PII Pseudonymizer

Terms of service

Last updated: 2026-10-03

These terms apply to PII Pseudonymizer (the “service”), operated by Kwizmo d.o.o., Ogrinova 31, 1291 Škofljica, Slovenia (“we”, “us”). By using the service you agree to these terms. If you do not agree, do not use the service.

1. What the service does

The service looks for personal data in a text you submit, such as names, addresses, phone numbers, e-mail addresses, bank and card numbers and identification numbers, and replaces what it finds with fictitious values. It can also put original values back into a text when you provide the list of replacements. The service is available through the web page, through a programming interface (the “API”, documented at api-docs.php). These terms apply to all of them.

The browser extension offered on this site processes text only on your own device and sends nothing to us; these terms apply to it as far as they concern correct detection, liability and acceptable use.

If your organisation has a separate written agreement with us (for example a business plan with a data processing agreement or a service level agreement), that agreement takes precedence over these terms where they differ.

You accept these terms by ticking the box on the web page, or by sending "accept_terms": true with an API request. If you use the API on behalf of an organisation or build it into your own product, you confirm that you are authorised to accept these terms for that organisation, and you are responsible for the use of the service through your product.

2. What we store

For each text you submit, through the web page or the API, we store only:

We use this information only to limit the number of requests (currently 10 per minute per network) and to detect and stop abuse of the service.

If you use an API key (business plans), we additionally store the key's identifier with each log line and count your requests per month, for billing and to enforce the limits agreed with you. For each key we keep the customer name, the agreed limits and a one-way hash of the key; the key itself is not stored.

The legal basis for this processing is our legitimate interest in keeping the service available and secure (Article 6(1)(f) GDPR).

3. What we never store

No input or output data is ever stored. The text you submit, the result, the list of replacements (including a list you send to restore a text), the names you enter, the consistency key and your chosen options are processed only in the server’s working memory while your request is handled, and are discarded as soon as the response has been sent. They are not written to disk, databases or logs, not shared with third parties and not used to train any system.

When you use the LLM gateway, the protected version of your request is sent to the AI provider that is configured for the model you chose, and the provider's answer is returned to you with the original values put back. We store neither the request nor the answer. The AI provider is an independent recipient: its own terms and privacy policy apply to what it receives, and we have no control over what it stores.

The public pages set no cookies, use no analytics or tracking, and load no resources from other websites. (The operator’s own administration page uses a session cookie; it is not part of the service offered to you.) The “Put the real data back” tool runs entirely in your browser; its content is not sent to us.

4. No guarantee of correct detection

Detection is automatic and based on patterns, heuristics and a statistical (machine-learning) model. Measured results are published on the accuracy page; they describe test texts, not your texts. It will not find all personal data and it may replace text that is not personal data. In particular:

You must review every result before you use or share it. You alone decide whether a result is suitable for your purpose.

5. Acceptable use

You may use the service only for lawful purposes and only for texts you are entitled to process. You must not:

Automated use through the API is welcome within the published limits. You are responsible for keeping lists of replacements that you receive secure, because they contain the original personal data.

We may block IP addresses or networks that break these rules.

6. Warranties

Free use. The free web page, the free API allowance and the browser extension are provided free of charge, “as is” and “as available”, without warranties of any kind, express or implied, including warranties of accuracy, completeness, fitness for a particular purpose, availability or non-infringement. We may change, limit or discontinue the free service at any time without notice.

Paid plans. If you pay for a plan, we warrant that the service will perform materially as described in its documentation, and that its availability will meet the figure published for that plan on the business page or agreed in a service level agreement. Where a service level agreement applies, the service credits set out in it are your only remedy for availability below that figure. We may change the service; for a change that materially reduces the functions of a paid plan, and before we discontinue a paid plan, we will give you at least 30 days’ notice by e-mail, and you may then end the plan and receive back the unused part of any fee you have paid in advance.

Software you run yourself. A self-hosted installation and the browser extension run on your own systems and under your control. We warrant that the package matches its documentation when it is delivered; its operation in your environment is covered only by a support or maintenance contract, if you have one.

Both. We give no warranty of any kind, in any plan, that detection is complete or correct: clause 4 applies to free and to paid use alike, and no plan, availability figure or support contract changes it.

7. Limitation of liability

To the fullest extent permitted by law, we are not liable for any damage or loss arising from or related to the use of the service, including in particular:

For a paid plan, where liability cannot be excluded under the paragraph above, our total liability for all claims arising in any twelve-month period is limited to the fees you paid for the plan in the twelve months before the event that gave rise to the claim. Neither party is liable for indirect or consequential loss, loss of profit, loss of business or loss of goodwill.

Nothing in these terms limits liability that cannot be limited under applicable law, such as liability for intent or gross negligence where the law does not allow it to be excluded, or liability for death or personal injury.

8. Your responsibility

You are responsible for the texts you submit, for complying with data protection and other laws when you process them, and for everything you do with the results. You agree to indemnify us against claims by third parties arising from your use of the service in breach of these terms or of the law.

9. Your rights

Under the GDPR you can ask for access to, erasure of, or restriction of the IP address records described in section 2, and you can object to their processing. Because we store no other data, we cannot link records to your name; please tell us the IP address and the approximate time of your requests. You also have the right to lodge a complaint with a data protection supervisory authority.

10. Changes

We may update these terms. The date at the top shows the latest version. Using the service after a change means you accept the updated terms.

If you are on a paid plan, we will tell you by e-mail at least 30 days before a change to these terms takes effect. If you do not accept it, you may end the plan before that date and receive back the unused part of any fee you have paid in advance.

11. Governing law

These terms are governed by the law of the Republic of Slovenia. The courts of Ljubljana, Slovenia have jurisdiction, unless mandatory consumer protection law provides otherwise. If a provision of these terms is invalid, the remaining provisions stay in effect.

12. Contact

Kwizmo d.o.o.
Ogrinova 31, 1291 Škofljica, Slovenia
info@kwizmo.eu