Privacy Policy
1. Introduction
AI Router Switzerland, operated by Nextgen Computing GmbH, is committed to protecting your personal data.
We comply with the Swiss Federal Act on Data Protection (nFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
2. Responsible Entity
Nextgen Computing GmbH
Schönaustrasse 61
5430 Wettingen
Switzerland
Email: chris@nextgen.ch
3. Data We Process
a) API Usage (Core Service)
- Input data (prompts) is processed transiently in memory
- No persistent storage of prompts or outputs
- No profiling, analytics, or model training
A response cache may store exact request/response pairs for up to 24 hours to serve identical repeat requests. Cached entries are automatically evicted after 24 hours and are never used for any other purpose.
We act as a data processor for API content.
b) Account and Billing Data
- email address
- subscription information
- billing data (processed via Stripe)
c) Technical Logs
- IP address
- timestamps
- request metadata
- endpoint
- status codes
- user agent
- token usage / cache hits
Used for security, abuse prevention, system stability, and usage statistics.
Retention: at least 12 months.
4. Legal Basis for Processing (GDPR where applicable)
Where GDPR applies, we process personal data based on:
- Contract performance (Art. 6(1)(b)) — providing the API service
- Legitimate interests (Art. 6(1)(f)) — security, abuse prevention, and system stability
5. Data Retention
- API data (prompts, outputs): not persistently stored, except for a transient response cache (exact request/response pairs, automatically evicted after 24 hours)
- Technical and security logs: at least 12 months
- Account data: until account deletion, then up to 3 months for legal obligations
- Invoices and accounting records: as required by Swiss law (Art. 958f CO, 10 years)
6. Data Sharing
We do not sell personal data.
The AI inference service is operated exclusively on our own infrastructure in Switzerland (firewall, reverse proxy, load balancer, API router, and inference nodes). We do not engage sub-processors for the processing of API data.
In exceptional cases (e.g., temporary capacity scaling), we may operate our own software images on rented GPU hardware located in Switzerland or the European Economic Area. Such providers are pure infrastructure providers with no access to personal data (traffic is tunneled and end-to-end encrypted, and we retain exclusive control). They are not sub-processors. Should we ever engage sub-processors, we will inform you in advance.
For payment processing, we use the following service provider:
- Stripe — payment processing (billing data only; no access to API prompts or outputs)
Stripe is bound by contractual data protection obligations. Stripe processes payment data under its own data processing agreement and applicable safeguards.
7. International Transfers
API prompts and outputs are processed in Switzerland. In exceptional cases (temporary capacity scaling), processing may occur on rented infrastructure within Switzerland or the European Economic Area, as described above.
Payment data processed via Stripe may be transferred outside Switzerland/EEA. Safeguards include:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions where applicable
8. Your Rights (GDPR)
Where applicable under the GDPR, you may have the right to:
- Access your personal data
- Request correction or deletion
- Restrict or object to processing
- Data portability
- Lodge a complaint with a supervisory authority
9. Swiss Rights (nFADP)
With respect to your account data, you also have equivalent rights under Swiss data protection law.
10. Cookies
No tracking cookies are used. Only essential session cookies for technical functionality.
11. Security
We implement appropriate technical and organizational measures including:
- TLS encryption
- Access controls
- Secure authentication
- Password hashing (Argon2)
- Isolated compute environments
12. EU Representative
We do not currently maintain an establishment in the EU. Where Article 27 GDPR requires the appointment of an EU representative, we will appoint one.
13. Contact
For any privacy-related inquiries, contact chris@nextgen.ch.
14. Changes
We may update this policy. The latest version is always published here. Material changes will be announced on this page.
Last updated: August 10, 2026