Legal
Privacy notice
In counsel review, not yet published. When it is, it will describe what data reaches our systems, how long it stays, and who else can see it, in terms specific enough to be checked.
01Status
This document is in counsel review and is not yet published
Seldon Compute, Inc. publishes a legal document only once counsel has reviewed it against the system as actually built. That review is not finished for this one, so no version of it is published here. Nothing on this page is operative, and nothing on this page should be relied on when assessing whether to send us data.
We would rather say that plainly than publish borrowed boilerplate. A privacy notice describes what a company actually does with data, and terms of service are a contract. Both are only worth reading if they are true, and neither is true until the words have been checked against the operational practice behind them.
The finished document will be published here with its effective date recorded at the top. If you need the terms that apply to you before then, ask: customers under agreement contract on written terms today, and we will send what governs your account rather than point you at a page.
Contact
Security, privacy, data handling, and vendor due diligence. Also the address for responsible disclosure.
Contracting, commercial terms, and anything a procurement team needs in writing.
Published today
The trust center already documents data handling commitments, the controls behind them, and the carve-outs to each one. It is written to survive a security questionnaire, and it is accurate today.
Read the trust center02Intended scope
What the document will cover
A list of topics, not a summary of terms. Each item below describes something the finished document will address, and nothing below is operative until that document is published.
- 01Categories of personal data processed, separated into account data, billing data, and the contents of API requests, because those are governed differently and conflating them is how privacy notices become misleading.
- 02Retention windows for prompts, completions, and logs, stated as durations rather than as a general commitment to minimisation.
- 03The legal bases relied on under GDPR Article 6, and the controller and processor roles for each processing activity.
- 04Cross-border transfer mechanisms, including which standard contractual clause modules apply and to which flows.
- 05Data subject rights and the operational process for exercising them, including the response window we can actually meet.
- 06Whether request content is used for model training. The answer will be stated in one unambiguous sentence with its exceptions named.
- 07Cookies and analytics on this website, and whether consent is required for each category in each jurisdiction.
- 08How material changes to the notice are communicated, and the notice period before they take effect.
If you need something in writing before this is published
Security reviews and procurement processes do not wait for a publication schedule. Write to security@seldon.ai and describe what your process requires. Where an accurate answer exists we will put it in writing, and where one does not we will say so rather than send a document that reads well and means nothing.
The trust center lists the controls that are implemented today and the certifications that are not, with the distinction between the two made explicit.