Legal

Privacy Policy

What we collect, why we collect it, where it lives, and how to get it removed.

Last updated: 10 August 2026

1. Who we are

Nevastack ("we", "us") — company registration no. HE 495245, VAT CY60379604J — operates a European GPU cloud and private AI platform. Our registered office is Alexandrou Papadiamanti 1, 6035 Larnaca, Cyprus. For any privacy question, write to privacy@nevastack.com or support@nevastack.com.

This policy explains what we do with personal data. It is written as a plain-language description of our practices and is not legal advice; a signed Data Processing Agreement governs customer deployments.

2. Two kinds of data

We distinguish account data from customer content. Account data is information about the person or company using Nevastack: name, work email, company, billing details, and console activity. Customer content is whatever you upload, train on, or send through an endpoint.

We act as controller for account data and as processor for customer content. You decide what customer content contains and how long it lives.

3. What we collect and why

We collect only what a hosting and inference platform needs to run:

  • Account details — to create your workspace, authenticate you and contact you about your services.
  • Billing data — to issue invoices and take payment. Card details are handled by our payment provider; we do not store full card numbers.
  • Technical logs — IP address, request timestamps, endpoint and job identifiers, error traces. Used for security, abuse prevention, capacity planning and support.
  • Enquiry data — what you type into our contact form, so a person can reply.
  • Cookies — an essential session cookie for the console, plus optional analytics if you accept them in the cookie banner.

4. Customer content and model training

Customer content is not used to train shared or public models. Adaptation runs — RAG indexes, LoRA adapters, fine-tuned checkpoints — are produced for your workspace only and are not shared with other customers.

Prompts and completions sent to your endpoints are retained only as long as needed to operate and debug the service, and can be configured for zero retention on request.

5. Where your data is processed

Compute and storage stay in the region you select: Frankfurt, Amsterdam, Helsinki, Paris. We do not silently move workloads outside the EU/EEA.

A small number of support subprocessors (payment, email delivery, error reporting) may process account data. We keep this list current and will provide it on request before you sign.

6. How long we keep it

Account data is kept while your account is active and for as long as tax and accounting law requires afterwards. Technical logs are kept on a rolling short-term window for security and troubleshooting.

Customer content is deleted when you delete it, or on termination of your contract, according to the deletion window agreed in your DPA.

7. Your rights

If you are in the EU/EEA or UK, you can request access, correction, deletion, restriction, portability, or object to processing. Write to privacy@nevastack.com and we will respond within one month.

You may also complain to your national data protection authority. We would rather you told us first so we can fix it.

8. Security

Access to production systems is limited to named staff, protected by multi-factor authentication and logged. Data is encrypted in transit, and at rest on managed storage.

If a breach affects your data, we notify you without undue delay and share what we know, what we have done, and what you should do.

9. Cookies

We set strictly necessary cookies and local storage to sign you in, keep your console session, remember your cookie choice and protect against abuse. These have no consent requirement under the ePrivacy Directive because the service cannot be delivered without them.

Everything else is off by default. No preference, analytics or marketing cookie is set before you opt in, nothing is pre-ticked, and rejecting is a single click with the same prominence as accepting.

  • Strictly necessary — session and authentication, consent record, abuse protection. Always on.
  • Preferences — remembers interface choices such as region and console layout. Off until allowed.
  • Analytics — aggregated, pseudonymised page measurement. Off until allowed.
  • Marketing — campaign attribution and ad measurement. Off until allowed.
  • Your choice is stored for at most six months, after which we ask again. You can change or withdraw consent at any time via “Cookie settings” in the footer, as easily as you gave it.

10. Changes

We update this page when our practices change and note the date below. Material changes affecting customer content are communicated by email before they take effect.