{-- Shared page body for /legal/privacy and its localized URLs. The copy is English-only for now -- translating legal text needs counsel, not a content pass -- but each locale serves it from its own URL so the nav, footer and language switcher stay in the visitor's language instead of the whole site flipping to English. Same shape as the blog, whose localized pages render English posts in the localized layout. --} Privacy Policy | Akumi
The EU AI Act arrives August 2. Can you prove where your AI data goes?

Privacy Policy

Last updated: 28 June 2026

Who we are

Akumi is an EU-sovereign, OpenAI-compatible inference platform ("Akumi", "we", "us"). This Privacy Policy explains how we process personal data when you visit our website, create an account, and use the platform.

For questions about this policy or your personal data, contact our privacy team at privacy@akumi.cloud. Where a Data Protection Officer is appointed, their contact details will be published here.

Controller and processor: our two roles

We act as a controller for the personal data we decide the purposes and means of: your account, your use of our website, and our communications with you. This policy governs that processing.

For the content you send through the inference API, you are the controller and we act as your processor, processing it only on your instructions. That relationship is governed by our Data Processing Agreement, not by this policy.

Personal data we process

Depending on how you use Akumi, we process:

  • Account data: name, work email, organization details, and authentication identifiers you provide to register and sign in.
  • Customer content: the prompts, documents, and related data you send to the API, processed on your behalf as your processor (see the DPA).
  • Usage and billing data: the requests, tokens, modules, and credits consumed, and the payment details needed to bill the service.
  • Technical data: IP address, device and browser information, and security and diagnostic logs generated when you use the platform.
  • Communications: the content of support requests, sales enquiries, and other correspondence with us.

Cookies and similar technologies

Our website uses strictly necessary cookies to operate and secure the site, and, subject to your consent where required, limited analytics to understand and improve usage. You can control analytics cookies through the banner we present. Our Cookie Policy at akumi.cloud/legal/cookies details the specific cookies used.

How we use personal data

We use personal data to:

  • Provide, operate, secure, and improve the platform and website.
  • Authenticate users and manage accounts, roles, and access.
  • Meter usage and process billing and payments.
  • Provide support and respond to your enquiries.
  • Detect, prevent, and investigate abuse, fraud, and security incidents.
  • Comply with legal obligations and enforce our terms.

How we do not use it

We do not sell personal data. We do not use your customer content to train, fine-tune, or improve any models. Memory and retrieval features process your content only as you configure them, on EU-sovereign infrastructure.

Legal bases

Where we act as controller, we rely on one or more of the following legal bases under the GDPR:

  • Performance of a contract, to provide the service you signed up for.
  • Legitimate interests, to secure, operate, and improve the platform, balanced against your rights.
  • Consent, where required, for example for non-essential cookies or marketing, which you may withdraw at any time.
  • Compliance with a legal obligation, for example tax, accounting, and responding to lawful requests.

Sharing and recipients

We share personal data only as needed to run the service:

  • Sub-processors and service providers that host and support the platform, bound by contract and processing only on our instructions. The current sub-processor list is published at akumi.cloud/legal/sub-processors and forms part of the DPA.
  • External model providers, only where you have explicitly allowed routing to them through the egress guard, with personal data pseudonymized by the firewall or under a recorded acknowledgment.
  • Authorities or third parties, where required by law or to protect our rights, users, or the security of the platform.
  • A successor entity, in connection with a merger, acquisition, or reorganization, subject to this policy.

International transfers

The platform and your data are EU-resident. We do not transfer personal data outside the EU in the ordinary course of operating the service. Where you choose to allow routing to an external or non-EU model, that transfer happens only through the egress guard and under appropriate safeguards, such as the European Commission's Standard Contractual Clauses, and remains your decision as controller.

Retention

We keep personal data only as long as necessary:

  • Account and billing data: for the life of your account and as required afterwards by law (for example, accounting records).
  • Audit and trace records: for a fixed retention window, then pruned automatically.
  • Customer content: according to the retention you configure for each module; you can erase an end-user's data on demand.
  • Logs and security data: for a limited period proportionate to security and diagnostic needs.

Security

We protect personal data with the technical and organizational measures described on our Security and Trust page, including EU residency, tenant isolation, encryption in transit and at rest, role-based access control, and a metadata-only audit trail.

Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you, and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data in certain circumstances.
  • Restrict or object to certain processing, including processing based on legitimate interests.
  • Data portability, to receive your data in a structured, commonly used format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with your local data protection supervisory authority.

Exercising your rights

To exercise any of these rights, contact privacy@akumi.cloud. For personal data you process as a controller through the platform, you can fulfil end-user requests directly: the platform provides an erasure API to delete an end-user's stored data on demand.

Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. The models you run on the platform are under your control and configuration as the controller.

Children

Akumi is a business platform and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16.

Changes to this policy

We may update this policy as the platform and our obligations evolve. We will post the updated version here and revise the date below. Material changes will be communicated through the service or by email where appropriate.

Contact

For privacy questions, requests, or complaints, contact privacy@akumi.cloud. You also have the right to contact your local data protection supervisory authority.