Effective 1 September 2026
Privacy Policy
This policy explains how personal data is processed when you use the Nagame website and inference service.
Controller and contact
The service operator and data controller is Bartłomiej Brzozowski, trading as Nagame, NIP 9561854023, EU VAT ID PL9561854023, REGON 385636679, Poland. For privacy enquiries and requests, use the contact section on the Nagame homepage.
Data processed
When you use the inference API, Nagame processes prompts, messages, supplied files or tool data, and model completions as necessary to provide the requested inference. Please do not submit personal data or confidential information unless it is necessary and you are authorised to do so.
Operational systems may also process timestamps, requested routes, response status, token counts, latency, backend selection, error diagnostics, and source IP addresses. API credentials are processed for authentication. They must not be included in application logs.
Purposes and legal bases
- Providing, authenticating, securing, and supporting the service: performance of a contract or steps requested before entering one under Article 6(1)(b) GDPR.
- Operating, troubleshooting, protecting, and improving service reliability: Nagame's legitimate interests under Article 6(1)(f) GDPR, balanced against users' rights.
- Accounting, billing, and responding to binding legal requirements: compliance with legal obligations under Article 6(1)(c) GDPR.
Inference content
Prompts and completions are not used to train or fine-tune models and are not intentionally retained as an inference dataset. Nagame does not routinely conduct human review of prompts or completions. Limited access may nevertheless be required where necessary to investigate a reported incident, meet a legal obligation, or protect the service and its users.
Retention
Inference content is processed for service delivery and is not intentionally retained as a dataset. Operational records and diagnostics are retained only as long as reasonably necessary for security, troubleshooting, billing, and legal obligations. Retention varies by system and record type; Nagame does not promise a fixed retention period. Backups and records required by law may remain for longer.
Recipients and transfers
Infrastructure, hosting, DNS, connectivity, and marketplace services may process limited personal data as processors or independent controllers, as applicable. Data is disclosed only where needed to provide and protect the service or where legally required. If personal data is transferred outside the European Economic Area, Nagame will use an applicable GDPR transfer mechanism and safeguards where required.
Security
Nagame uses technical and organisational measures intended to protect data, including HTTPS at the public edge, encrypted private connectivity between infrastructure components, access controls, and authentication controls. No system can guarantee absolute security.
Your rights
Subject to the GDPR and applicable limitations, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may also withdraw consent where consent is the legal basis. Deletion requests may be limited by legal, billing, security, backup, and technical requirements.
Submit requests through the contact section on the Nagame homepage. Nagame may need to verify your identity. You may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) in Poland or another competent supervisory authority.
Changes
This policy may be updated as the service or legal requirements change. The effective date above identifies the current version. Material changes will be communicated through an appropriate service channel.