1. Introduction and scope
This Privacy Policy explains how Xinference Holdings Pte. Ltd. ("Xinference", "we", "us" or "our") collects, uses, discloses and protects personal data in connection with Xinference. Xinference is a model inference and serving platform that enables organisations to deploy, manage, serve and route machine learning and large language models through APIs and related platform tools.
This Policy applies to Xinference websites and managed services that we operate, related sales and support activities, and personal data that we otherwise receive in connection with Xinference. It also explains the more limited circumstances in which this Policy applies to self-hosted or marketplace deployments.
When an organisation uses Xinference to process personal data contained in prompts, documents, inputs, outputs or other customer-provided material ("Customer Content"), that organisation normally determines why and how the Customer Content is processed. In that situation, the organisation is the controller or business and Xinference acts as its processor or service provider to the extent we process that Customer Content. The applicable customer agreement and Data Processing Agreement ("DPA") govern that processing and take precedence over this Policy to the extent of any conflict.
2. Deployment models and responsibility
2.1 Xinference-managed deployments
For a cloud or other managed deployment operated by Xinference, we process account, service and usage data, together with Customer Content, as reasonably necessary to provide, secure and support the service, subject to the customer's configuration and agreement with us.
2.2 Self-hosted Xinference
For a self-hosted deployment, the customer operates Xinference in infrastructure it selects. This Policy applies only to personal data that Xinference actually receives, such as account, licensing, support, security, update or optional telemetry information. We do not control Customer Content that remains solely within the customer's environment. The customer is responsible for the infrastructure, region, access controls and third-party providers it selects for that deployment.
2.3 Marketplace deployments
Where Xinference is obtained through a third-party cloud marketplace or similar channel and the customer's own cloud account provides the underlying compute or storage, that third-party provider processes data under its own terms. Xinference processes only the personal data that we actually receive in order to license, support, operate or secure the Xinference service.
3. Personal data we collect
3.1 Account, organisation and commercial information
We may collect names, usernames, work email addresses, telephone numbers, organisation names, roles, account preferences, subscription and order information, billing contacts, transaction records and communications with our sales, support and customer-success teams. Payment-card information may be collected directly by our payment provider rather than stored by Xinference.
3.2 Customer Content
Depending on the deployment and configuration, Customer Content may include prompts, instructions, documents, datasets, embeddings, model inputs and outputs, model configuration information, retrieval results and other data that a customer or its users submit to or generate through Xinference. Customer Content may contain personal data if the customer chooses to include it.
3.3 Service, device and usage information
We may collect IP address, browser and device information, authentication events, organisation and user identifiers, dates and times of access, API and feature usage, model selections, token or resource consumption, latency, errors, diagnostic events and security or audit information. The precise content of operational logs depends on the deployment, configuration and support context. We do not intentionally log prompt or output content unless this is required for a customer-requested support process or is otherwise agreed with the customer.
3.4 Website and cookie information
Our websites and managed services may use cookies, local storage and similar technologies for authentication, security, preferences, service operation and analytics. Where required by law, we request consent before using non-essential technologies. Browser settings and any consent controls we provide can be used to manage these technologies.
3.5 Information from other sources
We may receive business contact information from a customer, partner or public professional source, and information from identity, payment, security or other service providers when a user chooses to use those services with Xinference.
4. How we use personal data
We use personal data to provide, operate, maintain and support Xinference; create and administer accounts, subscriptions and permissions; authenticate users and protect Xinference, customers and third parties from fraud, abuse and security threats; meter usage, administer plans and process payments; monitor service health and troubleshoot faults; communicate about transactions, support, service changes, security and, where permitted, relevant products; enforce agreements and acceptable-use requirements; and comply with legal, regulatory, tax and accounting obligations and protect legal rights.
4.1 AI training and service improvement
Xinference does not use Customer Content, inputs or outputs to train or fine-tune foundation models unless the customer expressly agrees in writing. We may use service and usage information, feedback, and aggregated or de-identified information to secure, operate and improve Xinference. If a customer selects or configures a third-party model provider, that provider's handling of data is governed by the customer's configuration and the provider's applicable terms and privacy policy.
5. Legal bases and Singapore privacy law
Xinference Holdings Pte. Ltd. is established in Singapore. Where the Singapore Personal Data Protection Act 2012 ("PDPA") applies, we collect, use and disclose personal data in accordance with the PDPA, including applicable notification, consent or exception, purpose limitation, protection, retention limitation, access and correction, accountability and transfer limitation requirements. Where applicable, we also comply with the PDPA's Do Not Call provisions.
Where the EU GDPR or UK GDPR applies and a legal basis is required, we process personal data as necessary to perform a contract or take requested pre-contract steps; for legitimate interests such as operating, securing, supporting and improving Xinference and conducting business-to-business communications; to comply with legal obligations; and with consent where consent is required. Where Xinference acts as a processor or service provider, we process Customer Content on the customer's documented instructions.
6. How we disclose personal data
We may disclose personal data to cloud, hosting, database, authentication, payment, email, analytics, customer-support and security providers that process data for us; model or inference providers selected or enabled for the relevant deployment; the customer that controls the relevant account and its authorised administrators; professional advisers, auditors and insurers under appropriate duties of confidentiality; law-enforcement authorities, regulators, courts or other parties where required by law or reasonably necessary to protect rights, safety, security or integrity; and an acquirer, investor or successor in connection with a financing, reorganisation, merger, acquisition or sale, subject to appropriate protections.
We do not sell personal data. A current list of subprocessors applicable to a contracted managed service may be provided through our contractual, trust or support channels. Customer-selected providers may act independently under their own terms.
7. Subprocessors and third-party model providers
For self-hosted deployments, Customer Content that remains solely within the customer's environment is not processed by Xinference subprocessors. The customer may nevertheless choose its own cloud, infrastructure or model providers, and those providers process data under the customer's relationship with them.
For Xinference-managed deployments, we may use service providers to support hosting, databases, authentication, payments, email, support, security and related operations. We require service providers that process personal data on our behalf to be subject to appropriate confidentiality and data-protection obligations.
If a customer uses a third-party model provider through its own account, API key or other customer-controlled configuration, that provider's processing is governed by the customer's relationship with that provider and the provider's terms and privacy policy. Public model repositories may be used to obtain model software or weights, but Customer Content is not sent to a repository solely because a model is downloaded from it.
8. International data transfers
8.1 Self-hosted deployments
For a self-hosted deployment, the customer chooses the infrastructure and region in which Customer Content is processed. Customer Content that remains solely in that environment is not transferred by Xinference. If the customer sends information to Xinference for support, licensing, security, updates or optional telemetry, that information may be processed in locations used by Xinference and its service providers as described in this Policy.
8.2 Xinference-managed deployments
For a managed deployment, personal data may be processed in the selected deployment region and in other countries where Xinference or its service providers operate. The locations involved depend on the deployment, support arrangements and service providers used. Where required by applicable law, we use recognised transfer safeguards, including contractual protections and other measures appropriate to the circumstances. For transfers from Singapore, we take steps intended to ensure that transferred personal data receives a standard of protection comparable to that required under the PDPA.
9. Storage, retention and deletion
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the service, comply with law, maintain security, resolve disputes and enforce agreements. Retention periods vary by data type, deployment, customer instruction and contractual requirement.
For Xinference-managed deployments, personal data and Customer Content may be stored in the selected deployment region and in systems used by Xinference and its service providers as described in this Policy. For self-hosted deployments, Customer Content that remains solely within the customer's environment is stored under the customer's control.
To request deletion of personal data controlled by Xinference, including account data, email legal@xinference.co and identify the account or data concerned. We may take reasonable steps to verify identity and authority before acting on the request. Where Xinference processes Customer Content for a business customer, deletion requests concerning that Customer Content should ordinarily be directed to the customer, and the applicable customer agreement and DPA govern export, return and deletion. We will delete or de-identify data under our control when required by applicable law or our contractual commitments, subject to information we must retain for legal, security, fraud-prevention, dispute-resolution or similar legitimate purposes. Data may remain for a limited period in backups or restricted records before being overwritten or deleted.
10. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. Measures are selected according to the deployment and risk and may include access controls, authentication, encryption in transit, logging, monitoring, backup and recovery controls, personnel controls and vendor-management practices. No system is completely secure. Customers remain responsible for the infrastructure, user permissions, credentials, models, third-party services and configuration choices they control.
11. Your choices and rights
Depending on where you live and the role in which we process your data, you may have rights to request access, correction or deletion; withdraw consent; request restriction or portability; object to certain processing; opt out of certain communications; and complain to a data-protection authority. These rights may be subject to legal exceptions and may differ by jurisdiction.
Individuals in Singapore may exercise applicable rights under the PDPA, including rights of access and correction, and may raise concerns with the Personal Data Protection Commission where appropriate. Individuals in the European Economic Area or United Kingdom may have rights under the GDPR or UK GDPR. Individuals in other jurisdictions may have comparable rights under applicable law. To exercise a right relating to data controlled by Xinference, contact legal@xinference.co. If the data is controlled by a Xinference customer, please contact that customer first.
12. Children
Xinference is intended for business and professional use and is not directed to children under 18. We do not knowingly collect personal data directly from children through Xinference accounts. If you believe a child has provided personal data to us, contact legal@xinference.co.
13. Third-party models and services
Xinference may enable customers to use third-party models, cloud infrastructure or related services. Those third parties control their own privacy practices when they act independently. This Policy does not replace their terms or privacy notices, and Xinference is not responsible for processing performed independently by them. Customers are responsible for selecting providers suitable for their use case and for obtaining any notices, consents or other authority required for data they make available.
14. Changes to this Policy
We may update this Policy as Xinference, our data practices or legal requirements change. We will update the effective date and provide additional notice where a change is material or applicable law requires it. Changes do not authorise us to use previously collected personal data in a materially incompatible way without any notice or consent required by law.
15. Contact us
Questions, privacy requests, deletion requests and complaints may be sent to legal@xinference.co.
Xinference Holdings Pte. Ltd.