Privacy and data boundaries

This notice explains what the LLMLab.ee website processes and how that differs from a local AI system operating in a customer-controlled environment.

Business details

Pojeng-Sidur OÜ

Registry code
17548386
VAT number
EE103005261
Registered address
Harju maakond, Saue vald, Laagri alevik, Pilliroo tn 67, 76401

Controller and contact

Pojeng-Sidur OÜ, operating LLMLab.ee, is responsible for processing website account, enquiry, order, payment, customer-communication, and security data.

Privacy and data-protection questions: gustav@llmlab.ee.

What the website collects

For accounts, we store the email address, password hash, and security records for account verification, password recovery, and sessions.

A quote or order request may include a name, email address, phone number, preferred contact method, company name, registry and VAT numbers, delivery information, and buyer-provided notes. The forms do not request patient, customer, login, or other special-category or sensitive data; do not place it in free-text fields.

For payment-related orders, we retain the selected item, price snapshot, currency, order status, and technical references for payments, refunds, or disputes. LLMLab.ee does not store full card details.

Purposes and legal bases

We use enquiry data to take pre-contract steps at your request and prepare a written quote. We use order, delivery, and support data to perform the contract.

We process payment and accounting data to meet contractual and statutory obligations. We process service-security, abuse-prevention, and legal-protection data on the basis of legitimate interests, taking the effect on users into account.

If an optional activity requires consent or a separate contractual basis, we obtain it before that activity begins.

Customer-controlled local AI systems

Using a local system does not automatically send customer files, prompts, model outputs, attachments, or knowledge-base content to LLMLab.ee. The actual data boundary depends on the agreed architecture, network connections, model-download path, logging, backups, telemetry, and support arrangement.

Remote access, telemetry, a managed service, or access to customer data is not included in a quote request by default. Those capabilities, their purpose, and how they can be disabled or ended are agreed in writing before access is enabled.

If LLMLab.ee processes personal data on a customer's behalf, the required data-processing agreement is completed before processing. It describes instructions, roles, security measures, subprocessors, locations, incident handling, retention, and deletion.

Payments and service providers

Card details are processed by Stripe. To deliver order and enquiry emails, the recipient address and delivery status are processed through an email service provider. Hosting, database, and logging providers may process technical information needed to operate the service.

For a contracted service, the providers, processing locations, and relevant safeguards are identified in procurement or data-processing materials when they are relevant to customer data.

Security and administration logs

Website traffic uses encrypted transport. To protect the service, we may process IP addresses, browser user agents, session data, pseudonymized rate-limit keys, and the time, actor, and result of administrator actions. Persistent rate-limit keys are stored as HMAC pseudonyms.

Administrative overviews show buyer contact and delivery data in a restricted or masked form by default. Technical logs and email-delivery errors may contain internal order or enquiry references, but they are not intended to store customer workload data.

Retention and deletion

We retain enquiry and contact data during the active discussion and afterward only as needed for the quote, support, disputes, or protection of legal rights. Order and payment records follow accounting and other statutory retention requirements.

Security and technical logs are kept for the period needed to operate the service, investigate abuse, and protect legal rights. Fixed automated deletion periods are not yet available for every technical record; justified deletion requests are handled manually where needed.

For closed or spam website enquiries, an authorized administrator can permanently remove the stored name, email address, topic, message, internal note, and delivery error while retaining a non-personal operational and audit record.

When required retention ends, data is deleted or anonymized unless another lawful basis applies.

Your rights

You may request access, correction, export, or deletion of your data, or object to or restrict processing. We may verify identity before disclosing or changing personal data.

If a statutory duty, dispute, or service-security need requires us to retain certain records, we explain that in the response. You may also lodge a complaint with the Estonian Data Protection Inspectorate.