Privacy Notice
Effective Date: July 7, 2026
Constellation Network, Inc., a Delaware corporation, with its principal address at 2140 S Dupont Hwy, Camden, Delaware 19934 (“Constellation,” “we,” “us,” or “our”) provides this Privacy Notice to explain how we collect, use, disclose, and otherwise process personal data in connection with our websites, Gate AI, related applications, APIs, support channels, and other products and services that link to or reference this Privacy Notice (collectively, the “Services”).
This Privacy Notice is addressed to website visitors, prospective customers, customers, business contacts, and users of the Services. If we process personal data on behalf of a business customer as a processor or service provider, that customer’s privacy notice and our agreement with that customer govern that processing relationship.
1. Categories of Personal Data We Collect
We may collect the following categories of personal data:
A. Information You Provide Directly
- name, employer, job title, business email, phone number, and contact details;
- account registration details and authentication information;
- billing, payment, and transaction information;
- communications you send to us, including support requests, survey responses, and sales inquiries;
- prompts, inputs, uploaded files, settings, and related content you submit through the Services;
- outputs, feedback, and other content you choose to share with us.
B. Information We Collect Automatically
- device information, browser type, operating system, IP address, and approximate location derived from IP;
- log data, usage data, timestamps, feature interactions, and service events;
- cookie data and similar technologies used on our websites and online services;
- telemetry, performance metrics, error reports, and diagnostic data.
C. Information From Third Parties
- information from identity providers, payment processors, resellers, partners, and service providers;
- information from public sources, sanctions screening sources, and corporate data providers;
- information from customers or administrators who invite, create, or manage user accounts.
2. How We Use Personal Data
We use personal data for the following purposes:
(a) to provide, operate, secure, maintain, and improve the Services; (b) to authenticate users, manage accounts, and provide customer support; (c) to route prompts and related content to selected model providers and other service providers necessary to deliver requested functionality; (d) to detect abuse, fraud, prompt injection, malicious activity, security events, and policy violations; (e) to generate logs, alerts, analytics, and tamper-evident audit records; (f) to process transactions, subscriptions, usage-based charges, and related billing matters; (g) to communicate with you about the Services, updates, notices, offers, events, and support matters; (h) to comply with legal obligations, enforce agreements, and protect our rights, users, systems, and business; (i) to conduct internal reporting, product development, testing, debugging, and service improvement; and (j) to create aggregated or de-identified data that does not identify you, which we may use for lawful business purposes.
3. Legal Bases for Processing
Where the GDPR, UK GDPR, or Swiss FADP applies, we rely on one or more of the following legal bases:
- performance of a contract with you or your organization;
- compliance with legal obligations;
- our legitimate interests, including operating, securing, improving, and supporting the Services, preventing misuse, and protecting our business;
- your consent, where required by law; and
- other legal bases available under applicable law.
Where we process Customer Personal Data on behalf of a business customer, we do so as a processor acting on that customer’s instructions.
4. AI and Third-Party Model Providers
Gate AI acts as a gateway and security layer that may route prompts, responses, metadata, and related content to third-party model providers and other supporting service providers selected by the customer, enabled through the Services, or required to deliver the requested functionality.
These third parties may process personal data in the United States and other countries. Their processing may be governed by separate contractual and privacy terms. We encourage customers to evaluate enabled model providers carefully and to avoid submitting unnecessary personal data or sensitive information unless appropriate safeguards and legal bases are in place.
5. Tamper-Evident Audit Trail
The Services may create logs, metadata, security alerts, fingerprints, and related audit records to support integrity, abuse prevention, incident review, customer reporting, and service operations.
To support tamper-evident verification, we may anchor cryptographic fingerprints or similar integrity markers to immutable or append-only systems. These markers are intended to evidence record integrity and are designed not to contain intelligible personal data. Underlying logs and records stored in ordinary systems remain subject to applicable retention and deletion processes.
6. Cookies and Similar Technologies
We and our service providers may use cookies, SDKs, pixels, local storage, and similar technologies to operate our websites, remember preferences, analyze traffic, improve performance, and support security and marketing activities.
Where required by law, we will obtain consent before using non-essential cookies or similar technologies. You can manage cookie preferences through your browser settings, our cookie tools, or other mechanisms we make available.
7. How We Disclose Personal Data
We may disclose personal data to:
(a) affiliates and related entities; (b) vendors, contractors, advisors, and service providers that support our business and Services; (c) third-party model providers and other technology providers involved in delivering requested functionality; (d) payment processors, fraud prevention providers, and business partners; (e) professional advisors, auditors, insurers, and financing counterparties; (f) government authorities, regulators, courts, and law enforcement where required by law or reasonably necessary to protect rights or safety; (g) a buyer, investor, merger partner, or other successor in connection with a corporate transaction; and (h) other parties with your direction or consent.
8. International Data Transfers
We are based in the United States and may process personal data in the United States and other countries where we or our service providers operate.
Where applicable law requires a transfer mechanism for personal data transferred internationally, we will use an appropriate mechanism, such as the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, Swiss transfer terms, or another recognized mechanism.
9. Data Retention
We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Notice, including to provide the Services, comply with law, resolve disputes, enforce agreements, maintain security, and support legitimate business operations.
Retention periods may vary depending on the nature of the data, the role it plays in the Services, contractual requirements, legal obligations, and operational needs. Where feasible, we will delete or de-identify personal data when it is no longer reasonably necessary.
10. Your Rights and Choices
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, object to, or port certain personal data, or to withdraw consent where processing is based on consent.
If we process your personal data on behalf of a business customer, you should direct your request to that customer in the first instance. We will assist our customers as required by applicable law and our contractual commitments.
You may also have the right to complain to a supervisory authority, regulator, or data protection authority.
11. U.S. State Privacy Disclosures
Residents of certain U.S. states may have additional privacy rights under applicable state privacy laws, subject to exemptions and limitations. Depending on the law that applies, these rights may include the right to know, access, correct, delete, opt out of certain profiling or targeted advertising, and appeal a denial of a privacy request.
We do not sell personal data for money. We do not use personal data submitted through the business-facing Services for targeted advertising.
Requests may be submitted using the contact details below.
12. Children
The Services are not directed to children under 13, and we do not knowingly collect personal data from children under 13 through the Services. If you believe a child has provided us personal data, contact us so we can investigate and take appropriate action.
13. Security
We use reasonable administrative, technical, and organizational measures designed to protect personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
14. EU and UK Representative
If required by applicable law, we will appoint an EU representative and/or UK representative and identify those representatives in this Privacy Notice or in another legally sufficient public-facing notice.
- EU Representative: Not yet appointed.
- UK Representative: Not yet appointed.
15. Changes to This Privacy Notice
We may update this Privacy Notice from time to time. If we make material changes, we will post the updated notice and revise the effective date. Where required by law, we will provide additional notice or obtain consent.
16. Contact Us
If you have questions about this Privacy Notice or wish to submit a privacy request, contact:
Constellation Network, Inc. 2140 S Dupont Hwy Camden, Delaware 19934 Email: privacy@constellationgate.ai