Privacy Policy
What we collect, why we collect it, where it lives, and how to get it removed.
Last updated: 10 August 2026
1. Who we are
Nevastack ("we", "us") — company registration no. HE 495245, VAT CY60379604J — operates a European GPU cloud and private AI platform. Our registered office is Alexandrou Papadiamanti 1, 6035 Larnaca, Cyprus. For any privacy question, write to privacy@nevastack.com or support@nevastack.com.
This policy explains what we do with personal data. It is written as a plain-language description of our practices and is not legal advice; a signed Data Processing Agreement governs customer deployments.
2. Two kinds of data
We distinguish account data from customer content. Account data is information about the person or company using Nevastack: name, work email, company, billing details, and console activity. Customer content is whatever you upload, train on, or send through an endpoint.
We act as controller for account data and as processor for customer content. You decide what customer content contains and how long it lives.
3. What we collect and why
We collect only what a hosting and inference platform needs to run:
- Account details — to create your workspace, authenticate you and contact you about your services.
- Billing data — to issue invoices and take payment. Card details are handled by our payment provider; we do not store full card numbers.
- Technical logs — IP address, request timestamps, endpoint and job identifiers, error traces. Used for security, abuse prevention, capacity planning and support.
- Enquiry data — what you type into our contact form, so a person can reply.
- Cookies — an essential session cookie for the console, plus optional analytics if you accept them in the cookie banner.
4. Customer content and model training
Customer content is not used to train shared or public models. Adaptation runs — RAG indexes, LoRA adapters, fine-tuned checkpoints — are produced for your workspace only and are not shared with other customers.
Prompts and completions sent to your endpoints are retained only as long as needed to operate and debug the service, and can be configured for zero retention on request.
5. Where your data is processed
Compute and storage stay in the region you select: Frankfurt, Amsterdam, Helsinki, Paris. We do not silently move workloads outside the EU/EEA.
A small number of support subprocessors (payment, email delivery, error reporting) may process account data. We keep this list current and will provide it on request before you sign.
6. How long we keep it
Account data is kept while your account is active and for as long as tax and accounting law requires afterwards. Technical logs are kept on a rolling short-term window for security and troubleshooting.
Customer content is deleted when you delete it, or on termination of your contract, according to the deletion window agreed in your DPA.
7. Your rights
If you are in the EU/EEA or UK, you can request access, correction, deletion, restriction, portability, or object to processing. Write to privacy@nevastack.com and we will respond within one month.
You may also complain to your national data protection authority. We would rather you told us first so we can fix it.
8. Security
Access to production systems is limited to named staff, protected by multi-factor authentication and logged. Data is encrypted in transit, and at rest on managed storage.
If a breach affects your data, we notify you without undue delay and share what we know, what we have done, and what you should do.
10. Changes
We update this page when our practices change and note the date below. Material changes affecting customer content are communicated by email before they take effect.