SovInfra · Privacy
Privacy Policy
SovInfra — FPLC SAS
Last updated: 26 August 2026
1. Data controller
The controller of personal data collected through sovinfra.ai, arena.sovinfra.ai and the SovInfra services is:
FPLC SAS · 10 Place Vendôme, 75001 Paris, France · Paris Trade and Companies Register 934 780 917 · Contact: contact@sovinfra.ai
2. General principle
SovInfra operates a sovereign European inference platform. The content you submit to our APIs — your requests, your documents, your audio files, the generated responses — is not retained after processing and is never used to train a model, either by us or by any third party.
Data strictly necessary for account management and billing is, however, retained under the conditions described below.
This policy covers two distinct services, whose retention regimes differ:
- SovAPI, the inference programming interface, which retains no content;
- SovAgent, the conversational application, which retains conversation history so that the agent can function.
3. Data collected
3.1 Account data
Collected when an account is created:
- email address
- password (stored as a hash, never in clear text)
- name or company name, where you provide it
- API keys generated for your account
Legal basis: performance of the contract (Article 6(1)(b) GDPR).
3.2 Billing data
For paid accounts:
- billing details
- invoice history
Payment card details do not pass through our servers and are never stored by us: they are processed directly by our payment provider (see section 6).
Legal basis: performance of the contract and legal accounting retention obligation (Articles 6(1)(b) and 6(1)(c)).
3.3 Usage data
For each API call, we record:
- the identifier of the key used
- the timestamp
- the model called
- the number of input tokens, output tokens and, where this information is available, cache-read tokens
- the response status code
These records contain neither the content of the request nor that of the response. They are used for metering, billing and rate-limit enforcement.
Legal basis: performance of the contract and legitimate interest (Articles 6(1)(b) and 6(1)(f)).
3.4 Content submitted for inference (SovAPI)
The text, images, documents and audio files you send to our APIs are processed in memory for the time needed to generate the response, then discarded. They are not written to disk, not logged, not retained, and are not used for any training.
The API is stateless: continuity within a conversation is maintained by the client, which sends the necessary context with each call. No history is retained server-side.
This also applies when SovAPI is used from the Console at app.sovinfra.ai. Conversation titles and text history are stored only in your browser's localStorage. The sidebar and ⌘K search read that local browser data directly; they do not query or write a server-side conversation database. Attachments are processed in memory for the active request and are not retained in browser history or on the server.
A prefix caching mechanism may temporarily hold in memory, on the inference server, a reusable context between two calls made with the same key. This cache is volatile, partitioned by key, and disappears when the session expires or when the service restarts.
3.5 SovAgent
SovAgent retains the history of your conversations, this retention being necessary for the agent to function. The history is attached to your account, accessible and deletable from your console, and erased when the account is deleted under the conditions set out in section 4.
Connectors to third-party services are activated only at your explicit request, service by service. They are described in section 6.
3.6 Arena
The Arena can be used without an account. The prompts you submit there follow the same regime as section 3.4: processed in memory, no retention. We measure only aggregate technical indicators (latency, throughput) which do not allow you to be identified.
3.7 Browsing data
The site uses cookies strictly necessary for its operation and for maintaining your authenticated session. No advertising cookies, no third-party trackers for profiling purposes.
4. Retention periods
| Data | Period |
|---|---|
| Content submitted for inference (SovAPI) | No retention |
| SovAPI Console conversation history | Browser only, until local browser data is cleared |
| Conversation history (SovAgent) | Lifetime of the account |
| Account and API keys | Lifetime of the account |
| Usage records | 12 months |
| Invoices and accounting records | 10 years (legal obligation) |
| Technical security logs | 30 days |
Technical security logs are limited to connection metadata (timestamp, IP address, method, path called, status code). They do not contain request bodies or authentication credentials, which are masked. They are used exclusively for the security of the service and the prevention of abuse.
When your account is deleted, server-held account data, keys and SovAgent conversation history are erased within 30 days. SovAPI Console history is held only by your browser and can be erased by clearing that site's local browser data. Only accounting records remain for the legally required period.
5. Data location
All processing and storage take place within the territory of the European Union. No data is transferred outside the European Economic Area in the course of the inference service, and our servers fall outside the scope of the US Cloud Act.
Our inference infrastructure and our gateway layer are hosted on servers located in the European Union — France, the Czech Republic and Germany — with the providers listed in section 6.
6. Processors
We use the following processors:
| Processor | Purpose | Location |
|---|---|---|
| VS Hosting s.r.o. | Hosting of inference servers | Czech Republic |
| Hetzner Online GmbH | Redundancy hosting and backup | Germany |
| RINF Outsourcing Solutions S.R.L. | Operation of the inference infrastructure | Romania |
| Selectiv T & C S.R.L. | Network supervision and technical monitoring | Romania |
| Stripe | Payment processing | EU / framed transfers |
| Brevo | Transactional emails | EU |
All our processors are established in the European Union and bound by a processing agreement compliant with Article 28 GDPR. Our database is self-hosted: it is not entrusted to any third-party provider.
No connector to a third-party service is active by default. The connectors offered within SovAgent are activated only at your initiative and for the services you designate; their activation entails the transmission of the relevant data to the corresponding service, under that service's own terms.
7. Your rights
In accordance with the General Data Protection Regulation, you have the rights of access, rectification, erasure, restriction, objection and portability in respect of your data.
To exercise them, write to contact@sovinfra.ai. We respond within one month.
You may also lodge a complaint with the French data protection authority, the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, 75007 Paris — www.cnil.fr.
8. Security
Exchanges with our services are encrypted in transit using TLS 1.3. Retained data — account, billing, usage records — is encrypted at rest using AES-256. Access to systems is restricted and logged. API keys can be revoked at any time from your console.
In the event of a data breach likely to result in a risk to your rights and freedoms, we will inform you and notify the CNIL under the conditions provided for in Articles 33 and 34 GDPR.
9. Changes
Any substantial change to this policy is flagged on this page, with the date at the top updated accordingly. Users holding an account are informed by email.
FPLC SAS · Paris Trade and Companies Register 934 780 917 · 10 Place Vendôme, 75001 Paris · Hosted in Europe · Outside the US Cloud Act
Terms of Service →