Privacy Policy
Disclaimer: This is a template document. Not legal advice. Have a Swedish data protection lawyer review before relying on it for production contracts. Last updated 2026-05-11.
Privacy Policy
Last updated: 2026-05-11
1.Who we are
Naetive is an AI routing and compliance service operated by Einar Näslund / Naetive AB (in formation), based in Sweden.
Instead of connecting their AI software directly to an AI provider such as Anthropic or OpenAI, Customers connect through Naetive. Naetive routes each request to the appropriate provider, returns the response, and records a tamper-evident audit trail that Customers can use as compliance evidence.
Contact: einar.naslund@naetive.eu
2.What data we collect
When you — or an AI Agent acting on your behalf — use Naetive, we process the following data.
2.1Request metadata
Information about each request: which Agent sent it, when it was sent, how long it took, how many tokens were used, which provider handled it, and which routing tier applied. This metadata is always collected.
2.2Prompt and response text
By default we store the full text of the prompt sent to the AI provider and the full text of the response. This is the foundation of Naetive's audit trail: it enables fault attribution (determining whether an unwanted outcome came from the Customer's input, Naetive's routing, or the AI provider) and forms part of the compliance evidence package. Customers can disable text storage for a specific Agent via the Agent configuration settings; some compliance-related features will then be unavailable for that Agent.
2.3Tool and capability declarations
When an AI request includes a list of tools or capabilities the Agent may use (for example, "this Agent may query a database" or "this Agent may call external web services"), Naetive stores a fingerprint of those declarations. This is treated as a description of the Agent's capabilities, not as user content.
2.4Routing Manifest
The configuration document produced at onboarding that specifies which Routing Tier applies to each category of the Agent's tasks. Stored as part of the Agent Audit Bundle.
2.5Compliance assessments
Naetive's automated compliance reviewer (the Auditor) periodically samples a share of requests and produces written findings — for example, whether a request matched the declared Routing Manifest, or whether a potential compliance risk was detected. These findings are stored in the Agent Audit Bundle.
2.6Performance data
Latency measurements, success and failure rates, and similar operational metrics per provider and per Agent.
3.Why we process this data
| Purpose | Explanation |
|---|---|
| Routing | To direct each AI request to the provider designated by the Customer's Routing Manifest for that type of task. |
| Billing | To calculate the cost savings achieved through Naetive compared with direct provider access (the Shared Savings fee model). |
| Compliance audit trail | To produce evidence required under GDPR Articles 12–13 and EU AI Act Articles 12–13 and 26. The tamper-evident log and Agent Audit Bundle are the primary evidence artefacts. |
| Fault attribution | To determine, if something goes wrong, whether the cause was the Customer's input, Naetive's routing logic, or the AI provider's output. |
| Security and abuse prevention | To detect unusual usage patterns, enforce rate limits, and respond to security incidents. |
4.Lawful basis
| Basis | When it applies |
|---|---|
| Performance of a contract (GDPR Art. 6(1)(b)) | When you are a Naetive customer, or an end user of a Naetive customer's AI Agent. |
| Legitimate interest (GDPR Art. 6(1)(f)) | Security, abuse prevention, and routing quality improvement. |
| Legal obligation (GDPR Art. 6(1)(c)) | Retaining audit trail data required by EU AI Act and similar regulation. |
5.Retention
| Category | How long we keep it |
|---|---|
| Prompt and response text | 12 months by default; shorter periods can be agreed contractually |
| Audit log, Agent Audit Bundles, compliance assessments | 7 years (required by EU AI Act Article 12 for high-risk AI systems; also necessary for DORA compliance for financial-sector customers) |
| Performance metrics | 24 months |
| Encrypted provider API keys (Customer-Key Routing) | Deleted within 24 hours of contract termination |
| Backups | 30 days |
Data subjects may request earlier deletion under GDPR Article 17.
6.Sub-processors
We share data with a small number of sub-processors — companies that process personal data on our behalf in order to deliver the Service. The current list, including the purpose of each company's involvement and where data is processed, is published at https://naetive.eu/legal/subprocessors.
7.Where your data is processed
Where data goes depends on which Routing Tier is declared in the Customer's Routing Manifest for a given type of task:
- EU-Managed Routing — the AI request is sent to Mistral infrastructure in France. No data leaves the EU at any point.
- Customer-Key Routing — the request is sent to the Customer's designated provider. If the Customer has designated a US-based provider (such as Anthropic or OpenAI), the prompt and response transit to the US under Standard Contractual Clauses and the Customer's own agreement with that provider.
- Cost-Optimised Routing — Naetive selects among available EU and US providers. US providers receive data under Standard Contractual Clauses (Commission Decision (EU) 2021/914).
The audit log and all Agent Audit Bundles are always stored in the EU (database in Frankfurt, Germany) regardless of Routing Tier.
Customers who need all AI processing to remain in the EEA can activate EU-only mode on their Agent. When active, any request that cannot be served within the EEA is blocked, and the block is recorded in the audit log as evidence that the policy was enforced.
8.Your rights
Under the GDPR you have the following rights. To exercise any of them, email einar.naslund@naetive.eu or use the self-service controls in the Customer portal.
| Right | What it means |
|---|---|
| Access (Art. 15) | Receive a copy of the personal data we hold about you |
| Rectification (Art. 16) | Have inaccurate data corrected |
| Erasure (Art. 17) | Have your data deleted (subject to legal retention requirements) |
| Restriction (Art. 18) | Limit how we use your data while a dispute is resolved |
| Portability (Art. 20) | Receive your data in a machine-readable format |
| Objection (Art. 21) | Object to processing based on legitimate interest |
| No automated decisions with legal effect (Art. 22) | Naetive's routing classifier makes routing decisions only; it does not produce decisions with legal or similarly significant effect on data subjects |
You also have the right to lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten / IMY): https://www.imy.se.
9.Security
We protect your data using: - Encrypted connections (TLS 1.2 or higher) for all data in transit - Encrypted storage (AES-256) for all data at rest - Per-Agent API key authentication — only the holder of an Agent's key can access that Agent's data - Encrypted storage of any provider API keys supplied by Customers — never stored in plain text - A tamper-evident, hash-chained audit log — each log entry is cryptographically linked to the previous one so that alterations are detectable - Strict database access controls
Detailed technical measures are described in our DPA at /legal/dpa.
10.Changes to this policy
We will publish updates at /legal/privacy-policy and notify Customers of material changes by email or via the Customer portal.
11.Contact
For privacy questions or to exercise your rights: einar.naslund@naetive.eu