Privacy Policy
Last updated: 21 August 2026
Our commitment to privacy
At Aqta, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose and safeguard your information when you use the Aqta platform and its services.
1. Information we collect
Personal information
- Email address (for account creation and communication)
- Name (if provided during registration)
- Payment information (processed securely by third-party providers)
- Organisation details (if applicable)
Usage information
- AI request metadata (timestamps, models used, costs)
- System performance metrics
- Feature usage analytics
- Error logs and debugging information
2. How we use your information
We use the collected information to:
- Provide and maintain our services
- Process payments and manage subscriptions
- Monitor and analyse AI request patterns
- Detect and prevent security threats
- Improve our platform and develop new features
- Communicate with you about service updates
- Provide customer support
3. Data security
We implement industry-standard security measures to protect your information:
- Encryption in transit and at rest
- Regular security audits and penetration testing
- Access controls and authentication
- Secure data centres with physical security
- Employee training on data protection
4. AI request data
Important: content privacy
We do not store or log the content of your AI requests. Content is inspected in transit solely to enforce your configured policies (e.g. PHI detection, loop detection, spend limits) and is immediately discarded. We collect only metadata such as timestamps, model names, token counts, policy outcomes, and costs for monitoring, billing, and audit purposes.
Your AI prompts and responses remain private. Seal enforces policy at the boundary without persisting message content. Cryptographic attestation records contain only metadata and hashes, not raw prompt or response text.
4a. Signed decision records
Seal clears the decision before the model call, then leaves one signed record of what was decided. Each record holds a timestamp, the policy applied, the outcome (allowed or blocked), and a one-way SHA-256 fingerprint of the request. It does not contain prompt content or model responses. A fingerprint cannot be read back, but it can confirm a guessed input, so we treat records as pseudonymous data rather than anonymous. The open envelope is ATTESTATION-v1; the signature ink is Ed25519.
A sceptical reviewer checks the file against a published key, on their own machine, with no call to anyone. Optional advanced proving modes for specific workflows are in preview and are not required to check a production receipt.
4b. PHI Guard processing (Health pack only)
PHI Guard is an optional pack for healthcare deployments. When enabled, it scans request payloads in transit for Protected Health Information (PHI) categories defined under HIPAA, blocks or redacts before the model call, and records a metadata-only finding (categories detected, action taken, hash of the redaction). No PHI text is stored, logged, or transmitted outside your enforcement boundary. The attestation record for a PHI-Guard decision contains the policy outcome and category codes only, not the underlying content.
Where PHI Guard is deployed under a Business Associate Agreement (BAA), the BAA governs processing terms and overrides general defaults in this policy. Contact hello@aqta.ai for the BAA template.
4c. Independent review (review.aqta.ai)
At review.aqta.ai a reviewer signs a verdict on a receipt using a credential held in their own wallet. Aqta does not issue that credential and never sees a password. To sign, the reviewer discloses one attribute from their wallet, today a verified email address, and the wallet asks them to approve that disclosure before anything is sent.
What we store, and where it is readable. We store the verdict, the fixed question, the receipt under review, the signed binding message, and the disclosed attribute value, which identifies the reviewer. The purpose is that a verdict from an anonymous reviewer would be worth nothing: being identifiable is the point of the record. Each verdict is written to a docket with an unguessable identifier, and anyone holding that docket link can read it, including the disclosed attribute, without an account. That is deliberate, because a reviewer's verdict has to be checkable by a third party, and it is why we say so here and on the page itself.
Legal basis is consent, given at the wallet disclosure step, and you may withdraw it. Verdict records are kept while the review flow runs and are deleted on request. To have a verdict record erased, or to ask what is held about you, write to hello@aqta.ai with the docket identifier. Section 8 sets out your rights in full. This flow is a prototype and is labelled as one wherever it appears.
5. Network Intelligence (opt-in pattern sharing)
Value exchange
When you opt in to Network Intelligence on an entitled deployment, your deployment can contribute anonymised threat patterns so that every customer benefits from better detection. Your raw request data never leaves your control. Only anonymised pattern signatures (e.g. hashes of threat signatures, not content) are shared to improve collective detection. Participation is opt-in; you can use Seal without contributing patterns.
What is shared when you contribute:
- Anonymised pattern hashes (no prompts, no responses, no PII)
- Threat type and severity metadata
- Aggregate counts (e.g. "patterns shared this week")
What is not shared: your organisation name, your request content, user identifiers, or any data that could identify you or your users. This helps the network protect all customers (e.g. "customers protected") while preserving your privacy.
6. Data sharing and disclosure
We do not sell, trade or rent your personal information. We may share information only in these limited circumstances:
- With your explicit consent
- To comply with legal obligations
- To protect our rights and prevent fraud
- With trusted service providers (under strict confidentiality agreements)
- In connection with a business transfer or merger
7. Data retention
We retain your information for as long as necessary to provide our services:
- Account information: until account deletion
- Usage metadata: 24 months for analytics
- Billing records: 7 years for tax compliance
- Security logs: 12 months for incident response
8. Your rights (GDPR)
If you are in the European Union, you have the right to:
- Access your personal data
- Correct inaccurate information
- Delete your data ("right to be forgotten")
- Restrict processing of your data
- Data portability
- Object to processing
- Withdraw consent at any time
9. Cookies and tracking
We use essential cookies only for:
- Authentication and session management
- Security and fraud prevention
We do not use cookies for advertising or marketing. Product analytics on app.aqta.ai use Vercel Web Analytics, which is cookieless by design (no advertising identifiers). Session cookies for sign-in are strictly necessary and exempt from consent under ePrivacy Art 5(3). The independent review site at review.aqta.ai sets no cookies at all.
10. International transfers
Your data may be processed in countries outside your residence. We ensure adequate protection through standard contractual clauses and other appropriate safeguards as required by applicable law.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through the service. The updated policy will be effective when posted.
12. Contact us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: hello@aqta.ai
Address: Aqta Technologies Limited
Dublin, Ireland