Data Processing Agreement
The data processing terms governing how GWMM LLC (operating as Inferway) handles Personal Data on behalf of Inferway customers.
GWMM LLC · a company registered in Wyoming, United States at 30 N Gould St, Sheridan, WY 82801
Data Processing Agreement
This Data Processing Agreement ("DPA") is entered into by and between GWMM LLC, operating as Inferway ("Inferway," "Company," "we," "us," or "our"), and the Customer entity accessing the Services ("Customer," "you," or "your"). This DPA forms part of, and is incorporated into, the Terms of Service, and governs the processing of Personal Data by the Company on behalf of the Customer in connection with the Services.
1. Definitions
- "Controller" means the entity that determines the purposes and means of processing Personal Data. For purposes of this DPA, the Customer is the Controller.
- "Processor" means the entity that processes Personal Data on behalf of the Controller. For purposes of this DPA, the Company is the Processor.
- "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject").
- "Customer Content" means the prompts, messages, parameters, and generated completions submitted to or produced by the AI models through the Services. Customer Content is processed under the Company's Zero Data Retention commitment (Section 4) and is not retained by the Company, subject to the bounded exceptions in Section 4.
- "Sub-processor" means any third-party Processor engaged by the Company to process Personal Data in connection with the Services.
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means.
- "Services" has the meaning given to it in the Terms of Service — the Inferway AI model inference endpoint, gateway, API, Sandbox, and console.
2. Scope and Purpose
This DPA applies to Personal Data processed by the Company in connection with the Services, including account and authentication data, billing data, and non-content request metadata submitted by or on behalf of the Customer (including by the Customer's end users, API consumers, or AI Agents acting under the Customer's account). The Company processes Personal Data only on the documented instructions of the Customer, which include processing necessary to operate the Services as described in the Terms of Service and Privacy Notice. Customer Content (prompts and completions) is processed transiently to execute inference requests and is governed by the Zero Data Retention commitment in Section 4; except for the bounded exceptions in Section 4, including generated H3 result videos stored in private Cloudflare R2 storage for 7 days for customer download, the Company does not store Customer Content, and never uses Customer Content to train, fine-tune, or evaluate any model.
3. Processor Obligations
a. The Company shall process Personal Data only on the documented instructions of the Customer. b. The Company shall ensure that personnel authorized to process Personal Data are bound by confidentiality obligations. c. The Company shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Section 4. d. The Company shall not engage a new Sub-processor without giving the Customer prior notice via the Sub-processor list in Section 5, and an opportunity to object as described therein. e. The Company shall assist the Customer, to the extent reasonably necessary, in responding to Data Subject requests and in meeting the Customer's obligations relating to data breach notification and data protection impact assessments.
4. Security Measures and Zero Data Retention
The Company implements technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, including: encryption in transit (TLS) for all API and console traffic; hashed storage of API keys (SHA-256, not reversible); access controls and role-based account membership; and per-request observability logging limited to non-content metadata for anomaly and fraud detection.
Zero Data Retention (ZDR). When an inference request is served by the Company's own infrastructure, Customer Content (the prompt, parameters, generated completion, and the derived KV cache) exists solely in GPU and system memory for the duration of a single request and is released and overwritten the moment the response finishes. Prompts and text completions are never written to disk, logged in readable form, persisted to any datastore, or used to train, fine-tune, or evaluate any model. As a bounded exception for video generation, generated H3 result videos are stored in a private Cloudflare R2 bucket so the customer can download them via a short-lived presigned URL, and are retained for 7 days before deletion; prompts for video generation remain transient and are not stored in R2. The Company retains only non-content request metadata — timestamp, input/output token counts, model name, latency metrics, HTTP status, and an anonymous session or authenticated account identifier — for operational and billing purposes.
Uploaded input media. If the Customer uses the media upload endpoint (/v1/media/uploads), the images the Customer uploads are stored in a private Cloudflare R2 bucket for at most 48 hours, or until the Customer deletes them with DELETE /v1/media/{id}, whichever comes first, and are used only to serve the Customer's own inference requests. They are deleted when the Customer's account is deleted. This is a second bounded exception to Zero Data Retention, alongside the H3 result-video exception above; apart from these two exceptions, request and response content is not stored.
Customer Content is processed only on the Company's self-hosted infrastructure under the Zero Data Retention commitment in Section 4. In Phase 1, no third-party AI inference Sub-processor is engaged and there is no failover or fallback inference path. Specific security documentation is available upon request to hello@inferway.ai.
5. Sub-processing
The Customer authorizes the Company to engage the Sub-processors listed below to deliver the Services. The Company will update this list when adding or replacing a Sub-processor; continued use of the Services after such an update constitutes notice to the Customer. Customers with a heightened need for advance notice (e.g., due to their own regulatory obligations) should contact hello@inferway.ai to arrange it.
<!-- DATA_FLOW:BEGIN --> <!-- Auto-generated from config/data-flow.yml (phase-1-public-beta-self-hosted-only). Do not edit between the markers. -->Sub-processors (Phase 1, self-hosted only)
Phase 1 inference is self-hosted only. DeepInfra and Together AI are not inference processors in Phase 1; they are not engaged as fallback providers and there is no third-party failover or fallback inference path.
Under normal Phase 1 operation, Customer Content is processed solely on the Company's self-hosted infrastructure and is not transmitted to any Sub-processor for inference. The Sub-processor table below is the single source of truth and is regenerated from the structured data-flow contract; no third-party inference fallback is engaged.
| Name | Classification | Purpose | Data categories | Direction | Retention authority | Public label |
|---|---|---|---|---|---|---|
| Cloudflare R2 (H3 result storage) | content storage processor | Stores the generated H3 768p result video in a private Cloudflare R2 bucket so the customer can download it, and serves it through a short-lived presigned URL. This entry receives Customer Content and holds it at rest. | Customer Content at rest (generated H3 result video, retained 7 days), Object key and content digest (no prompt or completion text) | egress | h3-retention-7d | Cloudflare R2 · H3 result video storage (7-day retention) |
| Cloudflare R2 (input media storage) | content storage processor | Stores media a customer uploads for up to 48 hours so their own later inference requests can reference it without the bytes entering the request envelope. Deleted on DELETE /v1/media/{id}, on account deletion, and by the reaper at the 48-hour retention boundary; the bucket lifecycle rule applies only as a backstop. | Customer Content at rest (customer-uploaded input media, retained 48 hours), Object key and content digest (no prompt or completion text) | egress | media-input-retention-48h | Cloudflare R2 · input media storage (48-hour retention) |
| Inferway self-hosted inference | inference processor | Executes model inference (prompt → completion) for the active Catalog models on GPU hosts that Inferway operates. | Customer Content (prompt and completion, in-memory only), Model identifier, Token counts (input and output), Request timestamp and latency, Authenticated account or anonymous session identifier | ingress | inferway-self-hosted-zero-data-retention | Inferway self-hosted inference (Canada and US) |
| Cloudflare, Inc. | metadata processor | Edge TLS termination/proxy and tunnel transport. The public edge may process plaintext request bytes depending on the active zone and tunnel configuration; the tunnel forwards traffic to the Inferway Gateway. Deployed logging, caching, WAF and retention settings require separate operator evidence. | Customer Content in transit (edge processing may be plaintext), Connection metadata (source IP at edge, TLS handshake) | transit | cloudflare-zone-policy | Cloudflare · edge/TLS and tunnel transport (configuration-dependent) |
| Functional Software, Inc. (Sentry) | metadata processor | Receives application error and performance diagnostics from the Inferway gateway and from inferway.ai. Does not receive Customer Content. Gateway events are rebuilt from a field allowlist before they leave the process (app/telemetry_privacy.py): prompts, completions, request bodies, headers, cookies and query strings are never copied, and an event that fails that rebuild is dropped rather than sent. Browser reporting is gated on analytics consent and applies the same allowlist rebuild. | Exception type and normalized error category (no Customer Content), Approved route template (no path parameter values), Release identifier and deployment environment, Browser error stack, user agent and client IP (website only) | egress | sentry-error-diagnostics | Sentry · error diagnostics |
| PostHog, Inc. | metadata processor | Product analytics for inferway.ai. Captures anonymized usage events; does not receive Customer Content. Funnel milestones (signup, API key created, first request, first top-up) are additionally synced server-side from operational records, keyed by a one-way hash of the account identifier — never the raw account id. | Product usage events (route, feature, no Customer Content), Pseudonymous session and account identifier, Server-synced funnel milestone events keyed by one-way-hashed account identifier, Anonymized visitor IP | transit | posthog-product-analytics | PostHog · product analytics |
| Resend, Inc. | metadata processor | Delivers transactional and consented marketing emails to customers. Resend receives the recipient address, subject, and rendered message body for transmission. Prompt and completion data never enter emails. Open and click tracking are disabled. | Recipient email address, Rendered email subject and content, Feedback message and optional reply email, Delivery event timestamps and status | egress | resend-email-delivery | Resend · customer email delivery |
| Vercel Inc. | metadata processor | Website hosting, performance telemetry, and edge rendering for inferway.ai. Does not receive Customer Content. | Page view and route metrics (no Customer Content), Core Web Vitals (aggregate), Anonymized visitor IP for rate limiting | transit | vercel-platform-aggregate | Vercel · website hosting |
| Amazon Web Services, Inc. | operator infrastructure | Hosts the Inferway control plane: the EC2 virtual machine that runs the gateway and workers, RDS PostgreSQL for accounts and billing records, S3 for encrypted database backups, and Systems Manager for configuration and operator access. Inference does not run on AWS. AWS never receives Customer Content (prompts, completions or generated media). | Account and billing records (email, wallet balance, transaction ledger), Non-content request metadata (timestamp, model, token counts, latency, status), Encrypted database backups (no prompt or completion content), Operational logs (no prompt or completion content) | internal | aws-control-plane-backup-retention-30d | Amazon Web Services · control-plane hosting and encrypted backups (US · us-west-2) |
| Inferway operator infrastructure | operator infrastructure | Provides request routing, storage, caching and observability on AWS infrastructure operated by Inferway in the United States (control plane), and inference on Inferway-operated GPU hosts. Receives Customer Content only in memory during inference. | Customer Content (transient, in-memory during inference), Non-content request metadata (timestamp, model, token counts, latency, status), Operational logs (no prompt or completion content), Audit and abuse-control signals (no prompt or completion content) | internal | inferway-self-hosted-zero-data-retention | Inferway operator infrastructure (US · control plane on AWS us-west-2) |
| Vast.ai Inc. | operator infrastructure | Provides the rented GPU hosts on which Inferway runs model inference. Customer Content is processed on these hosts during inference. | Customer Content (processed on the rented host during inference) | internal | inferway-self-hosted-zero-data-retention | Vast.ai · rented GPU hosts for inference (Canada and US) |
| Clerk, Inc. | payment identity provider | User authentication and account management for the Inferway console and API key lifecycle. Does not receive Customer Content. | Email address, Display name, Authentication credentials (hashed), Account identifier | ingress | clerk-account-lifecycle | Clerk · user authentication |
| Stripe, Inc. | payment identity provider | Payment processing, wallet top-ups, and billing records for Inferway direct customers. Does not receive Customer Content. | Payment instrument data (handled and stored by Stripe), Billing email and invoice metadata, Transaction records (amounts, timestamps, status) | ingress | stripe-billing-ledger | Stripe · payment processing |
Classification summary
- Inference Processor (1): Inferway self-hosted inference
- Metadata Processor (5): Cloudflare, Inc., Functional Software, Inc. (Sentry), PostHog, Inc., Resend, Inc., Vercel Inc.
- Payment Identity Provider (2): Clerk, Inc., Stripe, Inc.
- Operator Infrastructure (3): Amazon Web Services, Inc., Inferway operator infrastructure, Vast.ai Inc.
- Content Storage Processor (2): Cloudflare R2 (H3 result storage), Cloudflare R2 (input media storage)
The Company selects Sub-processors that publish retention commitments appropriate to the data they receive. The active backend at any time is reflected on the System Status page (https://inferway.ai/status).
6. Data Subject Rights
The Company will assist the Customer, taking into account the nature of the processing, in responding to Data Subject requests to exercise their rights (including access, rectification, erasure, restriction, and portability). End users may also submit such requests directly to the Company at https://inferway.ai/console#settings or https://inferway.ai/contact; the Company will notify the Customer without undue delay if it receives a request directly from a Data Subject that relates to the Customer's account.
7. Data Breach Notification
In the event of a confirmed Personal Data breach affecting the Customer's data, the Company will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of the breach, providing (to the extent known): a description of the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.
8. Audit Rights
The Customer may request evidence of the Company's compliance with this DPA (such as Sub-processor agreements or security documentation) no more than once per year, upon reasonable prior written notice, by contacting hello@inferway.ai. On-site audits are not offered; the Company will cooperate in good faith to provide reasonably requested documentation instead.
9. Data Retention and Deletion
Because of the Zero Data Retention commitment in Section 4, the Company does not retain Customer Content (prompts and completions) beyond the in-memory lifetime of a single request, except for the bounded exceptions in Section 4, including generated H3 result videos stored in private Cloudflare R2 storage for 7 days to enable customer download, after which they are deleted. The Company retains account and billing records for as long as the Customer maintains an account with the Services, and thereafter as required by applicable tax, accounting, or legal obligations. Upon account deletion — whether initiated by the Customer or in response to a verified deletion request — the Company anonymizes the associated user record (email and name are removed or replaced, and the Clerk authentication link is severed) within its systems. Billing and transaction records and per-request non-content usage records tied to the account are retained in de-identified form after anonymization for accounting, fraud-prevention, and legal-compliance purposes, consistent with the Prepaid Wallet & Credit Balance terms of the Terms of Service, under which prepaid credit balances are forfeited (not refunded) on deletion. Non-content request and usage metadata is retained for up to 90 days. The Customer or an end user may request deletion at any time via https://inferway.ai/console#settings or by contacting hello@inferway.ai.
10. International Transfers
The Company's control-plane servers are located in the United States, and, as described in Section 5, the Sub-processors currently engaged to deliver the Services, including the hosts on which inference runs, may operate in other countries, as stated for each in that list (with certain providers maintaining global edge networks). If the Customer is located in, or processes Personal Data of Data Subjects located in, the European Economic Area, United Kingdom, or Switzerland, and requires a specific transfer mechanism, the Company relies on the European Commission's Standard Contractual Clauses (SCCs), together with the UK International Data Transfer Addendum where applicable, as the transfer mechanism for such Personal Data. Customers requiring a countersigned SCC package should contact the Company at hello@inferway.ai before transferring such data through the Services.
11. Term and Termination
This DPA remains in effect for as long as the Company processes Personal Data on the Customer's behalf under the Terms of Service. Upon termination, the Company will proceed as described in Section 9 (Data Retention and Deletion). This DPA is incorporated into and forms part of the Terms of Service (https://inferway.ai/terms).
12. Miscellaneous
a. This DPA is governed by the laws of the State of Wyoming, United States, consistent with the Governing Law section of the Terms of Service. b. Any disputes arising under this DPA are subject to the dispute resolution terms of the Terms of Service. c. In the event of any conflict between this DPA and the Terms of Service on data processing matters, this DPA prevails. d. The Company may update this DPA from time to time; material changes will be reflected by an updated "Last updated" date above.
Contact for DPA Requests
To execute a signed, counterparty-specific version of this DPA or to discuss data processing terms, contact GWMM LLC (operating as Inferway) at hello@inferway.ai, 30 N Gould St, Sheridan, WY 82801, United States.