Worldline
Back to application

Privacy Policy

Sensitive Data De-identification Service

Data Processing Principles

This service is designed with privacy as a core architectural principle. All data processing follows these guarantees:

What Data Is Processed

Data Category Purpose Retention
Uploaded content (text, documents, images) Entity detection and de-identification Server: none — discarded after response. Browser: until tab is closed.
Authentication claims (username, user ID) Session management and access control Session duration only (JWT cookie)
Request metadata (method, path, status, duration) Operational monitoring and diagnostics Log rotation policy (no PII logged)
Usage counters (username, input type, mode) Prometheus metrics for capacity planning In-memory only — reset on restart

Reversible Mode & Encryption Keys

When using reversible de-identification, a unique encryption key is generated per request using cryptographically secure random generation (Fernet / AES-128-CBC + HMAC-SHA256). The key is delivered to you in the downloaded key file and is never stored on the server. Only you possess the key needed to restore the original content. If the key file is lost, the original data cannot be recovered.

Technical Safeguards

Your Rights (GDPR)

Assessment in progress: this service has not yet been formally assessed by the Compliance team for GDPR conformity. The assessment is ongoing, and the information below reflects the service's intended design rather than a validated compliance position.

Under the General Data Protection Regulation, you have the right to:

Last updated: September 2026