Home Product Solutions Pricing Measured accuracy Security & architecture Compare with other tools Developers VS Code and JetBrains plugins Contact Sign in

Legal & Privacy

This is the click-wrap form of the Data Processing Agreement for organisations using the shared service (tier A). Dedicated server, zero-knowledge relay, air-gapped and confidential-computing deployments (tiers B to E) sign the full agreement with Annex T.

Data Processing Agreement (Article 28 GDPR)

This Data Processing Agreement ("DPA") is entered into between the organisation accepting it through its account in the Service (the "Controller" or "Customer") and the operator of filterit (the "Processor" or "Operator"), and supplements the Terms of Service. The DPA is accepted by the organisation's OWNER, who represents that they are authorised to bind it. The acceptance is recorded with the version and language of the text, the time, the IP address, the browser identification and a fingerprint (SHA-256) of this text.


1. Definitions

"Personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in Regulation (EU) 2016/679 ("GDPR"). "Service" means the personal-data detection, pseudonymisation and safe-AI gateway marketed as Filterit.

2. Subject-matter, duration, nature and purpose (Art. 28(3))

Item Detail
Subject-matter Processing of personal data submitted to the Service by the Customer or its users.
Duration For the term of the organisation's subscription, plus the return/deletion period of Clause 11.
Nature and purpose Detection of identifiers in text and documents; reversible pseudonymisation (replacement with placeholders); transmission of the pseudonymised text to large-language-model (LLM) providers as sub-processors; restoration of values in the reply; visual redaction of images and PDFs; optional email-draft generation; audit logging; transcription and summarisation of meeting recordings on the Processor's infrastructure; question answering over document sets (review grid).
Types of personal data Identifiers in free text (names, addresses, phones, emails); national identifiers (Greek tax id, social security number, id card, IBAN, licence plates); account and authentication data of the Customer's users; email content when the email assistant is used; voice recordings when meetings or voice notes are used; special-category data that may inadvertently be present in content.
Data subjects The Customer's users and third parties named in submitted content.

3. Processor obligations (Art. 28(3)(a) to (h))

The Processor shall:

  1. process personal data only on documented instructions of the Customer, including for transfers, unless required by Union or Member State law, in which case it informs the Customer before processing unless prohibited. Instructions are given through the use of the Service and the organisation's settings;
  2. ensure that persons authorised to process the data are bound by confidentiality;
  3. implement the security measures of Art. 32 GDPR described in Clause 4;
  4. respect the conditions of Clause 5 for engaging sub-processors;
  5. assist the Customer with appropriate technical and organisational measures in responding to data-subject rights requests (Arts. 12 to 22 GDPR);
  6. assist the Customer with the obligations of Arts. 32 to 36 GDPR (security, breach notification, impact assessment, prior consultation);
  7. at the Customer's choice, delete or return all personal data after the end of the provision of services, per Clause 11;
  8. make available all information necessary to demonstrate compliance and allow for and contribute to audits, per Clause 6;
  9. immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other data-protection provisions.

4. Security measures (Art. 32)

The Processor maintains, at minimum:

Domain Measure
Encryption at rest The placeholder to value mapping is stored encrypted with AES-256-GCM and deleted 30 days after creation; conversations, messages, project texts and drafts are encrypted at rest; email credentials are encrypted. Database backups are kept on the server for up to 14 days.
Search without decryption HMAC-SHA256 index; the database administrator cannot reverse values.
Minimisation Conversations, messages and files are stored pseudonymised only and encrypted; email threads are not stored (opt-in automation items are stored pseudonymised and encrypted); original files are held in temporary storage for at most 30 minutes (10 minutes for redaction originals) and never in the database.
Mask integrity Pseudonymisation is fail-closed: if detection is unavailable the text is not sent; placeholder uniqueness enforced by a database constraint per customer; leak check on the reply stream.
Access Roles per organisation (owner, admin, member, auditor); least privilege; audit log per action.
Transport TLS on every external communication.
Hosting Infrastructure within the European Union (Hetzner Online GmbH, Falkenstein, Germany).
Keys High-entropy master key held only in an environment variable of the application host; rotation procedure. In the shared service, organisation data is protected under the Processor's key; a customer-held key exists for individual password accounts, and customer-controlled keys for organisations are offered in the dedicated tiers (B to E).

Details: the Security page and, on request, the Operator's security policy.

5. Sub-processors (Art. 28(2) and (4))

5.1 The Customer gives general written authorisation for the sub-processors listed on the Sub-processors page, which forms an integral part of this DPA.

5.2 The Processor informs the Customer of any intended addition or replacement of a sub-processor through that page and by e-mail to the organisation's owner, allowing 30 days to object on reasonable data-protection grounds. If the objection cannot be accommodated, the Customer may terminate the subscription.

5.3 The Processor imposes on each sub-processor the same data-protection obligations as in this DPA, by contract, and remains fully liable to the Customer for their performance.

5.4 The Customer may ask the Processor to restrict the LLM providers used for its workspace (residency policy). The Processor uses no LLM provider other than those listed on the sub-processors page; at present all of them are established in the United States, so an EU-only restriction becomes available only once an EU-established provider is listed.

6. Audits (Art. 28(3)(h))

The Processor makes compliance information available and permits audits by the Customer or a mandated auditor, on 30 days' written notice and at the Customer's cost, no more than once per 12 months absent a breach or a supervisory-authority request, subject to confidentiality. The Service's audit log and the organisation's evidence pack satisfy routine audit requests.

7. International transfers (Chapter V)

7.1 Pseudonymised content is transferred to the LLM providers on the sub-processors page, which are established in the United States. As pseudonymised data remains personal data, the Processor bases these transfers on the Standard Contractual Clauses contained in the provider's data processing agreement, with pseudonymisation as a supplementary measure. Hosting (Hetzner Online GmbH, Germany) and transactional e-mail (Brevo, France) involve no third-country transfer.

7.2 The Processor does not transfer personal data outside the EEA except under a valid Chapter V mechanism and on the Customer's instructions. The Customer may ask to exclude non-EU LLM transfers under the residency policy of Clause 5.4 once an EU-established provider is listed.

8. Data-subject rights assistance

The Processor provides technical means (deletion, export of pseudonymised records, search and restoration of values from the mapping on authorised request) so the Customer can satisfy access, rectification, erasure, restriction, portability and objection requests within statutory deadlines. Requests received directly by the Processor are forwarded to the Customer without delay.

9. Personal data breach (Arts. 33 to 34)

The Processor notifies the Customer of any personal data breach without undue delay and in any case within 48 hours of becoming aware of it, providing the information the Customer needs for its own Art. 33 notification, and supplements the notice as further information becomes available.

10. Liability, governing law

The parties' liability is governed by the Terms of Service and Art. 82 GDPR. Governing law: Greece; the courts of Athens have jurisdiction. The Customer's supervisory authority in Greece is the Hellenic Data Protection Authority.

11. Return and deletion

At the end of the subscription the Processor, at the Customer's choice, returns or irreversibly deletes all personal data (mapping, pseudonymised records, ephemeral data, backups on their cycle) within 30 days and certifies deletion, unless retention is required by law.

12. Statement of limits

The Processor states and the Customer acknowledges that:

  1. pseudonymisation is not anonymisation: the data remains personal data and this DPA applies in full;
  2. identifier detection is not complete; accuracy measurements are published on the Accuracy page and refreshed with every release; the Customer reviews the output before using it;
  3. in the shared service the Processor processes the Customer's text unpseudonymised in memory, during detection, and holds the key under which organisation data is encrypted at rest, so it is technically able to access that data; it undertakes contractually to do so only to provide the Service;
  4. LLM models may produce inaccurate content; responsibility for the use of the output lies with the Customer.

13. Precedence and amendment

In case of conflict, this DPA prevails over the Terms of Service as regards the processing of personal data. A new version of this DPA is notified to the organisation's owner and requires a new acceptance; until then the accepted version applies.


Data-protection contact: contact@filterit.app. No Data Protection Officer has been appointed.

Pseudonymisation of personal data in Greek and English.

Product

  • Product
  • How it works
  • Pricing
  • Measured accuracy
  • Security & architecture
  • Compare with other tools
  • Contact

Solutions by sector

  • Law firms
  • Accounting firms
  • HR teams
  • Clinics & practices
  • Public sector
  • Guide: GDPR checklist for AI (Greek)
  • Guide: AI without leaks for lawyers (Greek)

Developers

  • Masking API
  • Python and Node SDKs
  • MCP server
  • VS Code and JetBrains plugins
  • Browser extension
  • Word add-in
  • Desktop agent

Legal

  • Terms of Service
  • Privacy Policy
  • Acceptable use policy
  • AI Disclosure
  • Cookies
  • Sub-processors
  • Data processing agreement (DPA)

filterit detects and pseudonymises or redacts the personal data it recognises. No automated tool can guarantee complete coverage: our accuracy is measured and published, and the tool improves with every release. Review the findings before you send a text, submit data on your own responsibility and only where you are entitled to, and use the service for lawful purposes only. Terms of Service, Acceptable use policy.

© 2026 filterit. All rights reserved.

ChatGPT, Claude and other product names belong to their respective owners. filterit is not affiliated with or endorsed by them.