Terms of service
Last updated: 2026-10-03
These terms apply to PII Pseudonymizer (the “service”), operated by Kwizmo d.o.o., Ogrinova 31, 1291 Škofljica, Slovenia (“we”, “us”). By using the service you agree to these terms. If you do not agree, do not use the service.
1. What the service does
The service looks for personal data in a text you submit, such as names, addresses, phone numbers, e-mail addresses, bank and card numbers and identification numbers, and replaces what it finds with fictitious values. It can also put original values back into a text when you provide the list of replacements. The service is available through the web page, through a programming interface (the “API”, documented at api-docs.php). These terms apply to all of them.
The browser extension offered on this site processes text only on your own device and sends nothing to us; these terms apply to it as far as they concern correct detection, liability and acceptable use.
If your organisation has a separate written agreement with us (for example a business plan with a data processing agreement or a service level agreement), that agreement takes precedence over these terms where they differ.
You accept these terms by ticking the box on the web page, or by sending "accept_terms": true with an API request. If you use the API on behalf of an organisation or build it into your own product, you confirm that you are authorised to accept these terms for that organisation, and you are responsible for the use of the service through your product.
2. What we store
For each text you submit, through the web page or the API, we store only:
- the date and time of the request, and
- the IP address the request came from.
We use this information only to limit the number of requests (currently 10 per minute per network) and to detect and stop abuse of the service.
- A request log with one line per request (time and IP address) is deleted automatically after 30 days.
- The rate-limit counter holds a one-way, keyed hash of the IP address together with request times and is deleted within a few minutes.
- Viewing the pages and the API information endpoints does not create entries in these records. Our hosting provider’s web server may keep its own technical access logs; we configure them to contain no more than the time, IP address and requested page.
If you use an API key (business plans), we additionally store the key's identifier with each log line and count your requests per month, for billing and to enforce the limits agreed with you. For each key we keep the customer name, the agreed limits and a one-way hash of the key; the key itself is not stored.
The legal basis for this processing is our legitimate interest in keeping the service available and secure (Article 6(1)(f) GDPR).
3. What we never store
No input or output data is ever stored. The text you submit, the result, the list of replacements (including a list you send to restore a text), the names you enter, the consistency key and your chosen options are processed only in the server’s working memory while your request is handled, and are discarded as soon as the response has been sent. They are not written to disk, databases or logs, not shared with third parties and not used to train any system.
When you use the LLM gateway, the protected version of your request is sent to the AI provider that is configured for the model you chose, and the provider's answer is returned to you with the original values put back. We store neither the request nor the answer. The AI provider is an independent recipient: its own terms and privacy policy apply to what it receives, and we have no control over what it stores.
The public pages set no cookies, use no analytics or tracking, and load no resources from other websites. (The operator’s own administration page uses a session cookie; it is not part of the service offered to you.) The “Put the real data back” tool runs entirely in your browser; its content is not sent to us.
4. No guarantee of correct detection
Detection is automatic and based on patterns, heuristics and a statistical (machine-learning) model. Measured results are published on the accuracy page; they describe test texts, not your texts. It will not find all personal data and it may replace text that is not personal data. In particular:
- names without a recognisable cue, unusual spellings, and data in unsupported formats or languages may be missed;
- ordinary words, numbers or dates may be replaced by mistake;
- the fictitious values may coincidentally match real people, addresses or numbers;
- the result is pseudonymized, not anonymized: the context of a text can still identify a person, so the result may still be personal data under data protection law.
You must review every result before you use or share it. You alone decide whether a result is suitable for your purpose.
5. Acceptable use
You may use the service only for lawful purposes and only for texts you are entitled to process. You must not:
- submit data you have no legal right to process;
- use the service to create false identities, forged documents or misleading content, or to deceive or defraud anyone;
- attempt to overload, circumvent the request limits of, probe, or attack the service;
- use multiple IP addresses or other means to exceed the published request limits.
Automated use through the API is welcome within the published limits. You are responsible for keeping lists of replacements that you receive secure, because they contain the original personal data.
We may block IP addresses or networks that break these rules.
6. Warranties
Free use. The free web page, the free API allowance and the browser extension are provided free of charge, “as is” and “as available”, without warranties of any kind, express or implied, including warranties of accuracy, completeness, fitness for a particular purpose, availability or non-infringement. We may change, limit or discontinue the free service at any time without notice.
Paid plans. If you pay for a plan, we warrant that the service will perform materially as described in its documentation, and that its availability will meet the figure published for that plan on the business page or agreed in a service level agreement. Where a service level agreement applies, the service credits set out in it are your only remedy for availability below that figure. We may change the service; for a change that materially reduces the functions of a paid plan, and before we discontinue a paid plan, we will give you at least 30 days’ notice by e-mail, and you may then end the plan and receive back the unused part of any fee you have paid in advance.
Software you run yourself. A self-hosted installation and the browser extension run on your own systems and under your control. We warrant that the package matches its documentation when it is delivered; its operation in your environment is covered only by a support or maintenance contract, if you have one.
Both. We give no warranty of any kind, in any plan, that detection is complete or correct: clause 4 applies to free and to paid use alike, and no plan, availability figure or support contract changes it.
7. Limitation of liability
To the fullest extent permitted by law, we are not liable for any damage or loss arising from or related to the use of the service, including in particular:
- misuse of the service or of its results by you or by anyone else;
- personal data that was not detected, incorrectly detected or incorrectly replaced, and any disclosure of personal data that results from this;
- decisions made on the basis of a result, errors in the fictitious values, or their resemblance to real persons or data;
- interruptions, delays, changes to the API, loss of data in your browser or systems, or unavailability of the service; where a service level agreement applies, the credits in that agreement are the remedy for unavailability;
- the security of replacement lists and results after they have been delivered to you.
For a paid plan, where liability cannot be excluded under the paragraph above, our total liability for all claims arising in any twelve-month period is limited to the fees you paid for the plan in the twelve months before the event that gave rise to the claim. Neither party is liable for indirect or consequential loss, loss of profit, loss of business or loss of goodwill.
Nothing in these terms limits liability that cannot be limited under applicable law, such as liability for intent or gross negligence where the law does not allow it to be excluded, or liability for death or personal injury.
8. Your responsibility
You are responsible for the texts you submit, for complying with data protection and other laws when you process them, and for everything you do with the results. You agree to indemnify us against claims by third parties arising from your use of the service in breach of these terms or of the law.
9. Your rights
Under the GDPR you can ask for access to, erasure of, or restriction of the IP address records described in section 2, and you can object to their processing. Because we store no other data, we cannot link records to your name; please tell us the IP address and the approximate time of your requests. You also have the right to lodge a complaint with a data protection supervisory authority.
10. Changes
We may update these terms. The date at the top shows the latest version. Using the service after a change means you accept the updated terms.
If you are on a paid plan, we will tell you by e-mail at least 30 days before a change to these terms takes effect. If you do not accept it, you may end the plan before that date and receive back the unused part of any fee you have paid in advance.
11. Governing law
These terms are governed by the law of the Republic of Slovenia. The courts of Ljubljana, Slovenia have jurisdiction, unless mandatory consumer protection law provides otherwise. If a provision of these terms is invalid, the remaining provisions stay in effect.
12. Contact
Kwizmo d.o.o.
Ogrinova 31, 1291 Škofljica, Slovenia
info@kwizmo.eu
