Legal
Privacy Policy
This Privacy Policy explains how Dr.Gero handles personal data when you visit drgero.ai, use app.drgero.ai, call our APIs, or communicate with us.
1. Contact and scope
Dr.Gero is provided by Higuera Ex Machina SL, a Spanish limited liability company with tax identification number ESB21770680 and registered address at Escultor Llimona 15, 08031 Barcelona, Spain ("Dr.Gero", "Higuera", "we", "us", or "our"). For privacy requests, contact drgero@higuera.ai.
For account, billing, website, support, and service administration data, we generally act as a controller. For personal data included in datasets, prompts, traces, model inputs, outputs, and other Customer Content that you submit to the Service, we generally act as your processor or service provider under our Data Processing Addendum.
2. Personal data we collect
Account and workspace data
Email address, authentication identifiers, workspace membership, roles, invitations, plan status, preferences, and account metadata such as policy acceptance timestamps.
Customer Content
Prompts, questions, inputs, outputs, expected answers, rubrics, labels, datasets, uploaded or connected files, model names, model configuration, fine-tuning runs, evaluation results, traces, logs, and metadata that you provide or generate through the Service.
Integration and credential data
Provider names, endpoint URLs, configuration, API tokens, hashed Dr.Gero API tokens, budget settings, and related metadata needed to connect to model providers, dataset providers, billing platforms, cloud infrastructure, or customer-supplied endpoints.
Usage, security, and billing data
Request counts, token and budget usage, leaderboard run status, latency, cost metrics, error logs, device and browser information, IP address, timestamps, audit-style security events, invoices, payment status, credit balance, top-up and refund records, marketplace registration and procurement data, transaction identifiers, billing address, tax information, and support communications.
3. How we use personal data
We use personal data to:
- create and secure accounts, sessions, workspaces, invitations, and API tokens;
- provide leaderboards, model comparison, inference routing, traces, datasets, and fine-tuning features;
- call integrations and model providers that you select or configure;
- measure usage, enforce limits, manage budgets, process billing, and prevent abuse;
- debug, protect, maintain, and improve the reliability and security of the Service;
- respond to support, sales, legal, and privacy requests; and
- send service, security, administrative, and billing notices.
We do not use tracking cookies, advertising cookies, or third-party advertising pixels. We do not sell personal data or share it for cross-context behavioral advertising. We do not use Customer Content to train general-purpose models for other customers unless you instruct us to do so or separately agree.
4. Legal bases
Where European or similar privacy laws apply, our legal bases may include performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, your consent where required, and your instructions when we act as a processor for Customer Content.
5. Sharing and subprocessors
We share personal data only as needed to operate the Service, comply with law, protect rights and safety, or complete a transaction you request. Recipients may include cloud hosting, database, storage, authentication, email, payment, marketplace, monitoring, security, support, model, dataset, and fine-tuning providers. When you connect a third-party provider or endpoint, you authorize us to send the relevant Customer Content and instructions to that provider.
We may disclose information if required by law, legal process, or to protect Dr.Gero, customers, users, or third parties. If Dr.Gero is involved in a merger, financing, acquisition, reorganization, or sale of assets, information may be transferred as part of that transaction subject to appropriate safeguards.
6. International transfers
The Service may be provided using infrastructure and providers in different countries. Where required, we use appropriate transfer safeguards such as contractual commitments, data processing terms, standard contractual clauses, or other lawful mechanisms.
7. Retention
We keep personal data for as long as needed to provide the Service, maintain security and audit records, comply with legal obligations, resolve disputes, enforce agreements, and support legitimate business operations. Customer Content is retained according to your settings, product functionality, plan, legal obligations, and deletion requests. Backup or security copies may persist for a limited period before being overwritten or deleted.
8. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal data, and to withdraw consent where processing is based on consent. To make a request, email drgero@higuera.ai. We may need to verify your identity and may direct requests about Customer Content to the relevant customer administrator.
9. Security
We use technical and organizational measures designed to protect personal data, including access controls, credential protection, network and hosting security, logging, backup and recovery practices, and separation between customer workspaces where supported by the Service. No system is perfectly secure, so you should protect your credentials and avoid sending data you are not authorized to process.
10. Children
The Service is not directed to children. Do not create an account or submit personal data if you are not old enough to use the Service under applicable law.
11. Changes
We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the Service, by email, or by updating this page.
12. Contact
Privacy questions and requests can be sent to drgero@higuera.ai or by post to Higuera Ex Machina SL, Escultor Llimona 15, 08031 Barcelona, Spain.