Privacy Policy
This Privacy Policy explains how tokentoken OÜ (“tokentoken”, “we”, “us”) collects, uses, discloses, retains, and protects personal data when you visit our website or use our open-model inference API and related services (the “Services”). It does not apply to content we process on behalf of API customers; that content is governed by our Data Policy and your customer agreement.
1.Personal data we collect
Depending on how you interact with us, we collect the following categories of personal data:
- Account data — name, email and other contact details, login credentials, organisation, and role.
- Billing data — payment card details (via our payment processor), billing address, and transaction history.
- Content you provide — files, prompts, feedback, and support messages you send us directly.
- Technical data — IP address, browser and device type, log data, and cookie identifiers.
- Usage data — features used, pages viewed, timestamps, and approximate geolocation.
- Communications — records of messages you exchange with our team.
2.How we use personal data
We process personal data to operate, secure, and improve the Services; to authenticate accounts and process payments; to provide support; to send service and (where permitted) marketing communications; to detect and prevent fraud and abuse; and to comply with legal obligations. Under the GDPR, our legal bases are contract performance, legitimate interests, consent (where required), and legal obligation.
3.Use for model training
We do not use your personal data to train models. Personal data described in this policy is not used to train, fine-tune, or improve machine-learning models. Handling of API inputs and outputs is governed separately by our Data Policy.
4.How we share data
We do not sell personal data for money. We disclose personal data only to the following categories of recipients, under appropriate contractual safeguards:
- Infrastructure and cloud providers — hosting, GPU compute, and IT services.
- Analytics providers — to understand and improve usage.
- Payment processors — to bill and take payment.
- Cloud storage providers — to store account and operational data.
- Corporate affiliates — where they support delivery of the Services.
- Authorities — where disclosure is required by law or to protect rights and safety.
5.Data retention
We keep personal data only as long as necessary for the purposes above, then delete or de-identify it. Typical retention periods:
| Category | Retention |
|---|---|
| Account information | Duration the account is active, plus 7 years |
| Transaction & billing history | 7 years (tax and accounting compliance) |
| Communications records | 3 years from last contact |
| Technical & log data | 2 years (security and analytics) |
| De-identified / aggregated data | Retained indefinitely |
6.Your rights
EEA / UK (GDPR)
- Access, rectify, and erase your personal data.
- Restrict or object to processing, and request data portability.
- Withdraw consent at any time, without affecting prior processing.
- Lodge a complaint with your supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
California (CCPA/CPRA)
- Right to know, delete, and correct personal information.
- Right to opt out of “sale” or “sharing” of personal information.
- Right to limit use of sensitive personal information.
- Right to non-discrimination for exercising your rights.
To exercise any right, contact us at privacy@tokentoken.club. We may need to verify your identity before acting.
7.International transfers
We may transfer personal data outside the EEA. Where we do, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and, where applicable, the EU–U.S. Data Privacy Framework.
8.Security
We apply commercially reasonable technical, administrative, and organisational measures to protect personal data against loss, misuse, and unauthorised access, disclosure, alteration, or destruction, including encryption in transit and access controls on a need-to-know basis. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9.Do Not Sell or Share My Personal Information
You may opt out of any “sale” or “sharing” of your personal information by emailing privacy@tokentoken.club. We process opt-out requests within 15 business days. If you later wish to opt back in, a 12-month waiting period may apply before we ask.
10.Changes & contact
We may update this Policy from time to time and will post the revised version here with a new “Last updated” date. Continued use of the Services after an update constitutes acceptance of the revised Policy.
Controller: tokentoken OÜ, Tallinn, Estonia. Privacy contact: privacy@tokentoken.club.