Skip to main content

/legal/privacy

Privacy and GDPR transparency baseline

This page records the current technical data flows and the information that would be needed for a formal GDPR notice. IICP is currently an unfunded, non-commercial research project maintained by one private steward. It is not a company, association or customer service, and this website is a public reference rather than a commercial offering. Accordingly, this is a technical transparency baseline, not a lawyer-approved notice or a claim of satisfying GDPR Articles 13 and 14.

Research or non-commercial status does not by itself remove GDPR obligations when personal data is processed. The contact addresses on this page provide an operational request path, but they are not a substitute for identifying the responsible controller and supplying all information required by an applicable formal notice.

Most important point

The IICP directory is a control plane, not the task processor. A selected remote node can still read the task it executes. Use local/browser inference for sensitive data, or apply a routing policy that restricts remote providers before sending the task.

Project status and contact

The IICP Project is not a separate legal entity. Its public research materials and experimental infrastructure are currently maintained by a single private steward who is seeking co-stewards. The project publishes no private residential address. Independently operated provider nodes determine or process their own task data according to their relationship with the user or deployer. A node policy declaration is not proof of legal identity, a contract or compliance.

Official project, privacy and data-request contact: [email protected]. Security vulnerabilities can also be reported privately to [email protected]. The responsible-controller analysis and complete notice information remain unresolved for the current research infrastructure as well as for any future service. This does not prevent publication of a deliberately limited transparency baseline, but the baseline must not be mistaken for complete Article 13 or 14 information.

Processing purposes and legal-basis draft

Area and dataPurposeWorking basis and boundary
Website deliveryIP address, request time, requested path, user agent and security logsPublish and secure the research websiteLegitimate interests in publication and security; final legal review remains future organizational work
Directory discoveryIntent, region/model constraints, transient connection metadataReturn matching provider candidatesLegitimate interests in operating the experimental research infrastructure; the task prompt should not be sent to the directory
Node registrationEndpoint, node and operator identifiers, capabilities, health, routing signals and SDK versionMake current providers discoverableContract or steps requested by the operator; legitimate interests in mesh operation
Credits and integrityNode/operator identifiers, credit transactions, receipts and signed lifecycle eventsAccounting, abuse resistance and auditabilityContract and legitimate interests; some integrity records cannot simply be erased without affecting others
Remote task executionTask payload, response and execution metadataExecute the task at the selected providerDetermined by the user/deployer and provider operator; IICP does not supply a universal lawful basis
Relay or tunnelConnection metadata and forwarded payloads, encrypted or plaintext depending on the pathReach a provider that cannot accept a direct connectionDepends on the operator relationship and path; processor/subprocessor terms may be required
Browser/local inferencePrompt, response and model cache on the user's deviceRun a model locallyUser-controlled local processing, subject to the browser and model provider
Forum and supportAccount name, email, posts, moderation records and support evidenceOperate the community and respond to requestsContract, consent or legitimate interests depending on the action

Where legitimate interests are used, the final notice must name the specific interest and record the balancing assessment. Where consent is used, withdrawal must be as easy as giving consent.

Recipients, processors and transfers

  • Hosting, CDN/security, email and forum providers can receive the metadata needed to provide their service.
  • The selected provider receives the task; a relay or model backend may also process it depending on the selected route.
  • Remote routing can transfer personal data outside the EEA. A region label alone is not a transfer safeguard.
  • Users and deployers must verify operator identity, contracts, subprocessors, adequacy decisions or other transfer mechanisms for regulated processing.
  • A final public subprocessor/recipient list and the means to obtain applicable safeguards remain required.

Retention and source

IICP does not make a blanket “no logs” claim. Website and security logs, directory records, signed lifecycle events, accounting records, forum accounts and provider task data have different purposes and retention needs. The final notice must publish concrete periods or selection criteria for each category.

Most directory data comes from operators when they register or heartbeat a node, or from service/security observations. Provider task data comes from the user or deployer that selects the provider.

Your rights

Depending on the processing and legal basis, data subjects can request access, a copy, correction, erasure, restriction, portability or object to processing. They can withdraw consent where consent is the basis and complain to the competent supervisory authority.

Verified operators can use the operator rights guide and a local IICP client to export, restrict or anonymise records bound to their operator key. The private key stays on the operator's device. Lost-key, correction, objection and non-operator requests use the assisted contact path. Do not put personal data, prompts or credentials in public issues.

Required data and automated decisions

Node registration requires technical identity, reachability and capability fields so the directory can operate. Refusing those fields means the node cannot join. Ordinary website reading does not require an account; forum participation does.

IICP directory ranking supports route selection but is not intended to make a solely automated decision that produces legal or similarly significant effects about a person. Deployers must perform a separate assessment if they use IICP in such a workflow.

Before any future service offering

  • Establish the responsible legal person or body and a serviceable organizational contact address.
  • Approve the purpose-by-purpose lawful bases and legitimate-interest assessments.
  • Publish concrete retention periods, recipients/subprocessors and transfer safeguards.
  • Name the competent supervisory authority and final request procedure.
  • Complete qualified legal review before presenting IICP as a formally operated or commercial service.

Last reviewed 2026-08-01. This baseline deliberately identifies missing formal-notice fields instead of claiming legal certification from technical controls.