Data handling

A GDPR compliant AI API

GDPR compliant, and your data never leaves the EU: zero prompt retention, no training on customer data. The deeper story lives in the trust centre.

eu-se-1 · Stockholm eu-es-1 · Málaga Zero prompt retention
Get an API key Talk to an engineer Keys are allocated from the waiting list.

The claim

GDPR compliant — and provable

We prove it with specifics: EU processing on hardware we own, memory-only prompts, a public subprocessor register, a retention table and a DPA — all documented in the trust centre.

That is the whole pitch: compliance you can verify, not a badge. Point your DPO at the trust centre — the subprocessor register, the retention table and the DPA are ready to read.

Commitments

What the infrastructure does

PropertyCommitment
Prompt retentionZero. Prompts and completions are processed in memory in Sweden — not written to disk, not logged, not retained. Data that is never stored cannot leak from storage or be forgotten late: this is the strongest data-minimization posture an inference provider can take.
Training on customer dataNever. Prompts and completions are never used to train anything.
Retained metadataToken counts, timestamps, status — for billing and operations. Nothing else.
Processing locationEU regions on hardware AxForge owns: eu-se-1 · Stockholm and eu-es-1 · Málaga live; more EU regions — in deployment. Region pinned on the key via x-axforge-region, echoed on the response.
TransportTLS 1.3, terminated in the EU.
SubprocessorsEU-hosted infrastructure; details in the trust centre.
Written commitmentsThe privacy policy states all of the above as policy, not marketing.

Your side of the line

What stays the customer's responsibility

We handle the provider side. These stay yours with any provider — and our published facts make each one faster to close:

ObligationWhy it cannot be outsourced to infrastructure
Lawful basisOnly you know why you process personal data. An API cannot supply consent, contract necessity or legitimate interest on your behalf.
DPIAWhere your use of AI on personal data is high-risk, the impact assessment covers your whole workflow — the inference provider is one row in it.
Data minimization at the application layerWe retain nothing, but you decide what reaches the API in the first place. Sending less is still the best control.
Data-subject rightsAccess, rectification and erasure requests land in your systems. (On ours there is nothing to erase — prompts are never stored.)
Records of processingYour Article 30 records and processor agreements are your paperwork; our policy gives you the facts to put in them.

We remove every obstacle infrastructure can remove — retention, training, residency, transparency — and document each one, so your paperwork starts from published facts.

Data & privacy

Zero prompt retention

Prompts and completions are processed in memory in Sweden — not written to disk, not logged, not retained, and never used to train anything. We keep only request metadata (token counts, timestamps, status) for billing and operations. The full policy is at axforge.ai/privacy.

FAQ

GDPR compliant AI API — common questions

Is AxForge a GDPR compliant AI API?

Yes. AxForge is GDPR compliant — EU processing, zero prompt retention, no training on customer data. The full picture (subprocessors, retention, DPA) is in the trust centre.

Are prompts stored anywhere?

No. Prompts and completions are processed in memory in Sweden — not written to disk, not logged, not retained. Data that is never stored cannot leak from storage or be forgotten late.

Is customer data used to train models?

Never. Prompts and completions are never used to train anything — see the privacy policy.

What data does AxForge retain?

Only request metadata: token counts, timestamps and status, kept for billing and operations.

Where is my data processed?

Inference runs in memory in Sweden on hardware AxForge owns (region eu-se-1; eu-es-1 in Málaga is also live, and more EU regions are in deployment). TLS 1.3 terminates in the EU; the edge/TLS layer is EU-hosted; details in the trust centre.

Do I still need a DPIA and a lawful basis?

Yes. Your lawful basis, DPIA where required, records of processing and data-subject rights handling are yours regardless of infrastructure. Infrastructure can only remove obstacles — it cannot supply a lawful basis.

Related

Nearby on AxForge

The strongest data-minimization posture: keep nothing.

Get an API key Talk to an engineer
© 2026 AxForge · EU-hosted AI infrastructure Pricing Docs Trust Privacy Terms