confidentialnodes.com
Marketplace Inference GPU prices Finder Listings Contact us Account
Account

Privacy Policy

How Alexandria Cornerstone Inc. collects, uses, shares, retains, and protects personal data through Confidential Nodes.

Effective and last updated 24 August 2026

On this page

  1. Who we are
  2. Scope
  3. Data we collect
  4. Sources
  5. Purposes and legal bases
  6. Marketplace data
  7. How we share data
  8. International transfers
  9. Retention
  10. Security
  11. Your rights
  12. United States notices
  13. Automated decisions
  14. Children
  15. Changes
  16. Contact

1. Who we are

Confidential Nodes is a project operated by Alexandria Cornerstone Inc. (“Alexandria”, “we”, “us”, or “our”). For the website, marketplace enquiries, accounts, contracting, bookings, payments, and related business operations described here, Alexandria is generally the controller of your personal data.

Alexandria Cornerstone Inc.
Crusiusstraße 1
80538 Munich, Germany
hello@confidentialnodes.com

Our operational team is based in Munich, with an additional Alexandria office in London. A supplier, buyer, payment provider, or other transaction counterparty may separately control personal data it receives for its own purposes. A transaction-specific agreement or data processing addendum may provide more detail.

2. Scope

This Policy applies to confidentialnodes.com, our marketplace and finder, communications, provider onboarding, accounts, application programming interfaces, contracting and booking workflows, payments, transaction support, and related services that link to it (the “Services”). It does not govern a third party’s website or service, even when we link to it.

3. Personal data we collect

Contact and business identity
Name, work email, telephone number, job title, employer, business address, and the people authorized to act for an organization.
Marketplace requirements and listings
Requested or offered hardware, node counts, region, term, start date, price or floor, isolation and attestation requirements, capacity, notes, quote history, and matching status.
Account and authentication data
Account identifiers, verified email, organization membership, access roles, login and security events, tokens, and session information. Authentication may be provided by WorkOS.
Contract, booking, and transaction data
Orders, negotiated terms, signatures, service locations, acceptance tests, service levels, invoices, payment status, credits, cancellations, disputes, and communications among transaction participants.
Billing and compliance data
Billing contact, tax and VAT identifiers, bank or limited payment metadata, fraud signals, and information needed for business verification, sanctions, export-control, or know-your-business checks. A payment provider may collect full card or bank credentials directly.
Communications
Emails, support requests, meeting notes, call records, preferences, feedback, and messages sent through our provider and customer relationship tools.
Technical and usage data
IP address, browser and device information, referring page, approximate location derived from IP, pages and features used, timestamps, consent preference, error data, and—only with permission—analytics events and masked session replay.
Public and third-party business data
Provider specifications, public pricing, company and professional contact details, registry information, sanctions results, evidence sources, and other information from public sources or commercial data providers.

Please do not place special-category data, private keys, credentials, production datasets, patient information, or other unnecessary sensitive material in free-text fields. If a regulated workload requires such information, use the secure process specified in the applicable Order or data processing agreement.

4. Where data comes from

We collect personal data:

  • directly from you or your organization;
  • from buyers, suppliers, datacenters, resellers, advisers, and transaction counterparties;
  • from public websites, business registries, professional directories, sanctions lists, and provider documentation;
  • automatically from devices and browsers when you use the Services; and
  • from service providers that support authentication, payments, fraud prevention, analytics, communications, hosting, or support.

5. Why we use personal data

Where the EU GDPR, UK GDPR, or a similar law applies, we rely on the following legal bases:

Contract and steps requested before a contract
To review an enquiry, match supply and demand, create an account, negotiate and administer an Order, process a booking or payment, provide support, and enforce transaction terms.
Legitimate interests
To operate and secure the marketplace, research and verify business listings, prevent fraud and abuse, manage supplier and customer relationships, improve the Services, troubleshoot errors, establish or defend legal claims, and communicate about related business services. We balance these interests against your rights.
Legal obligation
To keep tax and accounting records, respond to lawful requests, conduct required sanctions or identity checks, comply with export controls, and meet consumer, platform, financial, or other legal duties.
Consent
For optional browser analytics and session replay, and for marketing or another use where consent is required. You may withdraw consent at any time without affecting earlier lawful processing.

We may send service messages needed to handle your request or transaction. We send optional marketing in accordance with applicable law, and each marketing message will provide an appropriate way to opt out.

6. Marketplace and transaction data

We use submitted requirements and capacity information to assess fit, compare offers, contact potential counterparties, support diligence, prepare transaction documents, administer bookings, and resolve service or payment issues. We may initially mask a party’s identity and share a requirement or quote without direct contact details. We disclose identity and contact information when authorized, when needed to progress a requested transaction, or as stated in the applicable workflow or Order.

A supplier receiving buyer data and a buyer receiving supplier data must use it only to assess, enter, or perform the relevant transaction; protect it appropriately; and comply with its own data-protection duties. If Alexandria processes customer workload data on a customer’s behalf, that processing is governed by the applicable Order and data processing agreement rather than this general marketplace Policy alone.

7. How we disclose personal data

We may disclose personal data to:

  • buyers, suppliers, datacenters, resellers, and other transaction participants as needed to evaluate, enter, or perform a requested transaction;
  • service providers, including Railway for application and database infrastructure, AgentMail for marketplace notifications and email operations, PostHog for EU-hosted analytics and error monitoring, WorkOS for authentication, and payment, identity, compliance, support, or document-signing providers used in a transaction;
  • professional advisers and financing partners, including lawyers, auditors, insurers, banks, and transaction or infrastructure-finance partners, subject to appropriate confidentiality;
  • authorities and affected parties when required by law or reasonably necessary to protect rights, safety, security, prevent fraud, or establish and defend legal claims; and
  • a successor or transaction participant in a merger, financing, reorganization, sale of assets, insolvency, or similar corporate event, subject to appropriate safeguards.

We do not sell personal data for money. We do not disclose personal data for cross-context behavioral advertising, and we do not use advertising cookies.

8. International data transfers

We operate globally and may disclose data to organizations in countries other than the one where it was collected. Where required, we use an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or another lawful transfer mechanism, together with supplementary measures where appropriate. You may contact us for information about the relevant safeguard.

9. How long we keep data

We retain personal data for the shortest period reasonably needed for the purpose described, including to provide the Services, complete requested transactions, comply with law, resolve disputes, and enforce agreements. Our criteria include the relationship’s status, transaction and warranty periods, security needs, limitation periods, and statutory recordkeeping duties.

  • Unsuccessful marketplace enquiries and quotes are ordinarily reviewed for deletion or anonymization after 24 months without meaningful activity.
  • Account and relationship records are kept while active and through a reasonable closure and backup period.
  • Orders, invoices, payment, tax, and core contract records may be retained for up to 10 years, or longer where law or an active claim requires.
  • Compliance and verification records are kept for the legally required period and while needed to manage fraud, sanctions, export-control, or counterparty risk.
  • Analytics events, masked replay, and technical logs follow configured deletion windows based on diagnostic and trend-analysis needs. Browser-storage duration is described in our Cookie Notice.

We may retain de-identified or aggregated information that no longer identifies an individual.

10. Security

We use administrative, technical, and organizational measures designed to protect personal data, including access controls, encryption in transit, environment and secret separation, audit logging for privileged workflows, masked analytics inputs, and provider diligence. No system is completely secure. You are responsible for protecting credentials and promptly notifying us of suspected unauthorized access.

11. Your data-protection rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or port personal data; object to processing based on legitimate interests or to direct marketing; and withdraw consent. You may also have the right to complain to a competent supervisory authority, including the authority in your country of residence, work, or the alleged violation.

To exercise a right, email hello@confidentialnodes.com. State the right you wish to exercise and the relevant account, organization, or transaction. We may verify identity and authority before acting. Certain data may be exempt, and legal or contractual duties may require us to retain some records.

12. United States state privacy notices

Where a US state privacy law applies, residents may have rights to confirm processing, access, correct, delete, or obtain a portable copy of personal data; opt out of sale, targeted advertising, or certain profiling; limit some uses of sensitive data; and appeal a denied request. We do not discriminate against a person for exercising an applicable privacy right.

The categories collected in the preceding 12 months may include identifiers, commercial and transaction information, internet or electronic activity, professional or employment-related information, approximate location, communications, and—where required for authentication, payment, or compliance—account credentials or government identification. The sources, purposes, and recipient categories are described above. We disclose these categories for the business purposes described in this Policy. We do not sell them or share them for cross-context behavioral advertising.

You or an authorized agent may submit a request by email. We will verify the request in a way proportionate to its sensitivity. Browser Global Privacy Control and Do Not Track signals are treated as a rejection of optional analytics on supported browsers.

13. Automated recommendations and decisions

The Finder uses the configuration you enter and published marketplace data to generate planning recommendations. These recommendations do not produce legal or similarly significant effects, and a person reviews requirements before contracting. We do not currently make final decisions with legal or similarly significant effects based solely on automated processing. If that changes, we will provide the notices and choices required by applicable law.

14. Children

The Services are intended for business users and are not directed to children under 18. We do not knowingly collect personal data from children. Contact us if you believe a child has provided personal data so that we can investigate and take appropriate action.

15. Changes to this Policy

We may update this Policy as the Services, transaction model, providers, or law changes. We will post the updated version and revise the effective date. If a change materially affects how we use data already collected, we will provide any additional notice or choice required by law.

16. Contact

Privacy — Confidential Nodes
Alexandria Cornerstone Inc.
Crusiusstraße 1, 80538 Munich, Germany
hello@confidentialnodes.com

Explore

Marketplace Confidential inference Finder Listings For suppliers About us Contact us

Directories

GPU prices GPU providers Blog GPU guides Technologies GPU attestation Cost calculator RSS feed

Legal

Privacy Policy Terms of Use Cookie Notice
by Alexandria
confidentialnodes.com

Pricing and specifications may change.

Alexandria Cornerstone Inc.