Compliance · GDPR
GDPR, by construction
AxForge is GDPR compliant: EU-only processing on hardware we own, zero prompt retention, documented data-processing practices. This page shows the responsibility split — the trust centre carries the evidence.
The split
What we handle, what stays yours
| AxForge as processor | Prompts, completions and uploaded context — processed in memory in the EU on your documented instruction (each API request is the instruction), never stored, never used for training. Terms in the DPA. |
|---|---|
| AxForge as controller | Your account, billing contact and support messages — each with a stated retention period in the retention table. |
| You as controller | What you send through the API and your lawful basis for it. Your users, your purposes — our infrastructure is built so the data-residency and retention part of that job is already done. |
Controls
The concrete properties
| Residency | Inference in Sweden and Málaga, Spain — no processing outside the EEA, no foreign failover. Data residency. |
|---|---|
| Retention | Prompt bodies: zero retention. Everything else: the published table, item by item. |
| Subprocessors | One authoritative register with change notice — referenced by the DPA, not duplicated across pages. |
| Paper | DPA (launch draft), privacy notice, security posture — written to be read, not framed. |