Privacy policy
Last updated: August 2026
beServe (Belgium) operates an AI inference gateway. This policy explains what personal data we process and why, in accordance with the GDPR (RGPD).
1. Data controller
beServe, Belgium. Contact: privacy@beserve.eu.
2. Data we process
- Account data: email, name, password hash (argon2id), TVA number if provided.
- Usage metadata: per API request — model, token counts, latency, status code, timestamp. We do not store prompt or response content.
- Billing data: processed by Paddle (merchant of record, EU). We store invoice references only.
- Technical logs: request IDs and rate-limit counters, kept briefly for security and abuse prevention.
3. Why (legal bases)
- Contract performance (Art. 6(1)(b)): providing the inference service, account management.
- Legitimate interest (Art. 6(1)(f)): service security, abuse prevention.
- Legal obligation (Art. 6(1)(c)): accounting and TVA records.
4. Processors and hosting
- Scaleway — inference compute, Paris (France) datacenter. Your prompts are forwarded to Scaleway to fulfil the request and are not used by Scaleway for model training under their EU terms.
- Paddle — payments, merchant of record.
- Hetzner — application hosting (EU datacenter).
No data is transferred outside the European Union.
5. Retention
- Account data: for the life of the account.
- Usage metadata: 24 months, then aggregated.
- Invoices: 7 years (Belgian accounting law).
6. Your rights
Access, rectification, erasure, restriction, portability and objection. Exercise them from your dashboard settings or via privacy@beserve.eu. You may lodge a complaint with the Belgian DPA (Gegevensbeschermingsautoriteit / Autorité de protection des données).
7. Cookies
We use a single strictly-necessary session cookie for login. No analytics or tracking cookies.