Version 1.0 · Effective 1st Oct 2026 · SHA-256 of canonical text: 04ab85adfc974939b3a92070dcea58921ffb722396339bca4ede4b1df83a6b7d
1. Purpose of This Document
This document is NOMYO’s single statement of fact about how it handles data. It is incorporated into the Terms of Service and forms Annex II of the Data Processing Addendum; the Subprocessor List forms Annex III. Other NOMYO documents cite it by section number rather than restating its content. Where another NOMYO document appears to say something different about data handling, this document governs.
Each version is dated and permanently archived. A signed agreement references a specific version, and that version continues to apply to that agreement until the customer agrees to a newer one.
2. Definitions
- Customer means the business entity that has accepted the Terms of Service or signed a Master Services Agreement with NOMYO.
- Customer Content means the prompts, messages, files, and other inputs that Customer submits to a NOMYO product, and the outputs the product returns.
- Service Metadata means the operational records about a request that NOMYO retains, listed exhaustively in Section 10.
- Account Data means the information NOMYO holds about Customer’s account and users, described in the Privacy Policy. NOMYO is the controller of Account Data; it is not covered by this document.
- Local Models means AI models that NOMYO hosts at the Hosting Facility. Remote Models means models served by a third-party provider listed in the Subprocessor List.
- Hosting Facility means the data centre in Germany operated by the Hosting Entity identified in the Subprocessor List, where all NOMYO products run.
- Subprocessor means a third party that processes Customer Content or Service Metadata on NOMYO’s behalf, listed in the Subprocessor List.
- The products are defined in Section 3.
3. Products at a Glance
NOMYO offers the six products defined in Sections 4 to 9; Encrypted Inference and the Assistant each have security tiers or configurations that share a product section. Each row below is a distinct offering, and each Customer agreement states which offerings it covers.
| Endpoint | Inference runs | NOMYO visibility of Customer Content | Customer Content stored | Subprocessors | Encryption | |
|---|---|---|---|---|---|---|
Encrypted Inference, standard (Section 4) |
api.nomyo.ai | Local Models only | None by design | No | Hosting Entity | TLS, plus payload AES-256-GCM, plus secure tokenizer |
Encrypted Inference, high and maximum (Section 4) |
api.nomyo.ai | Local Models only | None by design | No | Hosting Entity | TLS, plus payload AES-256-GCM, plus inference inside an Intel SGX enclave with hardware-encrypted host memory |
| Assistant, local configuration (Section 5) | chat.nomyo.ai | Local Models only | Full: stored conversations, access restricted per Section 5 | Yes: conversation history | Hosting Entity | TLS in transit |
| Assistant, remote configuration (Section 6) | chat.nomyo.ai | Local and Remote Models | Full: stored conversations, access restricted per Section 6 | Yes: conversation history | Hosting Entity; Remote Model providers | TLS in transit |
| Chat Router (Section 7) | chat.nomyo.ai/api | Local and Remote Models | None by policy: transient processing, not stored, not logged, not inspected | No | Hosting Entity; Remote Model providers | TLS in transit |
| nomyo-router (Section 8) | Customer’s own infrastructure | Customer’s own | None: NOMYO receives nothing | Not by NOMYO | None | Customer’s own |
| aissurance (Section 9) | aissurance.eu | Not applicable | None: NOMYO receives nothing | Yes | Hosting Entity | TLS in transit; per-tenant envelope encryption at rest |
“None by design” means NOMYO’s systems cannot read the content. “None by policy” means NOMYO’s systems handle the content transiently in order to serve the request and NOMYO commits not to store, log, or inspect it.
4. Encrypted Inference
4.1 Scope
This section applies when Customer submits a request through the nomyo SDK with encryption enabled to api.nomyo.ai. Encrypted Inference is served exclusively by Local Models at the Hosting Facility. Remote Models are not available through Encrypted Inference.
4.2 Guarantee
For every request within Section 4.1:
(a) the request and response payloads are encrypted on Customer’s systems with an AES-256-GCM key generated there for that request alone;
(b) on the high and maximum tiers, the inference process runs inside an Intel SGX enclave with hardware-encrypted memory on the host, so that at no point can NOMYO, its personnel, the host operating system, or any software outside the enclave read the payload;
(b′) on the standard tier, the payload exists inside the inference process only transiently and only as token identifiers produced by a secure tokenizer mapping, in protected memory that is never swapped to disk and is not accessible to NOMYO personnel or operational tooling; it is zeroed when the request completes;
(c) payloads are never written to persistent storage, never logged, never included in backups, and never transmitted to any third party;
(d) the key for each request is destroyed when the request completes, and NOMYO retains no key capable of decrypting any past request;
(e) NOMYO retains only the Service Metadata listed in Section 10.
As a consequence, NOMYO cannot use Customer Content for any purpose of its own, including training; cannot recover it after the request completes; and cannot produce it to any third party, including in response to legal process.
4.3 Security Tiers
Customer selects a security tier per request. Each tier adds controls to the one before it.
| Tier | Controls | Intended for |
|---|---|---|
standard |
Section 4.2 with clause (b′): payload handled transiently as token identifiers in protected memory; secure tokenizer enforced | General business data |
high |
Section 4.2 with clause (b): inference inside an Intel SGX enclave, CPU and GPU memory hardware-encrypted, unreadable by NOMYO or its host systems; plus secure memory on the client, plaintext never swapped to disk, key material zeroed after use | Sensitive business data |
maximum |
high plus hardware attestation: every response carries a TPM 2.0 quote of the server’s firmware, Secure Boot state, and application binary, signed by a key generated for that request and bound to the request identifier; a request to a server without TPM 2.0 is rejected. [Confirm whether the response also carries an attestation of the enclave itself.] |
Regulated data, subject to Section 4.5(e) |
The consequence clause at the end of Section 4.2 applies in full on the high and maximum tiers. On the standard tier, NOMYO’s inability to read Customer Content rests on the transient, token-only handling in clause (b′) and on the operational controls in clauses (c) to (e) rather than on hardware enforcement.
4.4 Keys
Customer generates and holds its own keys. NOMYO never receives a Customer private key, offers no key escrow, and cannot recover Customer Content if Customer loses a key. Persistent keys are optional and, when used, are Customer’s responsibility to protect.
4.5 Customer Responsibilities
The guarantee in Section 4.2 depends on Customer:
(a) using the nomyo SDK with encryption enabled, over HTTPS, and verifying NOMYO’s server key fingerprint before first use;
(b) selecting a security tier appropriate to the sensitivity of the data;
(c) protecting its own keys and, when using persistent keys, password-protecting them;
(d) minimising how long decrypted responses remain in memory on its own systems;
(e) not submitting special-category personal data (including health data) unless a written addendum covering that data is in place. NOMYO does not currently offer a HIPAA Business Associate Agreement.
5. Assistant
(a) Conversations are stored so that Customer’s users can return to them.
(b) Conversations are readable by NOMYO’s systems in order to provide the service. Human access is restricted to NOMYO officers who hold the database administration key, is used only for support at a user’s request or to investigate a security incident. No other NOMYO personnel or system can read conversations.
(c) A user can delete any conversation at any time and can export all conversations. Deleted conversations are removed from live systems immediately and from backups within 30 days.
(d) Conversations are retained until the user deletes them or until 30 days after the account is closed.
(e) Conversations are not used to train or improve any model. This applies equally to free and paid tiers.
(f) In transit, conversations are protected by TLS. The Assistant does not use the Encrypted Inference payload encryption of Section 4.
(g) The conversation is sent in plaintext over TLS to the Remote Model provider listed in the Subprocessor List. That provider’s own data-handling terms apply to its processing.
(h) NOMYO does not retain the provider’s copy and has no control over it beyond the contractual terms referenced in the Subprocessor List.
7. Chat API
(a) The Chat Router at chat.nomyo.ai/api is a text/image API to the same Local and Remote Models as the Assistant, without conversation storage.
(b) Requests are protected in transit by TLS. NOMYO’s servers process each request transiently in order to route it to a model. NOMYO does not store, log, or inspect request or response content. Nothing is retained except the Service Metadata in Section 10.
(c) When Customer selects a Remote Model, the request is forwarded in plaintext over TLS to the Remote Model provider listed in the Subprocessor List. That provider’s own data-handling terms apply to its processing.
(d) Customer may restrict its use to Local Models, in which case no Customer Content leaves the Hosting Facility.
8. nomyo-router
nomyo-router is an open-source Python package that Customer installs and operates on its own infrastructure to run its own model servers. NOMYO receives no Customer Content, Service Metadata, or telemetry from a nomyo-router installation. Nothing in this document applies to data that Customer processes with it, because NOMYO does not process that data.
9. aissurance
(a) aissurance at aissurance.eu receives from Customer’s infrastructure, through a reporting component that Customer installs, configures, and licenses separately, at intervals Customer sets: model inventory (model names, versions, quantisation, request counts, latency per endpoint); endpoint registry (backends, health status, connection counts); traffic telemetry (request volumes, cache hit rates, error rates). It also holds compliance evidence and documentation that Customer uploads or generates, and the accounts of Customer’s users.
(b) Reports are signed with HMAC-SHA256 and transmitted over TLS 1.3.
(c) Data is stored at the Hosting Facility under per-tenant envelope encryption. Destroying the tenant key permanently and irreversibly erases all of Customer’s aissurance data.
(d) Human access to aissurance data is impossible as the data is encrypted on behalf of the customer with customer owned encryption keys in transit and at rest.
(e) Retention: compliance evidence and post-market monitoring records are retained for 10 years, as EU AI Act Article 73 obligations require, unless Customer instructs earlier deletion; telemetry is retained for 12 months; on termination, Customer’s tenant key is destroyed instantly.
10. Service Metadata
NOMYO retains only the following records about a request to Encrypted Inference, the Assistant, or the Chat Router. Anything not listed here is not retained.
| Item | Purpose | Retention |
|---|---|---|
| Request timestamp | Billing, rate limiting, abuse prevention | Life of account |
| Account or API key identifier | Authentication, billing | Life of account plus 30 days |
| Product, model name, and security tier | Billing, capacity planning | Life of account |
| Input and output token counts | Billing | Life of account; invoice records as required by tax law |
| Request identifier (random value) | Attestation binding, support | Life of account |
| Latency and HTTP status code | Operations | 1 day |
| Client IP address | Abuse prevention | Not stored: held only in memory for the duration of the request, then discarded |
| Hardware attestation quote | Returned to Customer with the response | Not retained |
| Error logs, with payload excluded | Operations | 30 days |
Service Metadata is used only for the purpose listed. None of it contains or is derived from the content of a request.
11. Training and Model Improvement
NOMYO does not use Customer Content, Service Metadata, Assistant conversations, or aissurance data to train, fine-tune, evaluate, or otherwise improve any model, on any tier, free or paid. Under Encrypted Inference this is a structural property (Section 4.2); for all other products it is a commitment.
12. Hosting and Location
All NOMYO products run at the Hosting Facility in Germany, operated by the Hosting Entity, an affiliate of NOMYO LLC identified in the Subprocessor List. Customer Content under Encrypted Inference is never accessible from outside the Hosting Facility. Service Metadata, Assistant conversations, and Account Data may be accessed by NOMYO LLC personnel in the United States for billing, support, and operations, subject to the access restrictions in Sections 5(c) and 9(d).
13. Subprocessors
The current Subprocessor List is at /subprocessors/. It states, for each Subprocessor, which products it applies to. NOMYO gives 30 days’ notice of any addition or replacement by updating the list and emailing the Customer’s registered contact. Customer may object as set out in the Data Processing Addendum.
14. Deletion
| Data | On Customer request | On termination |
|---|---|---|
| Customer Content under Encrypted Inference | Nothing to delete; never held | Nothing to delete |
| Service Metadata | Deleted within 30 days, except billing records required by law | Deleted within 30 days, except billing records required by law |
| Assistant conversations | Per Section 5(d) | Per Section 5(e) |
| aissurance data | Per Section 9(e) | Per Section 9(e) |
| Account Data | Per the Privacy Policy | Deleted within [30] days |
NOMYO confirms deletion in writing on request.
15. Security Incidents
NOMYO notifies Customer of a personal data breach affecting Customer’s data without undue delay after becoming aware of it. Under Encrypted Inference, a breach of NOMYO’s systems cannot expose Customer Content, because NOMYO never holds it in readable form. Data that could be affected by an incident is limited to Service Metadata, Account Data, Assistant conversations, and aissurance data.
16. Verification
(a) On the maximum tier, every response carries a hardware attestation that Customer can verify independently, as described in the nomyo SDK documentation.
(b) NOMYO answers reasonable written security questionnaires.
(c) This document is version-controlled. Each release is archived at a permanent URL with its content hash, so that any party can confirm which version applied at a given date.
17. Version History
| Version | Effective | Change |
|---|---|---|
| [1.0] | 1st Oct 2026 | Initial release |