Skip to content

Legal

Privacy Policy

Last updated & Effective: 28 June 2026

This Privacy Policy explains how Titan Tech Development L.L.C-FZ (“the Company”, “we”, “us”), the operator of the HyperInfer platform, handles personal data. Our guiding principle is simple: we process your data, we don’t possess it.

1. Who we are & scope

The data controller is Titan Tech Development L.L.C-FZ (Commercial Licence No. 2423941.01), a company incorporated in the United Arab Emirates. This policy covers our website, sales interactions, and the operational data of the Service; it does not cover inference content, which we do not retain (see §2).

For general privacy enquiries, contact [email protected]. We have appointed a Data Protection Officer, who is reachable at [email protected]. We have also appointed an EU representative (GDPR Art. 27) and a UK representative; both are reachable at the same address, [email protected].

2. Our core principle — zero data retention

For inference traffic we operate under zero data retention: inputs and outputs are processed transiently in volatile memory only for the time needed to generate a response, are never written to disk, logged, or used for training, and are purged on completion.

3. Information we collect

We collect the minimum needed to operate the Service and a business relationship:

  • Account information — name, work email, company and role, given when you contact sales or create an account.
  • Operational metadata — request timestamps, latency, token counts for billing, model IDs, region and error classes (no content).
  • Website data — privacy-respecting analytics and cookies (see our Cookie note).

4. What we never collect

We do not collect, store, log, or retain:

  • The content of your prompts, messages, or system instructions;
  • Model completions or responses;
  • Any files submitted for inference.

This content exists only in volatile memory for the duration of a single request.

5. How & why we use information

We use the limited information we do collect to provide and secure the Service; bill accurately; communicate with you about your account; meet legal and compliance obligations; detect and prevent abuse; and improve our website and products. We do not sell or “share” personal information (as defined under CCPA/CPRA), and we do not use inference content for any purpose.

6. Legal bases

Under the UAE PDPL (Decree-Law 45/2021) we rely on: performance of a contract with you; our compliance with legal obligations; protection of interests; and consent where required. Where the EU/UK GDPR applies (Art. 3(2)), we rely on the corresponding Art. 6 bases — contract, legitimate interests (to secure and improve the Service and prevent abuse), legal obligation, and consent. You may withdraw consent at any time.

Note: PDPL is consent-centric; where we cite “legitimate interests” it applies under GDPR, with a PDPL-recognised basis applied for UAE-scope processing.

7. Sharing & sub-processors

We share operational data only with vetted sub-processors that provide infrastructure and tooling (cloud and edge providers; metadata observability). Sub-processors never receive prompt or completion content. The current sub-processor list is published in the Trust Center, with 30 days’ notice of changes. We also disclose data where required by law, to protect rights and safety, or in a corporate transaction (subject to this policy).

8. International transfers

We are based in the UAE and may process operational data with sub-processors in other regions. For personal data originating in the EEA, UK or Switzerland, we use EU Standard Contractual Clauses, the UK IDTA/Addendum, and the Swiss addendum as applicable, plus a transfer-impact assessment; our zero-retention architecture and region pinning are supplementary safeguards. Transfers from the UAE follow PDPL Art. 22–23 (adequacy or appropriate safeguards).

9. Your rights

Subject to applicable law you may access, correct, delete, port, restrict, or object to processing of your personal data, and object to automated decision-making (PDPL Art. 13–18; GDPR Art. 15–22). Under CCPA/CPRA you may request disclosure of categories collected, deletion, correction, and to opt out of sale/sharing (we do not sell or share). We act as a “service provider” for customer data. To exercise a right, contact [email protected]; we respond within the period required by law (generally one month). You may also complain to the UAE Data Office, your EU supervisory authority, or the UK ICO.

10. Data retention

Inference content: zero retention. Account and billing records: for the life of the relationship and as required by law (e.g., UAE bookkeeping rules). Operational metadata: a limited period for security and capacity planning, then deleted or aggregated.

11. Security

We protect information with TLS 1.3 in transit; AES-256 for any at-rest artifacts; single-tenant isolation; role-based access control; SSO/SAML; audited access logging that excludes content; and a security program independently assessed (see the Security and Compliance pages for current certifications).

12. Children

The Service is for businesses and is not directed to individuals under 18; we do not knowingly collect their personal data.

13. Changes

We may update this policy; we will post the new effective date and, for material changes, provide notice. Continued use after the effective date constitutes acceptance.

14. Contact

Questions about this policy or your data can be directed to [email protected] or [email protected]. EU and UK residents may contact our appointed representatives, who are reachable at [email protected].