trackers.

How we protect your data

The content you send us can contain personal data about your own users. We only need the original for the moment of the check, not for long-term storage.

Before a request is saved, an automated step finds and removes personal data and replaces each item with a neutral placeholder that cannot be traced back to the original. This covers things like names, postal and email addresses, phone numbers, ID and payment numbers, and sensitive data such as health or biometric information. When it is not sure, it removes the data anyway. The original, un-redacted content is then deleted automatically, and only the redacted version is kept.

We keep that redacted version as the log of your request. It is what powers the request history and usage figures you see in your portal, it gives you and your auditors a record of what was checked and what we found, and it helps us improve our threat detection. Because the personal data has already been removed, this log does not identify anyone.

How we use it

We use this data to run the service, keep your account secure, measure usage and bill you, send transactional emails such as receipts, alerts and account notices, answer support requests, prevent abuse, and improve our detection using data that has already had personal data removed.

We do not sell your personal data, we do not use it for advertising, and we do not use the content you submit to train general-purpose AI models.

Storage & retention

All data is stored, processed and backed up inside the European Union, and is not transferred outside the EU/EEA.

The original content you submit is kept only briefly and then deleted automatically. The redacted request log, which no longer contains personal data, is kept so it stays available to you in your portal. Account, organisation and billing records are kept for as long as you have an account, plus any period we are legally required to keep them. When you close your account, or ask us to erase your data, we delete or permanently anonymise it, except where the law requires us to keep it.

Sharing & disclosure

We work with as few third parties as possible, and all of them are based in the European Union. Our sub-processors are:

  • Hetzner (Germany) provides cloud hosting, storage and backups for the service.
  • NetiServer (Estonia) provides hosting and infrastructure.
  • Plausible (Estonia) provides privacy-focused, cookieless website analytics.

The content you submit to the API is never shared with our analytics provider, any AI provider, or any advertising network. We will update this list if our sub-processors change.

We only disclose data when the law or a valid legal order requires it, and we will tell the affected customer whenever we are allowed to.

Your rights

Under the GDPR you can ask to access, correct, erase, restrict or port your personal data, object to how we process it, and withdraw consent where we rely on it. For account and organisation data, write to [email protected].

For personal data inside content you send to the API, your organisation is the data controller, so those requests go through your organisation and we help fulfil them. Because we remove personal data before storing submitted content, exported records contain only the redacted version, not the original values, which we cannot recover.

You can also complain to the Estonian Data Protection Inspectorate ([email protected]) or your local supervisory authority.

Cookies

Our dashboard uses only essential cookies: one to keep you signed in, and one to protect against cross-site request forgery. We also use local storage in your browser to remember your light or dark theme. Our website analytics (Plausible) is cookieless. We do not use advertising, cross-site tracking, or third-party analytics cookies.

Contact & DPO

For questions about this policy or your data, contact our Data Protection Officer:

Data Protection Officer
Kempu OÜ (reg. 14643339), operating as heySec
European Union
[email protected]

We may update this policy from time to time. If we make a significant change, we will let customers know, and we will update the “Last updated” date at the top.

heySec

Prompt Firewall for AI applications. Scans and contains untrusted content before it reaches the model. Cybersecurity, made simple.

Product
  • How it works
  • Features
Enterprise
  • On-premises
Company
  • About
  • Blog
  • Contact
heySec · European Union
EU infrastructure only
All data processed within the EU
GDPR Compliant by design
© 2026 heySec. All rights reserved.
ThreadsFacebookXLinkedInInstagramBluesky