A transparent, technical breakdown of what happens when you make an API call to JuiceFactory — from the moment your request arrives to the moment it is discarded.
AB Juice Factory AI, reg. no. 559484-2246, is a Swedish company (EU jurisdiction). All processing occurs within the EU/EEA.
Every API request follows the same five-step pipeline. No step persists your prompt or completion to disk.
Your HTTPS request arrives at an EU edge location operated by our CDN sub-processor, where TLS terminates. TLS 1.3 is used where the client supports it. The request is then forwarded to our API gateway in Solna, Sweden over an encrypted connection.
We validate your API key and check rate limits. No request body content is logged during authentication.
Your prompt is forwarded to the inference engine and held exclusively in volatile memory (RAM). It is never written to disk, object storage, or any persistent logging system.
The model completion is streamed back to you over the same TLS connection. For streaming requests, tokens are delivered as server-sent events.
Once the response is fully delivered, the prompt and completion are purged from memory. The only record created is a billing metadata entry (see below).
We retain only the minimum billing and security metadata required to invoice you accurately, meet our accounting obligations under Swedish law (Bokforingslagen) and protect the service against abuse. None of these fields contain your prompt or response content.
| Field | Purpose |
|---|---|
| Timestamp | UTC time the request was processed — required for billing and usage reporting. |
| Token count | Input and output token counts — used to calculate usage-based billing. |
| Model identifier | Which model was invoked — needed for per-model pricing. |
| Request ID | A random UUID for idempotency and support troubleshooting. Contains no payload data. |
| HTTP status code | Whether the request succeeded or failed — used for uptime monitoring and SLA reporting. |
| IP address | The calling IP address, written to access logs and retained for up to 14 days for security, abuse prevention and rate-limit enforcement. It is never linked to prompt or completion content. |
The following data categories are never written to disk, logged, cached, or retained in any form after your API response is delivered. This is guaranteed by our zero-retention architecture and codified in the DPA.
Under GDPR Article 28, any entity that processes personal data on behalf of a controller must have a Data Processing Agreement in place. Our DPA covers:
The DPA is issued on request. Contact privacy@juicefactory.ai and we will send it as a signable PDF, countersign it on return, and send the completed copy back.
As the data controller (GDPR Article 4(7)), you determine the purposes and means of processing personal data sent through our API. Here is how our stateless architecture intersects with data subject rights under GDPR Articles 15–21.
No prompt or completion data exists in our systems to disclose. Billing metadata (token counts, timestamps) is available in the portal and does not contain personal data from your requests.
Since inference data is not retained, there is nothing to rectify on our side. Billing metadata can be corrected upon request.
Zero-retention means erasure is automatic — data is purged from memory after each response. For billing metadata deletion, contact support or use the portal.
You can stop sending data at any time by revoking your API key. No historical inference data needs to be restricted because none is stored.
Billing metadata and usage reports are exportable from the portal in standard formats. No inference content is available because it is never persisted.
We process data only to deliver the service you requested — there is no profiling, automated decision-making, or secondary processing to object to.
Our stateless architecture simplifies DSAR responses: because no personal data from inference requests is retained, the primary obligation shifts to confirming this fact to the data subject.
Per GDPR Article 28(2), we disclose all sub-processors involved in delivering the inference service. Changes to this list require prior written notification to customers with DPAs in place.
| Entity | Role | Location | Legal basis |
|---|---|---|---|
| AB Juice Factory AI | Inference processing, API gateway, billing | Solna, Stockholm, Sweden (EU) | Data processor under GDPR Article 28 DPA |
| BunnyWay d.o.o. (bunny.net) | CDN and TLS termination for api.juicefactory.ai and the web frontends | Ljubljana, Slovenia (EU) | Sub-processor under GDPR Article 28(2) with prior authorization |
All sub-processors are EU/EEA-incorporated entities. No data transfers to third countries occur. Last updated May 2026.
No. Your prompts and completions are never used for model training, fine-tuning, RLHF, or any form of model improvement. This is contractually guaranteed in our Data Processing Agreement (DPA) under GDPR Article 28. We process your data solely to deliver the inference response you requested.
All inference runs on hardware owned and operated by JuiceFactory in a colocation facility in Solna, Stockholm, Sweden. Data is processed within the EU/EEA. Our sub-processors are established in the EU; see the sub-processor list above for the role each one performs.
As the data controller (GDPR Article 4(7)), you decide what data to send. Our zero-retention architecture means personal data included in prompts is processed in volatile memory and discarded immediately after the response is delivered. It is never persisted, which significantly reduces risk. However, we recommend you minimize personal data in prompts per GDPR Article 5(1)(c) — the data minimization principle.
Because we operate a stateless inference pipeline with zero retention, there is no stored prompt or completion data to retrieve, rectify, or erase. For a DSAR under GDPR Articles 15-21, we confirm that no personal data from inference requests exists in our systems. Billing metadata (token counts, timestamps) does not contain personal data from your prompts.
Yes. A GDPR Article 28-compliant DPA is available on request from privacy@juicefactory.ai. We issue it as a signable PDF, countersign it on return, and send the completed copy back. The DPA covers all processing obligations including sub-processor disclosure, breach notification (Article 33), data deletion, and audit rights.
Zero retention. EU-only infrastructure. GDPR Article 28 DPA included. Start building with confidence.