Privacy Policy — OpenReef

Last updated: 12 July 2026

Controller: OpenReef (operator of https://openreef.network)

Contact: via channels published on the website / Telegram

Practical draft for launch and vendor DPAs. **Not legal advice.** Have a qualified counsel review for your entity and markets.

1. Scope

This Policy explains how we process personal data when you use OpenReef (website, API, accounts, jobs, payments).

It does not make us the controller of every byte inside a dataset you upload: for User Content, you typically act as controller and we act as processor (Section 5).


2. Roles (GDPR)

DataWho is controller?Who processes?
Account data (email, auth, credits metadata)OpenReefOpenReef + hosting / payment subprocessors
User Content (datasets, job configs you supply)You (usually)OpenReef as processor + subprocessors you instruct via jobs
Website logs / securityOpenReefOpenReef + hosting / CDN

3. Categories of data subjects

We do not intentionally target children.


4. Categories of personal data we process as controller

CategoryExamplesPurposeLegal basis (GDPR Art. 6)
ContactEmail addressAccount, noticesContract; legitimate interests
AuthPassword hash, session cookies, CSRFSecurity, loginContract; legitimate interests
TransactionCredit balance events, Stripe customer/session ids (not full card data — handled by Stripe)PaymentsContract; legal obligation
Usage / technicalIP, user-agent, timestamps, job status metadataSecurity, abuse prevention, service operationLegitimate interests
SupportMessages you send usSupportLegitimate interests / contract
IntegrationsWhether an HF token is stored, last4 only (not the secret)Gated model accessContract

Special categories (Art. 9)

We do not intend to process special-category data.

Our Terms prohibit uploading Art. 9 / sensitive personal data and third-party personal data without lawful basis.

If such data appears only because a user violates the Terms, we may delete it and take account action; that is not an offered processing purpose.


5. User Content (datasets) — processing on instructions

When you upload datasets or run jobs:

- Cloud hosting (e.g. VPS provider such as netcup for application servers);

- Object storage (e.g. Cloudflare R2);

- Payment provider (Stripe);

- Email (e.g. Resend) if verification is enabled;

- OpenGPU Network Providers — independent GPU operators who may process job inputs on their hardware when you launch a network job;

- Hugging Face (if you use Hub models/tokens under your account).

International transfers: Providers and infrastructure may be outside the EEA. We implement appropriate safeguards where required (e.g. SCCs, vendor terms). Network routing may send job-related data to non-EEA hardware; use local mode if that is unacceptable for your data.


6. Hugging Face tokens

If you save an HF access token:


7. Cookies

We use essential cookies for authentication (httpOnly session) and CSRF protection. We do not use them for third-party advertising by default. If analytics are added later, we will update this Policy and obtain consent where required.


8. Retention

DataRetention (typical)
AccountUntil deletion request + legal retention
Ledger / invoices metadataAs required for accounting/tax
Datasets & job artefactsUntil you delete them or account closure, subject to backup cycles
Server logsShort period (security), then rotation
HF tokenUntil you remove it or account deleted

9. Your rights (EEA/UK where applicable)

Access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority (in Spain: AEPD).

Contact us via the website channels. We may need to verify identity.


10. Security

Measures include: TLS in transit (production), access controls, encryption of selected secrets (e.g. HF tokens), least-privilege design, and subprocessors under contract where applicable. No method is 100% secure.


11. Changes

We may update this Policy by posting a new version with a new date. Material changes will be highlighted where appropriate.


12. Controller details

Legal entity name, registered address, and formal DPO contact (if any) will be published here when the operating company details are finalised. Until then, use the contact channels on https://openreef.network.