Skip to main content
Launching March 1, 2026

Legal

Privacy Policy

Last updated: February 12, 2026

1. Introduction

This Privacy Policy explains how Infinized B.V. ("Infinized", "we", "us", or "our") collects, uses, stores, and protects your personal data when you use the Infinized AI Control Plane ("Platform") and our related services.

We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.

By using the Platform, you acknowledge that you have read and understood this Privacy Policy. This Privacy Policy should be read in conjunction with our Terms of Service.

2. Data Controller

The data controller responsible for your personal data is:

Infinized B.V.

  • KVK (Chamber of Commerce): 88526461
  • VAT: NL864668788B01
  • Registered in the Netherlands
  • Email: contact@infinized.com

When you use the Platform to process personal data of your own end users or customers through your AI agents, you act as the data controller for that data, and Infinized acts as a data processor on your behalf. In such cases, a Data Processing Agreement (DPA) governs the processing relationship.

3. Data We Collect

Account Data

Information you provide when creating and managing your account:

  • Name and email address
  • Organization name and details
  • Password (stored in hashed form only)
  • Two-factor authentication settings
  • Role and team membership information
  • Communication preferences

Usage Data

Information collected automatically when you use the Platform:

  • IP address and approximate geolocation (country/region level)
  • Browser type, operating system, and device information
  • Pages visited, features used, and actions taken within the Platform
  • Timestamps and session duration
  • API usage patterns and request metadata (endpoints, response codes, latency)
  • Referral source and marketing attribution data

Agent Interaction Data

Data generated through the use of AI agents on the Platform:

  • Agent configurations, system prompts, and tool bindings
  • Conversation logs and chat history (as configured by your retention policies)
  • Model routing decisions and policy evaluation logs
  • Token usage and cost metrics per agent, project, and organization
  • Audit trail entries (actions taken, approvals, policy violations)

Note: The content of your prompts and AI outputs is processed to deliver the Services but is not used by Infinized for training AI models or for any purpose beyond service delivery.

Payment Data

Information related to billing and payments:

  • Billing name and address
  • Payment method details (processed and stored by our payment processor; Infinized does not store full credit card numbers)
  • Transaction history and invoice records
  • VAT identification number (where applicable)

4. How We Use Data

We use your personal data for the following purposes:

  • Service Delivery: To provide, operate, and maintain the Platform, including routing AI model requests, executing governance policies, and delivering agent functionality.
  • Account Management: To create and manage your account, authenticate your identity, and manage your subscription and billing.
  • Communication: To send you service-related notifications, security alerts, billing information, and responses to your inquiries. With your consent, to send marketing communications about new features and updates.
  • Platform Improvement: To analyze usage patterns, diagnose technical issues, and improve the Platform's performance, reliability, and user experience. This analysis uses aggregated and anonymized data wherever possible.
  • Security & Fraud Prevention: To detect, prevent, and respond to security incidents, fraud, abuse, and violations of our Terms of Service.
  • Legal Compliance: To comply with applicable legal obligations, respond to lawful requests from public authorities, and establish, exercise, or defend legal claims.
  • Audit & Governance: To maintain audit trails and governance logs as required by the Platform's functionality and your configured policies.

5. Legal Basis for Processing

Under the GDPR (Article 6), we process your personal data based on the following legal grounds:

Performance of Contract (Article 6(1)(b))

Processing necessary to perform our contract with you, including providing the Platform, managing your account, processing payments, and delivering the Services you have subscribed to.

Legitimate Interests (Article 6(1)(f))

Processing necessary for our legitimate interests, including improving the Platform, ensuring security, preventing fraud, and conducting analytics. We balance these interests against your rights and freedoms and do not process data where your interests override ours.

Consent (Article 6(1)(a))

Where we rely on your consent, such as for marketing communications or optional analytics cookies. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Legal Obligation (Article 6(1)(c))

Processing necessary to comply with legal obligations, such as tax and accounting requirements, responding to lawful data access requests, and maintaining records as required by law.

6. Data Sharing

We do not sell, rent, or trade your personal data to third parties. We only share data as described below and only to the extent necessary.

We may share your data with the following categories of recipients:

  • Third-Party AI Providers: When your agents route requests to AI model providers (such as OpenAI, Anthropic, Mistral, or Google), your prompts and relevant context are transmitted to those providers for processing. This sharing is initiated by your agent configurations and is necessary to deliver the AI functionality you have configured. Each provider processes this data under their own privacy policies.
  • Payment Processors: We share billing information with our payment processing partners to process transactions securely. These processors are PCI-DSS compliant and act as independent data controllers for payment data.
  • Infrastructure Providers: We use EU-based cloud infrastructure providers to host the Platform. These providers act as data processors under our instructions and are bound by Data Processing Agreements.
  • Analytics Providers: We use analytics tools to understand how the Platform is used. Where possible, we use privacy-friendly, EU-hosted analytics solutions. Data shared with analytics providers is anonymized or pseudonymized.
  • Legal & Regulatory: We may disclose data to law enforcement, regulatory authorities, or courts when required by law, to protect our legal rights, or to prevent harm.
  • Corporate Transactions: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you of any such transfer and any changes to this Privacy Policy.

All third-party recipients are required to protect your data in accordance with applicable data protection laws and our contractual requirements.

7. International Transfers

Infinized's Platform infrastructure is hosted entirely within the European Union. Your account data, usage data, and Platform metadata remain within the EU.

AI Provider Data Transfers

When you configure your agents to use Third-Party AI Providers, your prompts and context data may be transferred to and processed in countries outside the European Economic Area (EEA), depending on the provider you select. For example:

  • OpenAI and Anthropic may process data in the United States.
  • Mistral offers EU-hosted processing options.
  • Google may process data in various global locations.

These transfers are initiated by your agent configurations. You are responsible for assessing whether the transfer of data to a particular AI provider is appropriate for your use case and compliant with your data protection obligations.

Safeguards

Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) with our sub-processors.
  • Adequacy decisions by the European Commission, where applicable.
  • Supplementary technical and organizational measures to protect data in transit and at rest.

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Account Data

Retained for the duration of your account and for 30 days after account termination to allow for data export. Permanently deleted thereafter.

Agent Interaction Data

Retained according to the retention policies you configure per project and organization. You may set custom retention periods or request deletion at any time.

Audit Logs

Retained for a minimum of 12 months for compliance and security purposes, or longer if required by your subscription plan or applicable law.

Usage & Analytics Data

Aggregated and anonymized usage data may be retained indefinitely for statistical and improvement purposes. Identifiable usage data is retained for up to 24 months.

Payment & Billing Data

Retained for the duration required by applicable tax and accounting laws (typically 7 years in the Netherlands).

9. Your Rights

Under the GDPR, you have the following rights regarding your personal data. You may exercise these rights at any time by contacting us at contact@infinized.com.

Right of Access

You have the right to request a copy of the personal data we hold about you and information about how we process it.

Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data we hold about you.

Right to Erasure

You have the right to request deletion of your personal data, subject to legal retention requirements and legitimate interests.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format.

Right to Restriction

You have the right to request that we restrict the processing of your personal data in certain circumstances.

Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw your consent at any time without affecting prior lawful processing.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. Our lead authority is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).

We will respond to your request within 30 days. In complex cases, we may extend this period by an additional 60 days, in which case we will inform you of the extension and the reasons for it.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.
  • Access Controls: Role-based access controls (RBAC) with the principle of least privilege. Multi-factor authentication for all administrative access.
  • Infrastructure Security: EU-hosted infrastructure with network segmentation, firewalls, intrusion detection, and DDoS protection.
  • Monitoring: Continuous security monitoring, logging, and alerting for suspicious activities.
  • Vulnerability Management: Regular security assessments, penetration testing, and timely patching of known vulnerabilities.
  • Incident Response: Documented incident response procedures. In the event of a personal data breach, we will notify affected individuals and the relevant supervisory authority within 72 hours as required by the GDPR.
  • Employee Training: All employees with access to personal data receive regular data protection and security training.
  • Tenant Isolation: Data is isolated at the organization level. Cross-tenant data access is architecturally prevented.

While we strive to protect your personal data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to maintaining industry-standard protections.

11. Cookies

We use cookies and similar tracking technologies on the Platform and our website. Cookies are small text files stored on your device that help us provide and improve our services.

Types of Cookies We Use

  • Essential Cookies: Required for the Platform to function properly, including authentication, session management, and security. These cookies cannot be disabled.
  • Analytics Cookies: Help us understand how visitors interact with our website and Platform, allowing us to improve the user experience. These are only set with your consent.
  • Preference Cookies: Remember your settings and preferences, such as language and display options. These are only set with your consent.
  • Marketing Cookies: Used to deliver relevant advertisements and track campaign effectiveness. These are only set with your explicit consent.

You can manage your cookie preferences at any time through the cookie consent banner on our website or by adjusting your browser settings. Please note that disabling essential cookies may affect the functionality of the Platform.

12. Children's Privacy

The Platform is not intended for use by individuals under the age of 18 (or the age of legal majority in their jurisdiction). We do not knowingly collect personal data from children.

If we become aware that we have collected personal data from a child without appropriate parental or guardian consent, we will take steps to delete that data promptly. If you believe we may have collected data from a child, please contact us at contact@infinized.com.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or applicable laws. When we make changes:

  • We will update the "Last updated" date at the top of this page.
  • For material changes, we will notify you by email and/or by displaying a prominent notice within the Platform.
  • Material changes will take effect 30 days after notification, unless a longer period is required by law.

We encourage you to review this Privacy Policy periodically. Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

14. Contact & Data Protection

If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how we handle your personal data, please contact us:

General Inquiries

Data Protection Inquiries

  • For data protection related requests, data subject access requests, or to contact our data protection team:
  • Email: contact@infinized.com

Supervisory Authority

If you are not satisfied with our response to your data protection inquiry, you have the right to lodge a complaint with the Dutch Data Protection Authority: