Ask a normal question.
Leak nothing.
Nobody types card numbers at an AI — the leak happens when the AI pulls the answer from your tools, because that data arrives full of customer details. Pick a question and watch Waqi strip them out mid-flight, while you still get the answer.
Not ready to buy today? Take the Pilot Pack.
The 14-day pilot checklist, the DPA, and the security model — everything you need to evaluate Waqi properly or make the case to your team.
Sending customer data to an AI is a disclosure you're accountable for
Under UK and EU GDPR, personal data that reaches a third-party AI provider is processing you are responsible for — whether it went there by policy or by paste. The UAE's PDPL and Cybercrime Law carry their own duties around disclosing personal and financial data. What that exposure looks like in practice:
Fines that scale with you
The most serious UK GDPR breaches can be fined up to £17.5M or 4% of worldwide annual turnover, whichever is higher (€20M / 4% under EU GDPR). For a small business the headline number matters less than the fact that the regulator sets it — not you.
The 72-hour clock
A notifiable personal-data breach must be reported to the regulator within 72 hours of you becoming aware of it. If you can't say what left the building, you can't write that report — and "we don't know what the AI saw" is not an answer an investigator accepts.
The part no insurer covers
Enforcement action is public. Customers forgive outages; they rarely forgive finding out their card details or health notes sat in a third party's AI logs. The trust you lose costs more than any fine.
To be precise about what Waqi does and doesn't do: it is a control, not a compliance certificate. It minimises the personal data your AI provider ever receives (the identifiers it detects never leave), gives every listed free-text field a one-click hard wall, and writes a per-call audit log — the evidence trail that lets you answer "what exactly did the model see?" with a record instead of a guess. Your policies, contracts, and processes remain yours to get right — Waqi makes the data-minimisation part real. Read our DPA.
The real thing does more than this page
The hosted proxy runs these same rules on every tool response, plus field-aware detection (name and card-reference fields), one-click hiding of whole free-text fields, per-member links, and a per-call audit log of who asked for what and what was stripped.