← icetok
GDPR & Data Protection
Draft — for public sector and enterprise buyers
This page is a placeholder. A full data protection framework — DPA, subprocessor list, data flow map and security posture — will be published before production launch.
Legal basis & residency
icetok processes data under GDPR as a data processor, with processing occurring exclusively within the EEA (Iceland). We maintain a current data flow map showing that no inference traffic can physically egress the sovereign environment.
What we will provide
- A signed Data Processing Agreement (DPA) with standard contractual terms.
- A complete subprocessor list — with the default being: none for inference traffic.
- Data export assessments suitable for EU public procurement.
- Deletion guarantees and full log-retention transparency.
- Dedicated deployment options for the strictest requirements.
Security posture
Dedicated replica pairs, network isolation from shared traffic, no retention of prompt content for model improvement, and infrastructure in hardened Icelandic colocation facilities.
Contact
hello@icetok.is — icetok ehf., Reykjavík, Iceland