Data handling
GDPR compliant, and your data never leaves the EU: zero prompt retention, no training on customer data. The deeper story lives in the trust centre.
The claim
We prove it with specifics: EU processing on hardware we own, memory-only prompts, a public subprocessor register, a retention table and a DPA — all documented in the trust centre.
That is the whole pitch: compliance you can verify, not a badge. Point your DPO at the trust centre — the subprocessor register, the retention table and the DPA are ready to read.
Commitments
| Property | Commitment |
|---|---|
| Prompt retention | Zero. Prompts and completions are processed in memory in Sweden — not written to disk, not logged, not retained. Data that is never stored cannot leak from storage or be forgotten late: this is the strongest data-minimization posture an inference provider can take. |
| Training on customer data | Never. Prompts and completions are never used to train anything. |
| Retained metadata | Token counts, timestamps, status — for billing and operations. Nothing else. |
| Processing location | EU regions on hardware AxForge owns: eu-se-1 · Stockholm and eu-es-1 · Málaga live; more EU regions — in deployment. Region pinned on the key via x-axforge-region, echoed on the response. |
| Transport | TLS 1.3, terminated in the EU. |
| Subprocessors | EU-hosted infrastructure; details in the trust centre. |
| Written commitments | The privacy policy states all of the above as policy, not marketing. |
Your side of the line
We handle the provider side. These stay yours with any provider — and our published facts make each one faster to close:
| Obligation | Why it cannot be outsourced to infrastructure |
|---|---|
| Lawful basis | Only you know why you process personal data. An API cannot supply consent, contract necessity or legitimate interest on your behalf. |
| DPIA | Where your use of AI on personal data is high-risk, the impact assessment covers your whole workflow — the inference provider is one row in it. |
| Data minimization at the application layer | We retain nothing, but you decide what reaches the API in the first place. Sending less is still the best control. |
| Data-subject rights | Access, rectification and erasure requests land in your systems. (On ours there is nothing to erase — prompts are never stored.) |
| Records of processing | Your Article 30 records and processor agreements are your paperwork; our policy gives you the facts to put in them. |
We remove every obstacle infrastructure can remove — retention, training, residency, transparency — and document each one, so your paperwork starts from published facts.
Data & privacy
Prompts and completions are processed in memory in Sweden — not written to disk, not logged, not retained, and never used to train anything. We keep only request metadata (token counts, timestamps, status) for billing and operations. The full policy is at axforge.ai/privacy.
FAQ
Yes. AxForge is GDPR compliant — EU processing, zero prompt retention, no training on customer data. The full picture (subprocessors, retention, DPA) is in the trust centre.
No. Prompts and completions are processed in memory in Sweden — not written to disk, not logged, not retained. Data that is never stored cannot leak from storage or be forgotten late.
Never. Prompts and completions are never used to train anything — see the privacy policy.
Only request metadata: token counts, timestamps and status, kept for billing and operations.
Inference runs in memory in Sweden on hardware AxForge owns (region
eu-se-1; eu-es-1 in Málaga is also live, and more EU
regions are in deployment). TLS 1.3 terminates in the EU; the edge/TLS layer
is EU-hosted; details in the trust centre.
Yes. Your lawful basis, DPIA where required, records of processing and data-subject rights handling are yours regardless of infrastructure. Infrastructure can only remove obstacles — it cannot supply a lawful basis.
Related