Skip to main content

1. Introduction: Our Commitment to Your Privacy

At Nebius Token Factory, your trust is our top priority. We are committed to protecting your data, respecting your privacy, and operating in full compliance with applicable laws, including the General Data Protection Regulation (GDPR). This guide provides clear, plain-language answers to your most common questions about how we handle your data, where it is processed, and the rights and controls you have as a user. Please note: this guide is a summary for your convenience. It does not amend or replace our Terms of Service, Data Processing Agreement (DPA) or Privacy Policy; in case of any inconsistency, those documents prevail.

2. Who You Contract With

Your contract for Nebius Token Factory is with the applicable Nebius entity identified in the relevant Terms of Service. That entity also acts as the Data Processor under the applicable DPA, which is governed by the law specified in the Terms of Service, without prejudice to the governing law and jurisdiction applicable under the Standard Contractual Clauses. The contracting entity is part of the Nebius group, whose publicly listed parent company is Nebius Group N.V. (NASDAQ: NBIS).

3. Data Processing: What Happens to Your Data

To provide our service, we handle different types of data. It is important to understand our role in each case: 3.1. Data Controller: for your account information (e.g., email address, billing details), we act as the Data Controller: we determine how this data is used for authentication, billing and communication with you. 3.2. Data Processor: for the content you submit to our model inference and fine-tuning endpoints via the API or web interface (prompts, datasets, etc.) and the output you receive, we act as the Data Processor under our DPA. You are the Data Controller and remain in full control of this data. The detailed subject matter, duration, categories of data subjects and personal data are set out in Annex 1 of the DPA. 3.3. Speculative Decoding: to improve output speed, your inputs (prompts) and the corresponding outputs may be stored and used for Speculative Decoding. You have complete control over this and can switch it off (see Section 4).
  • How Speculative Decoding works and why we need your data: this feature speeds up inference by introducing a draft model. The draft model generates multiple candidate tokens, and the main model only verifies or corrects them. This reduces the number of expensive forward passes and improves throughput. It is enabled by default for best performance; you can opt out at any time by enabling Zero Data Retention. Enabling Zero Data Retention may impact the level of service provided (e.g., inference speed).

4. Your Controls: Data Retention, Opt-Outs & Deletion

4.1. Zero Data Retention (ZDR) For maximum privacy and control, you can enable Zero Data Retention in your account settings.
  • Scope: ZDR applies at the organization level and covers all projects and endpoints within your organization. Enabling or disabling ZDR is your responsibility as the account owner.
  • What it means: with ZDR enabled, your inputs (prompts) and outputs (responses) are not stored on our systems after each request is processed – no retained copy exists beyond ephemeral in-flight processing.
  • No training, no Speculative Decoding: with ZDR enabled, your data is not used for Speculative Decoding and is not used to train, fine-tune or improve any model – whether ours or a third party’s.
  • How to enable it: activate Zero Data Retention on your account profile page.
  • Written confirmation: if you need written confirmation of your organization’s ZDR status (e.g., for a data-protection review), contact our support team or your account manager.
4.2. Default Behavior Unless you enable Zero Data Retention, we keep your inputs and outputs to speed up inference using the Speculative Decoding technique described in Section 3. Your content is not used to train any models in either mode. 4.3. Return & Deletion at End of Contract When you stop using the service, you decide what happens to your data: upon termination or expiration of the services, we will delete or return Customer Personal Data at your choice, unless retention of certain data is required by applicable law (DPA, Section 7).

5. Data Location: Where Your Data Is Processed

5.1. Public endpoints: No Region Commitment For public model endpoints, the Region field shows Global. The processing location is decided dynamically, is not tied to any single data center, and can change at any time without prior notice. If your integration relies on a region-specific base_url (e.g. an endpoint URL containing us-central1), that URL may stop working if the processing region changes. Public endpoints are intended for testing and non-critical workloads where this variability is acceptable, and are not intended for production use cases that require a stable, predictable region. If you need assurance about where requests are processed, for compliance, latency, performance or capacity reasons, deploy the model on a Dedicated Endpoint in the region of your choice (see Section 5.2). Storage after processing: real-time processing and subsequent storage are distinct. If you have not enabled Zero Data Retention (see Section 4), the inputs and outputs retained for Speculative Decoding are stored in Finland (EU), regardless of where real-time processing takes place. With ZDR enabled, no inputs or outputs are retained. 5.2. Dedicated Endpoints: Region Commitment Unlike public endpoints, which offer no region guarantee (see Section 5.1), for dedicated endpoints the data-center region is fixed as part of the endpoint configuration – and it is a contractual commitment: under Section 6.1 of our DPA, we process your personal data within the region you selected for your dedicated endpoint.
  • We do not use multi-region routing, load balancing, or automatic overflow/failover to other regions for dedicated endpoints: inference runs only in the region you chose.
  • If your dedicated endpoint is configured in the EU, the inference content and related metadata remain within that region.
5.3. Fine-Tuning Data Location & Storage Fine-tuning workloads have fixed processing locations, and all resulting data is stored centrally in the EU to ensure consistent compliance and governance:
  • Data storage (global policy): regardless of customer origin (EU, US, or other regions), all fine-tuning datasets, artifacts, and model outputs are stored exclusively in EU data centers.
  • Processing for EU customers: fine-tuning jobs submitted by EU users are processed in EU data centers, and their data is stored in the EU.
  • Processing for US customers: fine-tuning jobs submitted by US users are processed in US data centers, but all data is stored in the EU.
Fine-tuning does not offer regional selection options, unlike inference endpoints. 5.4. Future Changes We notify customers in advance of changes that may affect their compliance posture:
  • Terms of Service and DPA changes: we provide notice of any changes to our Terms of Service, including the DPA. Previous versions of our legal documents remain available in the online archive on the documentation site.
  • Sub-processor changes: at least fifteen (15) days’ prior notice of any addition or replacement of a subprocessor.
  • Model deprecations: deprecations of models are announced in advance so you can migrate your workloads.

6. Sub-Processors

Like every cloud provider, we rely on carefully selected sub-processors – both Nebius group companies and external providers – for parts of the service such as cloud infrastructure, inference capacity, customer support, payments and billing.
  • Current list: we maintain a public, up-to-date Sub-processor List showing each sub-processor’s role and location, together with the list’s effective date: https://docs.nebius.com/legal/sub-processors_tofa.
  • Safeguards: each sub-processor is bound by a written agreement imposing data-protection obligations no less protective than those in our DPA.
  • Advance notice of changes: we will give you at least fifteen (15) days’ prior notice before adding or replacing a sub-processor. You may object on reasonable data-protection grounds; if no mutually acceptable solution is found, you may terminate the affected services and receive a pro-rata refund of prepaid, unused fees.

7. International Data Transfers

  • Standard Contractual Clauses (SCCs): where personal data protected by the GDPR, UK GDPR or Swiss FADP is transferred to a country without an adequacy decision, the transfer is governed by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into our DPA. This also covers administrative, maintenance and support access to data from outside the EEA – for example, by Nebius group entities in the United States, Israel or Serbia listed in the Sub-processor List.
  • United Kingdom and Switzerland: transfers of UK-protected data are additionally covered by the ICO’s International Data Transfer Addendum, and Swiss-protected data by the Swiss adaptations, both set out in Annex 2 of the DPA.
  • EU-US Data Privacy Framework (DPF): we are certified under the EU-US Data Privacy Framework, which enables compliant transfers of personal data from the EU/EEA to the United States in addition to other available transfer mechanisms. As a DPF-certified organization, we adhere to the DPF Principles and maintain safeguards designed to ensure an appropriate level of protection for EU personal data.

8. Compliance & Certifications

8.1. GDPR Compliance We are fully compliant with the General Data Protection Regulation (GDPR). Our practices and policies are built to meet these rigorous requirements for data protection. 8.2. Data Processing Agreement (DPA) We provide a DPA to all our customers. To keep the process simple, the DPA is incorporated directly into our Terms of Service: by signing up and agreeing to the Terms of Service, you are covered by the DPA – no separate signature is needed. If your procurement or regulatory process requires a countersigned copy of the DPA or additional contractual arrangements, contact your account manager or our support team. 8.3. Certifications We are a certified company holding ISO 27001, ISO 27701 and SOC 2 Type II certifications. These internationally recognized standards demonstrate our commitment to information security, privacy, and operational resilience. For details, visit our Trust Center: https://nebius.com/trust-center . 8.4. Requesting Audit Reports Audit reports and certificates (e.g., the SOC 2 Type II report) are available through our Trust Center; certain reports are shared under a non-disclosure agreement. If a third party – such as an external risk assessor – requests reports on your behalf, we will ask for your authorization first. In addition, under the DPA you may request, in writing and at no cost, documentation reasonably necessary to demonstrate our compliance, and you may commission an audit by an independent, suitably qualified auditor with at least 30 days’ notice, once per calendar year. 8.5. HIPAA Compliance We also provide secure services to help customers meet the requirements of the U.S. Health Insurance Portability and Accountability Act (HIPAA). More details: https://docs.nebius.com/legal/hipaa.

9. Security, Audits & Incident Response

  • Security measures: we implement and maintain appropriate technical and organizational measures, summarized in Annex 3 of the DPA. They include encryption at rest and in transit, access management based on need-to-know, least privilege and segregation of duties, logging and audit trails, physical security of data centers, personnel background checks and confidentiality training, change management, and business-continuity plans.
  • Breach notification: we will notify you without undue delay after becoming aware of a security breach affecting your personal data and will provide the necessary information and reasonable assistance.

10. Sensitive & Regulated Data

  • Special-category personal data (Art. 9 GDPR): our DPA expressly contemplates that Customer Content may include special categories of personal data – such as health data or biometric data – the extent of which you determine and control (DPA Annex 1(B)). As the Data Controller, you are responsible for ensuring a lawful basis and for any required notices, consents or authorizations before submitting such data.
  • Recommended controls: for sensitive workloads, or any production workload that depends on a stable, known processing region, we recommend enabling Zero Data Retention and using a dedicated endpoint in your preferred region (see Sections 4 and 5). Public endpoints should not be relied on for such workloads, as their processing region can change without notice.
  • US healthcare data: for HIPAA-regulated workloads, see our HIPAA guideline (Section 8.5).
You own what you create. We claim no rights to the intellectual property you develop on our platform.
  • You retain all ownership rights to your input data and datasets.
  • You retain all ownership rights to any fine-tuned and distilled models you create.
  • You retain all ownership rights to the content generated by the models from your inputs.
  • You acknowledge that your outputs may not be unique, and other users of the service may receive the same or similar outputs.

12. Key Documents & Contacts

Privacy contact: privacy@nebius.com (Data Protection Officer). For written confirmations, countersigned documents or contractual addenda, contact your account manager or our support team.

13. Frequently Asked Questions (FAQ)

Data Processing & Location

Will my dedicated endpoint ever process data in another region? No. Under Section 6.1 of our DPA, we process your personal data within the region you selected for the dedicated endpoint. There is no multi-region routing or automatic overflow to other regions. How will I be notified about changes in model hosting locations? For dedicated endpoints and model deprecations, we announce changes proactively via email to all account owners and through notifications within the Nebius Token Factory platform. Public endpoints are the exception: their processing region is decided dynamically and can change at any time without advance notice, which is why public endpoints are not recommended for production workloads requiring a stable region. Can I rely on a public endpoint for production traffic that needs a stable region? No. Public endpoints run on shared infrastructure with a Region field of “Global,” and the actual processing location can change at any time without notice. A region-specific base_url may stop working if this happens. For production workloads that depend on a stable region, use a Dedicated Endpoint instead (see Sections 5.1–5.2). If my data is processed in the US, how do you ensure it complies with EU regulations like GDPR? For any transfers to countries without an EU adequacy decision, we rely on legally established transfer mechanisms – in particular the Standard Contractual Clauses incorporated into our DPA – and we are certified under the EU-US Data Privacy Framework (see Section 7).

Data Retention & Control

Is my data used to train your AI models? No. We do not use your content to train, fine-tune or improve any AI models – ours or third parties’. Unless you enable Zero Data Retention, your inputs and outputs may be stored and used solely for Speculative Decoding (see Section 3), which does not involve training any model. What happens if I don’t enable Zero Data Retention? Your API inputs and outputs may be stored and used for Speculative Decoding – and for no other purpose. What happens to my data when I stop using the service? Upon termination or expiration of the services, we delete or return Customer Personal Data at your choice, except where retention is required by applicable law. Are you GDPR compliant? Yes. We are fully committed to and compliant with the GDPR. Do I need to sign a separate Data Processing Agreement (DPA)? No. Our DPA is an integral part of our Terms of Service: by agreeing to the ToS, you are automatically covered. If you need a countersigned copy for your procurement or regulatory process, contact your account manager. Who is my contracting party? Your contracting entity is the applicable Nebius entity within the corporate group headed by Nebius Group N.V. (NASDAQ: NBIS), as identified in the relevant Terms of Service. The DPA is governed by the law specified in those Terms of Service, without prejudice to the governing law and jurisdiction applicable under the Standard Contractual Clauses. How do I get your SOC 2 report or other security documentation? Through our Trust Center (https://nebius.com/trust-center); certain reports are provided under NDA. Requests from third-party assessors require your authorization. How will I know if you change sub-processors? We provide at least 15 days’ prior notice of any addition or replacement of a sub-processor, and you have the right to object on reasonable data-protection grounds. Can commitments such as ZDR or region pinning be recorded in my contract? The region commitment for dedicated endpoints is already a binding term of the DPA, which forms part of your agreement. If you require additional contractual documentation – for example, an order form or addendum reflecting your ZDR configuration – contact your account manager. Can I process health data or other special-category data? Yes, subject to your responsibilities as Data Controller (lawful basis, notices, consents) – see Section 10. For sensitive workloads we recommend Zero Data Retention and a dedicated endpoint; for US healthcare data, see our HIPAA guideline. If you are bound by professional-secrecy rules, contact privacy@nebius.com first. Who owns the content I generate or the models I fine-tune? You do. You retain all intellectual property rights to your inputs, outputs, and any models you fine-tune or distill on our platform. Note that outputs may not be unique, and other users may receive the same or similar outputs.