Privacy Policy

Last updated 22 July 2026 · Unit 37 OÜ, Tallinn, Estonia

This Privacy Policy explains how Unit 37 OÜ (“tokenclub”, “we”, “us”) collects, uses, discloses, retains, and protects personal data when you visit our website or use our open-model inference API and related services (the “Services”). It does not apply to content we process on behalf of API customers; that content is governed by our Data Policy and your customer agreement.

1.Personal data we collect

Depending on how you interact with us, we collect the following categories of personal data:

Children

The Services are not directed to children under 18, and we do not knowingly collect personal data from them. If we learn that we have collected personal data from a person under 18, we will delete it. If you believe a minor has provided us personal data, contact privacy@tokentoken.club.

2.How we use personal data

We process personal data to operate, secure, and improve the Services; to authenticate accounts and process payments; to provide support; to send service and (where permitted) marketing communications; to detect and prevent fraud and abuse; and to comply with legal obligations. Under the GDPR, our legal bases are contract performance, legitimate interests, consent (where required), and legal obligation.

3.Use for model training

We do not use your personal data to train models. Personal data described in this policy is not used to train, fine-tune, or improve machine-learning models. Handling of API inputs and outputs is governed separately by our Data Policy.

4.How we share data

We do not sell personal data for money. We disclose personal data only to the following categories of recipients, under appropriate contractual safeguards:

5.Data retention

We keep personal data only as long as necessary for the purposes above, then delete or de-identify it. Typical retention periods:

CategoryRetention
Account informationDuration the account is active, plus 90 days after closure
Transaction & billing history7 years (tax and accounting compliance)
Communications records3 years from last contact
Technical & log data2 years (security and analytics)
De-identified / aggregated dataRetained indefinitely

6.Your rights

EEA / UK (GDPR)

California (CCPA/CPRA)

To exercise any right, contact us at privacy@tokentoken.club. We may need to verify your identity before acting.

7.International transfers

We may transfer personal data outside the EEA. Where we do, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and, where applicable, the EU–U.S. Data Privacy Framework.

8.Security

We apply commercially reasonable technical, administrative, and organisational measures to protect personal data against loss, misuse, and unauthorised access, disclosure, alteration, or destruction, including encryption in transit and access controls on a need-to-know basis. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9.Do Not Sell or Share My Personal Information

You may opt out of any “sale” or “sharing” of your personal information by emailing privacy@tokentoken.club. We process opt-out requests within 15 business days. You may choose to opt back in at any time; after you opt out, we will wait at least 12 months before asking you to opt back in.

10.Changes & contact

We may update this Policy from time to time and will post the revised version here with a new “Last updated” date. Continued use of the Services after an update constitutes acceptance of the revised Policy.

Controller: Unit 37 OÜ (registry code 16961687), Tallinn, Estonia. Privacy contact: privacy@tokentoken.club.