Start free

Privacy policy

ALX AI Platform

Data controller for this platform: Alexandra Instituttet A/S, CVR 24213366, Helsingforsgade 12, 2100 København Ø, Denmark.

This privacy policy describes how Alexandra Instituttet A/S processes personal data in connection with operating the ALX AI Platform. It covers two distinct situations: (1) where Alexandra Instituttet processes your account information as a data controller, and (2) where a customer uses the platform to process data, in which case Alexandra Instituttet acts as a data processor on the customer's behalf. See section 2 for the distinction.

1. Who we are

The ALX AI Platform is provided by Alexandra Instituttet A/S. It is a locally hosted AI service where all data processing takes place at Danish locations.

You can contact us regarding this policy via:

Email: support-inference@alexandra.dk

2. Two roles: controller and processor

The ALX AI Platform consists of two elements, which are treated differently:

  • Dashboard (User Data). When you create and manage an account β€” contact details, login and payment β€” Alexandra Instituttet is the data controller for this information, and this policy applies directly.
  • API (Payload). When you, as a customer, send data to the AI models via the API, Alexandra Instituttet processes that data as a data processor, solely on your documented instructions. You (the customer) are the data controller for the content and are responsible for having a lawful basis for processing. The terms for this processing are set out in the data processing agreement, not in this policy.

3. What personal data we process

User Data (dashboard) β€” we are the controller

Ordinary personal data: username, password, email address, IP address and payment information.

API Payload β€” we are a processor on the customer's behalf

Potentially any type of personal data the customer chooses to submit as input, including ordinary personal data, sensitive personal data, national identification (CPR) numbers, criminal-record data and data concerning children under 15.

We do not select this data ourselves β€” it is determined by the customer's prompts and input to the service.

4. Purposes and legal basis

  • User Data is processed to create and operate your account, deliver the service, handle payment and ensure the security and operation of the platform. The legal basis is typically performance of a contract (GDPR Article 6(1)(b)) and our legitimate interest in secure operation (Article 6(1)(f)).
  • API Payload is processed solely to produce the AI model's response on the customer's instructions. The legal basis for the content is determined by the customer as data controller.

5. Retention and deletion

  • User Data is retained for as long as your account exists.
  • API Payload (including prompts) is deleted immediately after the model has finished producing its response. Payload data is not logged. Technical runtime data may be temporarily processed in volatile memory to the extent technically necessary to produce a response, but is not stored permanently, is not used for training, and is automatically deleted or overwritten.
  • On termination of the service, personal data is deleted. Data held in backups is deleted in accordance with our ordinary backup cycle.

6. Recipients and sub-processors

We use the following sub-processors, all of which process data at Danish locations:

  • A/S ScanNet (CVR 29412006), Skanderborg β€” GPU as a Service (hosting/compute).
  • Nets Denmark A/S (CVR 20016175), Ballerup β€” payment platform (a subset of user data).

There is no transfer of personal data to third countries outside the EU/EEA in connection with these sub-processors. Processing by sub-processors takes place exclusively at Danish locations with ISO 27001-certified providers.

7. Security

We implement appropriate technical and organisational measures, including:

  • ISO 27001 certification for the processor and sub-processors.
  • Encryption of API input in transit (HTTPS).
  • Access restriction, so that only relevant, authorised staff have access.
  • Confidentiality obligations for all staff.
  • Logging of dashboard activity and administrator actions to an appropriate extent (API Payload is not logged).
  • Physical security of server facilities (access control, alarm, surveillance, guard service).
  • Documented procedures for handling security breaches and disaster recovery, reviewed at least annually.

8. Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction, data portability and objection, as well as the right not to be subject to a decision based solely on automated processing.

  • If your request concerns User Data, you can contact us directly (see section 1).
  • If your request concerns data submitted via the API, you should contact the customer who is the data controller for that data. If we receive such a request directly, we will forward it to the relevant customer.

9. Complaints

You may lodge a complaint with the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, www.datatilsynet.dk.

10. Changes

We may update this policy. The current version is published at platform.alexandra.dk.