This Privacy Policy explains how Titan Tech Development L.L.C-FZ (“the Company”, “we”, “us”), the operator of the HyperInfer platform, handles personal data. Our guiding principle is simple: we process your data, we don’t possess it.
1. Who we are & scope
The data controller is Titan Tech Development L.L.C-FZ (Commercial Licence No. 2423941.01), a company incorporated in the United Arab Emirates. This policy covers our website, sales interactions, and the operational data of the Service; it does not cover inference content, which we do not retain (see §2).
For general privacy enquiries, contact [email protected]. We have appointed a Data Protection Officer, who is reachable at [email protected]. We have also appointed an EU representative (GDPR Art. 27) and a UK representative; both are reachable at the same address, [email protected].
2. Our core principle — zero data retention
For inference traffic we operate under zero data retention: inputs and outputs are processed transiently in volatile memory only for the time needed to generate a response, are never written to disk, logged, or used for training, and are purged on completion.
3. Information we collect
We collect the minimum needed to operate the Service and a business relationship:
- Account information — name, work email, company and role, given when you contact sales or create an account.
- Operational metadata — request timestamps, latency, token counts for billing, model IDs, region and error classes (no content).
- Website data — privacy-respecting analytics and cookies (see our Cookie note).
4. What we never collect
We do not collect, store, log, or retain:
- The content of your prompts, messages, or system instructions;
- Model completions or responses;
- Any files submitted for inference.
This content exists only in volatile memory for the duration of a single request.
5. How & why we use information
We use the limited information we do collect to provide and secure the Service; bill accurately; communicate with you about your account; meet legal and compliance obligations; detect and prevent abuse; and improve our website and products. We do not sell or “share” personal information (as defined under CCPA/CPRA), and we do not use inference content for any purpose.
6. Legal bases
Under the UAE PDPL (Decree-Law 45/2021) we rely on: performance of a contract with you; our compliance with legal obligations; protection of interests; and consent where required. Where the EU/UK GDPR applies (Art. 3(2)), we rely on the corresponding Art. 6 bases — contract, legitimate interests (to secure and improve the Service and prevent abuse), legal obligation, and consent. You may withdraw consent at any time.
Note: PDPL is consent-centric; where we cite “legitimate interests” it applies under GDPR, with a PDPL-recognised basis applied for UAE-scope processing.
7. Sharing & sub-processors
We share operational data only with vetted sub-processors that provide infrastructure and tooling (cloud and edge providers; metadata observability). Sub-processors never receive prompt or completion content. The current sub-processor list is published in the Trust Center, with 30 days’ notice of changes. We also disclose data where required by law, to protect rights and safety, or in a corporate transaction (subject to this policy).
8. International transfers
We are based in the UAE and may process operational data with sub-processors in other regions. For personal data originating in the EEA, UK or Switzerland, we use EU Standard Contractual Clauses, the UK IDTA/Addendum, and the Swiss addendum as applicable, plus a transfer-impact assessment; our zero-retention architecture and region pinning are supplementary safeguards. Transfers from the UAE follow PDPL Art. 22–23 (adequacy or appropriate safeguards).
9. Your rights
Subject to applicable law you may access, correct, delete, port, restrict, or object to processing of your personal data, and object to automated decision-making (PDPL Art. 13–18; GDPR Art. 15–22). Under CCPA/CPRA you may request disclosure of categories collected, deletion, correction, and to opt out of sale/sharing (we do not sell or share). We act as a “service provider” for customer data. To exercise a right, contact [email protected]; we respond within the period required by law (generally one month). You may also complain to the UAE Data Office, your EU supervisory authority, or the UK ICO.
10. Data retention
Inference content: zero retention. Account and billing records: for the life of the relationship and as required by law (e.g., UAE bookkeeping rules). Operational metadata: a limited period for security and capacity planning, then deleted or aggregated.
11. Security
We protect information with TLS 1.3 in transit; AES-256 for any at-rest artifacts; single-tenant isolation; role-based access control; SSO/SAML; audited access logging that excludes content; and a security program independently assessed (see the Security and Compliance pages for current certifications).
12. Children
The Service is for businesses and is not directed to individuals under 18; we do not knowingly collect their personal data.
13. Changes
We may update this policy; we will post the new effective date and, for material changes, provide notice. Continued use after the effective date constitutes acceptance.
14. Contact
Questions about this policy or your data can be directed to [email protected] or [email protected]. EU and UK residents may contact our appointed representatives, who are reachable at [email protected].