Skip to main content

1. Introduction: Our Commitment to Your Privacy

At Nebius Token Factory, your trust is our top priority. We are committed to protecting your data, respecting your privacy, and operating in full compliance with applicable laws, including the General Data Protection Regulation (GDPR). This guide provides clear, plain-language answers to your most common questions about how we handle your data, where it is processed, and the rights and controls you have as a user. Please note: this guide is a summary for your convenience. It does not amend or replace our Terms of Service, Data Processing Agreement (DPA) or Privacy Policy; in case of any inconsistency, those documents prevail.

2. Who You Contract With

Your contract for Nebius Token Factory is with Nebius B.V., a company incorporated in the Netherlands. Nebius B.V. also acts as the Data Processor under our DPA, which is governed by the laws of the Netherlands. Nebius B.V. is a subsidiary of Nebius Group N.V., the publicly listed parent company of the Nebius group (NASDAQ: NBIS). Other Nebius group companies may participate in delivering the service as sub-processors – see Section 6.

3. Data Processing: What Happens to Your Data

To provide our service, we handle different types of data. It is important to understand our role in each case: 3.1. Data Controller: for your account information (e.g., email address, billing details), we act as the Data Controller: we determine how this data is used for authentication, billing and communication with you. 3.2. Data Processor: for the content you submit to our model inference and fine-tuning endpoints via the API or web interface (prompts, datasets, etc.) and the output you receive, we act as the Data Processor under our DPA. You are the Data Controller and remain in full control of this data. The detailed subject matter, duration, categories of data subjects and personal data are set out in Annex 1 of the DPA. 3.3. Speculative Decoding: to improve output speed, your inputs (prompts) and the corresponding outputs may be stored and used for Speculative Decoding. You have complete control over this and can switch it off (see Section 4).
  • How Speculative Decoding works and why we need your data: this feature speeds up inference by introducing a draft model. The draft model generates multiple candidate tokens, and the main model only verifies or corrects them. This reduces the number of expensive forward passes and improves throughput. It is enabled by default for best performance; you can opt out at any time by enabling Zero Data Retention. Enabling Zero Data Retention may impact the level of service provided (e.g., inference speed).

4. Your Controls: Data Retention, Opt-Outs & Deletion

4.1. Zero Data Retention (ZDR) For maximum privacy and control, you can enable Zero Data Retention in your account settings.
  • Scope: ZDR applies at the organization level and covers all projects and endpoints within your organization. Enabling or disabling ZDR is your responsibility as the account owner.
  • What it means: with ZDR enabled, your inputs (prompts) and outputs (responses) are not stored on our systems after each request is processed – no retained copy exists beyond ephemeral in-flight processing.
  • No training, no Speculative Decoding: with ZDR enabled, your data is not used for Speculative Decoding and is not used to train, fine-tune or improve any model – whether ours or a third party’s.
  • How to enable it: activate Zero Data Retention on your account profile page.
  • Written confirmation: if you need written confirmation of your organization’s ZDR status (e.g., for a data-protection review), contact our support team or your account manager.
4.2. Default Behavior Unless you enable Zero Data Retention, we keep your inputs and outputs to speed up inference using the Speculative Decoding technique described in Section 3. Your content is not used to train any models in either mode. 4.3. Return & Deletion at End of Contract When you stop using the service, you decide what happens to your data: upon termination or expiration of the services, we will delete or return Customer Personal Data at your choice, unless retention of certain data is required by applicable law (DPA, Section 7).

5. Data Location: Where Your Data Is Processed

5.1. Choice of Location & Full Transparency Real-time processing (inference): the country flag displayed for each model indicates where your requests are processed in real time, that is, where inference on your inputs and outputs actually takes place. We offer models running in data centers located in the European Union (including Finland and France), Israel, and the United States. For public model endpoints, available processing locations may change from time to time, the current location for each model is always shown in the Nebius Token Factory interface (country flags) and in its documentation, so you can see exactly where your data will be processed before you use a specific model and make an informed, compliant choice. Storage after processing: real-time processing and subsequent storage are distinct. If you have not enabled Zero Data Retention (see Section 4), the inputs and outputs retained for Speculative Decoding are stored in Finland (EU), regardless of where real-time processing takes place. With ZDR enabled, no inputs or outputs are retained. 5.2. Dedicated Endpoints: Region Commitment For dedicated endpoints, the data-center region is fixed as part of the endpoint configuration – and it is a contractual commitment: under Section 6.1 of our DPA, we process your personal data within the region you selected for your dedicated endpoint.
  • We do not use multi-region routing, load balancing, or automatic overflow/failover to other regions for dedicated endpoints: inference runs only in the region you chose.
  • If your dedicated endpoint is configured in the EU, the inference content and related metadata remain within that region.
5.3. Fine-Tuning Data Location & Storage Fine-tuning workloads have fixed processing locations, and all resulting data is stored centrally in the EU to ensure consistent compliance and governance:
  • Data storage (global policy): regardless of customer origin (EU, US, or other regions), all fine-tuning datasets, artifacts, and model outputs are stored exclusively in EU data centers.
  • Processing for EU customers: fine-tuning jobs submitted by EU users are processed in EU data centers, and their data is stored in the EU.
  • Processing for US customers: fine-tuning jobs submitted by US users are processed in US data centers, but all data is stored in the EU.
Fine-tuning does not offer regional selection options, unlike inference endpoints. 5.4. Future Changes We notify customers in advance of changes that may affect their compliance posture:
  • Terms of Service and DPA changes: we provide notice of any changes to our Terms of Service, including the DPA. Previous versions of our legal documents remain available in the online archive on the documentation site.
  • Sub-processor changes: at least fifteen (15) days’ prior notice of any addition or replacement of a subprocessor.
  • Model deprecations: deprecations of models are announced in advance so you can migrate your workloads.

6. Sub-Processors

Like every cloud provider, we rely on carefully selected sub-processors – both Nebius group companies and external providers – for parts of the service such as cloud infrastructure, inference capacity, customer support, payments and billing.
  • Current list: we maintain a public, up-to-date Sub-processor List showing each sub-processor’s role and location, together with the list’s effective date: https://docs.tokenfactory.nebius.com/legal/subprocessors .
  • Safeguards: each sub-processor is bound by a written agreement imposing data-protection obligations no less protective than those in our DPA.
  • Advance notice of changes: we will give you at least fifteen (15) days’ prior notice before adding or replacing a sub-processor. You may object on reasonable data-protection grounds; if no mutually acceptable solution is found, you may terminate the affected services and receive a pro-rata refund of prepaid, unused fees.

7. International Data Transfers

  • Standard Contractual Clauses (SCCs): where personal data protected by the GDPR, UK GDPR or Swiss FADP is transferred to a country without an adequacy decision, the transfer is governed by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into our DPA. This also covers administrative, maintenance and support access to data from outside the EEA – for example, by Nebius group entities in the United States, Israel or Serbia listed in the Sub-processor List.
  • United Kingdom and Switzerland: transfers of UK-protected data are additionally covered by the ICO’s International Data Transfer Addendum, and Swiss-protected data by the Swiss adaptations, both set out in Annex 2 of the DPA.
  • EU-US Data Privacy Framework (DPF): we are certified under the EU-US Data Privacy Framework, which enables compliant transfers of personal data from the EU/EEA to the United States in addition to other available transfer mechanisms. As a DPF-certified organization, we adhere to the DPF Principles and maintain safeguards designed to ensure an appropriate level of protection for EU personal data.

8. Compliance & Certifications

8.1. GDPR Compliance We are fully compliant with the General Data Protection Regulation (GDPR). Our practices and policies are built to meet these rigorous requirements for data protection. 8.2. Data Processing Agreement (DPA) We provide a DPA to all our customers. To keep the process simple, the DPA is incorporated directly into our Terms of Service: by signing up and agreeing to the Terms of Service, you are covered by the DPA – no separate signature is needed. If your procurement or regulatory process requires a countersigned copy of the DPA or additional contractual arrangements, contact your account manager or our support team. 8.3. Certifications We are a certified company holding ISO 27001, ISO 27701 and SOC 2 Type II certifications. These internationally recognized standards demonstrate our commitment to information security, privacy, and operational resilience. For details, visit our Trust Center: https://nebius.com/trust-center . 8.4. Requesting Audit Reports Audit reports and certificates (e.g., the SOC 2 Type II report) are available through our Trust Center; certain reports are shared under a non-disclosure agreement. If a third party – such as an external risk assessor – requests reports on your behalf, we will ask for your authorization first. In addition, under the DPA you may request, in writing and at no cost, documentation reasonably necessary to demonstrate our compliance, and you may commission an audit by an independent, suitably qualified auditor with at least 30 days’ notice, once per calendar year. 8.5. HIPAA Compliance We also provide secure services to help customers meet the requirements of the U.S. Health Insurance Portability and Accountability Act (HIPAA). More details: https://docs.tokenfactory.nebius.com/legal/hipaa-guideline .

9. Security, Audits & Incident Response

  • Security measures: we implement and maintain appropriate technical and organizational measures, summarized in Annex 3 of the DPA. They include encryption at rest and in transit, access management based on need-to-know, least privilege and segregation of duties, logging and audit trails, physical security of data centers, personnel background checks and confidentiality training, change management, and business-continuity plans.
  • Breach notification: we will notify you without undue delay after becoming aware of a security breach affecting your personal data and will provide the necessary information and reasonable assistance.

10. Sensitive & Regulated Data

  • Special-category personal data (Art. 9 GDPR): our DPA expressly contemplates that Customer Content may include special categories of personal data – such as health data or biometric data – the extent of which you determine and control (DPA Annex 1(B)). As the Data Controller, you are responsible for ensuring a lawful basis and for any required notices, consents or authorizations before submitting such data.
  • Recommended controls: for sensitive workloads, we recommend enabling Zero Data Retention and using a dedicated endpoint in your preferred region (see Sections 4 and 5).
  • US healthcare data: for HIPAA-regulated workloads, see our HIPAA guideline (Section 8.5).
You own what you create. We claim no rights to the intellectual property you develop on our platform.
  • You retain all ownership rights to your input data and datasets.
  • You retain all ownership rights to any fine-tuned and distilled models you create.
  • You retain all ownership rights to the content generated by the models from your inputs.
  • You acknowledge that your outputs may not be unique, and other users of the service may receive the same or similar outputs.

12. Key Documents & Contacts

Privacy contact: privacy@nebius.com (Data Protection Officer). For written confirmations, countersigned documents or contractual addenda, contact your account manager or our support team.

13. Frequently Asked Questions (FAQ)

Data Processing & Location

Where is my data processed? The processing location depends on the specific AI model you choose. We host models in data centers within the European Union, the United States and Israel. You can see the specific location for each model in the Nebius Token Factory interface before you use it. Will my dedicated endpoint ever process data in another region? No. Under Section 6.1 of our DPA, we process your personal data within the region you selected for the dedicated endpoint. There is no multi-region routing or automatic overflow to other regions. How will I be notified about changes in model hosting locations? We announce such changes proactively via email to all account owners and through notifications within the Nebius Token Factory platform. If my data is processed in the US, how do you ensure it complies with EU regulations like GDPR? For any transfers to countries without an EU adequacy decision, we rely on legally established transfer mechanisms – in particular the Standard Contractual Clauses incorporated into our DPA – and we are certified under the EU-US Data Privacy Framework (see Section 7).

Data Retention & Control

Is my data used to train your AI models? No. We do not use your content to train, fine-tune or improve any AI models – ours or third parties’. Unless you enable Zero Data Retention, your inputs and outputs may be stored and used solely for Speculative Decoding (see Section 3), which does not involve training any model. What happens if I don’t enable Zero Data Retention? Your API inputs and outputs may be stored and used for Speculative Decoding – and for no other purpose. What happens to my data when I stop using the service? Upon termination or expiration of the services, we delete or return Customer Personal Data at your choice, except where retention is required by applicable law. Are you GDPR compliant? Yes. We are fully committed to and compliant with the GDPR. Do I need to sign a separate Data Processing Agreement (DPA)? No. Our DPA is an integral part of our Terms of Service: by agreeing to the ToS, you are automatically covered. If you need a countersigned copy for your procurement or regulatory process, contact your account manager. Who is my contracting party? Nebius B.V., a Netherlands company and a subsidiary of Nebius Group N.V. (NASDAQ: NBIS). The DPA is governed by Dutch law. How do I get your SOC 2 report or other security documentation? Through our Trust Center (https://nebius.com/trust-center ); certain reports are provided under NDA. Requests from third-party assessors require your authorization. How will I know if you change sub-processors? We provide at least 15 days’ prior notice of any addition or replacement of a sub-processor, and you have the right to object on reasonable data-protection grounds. Can commitments such as ZDR or region pinning be recorded in my contract? The region commitment for dedicated endpoints is already a binding term of the DPA, which forms part of your agreement. If you require additional contractual documentation – for example, an order form or addendum reflecting your ZDR configuration – contact your account manager. Can I process health data or other special-category data? Yes, subject to your responsibilities as Data Controller (lawful basis, notices, consents) – see Section 10. For sensitive workloads we recommend Zero Data Retention and a dedicated endpoint; for US healthcare data, see our HIPAA guideline. If you are bound by professional-secrecy rules, contact privacy@nebius.com first. Who owns the content I generate or the models I fine-tune? You do. You retain all intellectual property rights to your inputs, outputs, and any models you fine-tune or distill on our platform. Note that outputs may not be unique, and other users may receive the same or similar outputs.