Privacy Policy
PerimeterOne LLC ("PerimeterOne," "we," "us," or "our") is committed to protecting the privacy and security of every individual who interacts with our platform, website, and services. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website at perimeterone.ai (the "Site") or use any PerimeterOne product or service (collectively, the "Services").
By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of our Services immediately.
1. Information We Collect
1.1 Information You Provide Directly
- Contact Information — name, email address, phone number, and company name when you subscribe, request a demo, or contact us
- Account data — your email address (the only directly-identifying field we store), an optional display name, and login/role metadata (created/last-login timestamps, role). We use passwordless authentication (magic link or license key); we never set or store a password. Your user and tenant identifiers are derived from your email.
- Communications — any messages, feedback, or support requests you send to us
- Payment Information — billing details processed through our PCI-DSS-compliant payment processor; we do not store raw credit card numbers
1.2 Information Collected Automatically
- Device & Browser Data — IP address (used transiently for rate-limiting and in server access logs, not persisted to a profile), a device identifier used only to count licensed seats, and anonymized install/version telemetry that contains no email, license key, or IP.
- No usage analytics — We do not use third-party analytics, advertising, tracking pixels, beacons, or session-replay tools. We do not track pages visited, click paths, or time on page.
- Cookies & Tracking Technologies — see Section 5 below for detailed cookie disclosures
- Log Data — server logs recording access timestamps, request URLs, and response codes
1.3 Information from Third Parties
We do not buy, receive, or enrich your data from advertising networks, data brokers, or third-party analytics providers.
2. How We Use Your Information
We process your information exclusively for the following purposes:
- Service Delivery — to operate, maintain, and improve the PerimeterOne platform and deliver the governed-runtime services you request
- Communications — to send transactional emails, security alerts, product updates, and (with your consent) marketing communications
- Diagnostics — to diagnose technical issues from server logs and improve reliability. We do not perform behavioral usage analytics.
- Legal Compliance — to comply with applicable laws, regulations, and legal processes
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:
- Consent — where you have given explicit consent (e.g., marketing emails, non-essential cookies)
- Contract Performance — where processing is necessary to deliver Services you have requested
- Legitimate Interest — where processing is necessary for our legitimate business interests (e.g., abuse and budget-limit enforcement, fraud prevention), balanced against your rights
- Legal Obligation — where processing is required to comply with applicable law
4. Data Sharing & Disclosure
We do not sell your personal information. We may share your data only in the following circumstances:
- Sub-processors — Hetzner (EU hosting), Cloudflare (DNS, CDN & edge TLS termination), Stripe (payments — email + plan only; card data never touches our servers), our transactional email provider, Let's Encrypt (TLS), and the large-language-model providers (e.g. Anthropic, OpenAI, Google, or a local model) that process your run's prompt and completion content via the broker. Under BYOK, the LLM provider you choose processes that content under your own agreement with them.
- Legal Requirements — when required by law, subpoena, court order, or governmental request
- Business Transfers — in connection with a merger, acquisition, or sale of assets, with notice to affected users
- Security Purposes — to protect the rights, property, or safety of PerimeterOne, our users, or the public
5. Cookies & Tracking Technologies
We use only strictly-necessary cookies: a single httpOnly, Secure, SameSite session cookie. (A CSRF token is also used to protect form submissions — it is sent in a request header, not stored as a tracking cookie.) We use no analytics, advertising, or tracking cookies.
6. Data Retention
We prune short-lived items automatically (e.g., magic-link and payment-event records after 30 days, sandbox uploads). For runs you execute, we keep a tamper-evident, cryptographically signed audit log and a durable run journal (which retains agent outputs and coordination messages for replay) on our EU server; these are not shared. The signed audit log is append-only by design and cannot be selectively erased without destroying its integrity guarantee — a documented exception to routine deletion.
7. Data Security
We hold ourselves to a high standard of data protection:
- Your BYOK provider API keys are envelope-encrypted at rest per tenant, are never logged, are never transmitted for our own use, and never enter the agent execution sandbox — the broker is the sole egress.
- Sessions are encrypted with XChaCha20-Poly1305.
- Data is encrypted in transit with modern TLS.
- Access controls enforce least-privilege principles across all systems
While no system is 100% impenetrable, we employ defense-in-depth strategies to minimize risk.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate or incomplete data
- Erasure — you may request deletion of your account data. We will delete it except records we must retain or that are held in our tamper-evident audit log, which is append-only by design and cannot be selectively altered; we will explain what was deleted and what was retained and why.
- Restriction — request that we limit processing of your data
- Portability — request your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests or direct marketing
- Withdraw Consent — withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at privacy@perimeterone.ai. We will respond within 30 days (or the timeframe required by applicable law).
8.1 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete, and the right to opt out of the sale or sharing of personal information. We do not sell personal information.
9. International Data Transfers
Your data may be transferred to and processed in the United States or other jurisdictions where our service providers operate — for example, our hosting is in the EU (Hetzner) while some payment and AI-model providers are based in the United States. Where these providers process personal data on our behalf, they do so under their own data processing agreements, including Standard Contractual Clauses where applicable. By using the Services, you understand that your data may be processed outside your home jurisdiction.
10. Children’s Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 18, we will delete it promptly. Contact us if you believe we have inadvertently collected such data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Site at least 30 days before they take effect. Your continued use of the Services after the effective date constitutes acceptance of the revised policy.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us:
- Email: privacy@perimeterone.ai
- Mail: PerimeterOne LLC, 8 The Green, Suite A, Dover, DE 19901