Legal
Privacy policy
This policy explains how One To Infinity Power LTD("Aisty", "we") collects, uses and protects personal data in connection with the Aisty platform (the "Service"). It is written to the EU General Data Protection Regulation, the UK GDPR and the Data Protection Act 2018.
1. Controller and contact
- Controller: One To Infinity Power LTD, company number 14195440, England and Wales
- Data protection contact: [email protected]
2. Two roles, controller and processor
As a controller, we process personal data of our account holders and website visitors, such as account, billing and support data, for our own purposes, as described below.
As a processor, we process personal data contained in Customer Content, meaning datasets, prompts and inference inputs and outputs, on behalf of and under the instructions of our customers. For that processing the customer is the controller and our Data Processing Addendum governs. This policy describes our controller processing and summarises the processor processing for transparency.
3. Personal data we process as controller
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, work email, team membership, role, authentication identifiers | You |
| Billing | Billing contact, payment-method token and status, invoices, usage records | You and our payment processor |
| Usage and telemetry | API request metadata, deployment and training job metadata, log timestamps, IP address | Automatically |
| Support | Correspondence and tickets | You |
| Website | The single consent value described in the cookie policy | Automatically |
Payment card data is handled by our PCI DSS compliant payment processor. We do not store full card numbers.
4. Customer content, where we are processor
Datasets, prompts, model inputs and outputs, and fine-tuned artifacts may contain personal data that you choose to include. We process it only to provide the Service, for example transferring a dataset to a training instance, loading a model onto an inference instance, or serving responses. We do not use Customer Content to train or improve models for ourselves or for other customers. Stateless deployments retain no request content server-side.
5. Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Provide and operate the Service, manage accounts and teams | Contract, Article 6(1)(b) |
| Billing, invoicing and fraud prevention | Contract, and legal obligation, Article 6(1)(c) |
| Security, abuse prevention, logging and incident response | Legitimate interests, Article 6(1)(f), securing the Service |
| Product analytics and improvement | Legitimate interests, or consent for anything non-essential |
| Support and service communications | Contract, and legitimate interests |
| Legal compliance and responding to lawful requests | Legal obligation |
| Marketing, if any | Consent, Article 6(1)(a), withdrawable at any time |
Where we rely on legitimate interests we have balanced them against your rights, and you may object as described in Section 9.
6. Sub-processors and recipients
We share personal data with vetted sub-processors who process it only on our instructions under Article 28 contracts. They fall into these categories: GPU compute and infrastructure providers, object storage, payment processing, authentication, database hosting, edge network and TLS termination, secrets management, transactional email and support, and the repositories from which base model weights are pulled.
The current list, naming each sub-processor with its role, processing location and transfer safeguard, is provided to customers on request and at contracting. Write to [email protected] for a copy. Material additions or replacements are announced to team owners by email with 30 days' notice, and customers may object on reasonable data protection grounds under the Data Processing Addendum.
We may also disclose data to professional advisers, and to authorities where legally required.
7. International transfers
Where personal data is transferred outside the UK or the EEA, we rely on an appropriate safeguard under Chapter V of the GDPR, being Standard Contractual Clauses with the UK Addendum, or an adequacy decision, and we apply supplementary measures where needed.
On data residency, compute is provisioned in the United Kingdom by default, and object storage is configured to a UK or EU region for personal data originating in the UK or the EEA. If your deployment has a specific residency requirement, confirm the region configuration with us before you upload personal data.
8. Retention
We keep personal data only as long as necessary for the purposes above.
- Account data, for the life of the account and then per our retention and disposal schedule
- Billing and invoice records, for six years, as required by tax and accounting law
- Security logs, for twelve months, or longer where required for an investigation
- Customer Content, deleted or returned on termination or on your instruction. Ephemeral training instances are torn down after each job
9. Your rights
Subject to conditions and exemptions, you have the right to access, rectification, erasure, restriction, portability and objection, including objection to processing based on legitimate interests and to direct marketing, and the right to withdraw consent. You also have the right to lodge a complaint with a supervisory authority. In the UK that is the Information Commissioner's Office, and in the EU it is your local data protection authority.
- For data we hold as controller, write to [email protected]. We respond within one month
- For Customer Content, where we act as processor, we forward or assist with data-subject requests to the relevant customer, who is the controller
We do not carry out solely automated decision-making producing legal or similarly significant effects on individuals for our own purposes. Where you build such systems on the Service, you are responsible for Article 22 of the GDPR and for EU AI Act compliance.
10. Security
We implement technical and organisational measures aligned to ISO/IEC 27001, including TLS in transit, scoped and hashed API keys, per-deployment network firewalls and source allowlists, least-privilege access, logging and monitoring, and vendor security review. No system is perfectly secure. We maintain an incident response plan and will notify affected parties and regulators of a personal-data breach as required under Articles 33 and 34 of the GDPR, generally within 72 hours of becoming aware.
11. Children
The Service is not directed to children and is for business use only. We do not knowingly collect data from anyone under 18.
12. Changes
We may update this policy. The effective date above reflects the latest version, and material changes will be notified. Continued use after the effective date constitutes acknowledgement.
13. Contact
Privacy questions or requests go to [email protected]. One To Infinity Power LTD, company number 14195440, England and Wales.