Legal · Launch draft v0.1
Data Processing Agreement (launch draft)
AxForge's Article 28 processing terms in summary form, published for transparency and review. This draft is not yet offered for execution — the service has not begun. The executable agreement is offered before the first commercial contract is signed.
Read this first
What this draft is
This page is our own draft agreement text in summary form, published so prospective customers can review the processing terms we intend to offer before any contract exists. Every clause below is a launch draft and its wording may change before the executable version. It follows the structure of Article 28(3) GDPR, and IMY's processor-agreement checklist is the standard we check it against.
Scope
Parties, subject-matter and duration
| Parties and roles | The customer is the controller; AxForge is the processor. The contracting legal entity's registration details will be published on the legal notice before the first commercial contract is signed. |
| Subject-matter | Provision of AI inference services — the hosted-model API and dedicated deployments — on hardware AxForge owns and operates in the EEA. |
| Duration | The term of the service agreement. Processing ends when the agreement ends, followed by deletion or return as set out below. |
| Nature and purpose | Receiving customer-submitted prompts and context, running them through the selected models and returning completions. Prompt and completion bodies are processed in memory only and discarded when the request completes. No other purpose — and never training. |
Annex I summary
Data categories and data subjects
| Data categories | Prompts, completions, uploaded context and API request metadata — including any personal data the customer places in that content. |
| Special categories | Determined by the customer, who must have a lawful basis. Special-category data is discouraged on the shared API. |
| Data subjects | Determined by the customer — typically the customer's own users, employees and customers. |
Article 28(3)
Processor obligations
| Documented instructions | AxForge processes personal data only on the customer's documented instructions; each API request is such an instruction. If we believe an instruction infringes data-protection law, we inform the customer. |
| Confidentiality | Access is limited to named operators, each committed to confidentiality. |
| Technical and organisational measures | In summary: TLS 1.3 at the EU edge; an encrypted private WireGuard tunnel from edge to inference; prompt and completion bodies held in memory only, never written to disk; enforced row-level-security tenant isolation; cryptographically authenticated internal service calls; inference on hardware AxForge owns in a controlled-access facility in Sweden. The full TOMs annex is available under NDA. |
| Subprocessors | General written authorisation with a public subprocessor register — currently Hetzner Online GmbH (EU edge hosting, Germany) and Atom9 (console login, Sweden). Register subscribers are notified by email 30 days before a new subprocessor takes effect; objections via hello@axforge.ai. |
| Data-subject assistance | We assist the customer in responding to data-subject requests. Prompt and completion bodies are never stored, so there is typically nothing held to access or erase; retained metadata follows the retention table. |
| DPIA and regulatory assistance | We provide reasonable assistance with data-protection impact assessments and prior consultation (Articles 35–36), based on the information available to us as processor. |
| Personal-data breach notification | We notify affected controllers of a personal-data breach without undue delay (Article 33(2)), to the customer's registered contact. |
| Audits and inspections | We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, by the customer or a mandated auditor. Pre-release, the supporting audit evidence is being finalized for commercial launch. |
| Deletion and return | At the end of the service we delete or return personal data at the customer's choice and delete existing copies, unless EU or member-state law requires storage. Prompt and completion bodies are never stored, so end-of-service deletion covers account and metadata stores; backups hold metadata only, on a 35-day rotation, and never contain prompt or completion bodies. |
Residency
Processing location and disclosure
| EEA-only processing | All processing under this agreement takes place inside the EEA. |
| No foreign failover | If all EEA capacity is unavailable, requests queue or fail — they are never routed outside the EEA. |
| Legally compelled disclosure | If legally compelled to disclose customer personal data, we challenge the demand where lawful and notify the customer, unless we are legally prohibited from doing so. There are no stored prompt or completion bodies to hand over. |
Reference bar
The standard we check against
This draft is written against IMY's processor-agreement checklist — the Swedish supervisory authority's published guidance on what an Article 28 agreement must contain (imy.se). Review comments are welcome at hello@axforge.ai.
Related
Where the details live
Document history
Version
Version 0.1 (launch draft) · Effective 2026-08-26 · Not offered for execution.
- 2026-08-26 — first published draft. Published for transparency and review; the service has not begun and this draft is not yet offered for execution.