kontinent / compliance index

C

Inceptron

Inceptron AB · SE · Last reviewed: 2026-08-18

69

Data Protection Contracts

50/100

Inceptron offers a controller-processor Data Processing Addendum with an annex on processing details and sub-processors on request. It is not incorporated automatically with the terms of service; Kontinent requested it on 2026-07-30 and it is not yet concluded.

teilweise

Source: Inceptron Terms of Service (Stand 24.07.2026), §6.5 DPA — 'If you require processor terms, we can execute our standard Data Processing Addendum (controller–processor) with Annex on processing details/subprocessors.' Rollen nach §6.1: Processor für Customer Content. Anforderung versendet 30.07.2026, Nachfassen ~13.08.2026. (reviewed 2026-07-24)

For transfers of personal data outside the EEA or the UK, Inceptron provides for valid transfer mechanisms, explicitly Standard Contractual Clauses and, where applicable, DPF-certified recipients.

ja

Source: Inceptron Terms of Service (Stand 24.07.2026), §6.4 International transfers — 'If personal data is transferred outside the EEA/UK, we use valid mechanisms (e.g., SCCs and, where applicable, DPF-certified recipients).' (reviewed 2026-07-24)

No verifiable commitment

unbelegt

Data Residency & Sovereignty

67/100

Inceptron's privacy policy commits to processing customer content, including API payloads, exclusively within the EU/EEA and not transferring it outside. Its terms of service nevertheless leave third-country transfers open in general terms, and Inceptron runs on third-party cloud infrastructure. The commitment therefore sits in the policy rather than the contract.

teilweise

Source: Inceptron Privacy & Data Policy + Terms of Service (Stand 24.07.2026), Privacy Policy §6 Data Location — 'Customer Content, including API payloads, is processed exclusively within the European Union or European Economic Area... Inceptron does not transfer Customer Content outside the EU/EEA.' Gegenüber ToS §6.4 International transfers (Drittlandübermittlung mit SCCs vorgesehen) und ToS §6.6 ('We run on third-party cloud infrastructure'). (reviewed 2026-07-24)

Inceptron uses two sub-processors, both in the EU: Nebius (Finland, France) and Verda (Finland), named in Annex 3 of its data processing agreement. Asked about the discrepancy, Inceptron confirmed in writing on 2026-08-17 that this list is exhaustive and that no workloads run on AWS or Azure; the hyperscalers previously named as examples in its privacy policy were removed the same day. The agreement is not yet signed, however, and the privacy policy no longer names any sub-processors at all — so there is no publicly verifiable, versioned list with legal entities and processing locations.

teilweise

Source: E-Mail Nima Karimi (Inceptron) vom 17.08.2026; Annex 3 des DPA-Entwurfs vom 13.08.2026; Inceptron Privacy & Data Policy (Stand 17.08.2026), Annex 3 des DPA-Entwurfs: 'Nebius — infrastructure hosting/compute in Finland and France (EU/EEA) for EU region workloads' und 'Verda — infrastructure hosting/compute in Finland (EU/EEA) for EU region workloads'. E-Mail vom 17.08.2026: 'The subprocessors listed in the DPA are the only ones we use. AWS and Azure were included as examples in our Privacy Policy. We've removed those references. We do not host workloads on AWS or Azure.' Privacy & Data Policy in der Fassung vom 17.08.2026, §5 'How We Share Information': 'Service Providers / Subprocessors — who provide infrastructure, hosting, and networking' (ohne Nennung von Namen). (reviewed 2026-08-17)

Inceptron operates as Inceptron AB, based in Sweden, and is therefore a legal entity within the EU.

ja

Source: Inceptron Privacy & Data Policy (Stand 24.07.2026), Präambel — 'Inceptron AB (“Inceptron,” “we,” “us” or “our”)'; Land SE. Amtlicher Registerauszug noch nicht beschafft. (reviewed 2026-07-24)

Data Use

100/100

Inceptron enables zero retention by default: prompts and outputs are not logged or stored, and request data is processed only transiently. Logging applies only if the customer explicitly enables it.

ja

Source: Inceptron Terms of Service (Stand 24.07.2026), §6.2 Retention options — 'Zero-retention is enabled by default: prompts and outputs are not logged or stored. Request data is processed only transiently to serve the request, unless the customer explicitly enables logging or agrees otherwise in writing.' Vertraglich in den ToS, nicht nur in der Privacy Policy. (reviewed 2026-07-24)

Inceptron contractually does not train its foundation or fine-tuned models on customer content unless the customer actively opts in.

ja

Source: Inceptron Terms of Service (Stand 24.07.2026), §4.2 No training on Customer Content (default) — 'We do not use Customer Content to train our foundation or fine-tuned models unless you (i) explicitly opt in via product settings, or (ii) sign a separate agreement.' Bestätigt in der Privacy Policy §2. (reviewed 2026-07-24)

At Inceptron both training on customer content and retention of request data are off by default and can only be switched on by active customer consent, so no opt-out is required.

ja

Source: Inceptron Terms of Service (Stand 24.07.2026), §4.2 (Training nur bei explizitem Opt-in via Produkteinstellungen oder separatem Vertrag) und §6.2 (Zero Retention als Default, Logging nur bei ausdrücklicher Aktivierung). (reviewed 2026-07-24)

Certifications

50/100

Inceptron provides an accredited ISO/IEC 27001:2022 certificate whose scope expressly names the inference platform itself rather than general corporate functions alone. It was issued by Insight Assurance, a certification body accredited by the International Accreditation Service (IAS), which is a signatory to the IAF Multilateral Recognition Arrangement. The certificate is valid until 2028-12-21, with the next surveillance audit due 2026-12-21, and covers the Lund and Stockholm sites. It certifies Inceptron AB's own management system, not the infrastructure of the sub-processors it uses.

ja

Source: Inceptron ISO/IEC 27001:2022-Zertifikat IS-IA-2025-12-22-01 (Insight Assurance LLC), abgelegt als 10_Inceptron/Inceptron_ISO-27001-Zertifikat_2025-12-22.pdf, Scope: 'The scope of the certification is the Information Security Management System (ISMS) supporting the provision of the Inceptron AI inference platform.' Ausgestellt 22.12.2025, gültig bis 21.12.2028, nächste Überwachung 21.12.2026, SoA V1.1 vom 12.12.2025; Standorte Scheelevägen 15 Lund und Maria Bangata 6 Stockholm. Akkreditierung der Zertifizierungsstelle: IAS MSCB-306, Status 'Accredited' laut iasonline.org/ias_certificate/mscb-306/ (geprüft 18.08.2026), IAS-Akkreditierung läuft bis 01.12.2026. (reviewed 2026-08-18)

No verifiable commitment

unbelegt

AI Act Readiness

n/a

Pure inference/hosting provider: the AI Act's Article 53 documentation duty falls on the provider of the GPAI model, not on whoever runs the inference. This provider cannot discharge it for third-party models; the duty sits with the respective model provider.

nicht_anwendbar

Source: Verordnung (EU) 2024/1689 (KI-VO), Art. 53 Abs. 1 i. V. m. Art. 3 Nr. 3 – Pflichten des Anbieters eines GPAI-Modells (reviewed 2026-08-04)

Pure inference/hosting provider: the GPAI Code of Practice is open to providers of general-purpose AI models. A provider that merely operates third-party models is not eligible to sign, so an absent signature is not a shortcoming.

nicht_anwendbar

Source: Verordnung (EU) 2024/1689 (KI-VO), Art. 53 Abs. 1 i. V. m. Art. 3 Nr. 3 – Pflichten des Anbieters eines GPAI-Modells (reviewed 2026-08-04)

Contract Quality & Transparency

50/100

Inceptron publishes its terms of service and privacy policy in full on its own website; both were retrievable and reviewable without any contractual relationship.

ja

Source: inceptron.io/termsofservice und inceptron.io/privacy (abgerufen 24.07.2026), Beide Dokumente vollständig öffentlich abrufbar und als PDF in der Compliance-Ablage archiviert. Der AVV ist demgegenüber nicht öffentlich, sondern nur auf Anfrage erhältlich (ToS §6.5). (reviewed 2026-07-24)

No verifiable commitment

unbelegt

Inceptron remains responsible for its own contractual obligations but excludes liability for outages, data loss and security incidents attributable solely to the cloud providers it uses. Since Inceptron runs the service entirely on third-party cloud infrastructure, that exclusion covers a substantial part of the supply chain.

teilweise

Source: Inceptron Terms of Service + Privacy & Data Policy (Stand 24.07.2026), ToS §6.6 Subprocessors & IaaS posture — 'we remain responsible for our obligations under these Terms while not assuming liability for the third party's services beyond what law requires'; Privacy Policy §8 — 'Inceptron does not assume liability for outages, data loss, or security incidents attributable solely to those third-party providers.' (reviewed 2026-07-24)

Do you represent Inceptron and think something is inaccurate? Write to legal@kontinent.ai. We check every report and correct verified errors with full transparency.

Report error

Methodology Version 2.0