Legal

Privacy Policy

How we collect, use and protect your personal data — and the rights you have over it under the EU GDPR.

Last updated August 2026

Who we are

Gro is the AI model foundry operated by INSTRAT Technology ApS(“INSTRAT360”, “we”, “us”), a company registered in Denmark. For the purposes of the EU General Data Protection Regulation (GDPR), INSTRAT Technology ApS is the data controller for personal data processed through Gro. You can reach us about privacy at ale@instrat360.com.

What we collect

We keep data collection to the minimum needed to run the service:

  • Account data — your name, email address and hashed password (or provider identifier if you sign in through a third party).
  • Project & usage data — the projects, datasets, training runs and configuration you create in the studio.
  • Billing data — your credit ledger and a record of credit-pack purchases. Card details are handled by our payment processor and never stored on our servers.
  • Technical data — session metadata such as IP address and user-agent, used to keep your account secure.

How we use it, and our legal basis

We process your data to provide the service and manage your account (performance of a contract), to secure the platform and prevent abuse (legitimate interests), to take payment (contract), and to meet legal obligations such as accounting. Your corpus, datasets and models are yours. We never use your content to train models for other customers or for our own general-purpose models.

Where your data lives

Gro is built for EU data residency. Your corpus, training jobs and inference run within EU regions on our cloud infrastructure. Where a sub-processor operates outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

How long we keep it

We retain your account and project data for as long as your account is active. When you delete your account we erase your personal data promptly, except where we must retain limited records to meet legal obligations (for example, transaction records required by accounting law).

Your rights

Under the GDPR you have the right to:

  • access a copy of your personal data (Art. 15);
  • receive it in a portable, machine-readable format (Art. 20);
  • rectify inaccurate data (Art. 16);
  • erase your data — the “right to be forgotten” (Art. 17);
  • restrict or object to certain processing (Art. 18 & 21).

You can exercise the access, export and erasure rights yourself at any time from your Privacy & data settings, or by contacting us at ale@instrat360.com. You also have the right to lodge a complaint with your local supervisory authority (in Denmark, Datatilsynet).

Changes to this policy

We may update this policy as the service evolves. Material changes will be reflected here with a revised “last updated” date. See our Trust Center for how compliance is built into the product.