Privacy Policy
Effective Date: May 2026
NEXTBIT 256, S.L. (referred to as "us," "our," or "we") values your privacy and strives to safeguard any information you share with us or that we otherwise acquire.
This Privacy Policy explains our approach regarding the Personal Data gathered from you or about you while accessing our websites and services (collectively referred to as the "Services"). This Policy excludes data processed on behalf of our customers in the course of service provision; such data processing is governed by the Nextbit Data Processing Agreement (DPA), available at https://www.nextbit256.com/docs/dpa, which applies automatically when customers use the Services to process personal data of third parties.
Collection of Personal Data
We collect information which, individually or combined with other data available to us, can identify you ("Personal Data"), as detailed below:
Information Provided by You
We gather Personal Data when you register an account or interact with us directly, including:
Account Details: During account creation, we collect relevant information such as your name, contact details, login credentials, payment method details, and your transaction records (collectively "Account Data").
Content Submitted by Users: Utilizing our Services may involve submission of content containing Personal Data, including inputs and prompts submitted through the API, together with associated metadata such as model parameters, session identifiers, and configuration data (collectively "User Content"). Collecting this information is essential for delivering the functionalities you expect from our Services.
Communication Records: If you reach out to us, we may retain your identity details, contact information, and message content ("Communication Data").
Automatically Collected Information
When engaging with our Services, we automatically collect certain data concerning your interactions ("Technical Data"):
Log Information: Includes data automatically sent by your browser during website interactions ("Log Data"), comprising your IP address, browser specifics, request dates and times, and interaction patterns.
Usage Information: Covers your interactions with the Services, including viewed or accessed content, utilized features, actions performed, your geographic location, timestamps, device type, browser version, connection details, and IP address.
Device Details: Covers your device model, operating system, and browser specifics, varying based on device types and settings.
Cookies: Our Services utilize cookies to enhance functionality and user experience. Cookies are small data packets your browser receives from visited sites. You may customize cookie preferences within your browser settings; however, rejecting cookies may impact website usability or specific features.
Analytics Tools: We deploy analytical solutions utilizing cookies to study how visitors use our Services, enhancing user experience accordingly.
Infrastructure and Data Location
Nextbit operates compute infrastructure across two complementary environments:
Own data center
Nextbit operates its own physical data center located in Spain. Compute nodes hosted in this facility are located exclusively within the European Union.
Cloud infrastructure
In addition to its own data center, Nextbit provisions compute capacity through third-party cloud infrastructure providers. Some of these nodes are located within the European Economic Area (EEA); others may be located outside the EEA.
Identifying EU-resident endpoints
Each model or inference endpoint available through the Platform will indicate, in its product documentation or endpoint configuration page, whether it is hosted on EU-resident infrastructure. If an endpoint is not explicitly marked as EU-resident, it should be assumed that it may be hosted on infrastructure located outside the European Economic Area.
EU residence requirements
Each model or inference endpoint indicates in its product documentation whether it is hosted on EU-resident infrastructure. If you have specific data residency requirements not addressed by available endpoint documentation, contact us at [email protected].
International Data Transfers
Where Personal Data is processed on infrastructure located outside the EEA, the specific safeguards applied are primarily Standard Contractual Clauses (SCCs) approved by the European Commission. Where additionally applicable, Nextbit may rely on the EU–US Data Privacy Framework (DPF) for US-based sub-processors that have self-certified thereunder.
Customers who require documentation of the safeguards applicable to their specific data processing may request this by contacting us at [email protected].
Customers should be aware that cloud infrastructure providers incorporated or operating in the United States may be subject to US legislation, including the Clarifying Lawful Overseas Use of Data Act (Cloud Act, 2018) and the Foreign Intelligence Surveillance Act (FISA, in particular Section 702), which may permit US public authorities to compel disclosure of data held by those providers, regardless of the physical location of the servers on which such data is stored. This legal reality is not fully mitigated by Standard Contractual Clauses or other contractual transfer safeguards alone. The primary transfer mechanism Nextbit relies upon for such transfers is Standard Contractual Clauses (SCCs) approved by the European Commission. Where additionally applicable, Nextbit may rely on the EU–US Data Privacy Framework (DPF, adopted by the European Commission in July 2023) for US-based sub-processors that have self-certified under it. Customers should be aware that the DPF is subject to ongoing judicial review before the Court of Justice of the European Union and may be invalidated, as occurred with its predecessors (EU–US Safe Harbor in 2015 and EU–US Privacy Shield in 2020). In the event of such invalidation or any other change affecting the legal status of the DPF, Nextbit will transition to Standard Contractual Clauses or such other legally recognized transfer mechanisms as remain valid at that time. Nextbit accepts no liability towards customers, users, or any other third party arising from the potential invalidation or modification of the DPF or any other transfer mechanism by a competent court or regulatory authority, provided that Nextbit maintains at all times at least one valid transfer mechanism as required by applicable law. Customers for whom US government access represents a material risk — for example, those operating in regulated sectors or handling sensitive personal data — are strongly encouraged to contact us at [email protected] to discuss available alternatives.
Use of Personal Data
Your Personal Data will not be used to train AI models.
Nextbit does not intentionally collect or process Special Categories of Personal Data as defined in Article 9 of Regulation (EU) 2016/679 (GDPR), including health data, genetic data, biometric data, data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or data concerning a person's sex life or sexual orientation. Submission of such data through the standard Services is prohibited under the Terms of Service. If your use case requires processing Special Categories of Personal Data, you must contact [email protected] and execute a separate written addendum prior to any such use.
Your Personal Data primarily serves the following purposes:
- Providing, operating, maintaining, and analyzing our Services.
- Service performance and reliability improvement: Data associated with API requests made to the Services may be used on an occasional and targeted basis for the purpose of maintaining, diagnosing, and improving the performance and reliability of the Services. This does not constitute AI model training of any kind. The legal basis for this processing is our legitimate interest in maintaining and improving the efficiency and reliability of our Services.
- Improving our offerings through analysis and research.
- Facilitating communications with you.
- Protecting against fraud, crime, or misuse, and safeguarding our digital infrastructure.
- Complying with applicable legal obligations and processes, and defending our legal rights, property, or safety, including those of you or third parties.
AI Act. Nextbit provides AI inference infrastructure and operates as a technical infrastructure provider under Regulation (EU) 2024/1689 (EU AI Act). Customers who use the Services to develop or operate AI systems act as the provider or deployer of those systems under the AI Act and are solely responsible for their own compliance with applicable AI Act obligations. For details, see Section 8.2 of the Terms of Service.
Aggregate and Anonymized Data
We may aggregate or anonymize Personal Data to assess and improve our Services, enhance service features, and conduct research. We may also periodically evaluate user behavior patterns and share general user statistics with third parties or publicly disseminate these aggregated insights. Aggregated data collection occurs through our Services, cookies, and other described methods. Anonymized data is retained and utilized without attempts to re-identify individual users.
Disclosure of Personal Data
We may share your Personal Data under certain conditions without additional notice unless legally mandated:
Third-party Providers: To support our operational needs, we may share your Personal Data with service providers such as cloud hosting, IT services, email management systems, and analytics providers. These third parties process Personal Data solely based on our instructions for specified operational purposes.
Corporate Changes: In the event of strategic transactions such as mergers, reorganizations, bankruptcy proceedings, or transfers of service to another entity ("Transaction"), your Personal Data may be disclosed during the transaction process and transferred along with other assets to a successor or related entity.
Legal Obligations: If required by legal mandates or in good faith belief that disclosure is essential to comply with laws, safeguard our rights, combat fraud, protect user safety, or limit legal liability.
Your Rights
Depending on your geographic location, individuals in regions such as the European Economic Area (the "EEA"), Switzerland, or the United Kingdom (the "UK"), and elsewhere globally, may exercise specific statutory rights concerning their Personal Data, including:
- Accessing your Personal Data.
- Deleting your Personal Data.
- Correcting inaccuracies in your Personal Data.
- Transferring your Personal Data elsewhere.
- Withdrawing previously granted consent.
- Objecting to or limiting data processing where processing relies on legitimate interests, including service performance and reliability improvement as described above.
You may utilize these rights via your account settings. If unable to do so, contact us at [email protected]. We will respond within the timeframes required by applicable law. EEA residents may also lodge a complaint with their national data protection supervisory authority.
Minors
Our Services do not target individuals under 18 years of age, and we do not knowingly gather Personal Data from minors. If you suspect a minor has provided Personal Data through our Services, please notify us promptly at [email protected] for investigation and potential removal.
External Links
Our Services may include external links to third-party websites or social media platforms ("External Sites"). Information disclosed to External Sites is governed by their privacy policies, not this Privacy Policy. Links to External Sites do not imply our endorsement or review; please contact these third-party websites directly for their privacy practices. For instance, you can access Stripe's Privacy Policy here: https://stripe.com/es/privacy
Security and Data Retention
We apply commercially reasonable protective measures — technical, organizational, and administrative — to secure Personal Data against unauthorized access, loss, misuse, or alteration. Nonetheless, internet and email transmissions are never completely secure or error-free. Exercise caution when transmitting sensitive information via email or our Services. We are not accountable for bypassed security settings on our Services or external websites.
We retain Personal Data only as long as necessary to fulfill Service provisions or legitimate business purposes such as resolving conflicts, ensuring security, or complying with legal requirements. Retention periods depend on data volume, nature, sensitivity, associated risks, processing purposes, and legal obligations.
Nextbit collects and retains technical and operational data generated in connection with your use of the Services, including usage metrics, performance indicators, and service interaction records. This data is retained for as long as reasonably necessary for the purposes for which it was collected, including for the duration of the customer relationship and as required to comply with applicable legal obligations. Data associated with API requests made to the Services may be retained for a period of up to ninety (90) days following submission. During this period, Nextbit reserves the right to use such data on an occasional and targeted basis for the purpose of maintaining, diagnosing, and improving the performance and reliability of the Services. This does not constitute AI model training of any kind. Such data is stored in isolated environments with restricted access controls and is automatically and permanently deleted upon expiry of the retention period.
We may anonymize your Personal Data permanently for research or statistical use without further notification.
Privacy Policy Updates
This Privacy Policy may be periodically updated. Updates will be available on this page unless legally obligated otherwise. Continued use of our Services or provision of Personal Data following posted updates signifies consent to the amended Privacy Policy.
Contact Us
For unresolved questions or concerns regarding this Privacy Policy, please contact us at [email protected].
NEXTBIT 256, S.L. Carrer del Moll de la Duana, s/n, Edificio Lanzadera 46024 Valencia, Spain [email protected] https://www.nextbit256.com