Legal · Launch draft v0.1

Data Processing Agreement (launch draft)

AxForge's Article 28 processing terms in summary form, published for transparency and review. This draft is not yet offered for execution — the service has not begun. The executable agreement is offered before the first commercial contract is signed.

Draft — not offered for execution Version 0.1 · Effective 2026-08-26

Read this first

What this draft is

This page is our own draft agreement text in summary form, published so prospective customers can review the processing terms we intend to offer before any contract exists. Every clause below is a launch draft and its wording may change before the executable version. It follows the structure of Article 28(3) GDPR, and IMY's processor-agreement checklist is the standard we check it against.

Scope

Parties, subject-matter and duration

Parties and rolesThe customer is the controller; AxForge is the processor. The contracting legal entity's registration details will be published on the legal notice before the first commercial contract is signed.
Subject-matterProvision of AI inference services — the hosted-model API and dedicated deployments — on hardware AxForge owns and operates in the EEA.
DurationThe term of the service agreement. Processing ends when the agreement ends, followed by deletion or return as set out below.
Nature and purposeReceiving customer-submitted prompts and context, running them through the selected models and returning completions. Prompt and completion bodies are processed in memory only and discarded when the request completes. No other purpose — and never training.

Annex I summary

Data categories and data subjects

Data categoriesPrompts, completions, uploaded context and API request metadata — including any personal data the customer places in that content.
Special categoriesDetermined by the customer, who must have a lawful basis. Special-category data is discouraged on the shared API.
Data subjectsDetermined by the customer — typically the customer's own users, employees and customers.

Article 28(3)

Processor obligations

Documented instructionsAxForge processes personal data only on the customer's documented instructions; each API request is such an instruction. If we believe an instruction infringes data-protection law, we inform the customer.
ConfidentialityAccess is limited to named operators, each committed to confidentiality.
Technical and organisational measuresIn summary: TLS 1.3 at the EU edge; an encrypted private WireGuard tunnel from edge to inference; prompt and completion bodies held in memory only, never written to disk; enforced row-level-security tenant isolation; cryptographically authenticated internal service calls; inference on hardware AxForge owns in a controlled-access facility in Sweden. The full TOMs annex is available under NDA.
SubprocessorsGeneral written authorisation with a public subprocessor register — currently Hetzner Online GmbH (EU edge hosting, Germany) and Atom9 (console login, Sweden). Register subscribers are notified by email 30 days before a new subprocessor takes effect; objections via hello@axforge.ai.
Data-subject assistanceWe assist the customer in responding to data-subject requests. Prompt and completion bodies are never stored, so there is typically nothing held to access or erase; retained metadata follows the retention table.
DPIA and regulatory assistanceWe provide reasonable assistance with data-protection impact assessments and prior consultation (Articles 35–36), based on the information available to us as processor.
Personal-data breach notificationWe notify affected controllers of a personal-data breach without undue delay (Article 33(2)), to the customer's registered contact.
Audits and inspectionsWe make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, by the customer or a mandated auditor. Pre-release, the supporting audit evidence is being finalized for commercial launch.
Deletion and returnAt the end of the service we delete or return personal data at the customer's choice and delete existing copies, unless EU or member-state law requires storage. Prompt and completion bodies are never stored, so end-of-service deletion covers account and metadata stores; backups hold metadata only, on a 35-day rotation, and never contain prompt or completion bodies.

Residency

Processing location and disclosure

EEA-only processingAll processing under this agreement takes place inside the EEA.
No foreign failoverIf all EEA capacity is unavailable, requests queue or fail — they are never routed outside the EEA.
Legally compelled disclosureIf legally compelled to disclose customer personal data, we challenge the demand where lawful and notify the customer, unless we are legally prohibited from doing so. There are no stored prompt or completion bodies to hand over.

Reference bar

The standard we check against

This draft is written against IMY's processor-agreement checklist — the Swedish supervisory authority's published guidance on what an Article 28 agreement must contain (imy.se). Review comments are welcome at hello@axforge.ai.

Document history

Version

Version 0.1 (launch draft) · Effective 2026-08-26 · Not offered for execution.

  • 2026-08-26 — first published draft. Published for transparency and review; the service has not begun and this draft is not yet offered for execution.
© 2026 AxForge · EU-hosted AI infrastructure Pricing Docs Trust Privacy Terms