1. Who we are
Prosader Ltd. ("Prosader", "we", "us", or "our") is a company registered in England and Wales. Our registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
For the purposes of UK GDPR, Prosader Ltd. is the data controller in respect of personal data collected through our marketing website and during the sales and onboarding process. Where Prosader processes personal data on behalf of customers who use the Prosader gateway product, Prosader acts as a data processor and the customer is the data controller.
Our ICO registration number is [ICO_REG_NUMBER]. You can verify our registration on the ICO's Data Protection Register.
2. What data we collect
Marketing website and enquiries
When you submit a contact or demo request form on prosader.com, we collect:
- Your name and job title
- Your business email address
- Your company name
- Your message or enquiry content
Gateway product (processor role)
When a customer uses the Prosader runtime security gateway, the system processes data that may include:
- Agent identifiers and session identifiers
- AI tool call requests and responses (content depends on what tools the customer's agents use)
- Signed audit receipts recording enforcement decisions
- User identifiers for human step-up approvals
- IP addresses and timestamps
This data is processed solely on the instructions of the customer (the data controller). Our obligations as a processor are set out in our Data Processing Agreement.
3. How we collect it
We collect data directly from you when you complete a contact or demo request form on our website. We do not use cookies for analytics or advertising purposes on prosader.com. We do not use any third-party tracking scripts or pixels on our marketing website.
For the gateway product, data is transmitted to us by the customer's AI agents via our API.
4. Lawful basis for processing
| Processing activity | Lawful basis |
|---|---|
| Responding to website enquiries and demo requests | Legitimate interests (Article 6(1)(f)) — our interest in responding to potential customers who have contacted us |
| Providing the Prosader gateway service to customers | Performance of a contract (Article 6(1)(b)) — processing is necessary to deliver the subscribed service |
| Compliance with legal obligations | Legal obligation (Article 6(1)(c)) |
5. How long we keep it
- Enquiry and contact form data: retained for up to 24 months from the date of receipt, unless a business relationship is established, in which case the relevant data is retained for the duration of that relationship plus a further 6 years.
- Customer gateway data: retained for the duration of the subscription agreement, then deleted within 30 days of termination (backups within 90 days). See our DPA for full details.
6. Who we share it with
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes. We share data only with:
- Hetzner Online GmbH — cloud infrastructure provider hosting our servers in Germany (EU). Data is stored within the EU/EEA.
- Cloudflare, Inc. — CDN and DDoS protection. Cloudflare may process certain network-level data (e.g., IP addresses) as strictly necessary for this service.
- Professional advisors — lawyers and accountants bound by duties of confidentiality, where necessary.
- Law enforcement or regulatory authorities — where we are legally required to disclose data.
7. International transfers
Customer data is stored on servers in Germany, within the EU/EEA. The EU is covered by the UK's adequacy regulations, meaning transfers of personal data from the UK to EU-hosted servers are lawful without additional safeguards.
Cloudflare, Inc. is a US company. Data passing through Cloudflare's network is covered by the UK International Data Transfer Agreement (IDTA) and Cloudflare's applicable data transfer mechanisms. Cloudflare acts as a processor for network traffic routing only and does not have access to the content of our customers' agent data.
8. Your rights
Under UK GDPR you have the following rights in relation to personal data we hold about you as a data controller:
- Right of access — to obtain a copy of the personal data we hold about you.
- Right to rectification — to have inaccurate data corrected.
- Right to erasure — to have your data deleted in certain circumstances.
- Right to restriction — to restrict how we use your data in certain circumstances.
- Right to data portability — to receive your data in a structured, commonly used format.
- Right to object — to object to processing based on legitimate interests.
To exercise any of these rights, email us at legal@prosader.com. We will respond within one calendar month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO). You can do so at ico.org.uk/make-a-complaint or by calling 0303 123 1113.
9. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction. These measures include:
- Encryption in transit using TLS 1.2 or higher for all data exchanged with our services
- Encryption at rest for database storage
- Access controls limiting data access to authorised personnel only
- Cryptographically signed and tamper-evident audit logs
- Regular security reviews and penetration testing
10. Changes to this policy
We may update this privacy policy from time to time. When we make material changes, we will notify active customers by email and update the "Last updated" date at the top of this page. We encourage you to review this page periodically.
11. Contact
For any questions about this privacy policy or to exercise your data rights, please contact us:
Email: legal@prosader.com
Post: Prosader Ltd., 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ