Spheron AI Privacy Policy
GPU Compute Marketplace
Effective Date: August 11, 2026 · Version 1.0
Beta360 Pte Ltd · UEN: 202107371K
#19-02, 20 Collyer Quay, Singapore 049319
1. Introduction and Scope
This Privacy Policy ("Policy") describes how Beta360 Pte Ltd (UEN: 202107371K), a company incorporated in the Republic of Singapore with its registered office at #19-02, 20 Collyer Quay, Singapore 049319 ("Company," "we," "us," or "our"), collects, uses, discloses, transfers, retains, and otherwise processes personal data in connection with the Spheron AI GPU Compute Marketplace and any associated applications, APIs, dashboards, and services (the "Platform").
In this Policy, "personal data" means data, whether true or not, about an individual who can be identified from that data, or from that data together with other information to which we have or are likely to have access. "You" and "your" refer to any individual whose personal data we process, including account holders, authorised users of a corporate account, prospective customers, and visitors to the Platform.
This Policy forms part of, and should be read together with, the Spheron AI Terms and Conditions of Use (the "Terms"). Capitalised terms used but not defined in this Policy have the meanings given to them in the Terms. Where this Policy conflicts with the Terms in respect of the processing of personal data, this Policy prevails to the extent of that conflict.
BY ACCESSING, REGISTERING FOR, OR USING THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS POLICY. WHERE YOUR CONSENT IS REQUIRED BY APPLICABLE LAW, YOU CONSENT TO THE PROCESSING DESCRIBED HEREIN.
This Policy is issued primarily under the Personal Data Protection Act 2012 of Singapore (the "PDPA"). Where the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), or any other data protection legislation applies to our processing of your personal data, the additional provisions set out in Section 11 apply.
This Policy does not apply to the practices of third-party Providers, payment processors, or other third parties whose services you access through or alongside the Platform. Those parties process personal data in accordance with their own privacy policies, and we are not responsible for their practices. Please see Sections 5 and 13.
2. Our Role and How to Contact Us
As described in Section 3 of the Terms, the Company operates as a marketplace and aggregator. We do not own, operate, or manage the underlying compute infrastructure; all compute resources made available through the Platform are owned and operated by independent third-party Providers. This division of roles is material to how personal data is handled and is explained in Sections 5 and 6 of this Policy.
In respect of the personal data described in Section 3, the Company is the controller (or, under the PDPA, the organisation having control over the collection, use, and disclosure of that personal data). Where we process personal data contained within your workloads on our instructions, we act as a processor (or data intermediary) on your behalf, as set out in Section 6.
We have appointed a Data Protection Officer who may be contacted in respect of any matter arising under this Policy:
The Data Protection Officer
Beta360 Pte Ltd (UEN: 202107371K)
#19-02, 20 Collyer Quay
Singapore 049319
legal@beta360.org
info@spheron.ai
3. Personal Data We Collect
We collect personal data that you provide to us directly, personal data generated automatically through your use of the Platform, and personal data we receive from third parties such as payment processors and identity verification services. The table below sets out the categories of personal data we collect and the purposes for which each category is used.
| What We Collect | Why We Collect It |
|---|---|
| Account and Registration Data: your name, email address, username, hashed account credentials, organisation name, job title, country of residence or incorporation, and any other information you provide when registering an account under Section 8.1 of the Terms. |
|
| Identity and Verification Data: government-issued identification, business registration documents, beneficial ownership information, and sanctions and adverse-media screening results, where we are required or reasonably consider it necessary to verify your identity. |
|
| Billing and Payment Data: billing name and address, tax identification numbers, Credit purchase and consumption history, invoices, payment method type, card brand, expiry date, the last four digits of a payment card, and payment processor tokens and references. We do not collect or store full payment card numbers or security codes; those are collected directly by our PCI-DSS compliant payment processors. |
|
| Usage and Deployment Data: the instance types you deploy (Dedicated, Spot, On-Demand, or Reserved), GPU model, region, the Provider selected, deployment and termination timestamps, runtime hours, metered usage, the Prevailing Rate applied to each metering interval, and Credits consumed. |
|
| Technical and Log Data: IP address, approximate location derived from IP address, browser type and version, operating system, device identifiers, referring URL, pages and features accessed, session identifiers, API request logs, and error and diagnostic logs. |
|
| Communications and Support Data: the content of support tickets, emails, chat messages, and call notes; feedback and survey responses; and records of Non-Disclosure Agreements executed and compliance documentation disclosed under Section 7.3 of the Terms. |
|
| Marketing and Preference Data: your communication preferences, records of consent given and withdrawn, marketing campaign interactions, and the referral source or campaign parameters through which you reached the Platform. |
|
| Cookies and Analytics Data: identifiers and activity data collected through cookies, pixels, software development kits, and similar technologies, as described in Section 8. |
|
Data you are not required to provide. You are not obliged to provide any personal data to us. However, certain personal data is necessary for the performance of our contract with you, and if you decline to provide it we may be unable to create your account, verify your identity, process Credit purchases, provision compute resources, or provide support.
Special categories of personal data. We do not seek to collect any special category or sensitive personal data, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. Please do not submit such data to us except where we expressly request it.
4. Purposes and Legal Bases for Processing
We process personal data only where a lawful basis for doing so exists. The bases on which we rely are:
- Performance of a contract: processing necessary to enter into or perform our contract with you under the Terms, including account administration, provisioning of compute resources, metering, billing, and support.
- Compliance with legal obligations: processing necessary to comply with obligations to which we are subject, including tax, accounting, corporate record-keeping, sanctions, export control, and anti-money-laundering requirements, and lawful requests from competent authorities.
- Legitimate interests: processing necessary for our legitimate interests in securing and improving the Platform, preventing fraud and abuse, managing our Provider relationships, conducting business analytics, and establishing, exercising, or defending legal claims, except where those interests are overridden by your interests or fundamental rights. Under the PDPA we rely on the corresponding legitimate interests and business improvement exceptions.
- Consent: processing carried out with your consent, including marketing communications and non-essential cookies. Where we rely on consent, you may withdraw it at any time in accordance with Section 11, without affecting the lawfulness of processing carried out before withdrawal.
No automated decision-making. We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, including profiling.
Change of purpose. Where we intend to use your personal data for a purpose other than that for which it was collected, we will provide you with notice of that purpose and, where required by applicable law, obtain your consent before doing so.
5. Disclosure of Personal Data
We do not sell your personal data. We have not sold, and do not sell, personal data, and we do not share personal data for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. We disclose personal data only to the categories of recipients set out below, and only to the extent necessary for the purposes described.
- Providers: when you deploy a compute resource, we disclose to the Provider you have selected the information necessary to provision, operate, support, and bill that resource. This ordinarily comprises an account identifier, deployment parameters, region, resource specifications, and a technical point of contact. Each Provider determines the purposes and means of its own processing in respect of the infrastructure it operates and is an independent controller for those purposes. The Provider’s handling of personal data is governed by its own privacy policy and, as stated in Sections 3.3 and 6 of the Terms, the Company does not control and is not responsible for a Provider’s acts or omissions. You should review the relevant Provider’s privacy terms before deploying.
- Payment processors and financial institutions: to process Credit purchases, effect refunds, prevent fraud, and reconcile settlements.
- Service providers and processors: hosting, storage, logging, email delivery, customer support, identity verification, analytics, and security vendors engaged to process personal data on our behalf. Such vendors act on our documented instructions and are bound by written obligations of confidentiality and security.
- Professional advisers and auditors: legal, accounting, insurance, tax, and audit advisers, where necessary for the provision of their services to us.
- Corporate transactions: an actual or prospective acquirer, investor, or successor, together with their advisers, in connection with a merger, acquisition, corporate reorganisation, financing, or sale of all or substantially all of our assets, consistent with Section 17.4 of the Terms. Personal data disclosed for this purpose is limited to what is reasonably necessary and is subject to confidentiality undertakings.
- Legal and regulatory disclosure: courts, regulators, law enforcement, and other authorities where we are required to do so by law or where disclosure is reasonably necessary to comply with legal process, to enforce the Terms, to protect the rights, property, or safety of the Company, our Users, our Providers, or the public, or to detect and address fraud, security, or technical issues.
- With your consent or at your direction: to any other recipient where you have consented to or requested the disclosure.
6. Your Workloads, Content, and Data
You retain ownership of all data, models, code, and content that you upload to, store on, or generate using compute resources procured through the Platform ("Workload Data"), as provided in Sections 8.3 and 12 of the Terms.
We do not access or monitor Workload Data. Consistent with Section 8.3 of the Terms, the Company does not access, review, inspect, or monitor Workload Data except to the limited extent necessary for the operation or security of the Platform, or as required by law or lawful authority. We do not use Workload Data to train models, and we do not disclose Workload Data to third parties except as described in this Section.
Where Workload Data contains personal data. If your Workload Data contains personal data relating to your own customers, employees, or other individuals, you are the controller of that personal data and the Company and the relevant Provider act as processors on your behalf. In that capacity you are solely responsible for establishing a lawful basis for the processing, for providing any required notices to and obtaining any required consents from the individuals concerned, for responding to their requests to exercise their rights, and for otherwise complying with all applicable data protection legislation, as stated in Sections 8.3 and 13 of the Terms. You must not place personal data on the Platform where doing so would breach any law or any obligation owed by you to a third party.
Security of Workload Data. As set out in Section 8.4 of the Terms, you are responsible for implementing security measures appropriate to your deployments, including access controls, encryption of data at rest and in transit within your own environment, network configuration, and key management. You are also responsible for backup, checkpointing, and fault tolerance, in particular where you use Spot Instances, which may be reclaimed at any time under Section 4.2 of the Terms.
Deletion on termination. You acknowledge that, on termination of an instance or of your account, Workload Data stored on Provider infrastructure may be permanently deleted, as stated in Section 9.3 of the Terms. You should export any data you wish to retain before terminating.
7. International Transfers of Personal Data
The Company is established in Singapore. Our Providers, service providers, and processors operate data centres and facilities in multiple regions worldwide. Accordingly, your personal data may be transferred to, stored in, and processed in jurisdictions outside your country of residence, and those jurisdictions may not afford the same level of protection for personal data as your home jurisdiction.
Where we transfer personal data out of Singapore, we comply with the transfer limitation obligation under the PDPA by taking appropriate steps to ascertain that the recipient is bound by legally enforceable obligations to provide the transferred personal data with a standard of protection at least comparable to that under the PDPA. Those steps ordinarily take the form of contractual obligations imposed on the recipient.
Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on an adequacy decision of the relevant authority where one is available, and otherwise on the Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Agreement or Addendum, or another lawful transfer mechanism, together with any supplementary measures required following a transfer impact assessment.
You may request further information about the safeguards applied to a particular transfer, including a copy of the relevant contractual clauses with commercially confidential terms redacted, by contacting the Data Protection Officer at the details in Section 2. When you select a Provider in a particular region, you direct us to transfer the data necessary to provision that resource to that region.
8. Cookies and Similar Technologies
We and our service providers use cookies, pixels, tags, local storage, and similar technologies on the Platform and on our marketing websites. The categories we use are:
- Strictly necessary: required to operate the Platform, including session management, authentication, load balancing, fraud prevention, and bot mitigation. These cannot be disabled through our interfaces because the Platform will not function without them.
- Functional: used to remember your preferences and settings, such as interface and display choices.
- Analytics and performance: used to understand how the Platform is used in aggregate, to measure traffic, and to diagnose faults and improve performance.
- Marketing and attribution: used, where you have consented or where otherwise permitted by applicable law, to measure marketing campaigns and to attribute visits to their source.
The third parties whose technologies we currently deploy for analytics, attribution, and security purposes include Google (Google Tag Manager and Google Analytics), Amplitude, DataFast, Ahrefs, Apollo.io, and Cloudflare (Turnstile). Each processes data in accordance with its own privacy notice. The set of vendors may change from time to time, and material changes will be reflected in this Policy.
Most browsers allow you to refuse or delete cookies through their settings, and you may withdraw any consent given for non-essential cookies at any time. Blocking cookies may impair the functionality of the Platform, and blocking strictly necessary cookies will prevent you from signing in. Because there is no consistent industry standard for responding to browser "Do Not Track" signals, we do not currently respond to them; where the CCPA/CPRA applies, we honour recognised opt-out preference signals as described in Section 11.
9. Security of Personal Data
We implement technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, alteration, disclosure, or access. These measures include encryption of data in transit using industry-standard transport security, storage of account credentials in hashed and salted form, role-based access controls and least-privilege provisioning, network segmentation, logging and monitoring of administrative access, periodic review of access rights, secure development practices, and due diligence over vendors that process personal data on our behalf.
As stated in Section 7.4 of the Terms, we do not warrant, guarantee, or certify the compliance status of any Provider. Compliance certifications held by Providers, which may include ISO 27001, SOC 1, SOC 2, SOC 3, HIPAA, PCI-DSS, and GDPR compliance, are displayed on the relevant Provider listing within the Marketplace, and further documentation may be made available under a Non-Disclosure Agreement pursuant to Section 7.3 of the Terms. You remain responsible for conducting your own due diligence as to whether a Provider’s posture is adequate for your regulatory requirements.
No guarantee of absolute security. No method of transmission over the internet and no method of electronic storage is completely secure. While we endeavour to protect personal data using measures appropriate to the risk, we cannot and do not guarantee absolute security, and consistent with Section 10.1 of the Terms the Platform is provided without warranty that it will be secure or error-free. You are responsible for maintaining the confidentiality of your account credentials under Section 8.1 of the Terms, and you must notify us promptly at the contact details in Section 2 if you suspect any unauthorised use of your account.
Breach notification. In the event of a data breach that results in, or is likely to result in, significant harm to affected individuals or that is of a significant scale, we will notify the Personal Data Protection Commission of Singapore and affected individuals in accordance with the PDPA, and any other supervisory authority and individuals where required under other applicable law, within the periods prescribed by the relevant legislation.
10. Retention of Personal Data
We retain personal data only for as long as it is necessary for the purposes for which it was collected, or for such longer period as is required or permitted by applicable law. In determining the appropriate retention period we consider the volume, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and whether those purposes can be achieved by other means.
- Account and registration data: retained for the duration of your account and for a reasonable period following its closure to address post-termination queries and disputes.
- Billing, payment, and tax records: retained for the periods prescribed by applicable Singapore tax, accounting, and companies legislation, and for such longer period as may be necessary to resolve any outstanding dispute.
- Usage and deployment records: retained for the period necessary to substantiate charges, to support the billing dispute window in Section 5.10 of the Terms, and for capacity planning in aggregate form.
- Technical and security logs: retained for a limited period appropriate to incident detection and investigation, and for longer where required for an ongoing investigation or legal claim.
- Communications and support records: retained for as long as necessary to service the relationship and to establish, exercise, or defend legal claims.
- Identity and verification records: retained for the period required by applicable anti-money-laundering, sanctions, and record-keeping obligations.
Consistent with Section 8.3 of the Terms, we may retain and use data in aggregated, anonymised, or de-identified form, from which you cannot reasonably be identified, for analytics, capacity planning, service improvement, and business purposes without limitation of time. We will cease to retain personal data, or remove the means by which it can be associated with a particular individual, as soon as it is reasonable to assume that retention no longer serves the purpose for which it was collected and is no longer necessary for any legal or business purpose.
11. Your Rights
11.1 Rights Under the PDPA
Subject to the exceptions in the PDPA, you have the right to request access to the personal data about you that is in our possession or under our control and information about the ways in which it has been or may have been used or disclosed within the preceding year, and the right to request correction of an error or omission in that personal data. You may also withdraw any consent you have given, on reasonable notice, in respect of the collection, use, or disclosure of your personal data.
Withdrawal of consent may prevent us from continuing to provide the Platform or any part of it to you. We will inform you of the likely consequences before giving effect to a withdrawal request. Withdrawal of consent does not affect our ability to process personal data where we are required or authorised to do so under applicable law.
11.2 Rights Under the GDPR and UK GDPR
Where the GDPR or UK GDPR applies to our processing, you additionally have the rights, subject to the conditions and exceptions in that legislation, to obtain access to your personal data; to have inaccurate personal data rectified; to have personal data erased; to restrict processing; to data portability; to object to processing carried out on the basis of legitimate interests and to object at any time to processing for direct marketing purposes; and to withdraw consent where processing is based on consent.
You also have the right to lodge a complaint with a supervisory authority in the member state of your habitual residence, place of work, or place of the alleged infringement, or with the Information Commissioner’s Office in the United Kingdom. We would nonetheless appreciate the opportunity to address your concerns directly before you approach a supervisory authority.
11.3 Rights Under the CCPA/CPRA
Where the CCPA/CPRA applies, you have the right to know the categories and specific pieces of personal information we have collected, the categories of sources, the business or commercial purposes for collection, and the categories of third parties to whom it is disclosed; the right to request deletion; the right to request correction; the right to opt out of the sale or sharing of personal information, noting that we do not sell or share personal information as those terms are defined; the right to limit the use of sensitive personal information, noting that we do not collect sensitive personal information for purposes requiring such a limit; and the right not to receive discriminatory treatment for exercising any of these rights. You may use an authorised agent to submit a request on your behalf, subject to our verification of the agent’s authority.
11.4 How to Exercise Your Rights
You may exercise any of the rights described above by contacting the Data Protection Officer at legal@beta360.org or at the address in Section 2, specifying the right you wish to exercise and providing sufficient information for us to identify you and locate the relevant personal data. We may request additional information to verify your identity before acting on a request, and we may decline a request that is manifestly unfounded, excessive, or repetitive, or where an exception under applicable law applies.
We will respond to your request within thirty (30) days of receipt, or within such other period as is prescribed by the applicable legislation. Where we are unable to respond within that period, we will inform you of the reason and of the time by which we expect to respond. We do not charge a fee for responding to a request, except that we may charge a reasonable fee for an access request under the PDPA, of which we will notify you in advance.
Requests concerning Workload Data. Where your request concerns personal data contained within another User’s Workload Data, we act as a processor and are not in a position to respond directly. We will refer such requests to the relevant User, who is the controller of that data, as described in Section 6.
11.5 Marketing Communications
You may opt out of marketing communications at any time by using the unsubscribe link in any marketing email we send you or by contacting us at the details in Section 2. Opting out of marketing does not affect transactional and service communications relating to your account, deployments, billing, security, or changes to the Terms or this Policy, which we may continue to send you for as long as you hold an account.
12. Personal Data of Children
The Platform is intended for use by businesses and by individuals who are at least eighteen (18) years of age. It is not directed to children, and we do not knowingly collect personal data from any person under the age of eighteen (18). If you believe that a child has provided personal data to us, please contact the Data Protection Officer at the details in Section 2 and we will take steps to delete that data and to close any associated account.
13. Third-Party Links and Services
The Platform and our marketing websites may contain links to, or integrations with, websites, applications, and services operated by third parties, including Providers, payment processors, code repositories, and documentation sites. Those services are not under our control. This Policy does not apply to them, and we are not responsible for their content, security, or privacy practices. We encourage you to review the privacy notice of any third-party service before providing personal data to it.
14. Changes to This Policy
We may modify, amend, or update this Policy at any time to reflect changes in our practices, the Platform, or applicable law. Any changes will be effective immediately upon posting the revised Policy on the Platform, and the "Effective Date" and version number at the head of this Policy will be updated accordingly. This mirrors the approach to amendment of the Terms set out in Section 1 of the Terms.
Where a change is material and adversely affects your rights, we will take reasonable steps to bring it to your attention before it takes effect, such as by email to the address registered on your account or by prominent notice on the Platform. Your continued use of the Platform following the effective date of a revised Policy constitutes your acknowledgement of the revised Policy and, where consent is required by applicable law and you have not withdrawn it, your continued consent. It is your responsibility to review this Policy periodically.
15. Contact Us and Complaints
If you have any question, concern, request, or complaint regarding this Policy or our handling of your personal data, please contact our Data Protection Officer:
The Data Protection Officer
Beta360 Pte Ltd
UEN: 202107371K
#19-02, 20 Collyer Quay
Singapore 049319
legal@beta360.org
info@spheron.ai
Website: https://spheron.ai
We will investigate and respond to every complaint we receive. If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission of Singapore, or with the supervisory authority competent in your jurisdiction where other data protection legislation applies to our processing of your personal data.
This Policy is governed by and construed in accordance with the laws of the Republic of Singapore, and any dispute arising out of or in connection with it is subject to the dispute resolution provisions in Section 16 of the Terms.
Last updated: August 11, 2026
© 2026 Beta360 Pte Ltd. All rights reserved.