Privacy Policy

Perissos Limited

Last updated: 26 August 2026

This policy explains what personal data Perissos Limited holds, why we hold it, who we share it with, and what you can do about it. It is written to be read, so where something is a limit on us we say so directly.

1. Who we are

Perissos Limited is the data controller for the personal data described here. We are registered in Ireland under company number 822725, with registered office at 31 Danesfort, Ballincrokig, Whites Cross, Cork, T23 DC7K, Ireland.

We are not required to appoint a Data Protection Officer. Privacy questions go to reports@perissos.ai and are handled by the company's director.

2. What we collect

Account information. Your email address, short-lived sign-in links, and the name you give your workspace.

Workspace content. The records you create or upload: assessments you choose to save, policies, risk entries, competence and operating records, statement of applicability decisions, evidence files, and system descriptions. Some of these may contain personal data if you choose to put it there, for example the name of a person who owns a risk.

Connector data. Where you connect a system, the read-only facts our checks collect from it. These are configuration and posture facts, such as whether two-factor authentication is required across an organisation or whether a storage bucket is encrypted, and some include identifiers such as an account or repository name.

Connector credentials. The access you grant us, held so that scheduled collection can run. How these are protected is described in section 5.

Usage records. Logs of requests to the service, records of every Gate run including who ran it and when, and records of every access to a shared evidence pack.

Payment information. We do not hold your card. Stripe processes payments, and we hold the customer and subscription identifiers Stripe gives us, together with your plan and its status.

3. Why we hold it, and on what basis

WhatWhyLawful basis
Account informationTo sign you in and to contact you about the servicePerformance of a contract
Workspace contentTo provide the judgement the service exists to givePerformance of a contract
Connector data and credentialsTo collect the evidence you asked us to collectPerformance of a contract
Usage and audit recordsTo keep a record of who did what, which the product's own honesty depends on, and to secure the serviceLegitimate interests
Payment identifiersTo bill you and manage your subscriptionPerformance of a contract, and legal obligation for tax records
Service emailsTo tell you about billing, renewals and material changesPerformance of a contract

We send service emails only. We do not send marketing email, and no marketing consent is implied by creating an account. If that ever changes, it will be by your separate, explicit consent.

Where we rely on legitimate interests, our interest is in operating a service whose central claim is that every judgement can be traced to a record and a person. You can object; section 8 explains how.

4. AI processing

Perissos uses Anthropic's API to classify system descriptions, extract claims from text, draft documents, and power the assistant. When you run an assessment, what you enter, the details you select, and text fetched from any website address you give us are sent to Anthropic's API for processing. If you use the assistant, the messages you send it and the workspace records needed to answer them are also sent. Your uploaded evidence files are never sent.

That processing happens outside the EU. Our contracting entity is Anthropic Ireland, Limited, and the transfer is covered by Anthropic's data processing addendum, which incorporates the European Commission's Standard Contractual Clauses.

Under the commercial terms governing our use of the API, Anthropic may not train models on the content we send, and we have confirmed that no setting on our account changes that.

The product does not make decisions about individuals. It judges organisational records against published obligations, and every judgement it renders names the records it rests on so a person can check it.

5. How your data is protected, and what that protection does not cover

We protect two kinds of thing in two different ways, and the difference matters.

Credentials you give us to connect a system, such as an AWS role or a GitHub token, are encrypted by our application before they are stored, using AES-256-GCM under a key we hold separately from the database. Anyone with access to the database alone cannot read them.

Evidence files are different. Your uploaded documents and the snapshots our connectors collect are stored in Amazon Web Services in Frankfurt, encrypted at rest by AWS using AWS's own keys. We do not encrypt these files ourselves before storing them, so AWS can read their contents.

We describe evidence files as sealed. Sealing means we record a SHA-256 hash of the file and sign that record, so we can prove a file has not been altered since we received it. Sealing proves a file is unchanged. It does not keep the file secret from AWS.

Both of these are ordinary, defensible choices. We state them separately because describing one and letting you assume it applies to the other would be misleading.

6. Who we share it with

We do not sell your data and we do not share it for advertising.

We use the following providers, each under terms that restrict what they may do with your data:

ProviderWhat they doWhere
AnthropicModel inference for classification, extraction, drafting and the assistantOutside the EU, under the safeguards in section 4
NeonDatabase hostingFrankfurt, Germany
StripePayment processing; for eligible transactions Stripe is the merchant of record and handles tax on the salePer Stripe's own terms
Amazon Web ServicesStorage of sealed evidence files, meaning your uploaded documents and connector snapshots, encrypted at rest under AWS's keysFrankfurt, Germany
RailwayApplication hostingEU
BrevoTransactional email deliveryFrance
CloudflareDNS and email routing onlyGlobal network

One distinction we do not want blurred: Amazon Web Services appears above as our storage provider. Separately, AWS may be a system you connect so that we can read posture facts from your own account. In that second relationship, AWS (like GitHub or Google) receives the fact and timing of our requests under an authenticated identity you granted. Nothing of ours is stored there.

We also share data where you direct us to, for example when you grant a named reviewer access to an evidence pack, or publish a trust profile.

We may disclose data where the law requires it. Where we are permitted to tell you, we will.

7. Where your data is held

Your workspace data is stored in the European Union: the database and all evidence files are in Frankfurt, Germany. The one transfer outside the EU is the Anthropic processing described in section 4, under the safeguards described there.

8. Your rights

Under the GDPR you can ask us to give you a copy of your personal data, correct data that is wrong, delete data where we have no continuing basis to hold it, restrict how we use it or object to processing based on legitimate interests, and send your data to another provider in a portable format.

Two of those rights are built into the product itself. From your account page you can export your entire workspace: one file with every record and every evidence file, sealed, with an offline verification script that works without us, free on every plan including after you cancel. And you can delete your account: deletion is immediate, removes everything in one transaction, and removal of stored file copies completes moments after.

For anything else, email reports@perissos.ai. We will respond within one month.

If you are unhappy with how we handle your data you can complain to the Irish Data Protection Commission at dataprotection.ie, or to the supervisory authority where you live.

9. How long we keep it

Your data is kept for as long as your workspace exists. When you delete your account, everything in the workspace is deleted immediately in one transaction, and removal of stored file copies completes moments after. Records we are legally required to keep, such as billing records for tax purposes, are retained for the period Irish law requires, and nothing else survives.

Stored Gate runs are immutable while the workspace exists. A run records what was judged and when, and we do not rewrite it afterwards, because a record that can be revised is not a record. A past run may therefore contain a sentence we have since improved, shown with the date it was judged. When a workspace is deleted, its runs are deleted with it.

10. Cookies

The site sets exactly two cookies, both strictly necessary for signing you in securely and protecting your session. We set no analytics cookies, no advertising cookies, and no third-party trackers, which is why you do not see a cookie banner.

11. Publishing and public information

Some features publish deliberately. A public trust profile is visible to anyone with its address, and published profile links contain no personal data. An evidence pack shared with a reviewer is visible to whoever holds the link, for as long as the grant lasts, and every access is logged where you can see it.

Publishing is always your action, and you choose what is included.

12. Children

The service is for organisations and is not directed at children. We do not knowingly collect personal data from anyone under 16.

13. Changes to this policy

We will update this policy when what we do changes. The current version is always at perissos.ai/privacy with the date it was last updated. Where a change materially affects you, we will tell you rather than relying on you noticing.

14. Contact

reports@perissos.ai