1. Introduction: Our Commitment to Your Privacy
At Nebius Token Factory, your trust is our top priority. We are committed to protecting your data, respecting your privacy, and operating in full compliance with applicable laws, including the General Data Protection Regulation (GDPR). This guide provides clear, plain-language answers to your most common questions about how we handle your data, where it is processed, and the rights and controls you have as a user. Please note: this guide is a summary for your convenience. It does not amend or replace our Terms of Service, Data Processing Agreement (DPA) or Privacy Policy; in case of any inconsistency, those documents prevail.2. Who You Contract With
Your contract for Nebius Token Factory is with the applicable Nebius entity identified in the relevant Terms of Service. That entity also acts as the Data Processor under the applicable DPA, which is governed by the law specified in the Terms of Service, without prejudice to the governing law and jurisdiction applicable under the Standard Contractual Clauses. The contracting entity is part of the Nebius group, whose publicly listed parent company is Nebius Group N.V. (NASDAQ: NBIS).3. Data Processing: What Happens to Your Data
To provide our service, we handle different types of data. It is important to understand our role in each case: 3.1. Data Controller: for your account information (e.g., email address, billing details), we act as the Data Controller: we determine how this data is used for authentication, billing and communication with you. 3.2. Data Processor: for the content you submit to our model inference and fine-tuning endpoints via the API or web interface (prompts, datasets, etc.) and the output you receive, we act as the Data Processor under our DPA. You are the Data Controller and remain in full control of this data. The detailed subject matter, duration, categories of data subjects and personal data are set out in Annex 1 of the DPA. 3.3. Speculative Decoding: to improve output speed, your inputs (prompts) and the corresponding outputs may be stored and used for Speculative Decoding. You have complete control over this and can switch it off (see Section 4).- How Speculative Decoding works and why we need your data: this feature speeds up inference by introducing a draft model. The draft model generates multiple candidate tokens, and the main model only verifies or corrects them. This reduces the number of expensive forward passes and improves throughput. It is enabled by default for best performance; you can opt out at any time by enabling Zero Data Retention. Enabling Zero Data Retention may impact the level of service provided (e.g., inference speed).
4. Your Controls: Data Retention, Opt-Outs & Deletion
4.1. Zero Data Retention (ZDR) For maximum privacy and control, you can enable Zero Data Retention in your account settings.- Scope: ZDR applies at the organization level and covers all projects and endpoints within your organization. Enabling or disabling ZDR is your responsibility as the account owner.
- What it means: with ZDR enabled, your inputs (prompts) and outputs (responses) are not stored on our systems after each request is processed – no retained copy exists beyond ephemeral in-flight processing.
- No training, no Speculative Decoding: with ZDR enabled, your data is not used for Speculative Decoding and is not used to train, fine-tune or improve any model – whether ours or a third party’s.
- How to enable it: activate Zero Data Retention on your account profile page.
- Written confirmation: if you need written confirmation of your organization’s ZDR status (e.g., for a data-protection review), contact our support team or your account manager.
5. Data Location: Where Your Data Is Processed
5.1. Public endpoints: No Region Commitment For public model endpoints, the Region field shows Global. The processing location is decided dynamically, is not tied to any single data center, and can change at any time without prior notice. If your integration relies on a region-specificbase_url (e.g. an endpoint URL containing us-central1), that URL may stop working if the processing region changes. Public endpoints are intended for testing and non-critical workloads where this variability is acceptable, and are not intended for production use cases that require a stable, predictable region.
If you need assurance about where requests are processed, for compliance, latency, performance or capacity reasons, deploy the model on a Dedicated Endpoint in the region of your choice (see Section 5.2).
Storage after processing: real-time processing and subsequent storage are distinct. If you have not enabled Zero Data Retention (see Section 4), the inputs and outputs retained for Speculative Decoding are stored in Finland (EU), regardless of where real-time processing takes place. With ZDR enabled, no inputs or outputs are retained.
5.2. Dedicated Endpoints: Region Commitment
Unlike public endpoints, which offer no region guarantee (see Section 5.1), for dedicated endpoints the data-center region is fixed as part of the endpoint configuration – and it is a contractual commitment: under Section 6.1 of our DPA, we process your personal data within the region you selected for your dedicated endpoint.
- We do not use multi-region routing, load balancing, or automatic overflow/failover to other regions for dedicated endpoints: inference runs only in the region you chose.
- If your dedicated endpoint is configured in the EU, the inference content and related metadata remain within that region.
- Data storage (global policy): regardless of customer origin (EU, US, or other regions), all fine-tuning datasets, artifacts, and model outputs are stored exclusively in EU data centers.
- Processing for EU customers: fine-tuning jobs submitted by EU users are processed in EU data centers, and their data is stored in the EU.
- Processing for US customers: fine-tuning jobs submitted by US users are processed in US data centers, but all data is stored in the EU.
- Terms of Service and DPA changes: we provide notice of any changes to our Terms of Service, including the DPA. Previous versions of our legal documents remain available in the online archive on the documentation site.
- Sub-processor changes: at least fifteen (15) days’ prior notice of any addition or replacement of a subprocessor.
- Model deprecations: deprecations of models are announced in advance so you can migrate your workloads.
6. Sub-Processors
Like every cloud provider, we rely on carefully selected sub-processors – both Nebius group companies and external providers – for parts of the service such as cloud infrastructure, inference capacity, customer support, payments and billing.- Current list: we maintain a public, up-to-date Sub-processor List showing each sub-processor’s role and location, together with the list’s effective date: https://docs.nebius.com/legal/sub-processors_tofa.
- Safeguards: each sub-processor is bound by a written agreement imposing data-protection obligations no less protective than those in our DPA.
- Advance notice of changes: we will give you at least fifteen (15) days’ prior notice before adding or replacing a sub-processor. You may object on reasonable data-protection grounds; if no mutually acceptable solution is found, you may terminate the affected services and receive a pro-rata refund of prepaid, unused fees.
7. International Data Transfers
- Standard Contractual Clauses (SCCs): where personal data protected by the GDPR, UK GDPR or Swiss FADP is transferred to a country without an adequacy decision, the transfer is governed by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into our DPA. This also covers administrative, maintenance and support access to data from outside the EEA – for example, by Nebius group entities in the United States, Israel or Serbia listed in the Sub-processor List.
- United Kingdom and Switzerland: transfers of UK-protected data are additionally covered by the ICO’s International Data Transfer Addendum, and Swiss-protected data by the Swiss adaptations, both set out in Annex 2 of the DPA.
- EU-US Data Privacy Framework (DPF): we are certified under the EU-US Data Privacy Framework, which enables compliant transfers of personal data from the EU/EEA to the United States in addition to other available transfer mechanisms. As a DPF-certified organization, we adhere to the DPF Principles and maintain safeguards designed to ensure an appropriate level of protection for EU personal data.
8. Compliance & Certifications
8.1. GDPR Compliance We are fully compliant with the General Data Protection Regulation (GDPR). Our practices and policies are built to meet these rigorous requirements for data protection. 8.2. Data Processing Agreement (DPA) We provide a DPA to all our customers. To keep the process simple, the DPA is incorporated directly into our Terms of Service: by signing up and agreeing to the Terms of Service, you are covered by the DPA – no separate signature is needed. If your procurement or regulatory process requires a countersigned copy of the DPA or additional contractual arrangements, contact your account manager or our support team. 8.3. Certifications We are a certified company holding ISO 27001, ISO 27701 and SOC 2 Type II certifications. These internationally recognized standards demonstrate our commitment to information security, privacy, and operational resilience. For details, visit our Trust Center: https://nebius.com/trust-center . 8.4. Requesting Audit Reports Audit reports and certificates (e.g., the SOC 2 Type II report) are available through our Trust Center; certain reports are shared under a non-disclosure agreement. If a third party – such as an external risk assessor – requests reports on your behalf, we will ask for your authorization first. In addition, under the DPA you may request, in writing and at no cost, documentation reasonably necessary to demonstrate our compliance, and you may commission an audit by an independent, suitably qualified auditor with at least 30 days’ notice, once per calendar year. 8.5. HIPAA Compliance We also provide secure services to help customers meet the requirements of the U.S. Health Insurance Portability and Accountability Act (HIPAA). More details: https://docs.nebius.com/legal/hipaa.9. Security, Audits & Incident Response
- Security measures: we implement and maintain appropriate technical and organizational measures, summarized in Annex 3 of the DPA. They include encryption at rest and in transit, access management based on need-to-know, least privilege and segregation of duties, logging and audit trails, physical security of data centers, personnel background checks and confidentiality training, change management, and business-continuity plans.
- Breach notification: we will notify you without undue delay after becoming aware of a security breach affecting your personal data and will provide the necessary information and reasonable assistance.
10. Sensitive & Regulated Data
- Special-category personal data (Art. 9 GDPR): our DPA expressly contemplates that Customer Content may include special categories of personal data – such as health data or biometric data – the extent of which you determine and control (DPA Annex 1(B)). As the Data Controller, you are responsible for ensuring a lawful basis and for any required notices, consents or authorizations before submitting such data.
- Recommended controls: for sensitive workloads, or any production workload that depends on a stable, known processing region, we recommend enabling Zero Data Retention and using a dedicated endpoint in your preferred region (see Sections 4 and 5). Public endpoints should not be relied on for such workloads, as their processing region can change without notice.
- US healthcare data: for HIPAA-regulated workloads, see our HIPAA guideline (Section 8.5).
11. Ownership & Copyright
You own what you create. We claim no rights to the intellectual property you develop on our platform.- You retain all ownership rights to your input data and datasets.
- You retain all ownership rights to any fine-tuned and distilled models you create.
- You retain all ownership rights to the content generated by the models from your inputs.
- You acknowledge that your outputs may not be unique, and other users of the service may receive the same or similar outputs.
12. Key Documents & Contacts
- Nebius Services Agreement: https://docs.nebius.com/legal/agreement
- Privacy Policy: https://docs.nebius.com/legal/privacy
- Data Processing Agreement: https://docs.nebius.com/legal/dpa
- List of Sub-Processors: https://docs.nebius.com/legal/sub-processors_tofa
- HIPAA Guideline: https://docs.nebius.com/legal/hipaa
- Trust Center (certifications & reports): https://nebius.com/trust-center
13. Frequently Asked Questions (FAQ)
Data Processing & Location
Will my dedicated endpoint ever process data in another region? No. Under Section 6.1 of our DPA, we process your personal data within the region you selected for the dedicated endpoint. There is no multi-region routing or automatic overflow to other regions. How will I be notified about changes in model hosting locations? For dedicated endpoints and model deprecations, we announce changes proactively via email to all account owners and through notifications within the Nebius Token Factory platform. Public endpoints are the exception: their processing region is decided dynamically and can change at any time without advance notice, which is why public endpoints are not recommended for production workloads requiring a stable region. Can I rely on a public endpoint for production traffic that needs a stable region? No. Public endpoints run on shared infrastructure with a Region field of “Global,” and the actual processing location can change at any time without notice. A region-specificbase_url may stop working if this happens. For production workloads that depend on a stable region, use a Dedicated Endpoint instead (see Sections 5.1–5.2).
If my data is processed in the US, how do you ensure it complies with EU regulations like GDPR?
For any transfers to countries without an EU adequacy decision, we rely on legally established transfer mechanisms – in particular the Standard Contractual Clauses incorporated into our DPA – and we are certified under the EU-US Data Privacy Framework (see Section 7).