Legal · Launch draft v0.1

Your prompts are not stored.

How AxForge handles personal data — as controller for accounts and site visitors, as processor for prompts. Zero prompt retention, EEA-only processing.

Launch draft Version 0.1 · Effective 2026-08-26

Who we are

Two GDPR roles, one policy

AxForge operates EU-hosted AI infrastructure and APIs. Contact: hello@axforge.ai — one operational mailbox for operational, privacy and security matters; dedicated privacy@ and security@ aliases arrive at commercial launch. The contracting legal entity's registration details will be published on the legal notice before the first commercial contract.

AxForge acts in two GDPR roles, and this policy is structured around them: controller for the data we decide to process about you — accounts, this website, billing, support, security — and processor for the content customers send through the APIs.

Controller

AxForge as controller

For website visitors, customer accounts, billing contacts, support messages, security and access logs, and communication preferences, AxForge decides the purposes and means of processing and is the controller.

What we keep

Account data you give us: name, work email, company. Kept while your account exists.

Alongside it: billing contact details, support messages, security and access logs, and your communication preferences — each for the period in the retention table.

Legal basis and retention

Contract performance (Art. 6(1)(b) GDPR) for providing the service; legitimate interest (Art. 6(1)(f)) for security and abuse prevention; legal obligation (Art. 6(1)(c)) for accounting records. Prompts: zero retention. Metadata and account data: for the account's lifetime plus statutory bookkeeping periods.

The item-by-item schedule is the retention table.

Recipients

Personal data reaches only the subprocessors in the subprocessor register: Hetzner Online GmbH (EU edge hosting, Germany) and Atom9 (console login, Sweden). The register carries its change history and 30-day advance notice of any addition.

Your rights

Access, rectification, erasure, restriction, portability and objection — write to hello@axforge.ai. You may complain to your EU supervisory authority; for Sweden that is IMY (imy.se).

Processor

AxForge as processor

For prompts, completions, uploaded context, API request metadata and any personal data inside customer content, the customer is the controller and AxForge processes only on the customer's documented instructions — each API request is that instruction. The terms are in the Data Processing Agreement (launch draft).

Prompts and completions

Text you send to our inference APIs, and the responses, are processed in memory in Sweden for the duration of the request and are not written to disk, not logged, and not retained.

They are never used to train, fine-tune or evaluate any model. There is no exception to this.

API request metadata

Operational metadata: timestamps, token counts, model name, status codes — for billing, capacity and abuse prevention. This metadata contains no prompt or completion content.

Where

Where processing happens

Inference runs on hardware we control in Sweden. Network traffic terminates on infrastructure operated for us by Hetzner Online GmbH (EU). No processing outside the EU; no data sold or shared for marketing.

International transfers: none. No personal data leaves the EEA, and there is no failover outside the EEA — if all EEA capacity is unavailable, requests queue or fail; they are never routed outside the EEA.

Cookies

Only functional session cookies on signed-in surfaces. No tracking or advertising cookies.

This marketing site sets no cookies at all, and no analytics run on it.

Related

Where the details live

Questions: hello@axforge.ai · Version 0.1 (launch draft) · Effective 26 August 2026 · Change log: 2026-08-26 — restructured into controller and processor roles, added the transfers position and trust-page links; commitments unchanged.

© 2026 AxForge · EU-hosted AI infrastructure Pricing Docs Trust Privacy Terms