Privacy Policy

Last updated: July 3, 2026

1. Controller

Nodion GmbH
Königstraße 27
70173 Stuttgart, Germany
Email: privacy@nodion.ai

2. What We Collect

Data Purpose Legal Basis
Email address Account creation, login codes, service communication Art. 6(1)(b) GDPR
Billing information (name, address, VAT ID) Invoicing, tax compliance Art. 6(1)(b), (c) GDPR
Payment data (via Stripe) Processing top-ups and subscriptions Art. 6(1)(b) GDPR
API usage metadata (model, token counts, timestamps) Billing, rate limiting, abuse prevention Art. 6(1)(b), (f) GDPR
IP address, request metadata Security, abuse prevention Art. 6(1)(f) GDPR

3. API inference data

We never use your data to train or fine-tune models.

Endpoint Prompt / output storage
Completion endpoints Not stored. Only token counts are logged for billing.

4. What We Do Not Do

  • We do not use your data to train or fine-tune models
  • We do not use tracking cookies or third-party analytics on this website
  • We do not sell or share personal data with third parties for their marketing

5. Processors

We use the following third-party processors:

  • Stripe Payments Europe, Ltd. for payment processing. Card details are handled directly by Stripe; we only receive payment status and billing metadata. Stripe may process data outside the EU/EEA with appropriate safeguards (for example Standard Contractual Clauses). See Stripe's Privacy Policy.

All AI inference runs on infrastructure we operate in the EU (see section 6). We do not send your requests to third-party model APIs unless we say so for a specific model.

6. Data Location

AI inference and storage of API payloads (where applicable) are processed exclusively within the European Union. Our GPU infrastructure is located in Germany, Sweden and Finland. Our database and application servers are located in Germany.

Payment processing via Stripe may involve transfers outside the EU/EEA as described in Section 5. Account and billing data remain in the EU.

7. Cookies

This marketing website (nodion.ai) does not set tracking cookies. The customer portal (my.nodion.ai) uses strictly necessary session cookies to keep you logged in. These are required for the Service and are not used for advertising.

8. Data Retention

  • Account data: retained until account deletion
  • Usage and billing data: retained for the legally required period (10 years for tax records in Germany)
  • Responses API data: automatically deleted after 30 days
  • Uploaded files: automatically deleted after 24 hours
  • Security logs: retained for up to 30 days
  • Login codes: deleted after use or expiration (10 minutes)

9. Your Rights

Under GDPR, you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data ("right to be forgotten", Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)

To exercise these rights, email us at privacy@nodion.ai. We will respond within 30 days.

10. Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for Nodion GmbH is:
The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI BW)
Königstraße 10a
70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de

11. Changes

We may update this policy from time to time. Material changes will be communicated via email. The latest version is always available at this URL.

12. Contact

For privacy-related questions:
Email: privacy@nodion.ai