1. Scope and roles
This Privacy Notice describes how Palace Leap LLC, operating as Palace Ring, collects, uses, discloses and protects personal data in connection with its websites, communications, meetings, professional services and AI, compute, model-training and infrastructure services (the “Services”). In this Notice, “Palace Ring,” “we,” “us,” and “our” mean Palace Leap LLC.
When Palace Ring determines why and how website, account, business-contact, supplier, applicant or security data is processed, it acts as controller. When a customer determines why and how Customer Personal Data is processed through a Service, Palace Ring acts as processor or service provider. The Data Processing Agreement governs that customer-directed processing. Some engagements may make each party an independent controller for its own compliance and relationship records.
2. Personal data collected
Depending on the engagement, Palace Ring may collect:
- name, professional role, organization, contact details, account identifiers and communication preferences;
- orders, commercial correspondence, invoices, payment confirmation, supplier records and support communications;
- authentication, access, device, browser, network, approximate location derived from IP address, security, usage and performance data;
- prompts, inputs, files, datasets, audio, images, model responses, evaluations and fine-tuning materials submitted to a Service;
- facility-access, operator, diligence, safety and compliance records required for an authorized institutional mandate; and
- inferences needed for security, fraud prevention, capacity planning and service administration.
Sensitive or specially regulated personal data may be submitted only when the applicable Order expressly authorizes the data class and required controls are operating. Palace Ring does not ask website visitors to provide sensitive personal data for general inquiries.
3. Sources of personal data
Palace Ring receives data directly from individuals; from the customer or organization through which they use a Service; from authorized users, suppliers and project counterparties; from security, hosting, model, payment and communications providers; and from lawful public, professional and governmental sources. Palace Ring may generate service, security and operational records through an individual’s interaction with the Services.
4. Service data
Palace Ring processes customer prompts, inputs and outputs to provide, secure, support and administer the requested Service. Training a general model for unrelated customers requires the customer’s express opt-in. Customer-requested fine-tuning or training, evaluation, safety screening, abuse detection and technical processing remain service-related uses.
Retention controls, zero-retention configurations, region, private networking, access logging and deletion schedules depend on the operating form and must be recorded in the Order when required. Authorized subprocessors may process content only for the contracted Service and under data-protection obligations.
5. Purposes and legal bases
Palace Ring processes personal data to provide, operate, secure and improve Services; authenticate users; administer accounts, capacity, billing and support; coordinate authorized suppliers and delivery; prevent fraud and abuse; investigate incidents; maintain audit and operating records; communicate about an engagement; comply with law; and establish, exercise or defend legal claims.
Where law requires a legal basis, Palace Ring relies on performance of a contract or steps requested before a contract; compliance with legal obligations; legitimate interests in secure, reliable and accountable operations, balanced against individual rights; protection of vital interests; tasks carried out under an authorized public-interest mandate; or consent. Consent may be withdrawn for future processing without affecting earlier lawful processing.
Palace Ring may use aggregated or de-identified information for capacity planning, security, service analysis and research where it cannot reasonably be linked to an individual. Palace Ring will not attempt to re-identify data treated as de-identified except to test whether de-identification remains effective or as permitted by law.
7. International transfers
Services may involve processing in more than one jurisdiction. Palace Ring uses adequacy decisions, contractual safeguards, transfer assessments and technical or organizational measures appropriate to the transfer and operating form. For customer-directed processing, the Data Processing Agreement incorporates the EU Standard Contractual Clauses and UK Addendum when applicable.
Data residency, sovereign-cloud, private-network or on-premise requirements must be agreed before restricted data is submitted. Contracted customers may request information about applicable processing locations and transfer mechanisms through their contracting channel.
8. Retention
Palace Ring retains personal data for the period reasonably required by the purposes above, customer instructions, security and continuity needs, legal obligations, limitation periods and audit requirements. Account and commercial records generally follow the relationship and applicable statutory period; support and inquiry records follow operational need; service content follows the configuration and Order.
Backups and immutable security records may persist for a limited cycle after active deletion and remain protected until overwritten or isolated from use. Data subject to a legal hold, dispute or regulatory duty may be retained for that purpose. De-identified information may be retained where it can no longer reasonably identify an individual.
9. Individual rights
Depending on jurisdiction and context, an individual may have rights to access, correct, delete, restrict or object to processing; receive portable data; withdraw consent; opt out of sale, sharing, targeted advertising or certain profiling; limit certain uses of sensitive data; appeal a denied request; and complain to a regulator. Palace Ring will not discriminate against an individual for exercising an applicable right.
Palace Ring may verify identity, residence and authority before acting. Requests may be limited or denied where law permits, including when Palace Ring cannot verify the requester, must protect another person, or must retain the data. An authorized agent may submit a request with evidence of authority.
When Palace Ring processes Customer Personal Data for a customer, the customer is responsible for responding to individual requests. Palace Ring will refer the request to the customer and assist as required by the Data Processing Agreement.
EEA and UK residents may complain to their local supervisory authority. U.S. state residents may exercise applicable access, correction, deletion, portability, opt-out and appeal rights. Palace Ring’s current practices exclude sale and cross-context behavioral advertising, so an opt-out signal does not change those practices.
11. Security and children
Palace Ring maintains safeguards appropriate to its role and the risk, including access control, personnel confidentiality, vendor diligence, secure transmission, environment separation, monitoring, vulnerability management, resilience and incident procedures. Specific measures for Customer Personal Data are described in the Data Processing Agreement and applicable Order. Every system carries residual risk; customers must use appropriate credentials, configurations, data classifications and human oversight.
The Services are designed for organizations and authorized adult users. They are not directed to children for independent use. Children’s personal data may be processed only through an authorized institutional service with an appropriate lawful basis, notices, safeguards and consent where required. A parent, guardian or institution may contact Palace Ring if it believes a child’s data was submitted outside those conditions.
12. Contact and changes
Privacy questions and individual-rights requests may be sent to privacy@palacering.com. Contracted customers may also use their Palace Ring representative or the notice address in their Order. Palace Ring may require information necessary to verify identity, authority and jurisdiction before acting on a request.
General inquiries may be sent to info@palacering.com; legal notices may be sent to legal@palacering.com. Palace Ring may update this Notice as its Services or applicable law changes. The effective date will be revised, and material changes will be communicated through the Service, contracting channel or another legally required method.