Legal
Version 1.0 · Last updated: 10 July 2026
This addendum forms part of the Terms of Service between you (the customer) and Aeryn Quarmby, a sole proprietor trading as PII Shield, in South Africa. It applies whenever we process personal information on your behalf. It is written to satisfy section 21 of POPIA and Article 28 of the GDPR.
You are the responsible party (POPIA) and the controller (GDPR). We are the operator (POPIA) and the processor (GDPR). You determine why and how personal information is processed; we process it only to provide the service.
"Personal information" carries the meaning given in POPIA and includes "personal data" under the GDPR. "Data subject" includes POPIA's "data subject" and the GDPR's equivalent.
Note that the word "operator" is used in two senses in our documentation. In POPIA it means the processor, which is us. In our dashboard it means a member of PII Shield staff with access to the administrative console. Clause 5 explains what such a person can and cannot see.
| Category | What it covers |
|---|---|
| Data subjects | Your employees and contractors who use PII Shield; and any person whose personal information appears in the text, prompts or documents your people submit, including your own customers, patients, clients or counterparties. |
| Personal information | Whatever appears in the content you submit. The detectors cover, among others, names, email addresses, phone numbers, postal addresses, dates of birth, national identifiers (South African ID, US SSN, UK NINO, India PAN and Aadhaar), payment card numbers, IBANs, IP and MAC addresses, VINs, and cryptocurrency wallet addresses. You may add custom terms and patterns. |
| Special personal information | Not requested and not required. It may nonetheless appear in free text you submit. Health, biometric, religious, political and similar categories carry heightened obligations under POPIA section 26 and GDPR Article 9. You must have a lawful basis before submitting them. |
| Frequency | Continuous, for the duration of the service. |
We process personal information only on your documented instructions. The Terms, this addendum, and your configuration in the dashboard (which detectors run, whether automatic scanning is on, retention settings) are your complete instructions. We will tell you if we believe an instruction breaches POPIA or the GDPR, and we may decline it.
We will not process personal information for our own purposes, will not sell or share it, and will not use it to train any model. We do not use your content to improve our detection engine. The false positive learning described in our documentation stores a one way HMAC fingerprint scoped to your workspace, never a value, and never leaves your workspace.
Every person we authorise to process personal information is bound by a duty of confidentiality that survives the end of their engagement. Access is limited to those who need it to operate the service, and is granted by an explicit allow list of email addresses rather than by role.
We implement appropriate technical and organisational measures under POPIA section 19 and GDPR Article 32. The most important of these is architectural: for most of the service we never receive the personal information at all, and where we do receive it we do not persist it.
| Measure | How it is implemented |
|---|---|
| Processing on your device | The browser extension and the Claude Code plugin detect and redact locally. The personal information never leaves the device, and no network request carrying it is made to us. |
| No persistence in transit | The API gateway and MCP server redact in memory and forward. The token to value map exists only for the life of a single request. The original text is never written to disk or to the database. |
| Documents are not retained | An uploaded file is processed and the source discarded once the redacted output is returned. |
| The Leak Audit stores no readable value | Each row holds a fixed placeholder (•••), never a partial preview, because a partial such as j***@acme.com would disclose a domain to anyone with database access. The value is encrypted in your browser (AES-256-GCM under a key wrapped with RSA-OAEP to a public key your workspace generates and whose private key never leaves your browser). We hold no key that can decrypt it. Neither can our database provider, and neither can a PII Shield operator with full console access. |
| Fingerprints, not values | Deduplication and "Not PII" suppression key on an HMAC-SHA256 blind index, derived per workspace via HKDF from a server master secret. It is one way. It identifies a repeat of a value without revealing the value. |
| Encryption at rest and in transit | TLS for all traffic. Stored provider API keys are encrypted with AES-256-GCM. The database enforces row level security and is reachable only with a service role credential held in the hosting provider's secret store. |
| Minimisation in logs | Request logs record counts and types ("3 emails, 1 card"), never values. An apply response from the document redactor returns opaque finding identifiers, never the values it masked. |
| Access control | Console access is restricted to an explicit list of operator email addresses. Workspace data is scoped by workspace key; a seat key attributes usage to an individual and cannot read another workspace. |
| Secure development | Automated secret scanning (gitleaks), static analysis (CodeQL) and dependency audit on every commit. The server refuses to start in production if a required secret is missing rather than falling back to a default. |
| Resilience and restore | Managed Postgres with automated backups and point in time recovery, plus an independent logical dump. Our backup and continuity plan documents the recovery objectives and how we test them. |
You give general written authorisation for us to engage subprocessors. We impose data protection obligations on each one no less protective than those in this addendum, and we remain fully liable to you for their performance.
| Subprocessor | Purpose | What it receives |
|---|---|---|
| Render | Application hosting and the daily cron | Data in transit during processing. Nothing raw is persisted. |
| Supabase | Managed Postgres | Workspace and seat metadata, usage counts, ••• placeholders, ciphertext readable only by you, and blind indexes. Account email addresses are stored encrypted (AES-256-GCM) alongside a one-way index used only for lookup; the key is held by the application and never by the database. Never plaintext personal information. |
| Anthropic | Model inference, managed mode only | Redacted text, with personal information already replaced by tokens. In BYOK mode requests go to your own Anthropic account, where Anthropic is your processor and not ours. |
| Resend | Transactional email | Email addresses of your members, and the content of sign in links and usage notices. |
| Lemon Squeezy | Payments, as Merchant of Record | Billing name, address and tax details. As Merchant of Record it is the responsible party for cardholder data. We never see your card number. |
We will give you at least 30 days' notice before adding or replacing a subprocessor, by email to the workspace owner. If you reasonably object on data protection grounds within that period, you may terminate the affected service and we will refund any prepaid, unused fees.
If a data subject contacts us directly, we will not respond substantively; we will refer them to you and tell you promptly. Taking into account the nature of the processing, we will assist you in responding to requests for access, correction, deletion, objection and portability, by appropriate technical measures and insofar as possible.
In practice you can satisfy most requests yourself. The Leak Audit exports on demand, exposures can be deleted individually or in bulk, and deleting a workspace removes its rows. Because we cannot read the encrypted values, we cannot search them on your behalf; you can, from your browser, because you hold the key.
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a security compromise affecting your personal information, giving the nature of the compromise, the categories and approximate volume of records concerned, the likely consequences, and the measures taken or proposed. This is intended to leave you time to meet your own 72 hour obligation under GDPR Article 33, and your obligation under POPIA section 22 to notify the Information Regulator and affected data subjects as soon as reasonably possible.
We maintain a documented incident response plan and will cooperate with your investigation.
We will assist you with data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us. We publish a DPIA template and an employee notice covering the monitoring aspects of the Leak Audit, which is the part of the service most likely to require an assessment.
On termination, or on your written request at any time, we will delete all personal information we process on your behalf within 30 days, unless we are required by law to retain it. Billing records are retained for the period tax law requires. Backups age out on their normal cycle and are not restored except to recover the service, after which any restored personal information is re deleted.
Export your Leak Audit before you terminate. We cannot reconstruct it afterwards, and we could not read it even if we tried.
We will make available the information necessary to demonstrate compliance with this addendum, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. In the first instance we will answer a reasonable security questionnaire and provide our current security documentation. An on site audit may be requested once in any twelve month period, on 30 days' notice, at your cost, subject to confidentiality, and scoped so as not to compromise the security of other customers.
Our subprocessors operate outside South Africa. Transfers of personal information out of South Africa rely on POPIA section 72, on the basis that the recipient is subject to an agreement that upholds principles for the lawful processing of personal information substantially similar to those in POPIA. For personal data originating in the EEA or the UK, transfers rely on the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum, which are incorporated into this addendum by reference and take precedence over it in the event of conflict. We will provide our completed transfer documentation on request.
Each party's liability under this addendum is subject to the limitations in clause 13 of the Terms of Service. If this addendum conflicts with the Terms on the processing of personal information, this addendum prevails. If it conflicts with the Standard Contractual Clauses, those clauses prevail.
Data protection queries, countersignature requests, subprocessor objections and audit requests: [email protected]. Security compromises, including responsible disclosure: [email protected].