This Privacy Policy explains how KEYVERA B.V. collects, uses, shares, and protects personal data when you visit our websites, create an account, use our APIs, purchase prepaid balance or a subscription, or contact us.
KEYVERA B.V. is the controller for personal data processed for its own business purposes. When KEYVERA processes personal data contained in Customer Content solely on behalf of a Business Customer, the parties may have different roles as described in an applicable data processing agreement.
Privacy at a glance
- We collect account, billing, usage, technical, and support information needed to provide and protect the Services.
- Prompts, files, and other Customer Content may be transmitted to the model or upstream provider you select.
- We do not describe model access as private by default; provider-specific handling can differ by model and route.
- We use personal data to perform contracts, comply with law, protect legitimate interests, and obtain consent where required.
- We do not sell personal data as a standalone data-broker product.
- You may have rights to access, correct, erase, restrict, object to, or receive certain personal data.
1. Scope and controller
This Policy applies to the KEYVERA websites, account area, APIs, billing and usage tools, support channels, and related services that link to it. It does not govern a third party's independent websites, products, or processing.
Controller: KEYVERA B.V., Keizersgracht 391, 1016 EJ Amsterdam, The Netherlands. KVK 82146305. VAT NL216667690B01. Privacy enquiries may be sent to legal@keyvera.cloud.
2. Personal data we may collect
- Account and identity data: name, email address, organisation, account identifiers, login and authentication information, preferences, and account status.
- Billing and transaction data: billing contact, invoice details, country, VAT information, payment status, plan, balance, purchase and refund history. Payment-card details may be collected directly by a payment processor rather than KEYVERA.
- Customer Content: prompts, inputs, files, instructions, configurations, and related Output submitted or returned through the Services.
- Usage and metering data: selected model, token or unit counts, request time, response status, cost, plan, and other information needed to meter and troubleshoot usage.
- Technical and security data: IP address, browser or client type, device and network information, timestamps, request identifiers, diagnostic information, authentication events, fraud signals, and security logs.
- Communications: support requests, legal notices, feedback, survey responses, and other correspondence.
- Website data: pages viewed, referral information, consent choices, and information collected through necessary cookies or similar technologies.
3. How we receive personal data
We receive personal data directly from you, from authorised users or organisations managing an Account, automatically when the Services are used, from payment and fraud-prevention providers, and from upstream providers or support partners where necessary to operate the Services.
If you submit personal data about another person, you are responsible for having an appropriate lawful basis and providing any required notice.
4. Purposes and legal bases
Depending on the context, KEYVERA processes personal data for the following purposes and legal bases:
- Contract: creating and administering Accounts, authenticating requests, providing model access, metering usage, processing purchases, maintaining balances, handling refunds, and providing support.
- Legitimate interests: securing the Services, preventing fraud and abuse, diagnosing failures, improving reliability and usability, managing suppliers, establishing legal claims, and communicating with Business Customers, where those interests are not overridden by individual rights.
- Legal obligation: tax and accounting records, sanctions and fraud controls, lawful requests, consumer protection, and other duties imposed by applicable law.
- Consent: optional marketing, non-essential cookies, or another activity where consent is the appropriate basis. Consent may be withdrawn without affecting earlier lawful processing.
5. AI requests and upstream providers
When you select a model, KEYVERA may transmit Customer Content, technical request information, and related identifiers to the provider or upstream channel needed to fulfil the request. Data handling, location, retention, abuse monitoring, and model-improvement practices can differ between providers and service configurations.
Before submitting sensitive, regulated, or confidential data, review the Provider and Model Terms, the model information shown in the Account or Documentation, and any applicable data processing agreement. Do not assume that every model offers the same privacy or retention characteristics.
KEYVERA does not use Customer Content to train its own foundation model. This statement does not determine whether an independently operating upstream provider may process data under its applicable terms or configuration.
6. Recipients and disclosures
We may disclose personal data only as reasonably necessary to:
- the model provider or upstream service selected for a request;
- cloud, hosting, security, analytics, communications, support, and infrastructure providers acting for KEYVERA;
- payment processors, banks, accounting providers, and fraud-prevention services;
- professional advisers, auditors, insurers, and potential transaction counterparties subject to appropriate safeguards;
- courts, regulators, law-enforcement bodies, or other authorities where required or legally justified; and
- another party at your direction or with your consent.
KEYVERA does not sell personal data as a standalone data-broker product. We may use aggregated or de-identified information that no longer identifies an individual.
7. International transfers
KEYVERA is established in the Netherlands, but providers supporting the Services may process information in other countries. Where the GDPR or another law requires transfer safeguards, KEYVERA will use an applicable adequacy decision, approved contractual clauses, or another lawful transfer mechanism and supplementary measures where appropriate.
Provider-specific locations and safeguards may differ. Business Customers should request a DPA before regulated processing where one is required.
8. Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security and billing records, resolving disputes, and meeting legal obligations. Retention depends on the data category, Account status, selected provider, contractual settings, and applicable law.
- Account and contractual records may be retained while an Account is active and for an appropriate period afterward.
- Invoices, tax, and transaction records are retained for periods required by applicable accounting and tax law.
- Security and diagnostic logs are retained for a proportionate period based on operational and fraud risk.
- Customer Content retention may vary by selected provider and configuration; current information should be reviewed before submitting sensitive data.
Data may be retained longer where necessary for a legal claim, investigation, security incident, or valid preservation obligation. Backups are deleted or overwritten according to applicable backup cycles.
9. Security
KEYVERA uses reasonable technical and organisational measures appropriate to the nature of the Services and risk. These may include access controls, credential protection, monitoring, logging, encryption in transit where supported, supplier review, and incident-response procedures.
No online service is completely secure. You are responsible for protecting Account credentials and API Keys, restricting access, rotating compromised credentials, and avoiding submission of data that is unsuitable for the selected model or service configuration.
10. Your data-protection rights
Subject to applicable law and relevant exceptions, you may request access to personal data, correction, erasure, restriction, portability, or object to certain processing. You may also withdraw consent where processing relies on consent.
Send requests to legal@keyvera.cloud. Include enough information to identify the relevant Account and request. We may ask for proportionate identity verification and will respond within the legally required period.
If KEYVERA processes personal data solely for a Business Customer, the relevant Business Customer may be responsible for the request. We may refer you to that organisation and assist it as required.
11. Cookies and local storage
KEYVERA may use strictly necessary cookies or similar storage for authentication, security, session continuity, consent choices, and website preferences such as theme selection. Non-essential analytics or marketing technologies should be activated only after any consent required by law.
Your browser can remove or block storage, although doing so may affect authentication or site preferences.
12. Children
The Services are intended for adults who are at least 18 years old. KEYVERA does not knowingly offer Accounts to children. If you believe a child has provided personal data, contact us so that we can investigate and take appropriate action.
13. Changes to this Policy
We may update this Policy to reflect changes in law, providers, or the Services. The current version and last-updated date will remain available at this URL. Where a change materially affects an existing customer, KEYVERA will provide additional notice where required.
14. Contact and complaints
KEYVERA B.V.
Keizersgracht 391
1016 EJ Amsterdam
The Netherlands
Email: legal@keyvera.cloud
Support: KEYVERA Support
You may also lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or another competent supervisory authority.