This document is intended to inform you about the type of data we collect, why we collect it, and how we manage it, as well as your privacy rights and how you can exercise them.
Capitalized terms that are not defined in this document have the meaning given to them in the Open Models General Terms of Use, to which it is attached.
This Privacy Policy applies to all Shadow Services. It is intended to govern the processing of the personal data of all Users accessing the Shadow Services.
Shadow, located at 42 avenue de la Porte de Clichy, 75017 Paris, acts as the data controller within the meaning of Article 4(7) of the GDPR. You can reach the Data Protection Officer (DPO) at the following address: dpo@shadow.tech.
With respect to Client Content, Shadow acts as a processor on behalf of the Client, which is the controller. This processing is governed by the Data Processing Agreement (DPA) entered into between Shadow and the Client, which prevails in this respect.
This policy is subject to French Act No. 78-17 of 6 January 1978, as amended (on information technology, data files and civil liberties), and to Regulation (EU) 2016/679 (GDPR).
Where does your data come from, and what do we mean by “personal data”?
The term “personal data” means any information that makes it possible to identify a User, directly or indirectly. Irreversibly anonymized data is excluded.
Your data comes from three sources: the data you provide to us (registration, support requests, surveys), the data generated by your use of the Shadow Services, and the data provided by third parties with whom we contract (processors and partners).
Which data is subject to processing?
Shadow may collect Personal Data when a User uses the Shadow Services, in particular the following data:
Data categories | Data concerned |
|---|---|
Service registration data | When you create your account, you provide us with your identification data (last name, first name, business email address, company, job title, account ID). You also have the option to log in to your Blade account:
|
Financial Data | When you subscribe to one of our paid Services, you provide us with financial data (payment method, payment status, subscription type, amount due, amount paid, payment date). This data relates to the billing and payment of the Services. |
Service Usage Data | Data relating to your use of Open Models: inference API calls, models used, resource consumption and volumes, versions of the SDKs and services used, and the status and performance of allocated resources. |
Connection Data | We collect your connection data (logs, IP address, characteristics of the devices used to access the Services, internet service provider, and the characteristics and quality of the connection) in the form of identifiers (UUIDs). |
Communication Data | We may process the data you provide to us through your support tickets, your responses to satisfaction surveys or questionnaires, your messages on our channels (email, forum), and any communication addressed to Shadow. |
Shadow does not process or collect any sensitive data.
How is your data used by us and our Partners?
Purposes | Description | Legal basis |
|---|---|---|
Sending you marketing communications from Shadow. | If you have agreed to receive marketing communications from us, we may use your Registration Data in order to send them to you. Only Shadow may be the sender of these communications, and it will not commercialize them in any way. | Consent |
Management of the contractual and commercial relationship:
| When you subscribe to one of our Services, we may use your Registration Data and your Financial Data, in order to manage your subscription. For example: managing billing, managing your orders, and handling unpaid invoices. | Performance of the contract |
Operation and provision of the Shadow Services:
| We process your connection and usage data in order to allocate the necessary GPU resources to you, run your deployments and inference calls, manage autoscaling and scale-to-zero, and adjust capacity based on your actual usage in order to ensure a smooth and optimized service. | Performance of the contract |
Support for the use of the Shadow Services:
| When you request our support for the use of the Services, we may process your Connection Data, Communication Data and your Usage Data. For example, to respond to technical support requests, identify the user concerned and access the technical information needed to understand, reproduce, and resolve the reported problem, analyze technical logs, track tickets, and improve the quality and efficiency of support based on statistical analysis of the requests received. | Performance of the contract. |
Improvement / Maintenance and optimization of the Shadow Services. | We may process your Connection Data in order to ensure the security, stability, and proper operation of our Services. On this basis, this processing enables us in particular to detect and analyze technical incidents affecting the Services, prevent intrusion attempts or unauthorized access to the environment, and monitor infrastructure performance (response times, server load, system errors, etc.). | Legitimate interest |
Ensuring the security and integrity of systems, and meeting our legal obligations. | We may process your Connection Data and your Usage Data for the Services in order to secure access to our infrastructure. The purposes of this processing are to authenticate users and verify the legitimacy of connections, detect any suspicious activity, unauthorized access, or account compromise attempt, log and document connections as part of our IT security obligation, and respond to judicial requests by providing verifiable technical evidence. This includes access logging (logs) and responding to requisitions from authorized authorities, as well as the prevention and detection of fraud and abuse and identity verification (dispelling doubt). | Legitimate interest |
Measuring the performance of our emailing campaigns (trackers / tracking pixels) | Shadow and its technical service providers (including Brevo) use tracking pixels in emails in order to measure opens, the date, and the device type, to tailor the content and frequency of mailings, and to follow up with recipients who did not open an initial email. These trackers are placed on all of the devices on which you view your emails (computer, phone, tablet) and are associated with the email address you use to create your account. Consent may be withdrawn at any time via the link at the bottom of each email. | Consent |
Audience measurement, statistics, and journey analysis | Measuring the website's audience, producing statistics, and analyzing purchase journeys and the customer lifecycle via cookies/trackers and pseudonymous identifiers. | Consent |
How long do we keep your data?
Retention periods vary depending on the purpose of the processing and our legal obligations. After these periods, your data will be deleted or anonymized. The main periods are:
Processing / purpose | Legal basis | Retention period |
|---|---|---|
Account and customer relationship management | Performance of the contract / Consent / Legitimate interest | 24 months from the last subscription |
Billing and accounting | Performance of the contract / Legal obligation | Identification data: 36 months / Payment card data: not retained / Payment method used: 24 months |
Marketing communications and email marketing with tracking pixels | Consent | 24 months / Consent may be withdrawn at any time |
Audience measurement and statistics | Consent / Legitimate interest | 14 months |
Support and ticket management (Zendesk, Discord, Slack) | Performance of the contract / Legitimate interest | 24 months from the last subscription |
Detection of fraud and abuse, and deletion of infringing accounts | Performance of the contract / Legitimate interest / Legal obligation | 24 months |
Access logging (logs) | Legal obligation / Legitimate interest | 12 months (anonymization on request, or deletion) |
Content and requests (Open models ) | Performance of the contract | For the duration of the Service; pseudonymized technical statistics |
Product development and platform maintenance | Performance of the contract / Legitimate interest | 36 months |
Shadow will delete or anonymize any Client account whose Wallet has a zero balance and has remained inactive for a period of twenty-four (24) months, after prior notice to the Client by email and absent any reactivation on the Client's part.
Which data may be transferred?
In order to carry out the processing necessary for the purposes described in this Privacy Policy, Shadow may transfer Personal Data outside the European Union. These transfers are mainly explained by the location of the processors we have selected. Where they are established outside the European Union, Shadow ensures that the legal framework of the country concerned provides a satisfactory level of security, or implements the procedures required to obtain the safeguards necessary to secure the transfers.
The up-to-date list of our processors is available in the “List of Subprocessors” document.
Our partners may change. Any update to the list of processors is published on this page, without thereby altering the purposes of the processing or users' rights.
Cookies
Use of the Shadow website also involves the use of cookies. For more information, please refer to the Cookie Policy.
What are your rights?
In accordance with the French Data Protection Act and the GDPR, you have the following rights regarding your personal data:
The right to access your processed data in an understandable format,
The right to rectify and update inaccurate or incomplete data,
The right to erasure of data that is no longer necessary for the original purpose, where you have withdrawn the consent on which the processing of the data is based, where the data is subject to unlawful processing, or where the data must be erased to comply with a legal obligation,
The right to object to your data being used for direct marketing purposes or for other purposes based on our respective interests,
The right to data portability, i.e., to ask Shadow to provide the data in a structured, commonly used, and interoperable machine-readable format
These rights may be exercised by a request to the following email address: dpo@shadow.tech
You may also exercise your rights by post, addressed to the DPO at the following address:
Data Protection Officer
42 avenue de la Porte de Clichy
75017, Paris
You may also lodge a complaint with the data protection authority of your country (in France, this is the CNIL – www.cnil.fr).
This policy may change in order to reflect modifications made to our data processing. In the event of a substantial change (e.g., a new purpose or a change of legal basis), users will be informed in an appropriate manner.
Last Update : 23/09/2026
Back to top ↑