Privacy Policy — OpenReef
Last updated: 12 July 2026
Controller: OpenReef (operator of https://openreef.network)
Contact: via channels published on the website / Telegram
Practical draft for launch and vendor DPAs. **Not legal advice.** Have a qualified counsel review for your entity and markets.
1. Scope
This Policy explains how we process personal data when you use OpenReef (website, API, accounts, jobs, payments).
It does not make us the controller of every byte inside a dataset you upload: for User Content, you typically act as controller and we act as processor (Section 5).
2. Roles (GDPR)
| Data | Who is controller? | Who processes? |
|---|---|---|
| Account data (email, auth, credits metadata) | OpenReef | OpenReef + hosting / payment subprocessors |
| User Content (datasets, job configs you supply) | You (usually) | OpenReef as processor + subprocessors you instruct via jobs |
| Website logs / security | OpenReef | OpenReef + hosting / CDN |
3. Categories of data subjects
- Customers / registered users
- Website visitors
- (If applicable later) newsletter subscribers
- Individuals whose data appear only if a user unlawfully uploads them (prohibited; see Terms)
We do not intentionally target children.
4. Categories of personal data we process as controller
| Category | Examples | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Contact | Email address | Account, notices | Contract; legitimate interests |
| Auth | Password hash, session cookies, CSRF | Security, login | Contract; legitimate interests |
| Transaction | Credit balance events, Stripe customer/session ids (not full card data — handled by Stripe) | Payments | Contract; legal obligation |
| Usage / technical | IP, user-agent, timestamps, job status metadata | Security, abuse prevention, service operation | Legitimate interests |
| Support | Messages you send us | Support | Legitimate interests / contract |
| Integrations | Whether an HF token is stored, last4 only (not the secret) | Gated model access | Contract |
Special categories (Art. 9)
We do not intend to process special-category data.
Our Terms prohibit uploading Art. 9 / sensitive personal data and third-party personal data without lawful basis.
If such data appears only because a user violates the Terms, we may delete it and take account action; that is not an offered processing purpose.
5. User Content (datasets) — processing on instructions
When you upload datasets or run jobs:
- You warrant compliance with our Terms (no sensitive/third-party personal data without agreement).
- We process User Content to provide the Service you request (store, validate, route, train, deliver adapter).
- Sub-processors may include:
- Cloud hosting (e.g. VPS provider such as netcup for application servers);
- Object storage (e.g. Cloudflare R2);
- Payment provider (Stripe);
- Email (e.g. Resend) if verification is enabled;
- OpenGPU Network Providers — independent GPU operators who may process job inputs on their hardware when you launch a network job;
- Hugging Face (if you use Hub models/tokens under your account).
International transfers: Providers and infrastructure may be outside the EEA. We implement appropriate safeguards where required (e.g. SCCs, vendor terms). Network routing may send job-related data to non-EEA hardware; use local mode if that is unacceptable for your data.
6. Hugging Face tokens
If you save an HF access token:
- It is encrypted at rest and not returned in API responses (only status / last4).
- Used to download models / gated assets for your jobs (currently prioritised for local training paths).
- You can delete it in Settings at any time.
7. Cookies
We use essential cookies for authentication (httpOnly session) and CSRF protection. We do not use them for third-party advertising by default. If analytics are added later, we will update this Policy and obtain consent where required.
8. Retention
| Data | Retention (typical) |
|---|---|
| Account | Until deletion request + legal retention |
| Ledger / invoices metadata | As required for accounting/tax |
| Datasets & job artefacts | Until you delete them or account closure, subject to backup cycles |
| Server logs | Short period (security), then rotation |
| HF token | Until you remove it or account deleted |
9. Your rights (EEA/UK where applicable)
Access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority (in Spain: AEPD).
Contact us via the website channels. We may need to verify identity.
10. Security
Measures include: TLS in transit (production), access controls, encryption of selected secrets (e.g. HF tokens), least-privilege design, and subprocessors under contract where applicable. No method is 100% secure.
11. Changes
We may update this Policy by posting a new version with a new date. Material changes will be highlighted where appropriate.
12. Controller details
Legal entity name, registered address, and formal DPO contact (if any) will be published here when the operating company details are finalised. Until then, use the contact channels on https://openreef.network.