Zero Data Retention Statement

NEXTBIT 256, S.L. — Data Handling Attestation

Version 1.0 | June 2026


1. Purpose and Scope

This statement is issued by NEXTBIT 256, S.L. ("Nextbit") in response to requests from customers and prospective customers seeking attestation of our data retention practices in connection with the use of our AI inference Services.

For questions or to request copies of Nextbit's binding data protection agreements, contact [email protected].


2. Summary of Nextbit's Data Retention Position

Nextbit's standard offering is not a zero-retention service in the sense that API request data may be retained for a limited operational period of up to ninety (90) days (see Section 4 below). However, the following commitments apply unconditionally to all customers and constitute the core of our data handling posture:

CommitmentStatus
Customer data used to train AI modelsNever
Customer data used to fine-tune or adapt AI modelsNever
Customer data shared with third parties for their own purposesNever
Operational data stored in isolated environments with restricted accessAlways
Automatic deletion upon expiry of the retention periodAlways
EU-resident infrastructure available upon requestYes
Custom retention arrangements available for enterprise customersYes — contact [email protected]

3. What "Zero" Means at Nextbit

Nextbit distinguishes between two layers of data handling:

Layer 1 — AI model training and adaptation: Nextbit does not use any data submitted through its Services — including prompts, inputs, outputs, or any derivative thereof — to train, fine-tune, retrain, evaluate, or otherwise adapt any AI model, whether operated by Nextbit or any third party. This commitment is unconditional, applies to all customers and all service tiers, and is contractually binding under Nextbit's agreements with all customers.

Layer 2 — Operational and infrastructure data: For the limited purpose of maintaining, diagnosing, and improving the performance and reliability of its infrastructure, Nextbit may retain data associated with API requests for a period of up to ninety (90) days following submission. This is described in detail in Section 4 below.

For the vast majority of compliance requirements — particularly those concerned with preventing vendor AI model enrichment from customer data — Nextbit's posture is functionally equivalent to zero data retention.


4. Operational Data Retention — Detail

Retention period: Up to 90 days from the date of the API request.

Purpose: Exclusively for service maintenance, performance diagnostics, capacity planning, error investigation, and security monitoring. This processing is carried out on the basis of Nextbit's legitimate interest under Article 6(1)(f) of Regulation (EU) 2016/679 (GDPR).

Storage: Data is stored in logically isolated environments with strict access controls. Access is limited to authorized engineering personnel on a need-to-know basis.

Deletion: Data is automatically and permanently deleted upon expiry of the 90-day retention period. No manual intervention is required.

What it is not: This operational retention does not constitute AI model training of any kind. It does not affect the inference behavior of any model available through the Services. It is not used for commercial profiling, analytics sold to third parties, or any purpose other than those described above.

Dedicated endpoint arrangements. Customers operating under a dedicated inference endpoint agreement may specify their own data retention policy as part of that agreement, including a zero-retention commitment. In such arrangements, Nextbit applies only the retention policy contractually agreed with the customer — no operational data is retained beyond what the customer expressly authorises. Customers interested in a dedicated endpoint arrangement should contact [email protected].


5. No AI Model Training — Contractual Basis

The prohibition on using customer data for AI model training is not merely a policy statement. It is a binding contractual commitment. Nextbit's agreements with all customers include the following representations:

  • "Nextbit does not use customer data to train, fine-tune, or otherwise adapt any AI model."
  • "Your Personal Data will not be used to train AI models."
  • "Nextbit does not use Personal Data submitted by the Controller to train, fine-tune, or otherwise adapt any AI model."

These commitments apply across all service tiers and form part of the binding agreement between Nextbit and each customer.


6. Data Residency

Nextbit operates its own physical data center located in Spain (European Union). In addition, compute capacity is provisioned through third-party cloud infrastructure providers, some of which operate nodes outside the European Economic Area.

Each inference endpoint available through the Nextbit Platform indicates in its product documentation whether it is hosted on EU-resident infrastructure. Customers with data residency requirements should select EU-resident endpoints and confirm this selection prior to use. Customers requiring EU-only processing arrangements may contact [email protected] to discuss available options.


7. International Data Transfers

Where data is processed on infrastructure located outside the EEA, Nextbit applies appropriate transfer safeguards primarily consisting of Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Decision 2021/914), supplemented where applicable by the EU–US Data Privacy Framework (DPF) for US-based sub-processors that have self-certified thereunder.

Customers should be aware that infrastructure providers operating in the United States may be subject to US federal law, including the CLOUD Act (2018) and FISA Section 702, which may permit US public authorities to compel access to data. Customers for whom this represents a material risk are encouraged to use EU-resident endpoints and to contact [email protected] to discuss their requirements.


8. Special Categories of Personal Data

Nextbit's Services are not designed or intended for the processing of Special Categories of Personal Data as defined in Article 9 GDPR (including health data, genetic data, biometric identification data, and data concerning racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or sex life). Submission of such data through the standard Services is prohibited. Customers requiring such processing must execute a separate written addendum with Nextbit prior to use.


9. Customer Rights and Deletion

Upon termination of a customer's agreement with Nextbit, all personal data associated with that customer's account is deleted within 60 calendar days of termination, including any data within the 90-day operational window. Customers may also request deletion in writing at any time by contacting [email protected].

Customers retain the right to request information about their data, correct inaccuracies, object to processing, and request data portability, in accordance with applicable data protection law (GDPR, LOPDGDD). All such requests should be directed to [email protected].


10. Enterprise and Custom Arrangements

Customers operating in regulated sectors or with specific compliance requirements — including those requiring contractually committed zero-retention periods, enhanced audit rights, or dedicated infrastructure — are invited to contact Nextbit at [email protected] to discuss available arrangements. This includes dedicated endpoint arrangements under which the customer specifies the applicable data retention policy, up to and including zero retention.

Nextbit does not guarantee the availability of any specific custom arrangement but will engage in good faith with customers who present documented compliance requirements.


11. Contact

For questions regarding this statement or Nextbit's data handling practices:

NEXTBIT 256, S.L. Carrer del Moll de la Duana, s/n, Edificio Lanzadera 46024 Valencia, Spain [email protected] https://www.nextbit256.com


This document reflects Nextbit's data handling practices as of June 2026. It may be updated to reflect changes in Nextbit's Services or applicable law. The current version is available upon request from [email protected].

Was this page helpful?