AI AGENT INFERENCE

Privacy Policy

Effective 28 September 2026

This policy is specific to the AI Agent Inference product. Its guiding principle is simple: the Service handles the content of your requests but does not retain it. What we keep is the operational metadata needed to run the gateway reliably.

1. Who this policy covers

This policy explains how BastionShield Technologies Ltd ("BastionShield", "we", "us") handles data in connection with the AI Agent Inference product ("the Service"), a gateway that carries inference requests from your applications and agents to the model providers you configure.

It sits alongside our general website privacy notice. Where this policy and the general notice differ for the Service, this policy applies to the Service.

2. The core principle: metadata, not content

The Service is designed so that the content of your inference requests and the model responses is not retained. Prompts, inputs, messages and generated outputs pass through the gateway to and from the configured model provider and are not stored by us.

What we do process is operational metadata about each request, which is what allows the Service to route, handle errors, and report usage and latency.

3. What we process

Operational metadata for a request may include: a timestamp; the route or model identifier the request targeted; the calling application or agent identifier and the identity associated with the API key used; token counts reported by the provider; latency; HTTP status and error codes; and the provider the request was routed to.

Account and contact data: if you engage with us, we process the business contact details you provide (such as name, work email, company and the content of your enquiry) to respond and to manage the relationship.

We do not intentionally collect special category personal data through the Service, and you should not route such data expecting us to store it, because request and response content is not retained.

4. Controller and processor roles

For the request and response content that passes through the Service to a model provider, you are the controller and we act as a processor and conduit on your behalf. Your use of the underlying model providers is also subject to those providers’ own terms and privacy practices, which you are responsible for reviewing.

For the operational metadata we retain to run, secure, meter and support the Service, and for the account and contact data described above, we act as a controller.

5. Why we process it, and our legal bases

We process operational metadata to provide, secure, monitor, debug and meter the Service, and to investigate incidents. Our legal basis is our legitimate interest in operating a reliable service and, where applicable, the performance of a contract with you.

We process contact data to respond to enquiries and manage our relationship, on the basis of legitimate interest and, where relevant, steps taken at your request before entering a contract.

6. Retention

Operational metadata is retained for as long as needed to operate, secure and account for the Service, including usage reporting, and is then deleted or aggregated. Because request and response content is not retained, there is nothing of that kind to delete.

Contact and account data is retained for as long as needed for the relationship and for any legal, accounting or reporting obligations that apply.

7. Sharing

Requests are routed to the model providers you configure; that is the purpose of the Service. Beyond that, we share data only with service providers who help us run the Service (for example hosting and infrastructure) under appropriate contractual terms, and where required by law.

We do not sell personal data.

8. International transfers

Where data is processed outside the UK or the EEA, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses. Where you configure a model provider in a particular region, requests are routed accordingly.

9. Security

We apply technical and organisational measures appropriate to the risk, including access controls, encryption in transit, and the data-minimising design described above. No system is perfectly secure, and we do not claim certifications we do not hold.

10. Your rights

Subject to UK GDPR, you have rights to access, correct, delete, restrict and object to the processing of your personal data, and to data portability. To exercise them, contact us using the details below. You also have the right to complain to the Information Commissioner’s Office.

11. Cookies

Our website’s use of cookies is described in our Cookie Notice.

12. Changes and contact

We may update this policy and will change the effective date above when we do. For any privacy question about the Service, contact info@bastionshieldtechnologies.com, or write to BastionShield Technologies Ltd, 124 City Road, London, EC1V 2NX, United Kingdom.