Skip to main content
WAIMAKERS
About UsCareersContact
|
Start a conversation
Back to overview

Grok (SpaceXAI)

SpaceXAI

By deploymentEU: UnconfirmedPlan-dependentRetention by productEU unconfirmed

Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.

Rolling out Grok (SpaceXAI) safely?

We assess the actual plan, settings, data flows and governance controls, then turn the findings into a practical rollout decision.

Request an assessment

Pricing / Contract Route

Business/Enterprise and API pricing varies; verify current order form

Enterprise Features

DPA with SCCs, business/API no-training, ZDR, custom retention, regional processing/data-residency options, SOC 2 Type II assurance

Last Updated

September 10, 2026

Reviewed on 10 September 2026 by WAIMAKERS B.V.

🚨 Executive summary

Grok has distinct consumer, X-platform, API and enterprise routes. SpaceXAI's current business documentation now offers controls that older “US-only/no DPA” descriptions miss: a DPA with SCCs, no-training commitments for business/API data, Zero Data Retention for eligible API use, and enterprise regional-processing/data-residency options. The exact EU region and feature coverage still need contractual confirmation.

Comparison of Grok offerings (EU focus)

Route Training and retention Practical assessment
Grok consumer service SpaceXAI may use content and interactions for training. Users can opt out; Private Chat is excluded from training. Deleted chats and Private Chat are generally deleted within 30 days, subject to stated exceptions. Do not approve for confidential organisational data.
Grok on X Governed by X's terms and privacy policy, not automatically by SpaceXAI's business terms. Assess X separately, including its training controls and regulatory proceedings.
xAI API standard retention API inputs/outputs are not used for training without explicit permission. Encrypted request/response data is retained for 30 days for audit by default. Viable only after the DPA, region, stateful features and deletion are confirmed.
xAI API with ZDR SpaceXAI says covered request/response data is not retained. ZDR is team-wide and disables incompatible stateful features. Stronger privacy route; verify activation and endpoint/feature coverage.
Enterprise No training is advertised, with custom retention and regional processing/data-residency controls. Conditional business route; name the actual region and commitment in the order form.

Is Grok GDPR-compliant?

SpaceXAI's privacy policy, effective 24 August 2026, identifies SpaceXAI LLC as the operator and states that X Corp is separate and X use is governed by X's policies. It says consumer content may be used to improve and train models and gives Europe-specific rights and representatives.[1]

Its consumer FAQ says users can opt out of training and use Private Chat, while submitted feedback can be a separate training case. It says business and enterprise data is not used for training. Deletion is generally completed within 30 days, subject to security, legal and de-identification exceptions.[2]

Consumer, business and API controls

The xAI API security page says API data is not used for training without explicit permission, is encrypted, and is retained for 30 days for audit by default. It documents team-wide ZDR and says ZDR prevents use of stateful features. SpaceXAI also reports SOC 2 Type II assurance for its enterprise platform; obtain the report and scope.[3]

The current DPA covers SpaceXAI acting as processor, incorporates the EU Standard Contractual Clauses, addresses subprocessors and contains deletion/security provisions. Contract documents and the configured service determine whether it applies.[4]

The xAI API page advertises enterprise data residency and regional-processing options, but its public wording does not itself identify an EU region for every product or feature. Record the region, backup/support access and exclusions in the order form.[5]

Regulatory evidence involving X

The Irish Data Protection Commission opened an inquiry in April 2025 into X's use of public EU/EEA posts to train Grok.[6] In February 2026 it opened a separate inquiry into X's processing connected with Grok-generated sexualised images, including images of children.[7]

These notices describe investigations into X; they are not final GDPR judgments on every SpaceXAI API or Enterprise deployment. The European Commission's DSA investigation into X is also a different legal regime from GDPR.[8]

Recommendations and EU rollout checklist

  • ✅ Separate consumer Grok, Grok on X, API and Enterprise in policy and technical controls.
  • ✅ Execute the DPA and verify SCC module, subprocessors and controller/processor roles.
  • ✅ Contract the exact EU/EEA processing and storage region, including backups and support.
  • ✅ Enable and test ZDR where stateful features are not required; otherwise define the 30-day or custom retention route.
  • ✅ Disable training and control feedback channels.
  • ✅ Restrict sensitive data and monitor outputs, abuse controls and human review.

Prices, model names, context windows and product bundles change and do not determine GDPR compliance. Confirm them in the current order form.[9]

Verdict summary

Grok/SpaceXAI merits a deployment-specific review, not a provider-wide rejection. Enterprise and API routes publish meaningful privacy controls, while the consumer and X routes have different training terms and regulatory exposure. Regional processing is advertised, but exact EU residency remains a contract question.

Disclaimer

This is an editorial procurement assessment, not a legal determination or legal advice.

Compare related tools

DeepSeekFigma Weave

Need help navigating AI?

Start a conversation
WAIMAKERS

Learn. Lead. Make.

AI Transformation Boutique · Amsterdam

Make work exciting, make businesses unstoppable.

Who We Help

View all roles & industriesCEOs & Board MembersPE & Investment ManagersCFOs & Finance LeadersInnovation DirectorsCTOs & IT LeadersCommercial Directors

What We Do

View all servicesOur ApproachLearnTailored Training ProgrammesAI Champions ProgrammeAI Champions — Executive (London)Agentic Way of WorkingE-learningLeadMake

Company

About UsResourcesContactCareersPodcast ↗

© 2026 WAIMAKERS. All rights reserved.

Privacy PolicyCookie Policy