Privacy and data boundaries

This notice explains what the LLMLab.ee website processes and how that differs from a local AI system operating in a customer-controlled environment.

Business details

Pojeng-Sidur OÜ

Registry code
17548386
VAT number
EE103005261
Registered address
Harju maakond, Saue vald, Laagri alevik, Pilliroo tn 67, 76401

Controller and contact

Pojeng-Sidur OÜ, operating LLMLab.ee, is responsible for processing website account, enquiry, order, payment, customer-communication, and security data.

Privacy and data-protection questions: gustav@llmlab.ee.

What the website collects

For accounts, we store the email address, password hash, and security records for account verification, password recovery, and sessions.

A quote or order request may include a name, email address, phone number, preferred contact method, company name, registry and VAT numbers, delivery information, and buyer-provided notes. The forms do not request patient, customer, login, or other special-category or sensitive data; do not place it in free-text fields.

For payment-related orders, we retain the selected item, price snapshot, currency, order status, and technical references for payments, refunds, or disputes. LLMLab.ee does not store full card details.

Purposes and legal bases

We use enquiry data to take pre-contract steps at your request and prepare a written quote. We use order, delivery, and support data to perform the contract.

We process payment and accounting data to meet contractual and statutory obligations. We process service-security, abuse-prevention, and legal-protection data on the basis of legitimate interests, taking the effect on users into account.

If an optional activity requires consent or a separate contractual basis, we obtain it before that activity begins.

Customer-controlled local AI systems

Using a local system does not automatically send customer files, prompts, model outputs, attachments, or knowledge-base content to LLMLab.ee. The actual data boundary depends on the agreed architecture, network connections, model-download path, logging, backups, telemetry, and support arrangement.

Remote access, telemetry, a managed service, or access to customer data is not included in a quote request by default. Those capabilities, their purpose, and how they can be disabled or ended are agreed in writing before access is enabled.

If LLMLab.ee processes personal data on a customer's behalf, the required data-processing agreement is completed before processing. It describes instructions, roles, security measures, subprocessors, locations, incident handling, retention, and deletion.

Payments and service providers

Card details are processed by Stripe. To deliver order and enquiry emails, the recipient address and delivery status are processed through an email service provider. Hosting, database, and logging providers may process technical information needed to operate the service.

For a contracted service, the providers, processing locations, and relevant safeguards are identified in procurement or data-processing materials when they are relevant to customer data.

Security and access controls

Website traffic uses encrypted transport. To protect the service, we may process IP addresses, browser user agents, session data, and pseudonymized security identifiers. Access to customer and delivery data is restricted, and administrative activity is logged.

Technical logs and email-delivery errors may contain order or enquiry references needed to diagnose failures, but they are not intended to store customer workload data.

Retention and deletion

We retain enquiry and contact data during the active discussion and afterward only as needed for the quote, support, disputes, or protection of legal rights. Order and payment records follow accounting and other statutory retention requirements.

Security and technical logs are retained only as long as needed to operate the service, investigate abuse, and protect legal rights. Justified deletion requests are reviewed alongside legal and security requirements.

When required retention ends, data is deleted or anonymized unless another lawful basis applies.

Your rights

You may request access, correction, export, or deletion of your data, or object to or restrict processing. We may verify identity before disclosing or changing personal data.

If a statutory duty, dispute, or service-security need requires us to retain certain records, we explain that in the response. You may also lodge a complaint with the Estonian Data Protection Inspectorate.