Skip to content

Data processing agreement

Version 1.1 · August 28, 2026

Before you read it

  • Execution is by email. There is no countersigning flow in the console. Send a signed copy to sales@infro.io and you will have ours back within two business days.
  • EU data residency is not in place. Section 6 says where processing actually happens. If your purchase depends on residency, read that first — it is the most likely reason this document does not work for you.
  • No certification is held. Section 5 describes measures that are true today. See security for what is and is not audited.
  • This is a standing offer in plain terms, not legal advice. Redlines are expected and welcome.

1. Roles and scope

You are the controller of personal data contained in requests you send to INFRO. In this agreement, INFRO means Eslam Osama Mohamed, trading as INFRO. INFRO is a processor of that data, acting only on your documented instructions — which, for the API, means the requests themselves and the settings you configure in the console.

This agreement applies alongside the terms of service and takes precedence over them on any point about personal data. It incorporates the subprocessor list and the privacy policy by reference.

2. What is processed

CategoryRetentionBasis
Request and response contentNot stored by default. Stored only if you enable content logging, for the window you choose: 14 days, 30 days, 60 days, or 1 year.Your instruction
Request metadata — model, token counts, latency, cost, the tags you attach90 days for the request log; usage aggregates for as long as the account is active, because billing depends on themPerformance of the contract
Account data — names, email addresses, organisation membershipFor the life of the account, then 30 daysPerformance of the contract
Billing and subscription recordsSeven years, under the statutory accounting obligation. Subscription charges only — model usage is invoiced to you by your own providers and we hold no record of what they chargedLegal obligation
Security signals — the country an API key was used from, and a daily count30 days. No IP addresses are stored.Legitimate interest

Data subjects are whoever you choose to include in a request. We do not inspect content, so we cannot categorise it for you — if you send special-category data, section 3 is the part that matters.

3. Our obligations

  • Process only on your instructions. If we believe an instruction breaks data protection law, we tell you rather than carry it out.
  • Never use your data to train models. Not ours, not a provider’s. Every upstream agreement we hold excludes it, and there is no INFRO model to train.
  • Confidentiality. Everyone with access is bound by it. Access to production data requires an individually-provisioned operator account, and every operator action is recorded in an append-only audit log.
  • Assist you. With data subject requests, with impact assessments, and with regulator enquiries — see section 7.
  • Tell you about a breach without undue delay, and in any case within 48 hours of becoming aware, with what we know at the time rather than waiting until we know everything.

4. Subprocessors

You give general authorisation for the subprocessors listed at /subprocessors. We stay responsible for their performance as if it were our own.

30 days’ notice by email to account owners before a new subprocessor begins processing, and you may object in writing during that window. If we cannot accommodate an objection, you may terminate the affected processing; the refund policy governs the remainder of a paid period. Adding an AI provider is not a subprocessor event — those accounts are yours, not ours. Emergency additions of infrastructure during an outage are notified within 72 hours instead.

Model providers are listed by category on that page and by name under NDA. The reason is on the page. If your review cannot accept it, raise it at sales@infro.io before you sign rather than during the review — there is no configuration of INFRO that takes model providers out of this agreement.

5. Security measures

These are true today and are enforced by the system rather than by policy. They are what section 3 of the SCCs would call technical and organisational measures.

  • Encryption in transit — TLS 1.3 on every connection, including to upstream providers.
  • Encryption at rest — database and object storage encrypted by the platform. Provider credentials, including any you attach, are additionally sealed with AES-256-GCM under a key held outside the database, bound to the row they belong to.
  • API keys are hashed, never stored. A database copy contains no usable credential.
  • Least privilege. Operator access is a separate authentication realm from customer accounts, sharing no table, no secret and no session — a compromised customer account cannot become an operator one.
  • Append-only audit. The audit log refuses updates and deletes at the database level, including by us.
  • Content isolation. Stored content lives in a separate table from billing records with its own retention, so deleting it never damages the records we are obliged to keep.

What is not in place: no SOC 2 or ISO 27001 certification is held, and no independent penetration test has been performed. Both are stated on /security and neither is claimed here.

6. International transfers

Requests are served from the Cloudflare location nearest the caller, so processing in transit happens wherever you call from. The primary database is in Frankfurt (eu-central-1). Payment providers process buyer and transaction data globally under the role and terms identified at checkout; they do not receive API request content. Model providers are in the United States and the European Union, varying by provider.

For transfers out of the EEA, UK or Switzerland we rely on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, module two: controller to processor), incorporated into this agreement by reference, with the UK Addendum and the Swiss amendments where they apply.

We do not offer EU data residency, and a hostname that implied it would be false. Constraining processing to a region requires infrastructure entitlements we have not purchased, and the claim is one you could falsify in a single request. If residency is a hard requirement, tell us before you buy rather than after — the honest answer today is no.

7. Data subject requests

You handle requests from your own data subjects; we help. Because content is not stored by default, most requests need nothing from us. Where content is stored:

  • Access and export — every stored request is retrievable through the API and exportable in bulk.
  • Deletion — you can delete stored content at any time, and it expires on its own at the retention you set. Billing records survive deletion, because we are obliged to keep them; they contain no request content.
  • We will not respond directly to a data subject who contacts us about your data. We refer them to you and tell you it happened.

Write to support@infro.io for assistance. We respond within five business days.

8. Audit

On request, and no more than once a year unless a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this agreement. Once a certification report exists it will satisfy this section; until then it is answered in writing, and we would rather tell you what we have not done than describe an audit that has not happened.

9. Deletion on termination

Within 30 days of the account closing we delete stored content, account records, security signals and the provider credentials you connected. Billing records for the subscription are retained for seven years under the legal obligation in section 2, and they contain no request content.

You can export everything before then, and we will confirm deletion in writing if you ask.

10. Liability and precedence

Liability under this agreement is subject to the limitations in the terms of service. Where the SCCs conflict with this agreement, the SCCs prevail; where this agreement conflicts with the terms of service on personal data, this agreement prevails.

Executing it

Send a signed copy to sales@infro.io, naming the organisation it covers. We countersign and return it within two business days.

If your counsel needs a Word version, an entity-specific version, or has redlines, ask for those in the same email. A DPA that has been through a real review is worth more to us than one nobody read.

Material changes to this agreement are notified to account owners by email 30 days before they take effect. Superseded versions stay available on request.