Our engineers set up and run your first chatbot / LLM security scan. Get in touch

Privacy Notice

Version 1.0 · Effective 2026-05-22

Version: 1.0 Effective date: 2026-05-22 Data controller: Penaxtra (the "Provider")

This Privacy Policy explains how the Provider collects, uses, discloses, and protects personal data when you visit the website at penaxtra.com, sign up for an account, deploy the runtime gateway agent, or otherwise use the Penaxtra LLM Security Posture Management platform (collectively, the "Service").

For Customer Data processed on behalf of a Customer in the Service, the Provider acts as a processor under the Data Processing Addendum at /legal/dpa.

1. Who we are

The Provider is the data controller for personal data described in this Privacy Policy. For data protection matters, contact [email protected]. We process personal data in accordance with the EU General Data Protection Regulation (Regulation EU 2016/679, "GDPR") and the Turkish Personal Data Protection Law No. 6698 ("KVKK"), depending on the applicable jurisdiction.

2. Data we collect

We collect the categories of personal data below for the purposes stated in section 4.

  • Account data: name, email, hashed password, time-based one-time password seed (if enabled), magic-link tokens, language and theme preferences.
  • Usage data: pages visited, features used, scan execution counts, errors encountered, browser type, IP address, approximate location derived from IP, timestamps.
  • Customer Data: any content the Customer submits to the Service, including LLM endpoint configurations, adversarial probe responses, scan findings, and audit log entries. Customer Data is processed under the Data Processing Addendum and the Customer is the controller.
  • Billing data: company legal name, tax identifier, billing address. Cardholder data is collected directly by the payment processor and never reaches our servers.
  • Communications: contact form submissions, support tickets, and email correspondence.

3. Lawful basis (GDPR Art. 6)

We process personal data under the following lawful bases:

  • Performance of a contract (Art. 6(1)(b)): account, usage, and billing data necessary to provide the Service.
  • Legitimate interest (Art. 6(1)(f)): security, fraud prevention, product analytics, communications about the Service. We balance our legitimate interest against your rights and provide the right to object.
  • Consent (Art. 6(1)(a)): non-essential cookies and product marketing communications. You may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)): retention of records required by tax, accounting, or other applicable law.

For KVKK, the corresponding lawful grounds are Article 5 and Article 6 of the law.

4. Purposes of processing

  • Provision, maintenance, and improvement of the Service.
  • Authentication, authorisation, and audit logging.
  • Billing, invoicing, and tax compliance.
  • Security monitoring, abuse detection, and incident response.
  • Customer support, including responding to enquiries and tickets.
  • Product analytics and engagement metrics (aggregated, no cross-site tracking).
  • Communication about Service changes, security incidents, and (with consent) marketing.

5. Retention

We retain personal data only as long as necessary for the purposes for which it was collected, or as required by applicable law.

  • Account data: for the lifetime of the account plus 90 days after deletion.
  • Audit log: tenant-configurable retention from one day to ten years; the Customer controls the setting.
  • Usage data: aggregated within 30 days; individual session-level data retained for 90 days for incident response.
  • Billing data: ten years to satisfy tax and accounting law.
  • Contact form submissions: 24 months from the last interaction.

6. Sharing and subprocessors

We share personal data with subprocessors listed in the Trust portal at /trust. Each subprocessor is contracted under EU Standard Contractual Clauses where international transfer applies. Material changes to the subprocessor list are notified at least 30 days in advance.

We do not sell personal data. We do not share personal data for cross-context behavioural advertising.

7. International transfers

Customer data is hosted in the European Union (Germany region). Some subprocessors (notably the frontier LLM judge providers used in the adversarial scan pipeline) operate from outside the EEA. Transfers to those subprocessors rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and supplementary measures as required under the Schrems II ruling.

8. Customer rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete personal data.
  • Erase personal data ("right to be forgotten"), subject to legal retention obligations.
  • Restrict processing in certain circumstances.
  • Receive your personal data in a structured, machine-readable format (data portability).
  • Object to processing based on legitimate interest, including profiling for product analytics.
  • Withdraw consent at any time for processing based on consent.
  • Lodge a complaint with your local data protection authority (in Turkiye, the Kisisel Verileri Koruma Kurumu, KVKK).

To exercise these rights, email [email protected]. We respond within one month of receipt; complex requests may extend to three months with notice.

9. Cookies

We use a minimal set of strictly necessary cookies for session management, CSRF protection, and theme persistence. We do not use cross-site tracking cookies or third-party advertising tags. Full details are in the Cookie Policy at /legal/cookies.

10. Children

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we learn that a child has provided personal data, we will delete it.

11. Updates

We may update this Privacy Policy from time to time. Material changes will be communicated at least 30 days in advance via email and in-product notification.

12. Contact

Questions about this Privacy Policy: [email protected]. Postal address: published in the customer DPA on request.