1. Introduction
This AI Gateway Privacy Policy ("Gateway Privacy Policy") describes how BroadComms ("we", "us", "our") collects, uses, and shares data when you use the BroadComms AI Gateway ("Gateway"). This policy is a supplement to the BroadComms general Privacy Policy. In the event of conflict, this Gateway Privacy Policy prevails for Gateway-related data processing.
We are committed to protecting your privacy and complying with applicable data protection laws, including the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and where applicable, the EU General Data Protection Regulation (GDPR).
2. Data We Collect
When you use the Gateway, we collect the following categories of data:
2.1 API Call Data
- Prompt content: The text or messages you send to AI models via the Gateway.
- Completion content: The responses returned by AI models (stored for up to 90 days).
- Model used: The public model identifier (e.g.
kimi-3). - Token counts: Input and output token usage per call for billing purposes.
- Cost: The calculated cost of each call at our flat per-model price.
- Timestamps: Date and time of each API call (UTC).
- API key identifier: Which of your API keys was used.
2.2 Account & Billing Data
- Account credentials, email address, and organisation membership.
- Subscription plan, billing history, and credit ledger.
- Referral code usage and referral credit unlock status.
2.3 Technical Data
- IP address of API requests (retained for 90 days for security and abuse detection).
- HTTP headers and request metadata for routing and debugging.
- Redis rate-limiting counters associated with your API keys.
3. How We Use Your Data
We use your Gateway data for the following purposes:
- Service delivery: Routing your API calls to inference providers and returning responses.
- Billing: Calculating and charging your account for usage based on our flat per-model prices.
- Dashboard & analytics: Displaying your usage, costs, and token counts in the BroadComms dashboard.
- Rate limiting: Enforcing per-key and per-plan rate limits via Redis.
- Security & fraud prevention: Detecting and blocking abuse, credential stuffing, or API key misuse.
- Service improvement: Aggregated and anonymised usage analytics to improve routing, model availability, and pricing. We do not use the content of your prompts or completions for model training.
- Compliance: Retaining data as required by law (e.g. billing records for tax purposes).
5. Data Retention
We retain different categories of Gateway data for different periods:
| Data Type | Retention Period | Notes |
|---|---|---|
| API call logs (prompts, completions, tokens, cost) | 90 days | Used for dashboard display, billing disputes, and abuse detection. Automatically purged after 90 days. |
| IP addresses | 90 days | Retained for security and abuse detection. |
| Billing records | 7 years | Required for tax and financial compliance. |
| Account data | Retained while active + 30 days | Deleted within 30 days of account deletion request, subject to legal hold. |
| Managed Keys (encrypted) | Until deleted by user | Encrypted at rest; deleted within 30 days of user request. |
For AI chat assistant conversations (separate from Gateway API calls), retention is governed by the general Privacy Policy — see the Chat Messages section.
6. Data Security
- Encryption in transit: All API calls are served over HTTPS/TLS 1.2+.
- Encryption at rest: Managed Keys (BYOK) are encrypted using Fernet (AES-128-CBC) with a key managed by BroadComms.
- Access controls: Internal access to API logs and billing data is restricted to authorised personnel on a least-privilege basis.
- Provider data: We cannot guarantee the security practices of third-party inference providers. Their data handling is governed by their own policies.
- Data breaches: We will notify affected users and relevant authorities of any material data breach in accordance with applicable law.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of the personal data we hold about you (including API call logs).
- Correction: Request correction of inaccurate personal data.
- Deletion: Request deletion of your account and associated data, subject to billing record retention requirements.
- Portability: Request your data in a machine-readable format.
- Object: Object to certain processing activities, such as aggregated analytics use.
- Withdraw consent: Where processing is based on consent, withdraw that consent at any time.
To exercise any of these rights, contact us at privacy@broadcomms.net. We will respond within the timeframes required by applicable law.
8. Managed Keys (BYOK)
When you register a Managed Key (your own provider API key) in the Gateway, we store:
- The key name and base URL you provide (for display and routing purposes).
- The encrypted API key value — we store only the encrypted form; the plaintext is never persisted.
- Usage logs for requests routed through your Managed Key (for your dashboard analytics only).
We do not use your Managed Key data for any purpose other than routing your API requests and providing your dashboard analytics. The third-party provider receiving your requests will handle your data under their own privacy policy.
10. Changes to This Policy
We may update this Gateway Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated policy on this page with an updated "Last updated" date. For material changes, we will provide prominent notice (e.g. via email or a banner in the dashboard) at least 30 days before the change takes effect.
11. Contact
For questions or requests regarding this Gateway Privacy Policy or our data handling practices, contact our Privacy Officer:
Email: privacy@broadcomms.netBroadComms Privacy Officer
broadcomms.net