Last updated: March 2026
GreenLightz LLC ("GreenLightz," "we," "us," or "our") operates the GreenLightz governance API service. This Privacy Policy explains how we collect, use, and protect information when you use our service.
0. Our Role — Processor / Service Provider
For data the Customer organization submits to the GreenLightz governance API in connection with its own end users, the Customer is the data controller (GDPR) / business (CCPA/CPRA) and GreenLightz acts as a data processor / service provider, processing such data on the Customer's documented instructions and only to provide the governance evaluation service described in our Terms of Service.
In that processor / service-provider role, GreenLightz:
- does not sell Customer data;
- does not share Customer data for cross-context behavioral advertising;
- does not use Customer data to train machine-learning models;
- does not combine Customer data with data from other sources outside of providing the service;
- processes Customer data only for the documented purpose of governance evaluation, audit-trail generation, security, and service operation.
A formal Data Processing Addendum (DPA) covering GDPR Article 28 processor obligations, US state-privacy service-provider terms (CCPA / CPRA, VCDPA, CPA and similar), an up-to-date sub-processor list, and Standard Contractual Clauses where applicable is available on request from [email protected]. For business contact information about Customer's own personnel (e.g., name and work email of an onboarding contact), GreenLightz acts as an independent controller for the limited purpose of account administration and security.
1. Information We Process
Information you provide:
- Business contact information (name, email, company) provided during onboarding
- API requests sent to our governance endpoint for evaluation
- Policy configurations (YAML policy packs) you define
- Communications with our team
Information collected automatically:
- API usage metrics (request counts, latency, error rates)
- Standard HTTP headers for security and rate limiting
2. How We Handle API Data
GreenLightz is designed with a Privacy-First architecture:
- All identifiers are hashed. Actor IDs, target IDs, and tenant IDs in audit logs and evidence trails are stored as cryptographic hashes (SHA-256 with HMAC), not plaintext.
- No PII in logs. Our logging, monitoring, and API responses never contain personally identifiable information.
- No content storage. We evaluate the action metadata you send (amount, type, reason) but do not store or index free-text content beyond the evaluation window.
- Evidence is tamper-evident. Evaluation records are content-hash chained, with HMAC signing attached when the operator configures an evidence signing key. They contain hashed IDs only.
3. How We Use Your Information
- To provide the governance evaluation service
- To enforce your policy configurations
- To generate audit trails and evidence packets
- To detect and prevent abuse of the API
- To improve service reliability and accuracy
We do not sell your data to third parties. We do not use your policy configurations or evaluation data to train machine learning models.
4. Third-Party Services
We use the following services to operate:
- Vercel — website hosting and CDN.
- Render — API hosting and infrastructure.
- AI providers (optional) — LLM-enhanced classification. When enabled, only hashed metadata is sent. Core governance operates offline-first without any AI provider dependency.
5. Data Retention
Evaluation evidence is retained per your policy configuration. Default retention is 180 days for audit records. You can configure shorter retention periods via your policy pack. Hashed, aggregated metrics may be retained for service improvement.
6. Data Security
- HTTPS encryption for all data in transit
- Tamper-evident evidence packets via content-hash chain; HMAC signing attaches when an operator signing key is configured
- All identifiers hashed with per-tenant keys
- API key authentication with pepper-hardened storage
- Rate limiting and circuit breakers on all endpoints
7. Your Rights and Customer Control
Depending on your jurisdiction, you may have the right to:
- Access the data we hold about your organization
- Request correction of inaccurate data
- Request deletion of your data, subject to retention required by law or active dispute/audit obligations
- Export your evaluation history
In addition, at any time the Customer organization may request, in writing to the contact below, that GreenLightz:
- Pause processing of new API requests for its tenant
- Terminate its tenant and revoke all associated API keys
- Export its evaluation history, policy packs, and audit trail in a machine-readable format
- Delete its data, subject to any retention required by law or by Customer's own active dispute or audit obligations
Contact us at [email protected] to exercise any of these rights or to request a pause, termination, export, or deletion (subject to retention required by law or active dispute/audit obligations; tamper-evident evidence chain integrity preserved). We will acknowledge within five (5) business days and complete the action or respond substantively within thirty (30) days.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify customers of material changes via email. The "Last updated" date at the top reflects the most recent revision.