1. Data Controller
VOLTAGEGPU, operated by Monsieur Aubry Julien, is the data controller responsible for the processing of your personal data.
Contact: contact@voltagegpu.com
Address: 2311 chemin de la Blancherie, 69360 Solaize, France
SIRET: 943 808 824 00016
2. Data Collection and Use
2.1 Information We Collect
- Account Information: Email address, username, password (encrypted)
- Usage Data: API usage statistics, GPU rental history, billing information
- Technical Data: IP address, browser type, device information
- Payment Information: Processed securely through Stripe and Coinbase Commerce
2.2 How We Use Your Data
- To provide and maintain our GPU rental services
- To process payments and manage billing
- To communicate with you about your account and services
- To improve our services and develop new features
- To comply with legal obligations
3. Legal Basis for Processing
We process your personal data based on:
- Contract: To fulfill our service agreement with you
- Legitimate Interest: To improve our services and ensure security
- Legal Obligation: To comply with applicable laws
- Consent: For marketing communications (when applicable)
4. Data Sharing
We may share your data with:
- Service Providers: Distributed GPU providers (infrastructure), Stripe (payments), Coinbase (crypto payments)
- Legal Authorities: When required by law or to protect our rights
- Business Transfers: In case of merger, acquisition, or sale of assets
We never sell your personal data to third parties.
5. Data Retention, By Category
VoltageGPU separates retention by data category. Some categories are not retained by design(destroyed when the workload ends), while others (security and billing logs) are retained to meet legal obligations and to operate the service. This table is the authoritative retention schedule.
- Prompt content, inference inputs, agent inputs, document uploads (in enclave): No retention by design. Decrypted only inside the Intel TDX enclave; enclave memory and ephemeral disk are destroyed when the pod or session terminates. Not written to durable storage by VoltageGPU.
- Model outputs, generated text/images, agent outputs (in enclave): No retention by design, same lifecycle as inputs above. Outputs are returned to you over TLS and not stored server-side by VoltageGPU.
- Pod console / SSH logs, GPU telemetry, enclave attestation reports: 30 days, for operational debugging and incident response. After 30 days, automatically purged. Customers can request earlier deletion by writing to contact@voltagegpu.com.
- API request metadata (route, status, latency, token count, not body): 90 days, for abuse detection, rate-limit enforcement, and security incident investigation. Request bodies (prompts) are not stored.
- Security logs (authentication events, IP, user agent, admin actions): 12 months, retained to support investigation of security incidents and to meet ANSSI/CNIL recommendations for log retention. After 12 months, automatically purged.
- Account data (email, name, hashed password, API keys, billing address): Retained as long as your account is active. Deleted within 30 days of account closure (subject to legal-hold exceptions below).
- Billing & invoicing records (invoices, transactions, payment receipts): 10 years, as required by French Code de commerce art. L123-22 and General Tax Code art. 286.
- KYC / AML records (when applicable for enterprise contracts): 5 years after end of business relationship, as required by French AMLD / Code monétaire et financier art. L561-12.
- Marketing / consent data (email opt-in, cookie consent): Until consent is withdrawn, then 3 years to evidence prior consent.
- Support tickets and contact emails: 3 years, for service quality and dispute resolution.
- Backups (snapshots of operational systems, NOT enclave state): 30-day rolling. Backups exclude enclave memory, prompts, and outputs by design.
Legal-hold exceptions: data may be retained beyond the schedule above when subject to a legal hold, regulatory investigation, or pending dispute. In that case, retention is limited to what is necessary to comply with the legal obligation.
Reconciliation note: when other VoltageGPU pages describe "no retention by design," this refers specifically to prompt/output content processed inside Intel TDX enclaves. Security and billing logs (which do not contain prompt content) follow the schedule above. This page is the authoritative source on retention.
6. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a structured format
- Object: Oppose certain types of processing
- Restriction: Limit how we use your data
To exercise these rights, contact us at: contact@voltagegpu.com
7. Cookies
We use cookies to:
- Maintain your session and authentication
- Remember your preferences
- Analyze site traffic and usage patterns
- Improve user experience
You can manage cookie preferences through your browser settings.
8. Data Security
We implement appropriate technical and organizational measures to protect your data:
- SSL/TLS encryption for data transmission
- Encrypted password storage using bcrypt
- Regular security audits and updates
- Access controls and authentication
- Secure data centers with physical security
9. International Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
10. Children's Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children.
11. Updates to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes via email or through our platform.
Last Updated: May 2026
12. Contact Us
For any questions or concerns about this Privacy Policy or our data practices:
13. Supervisory Authority
You have the right to lodge a complaint with the French Data Protection Authority (CNIL):
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy
TSA 80715
75334 PARIS CEDEX 07
Website: www.cnil.fr