Privacy Policy

Last updated 22 July 2026 · tokentoken OÜ, Tallinn, Estonia

This Privacy Policy explains how tokentoken OÜ (“tokentoken”, “we”, “us”) collects, uses, discloses, retains, and protects personal data when you visit our website or use our open-model inference API and related services (the “Services”). It does not apply to content we process on behalf of API customers; that content is governed by our Data Policy and your customer agreement.

Template notice. This document is a starting template modelled on common industry practice. It is not legal advice. Have qualified counsel review and adapt it before you publish or rely on it.

1.Personal data we collect

Depending on how you interact with us, we collect the following categories of personal data:

2.How we use personal data

We process personal data to operate, secure, and improve the Services; to authenticate accounts and process payments; to provide support; to send service and (where permitted) marketing communications; to detect and prevent fraud and abuse; and to comply with legal obligations. Under the GDPR, our legal bases are contract performance, legitimate interests, consent (where required), and legal obligation.

3.Use for model training

We do not use your personal data to train models. Personal data described in this policy is not used to train, fine-tune, or improve machine-learning models. Handling of API inputs and outputs is governed separately by our Data Policy.

4.How we share data

We do not sell personal data for money. We disclose personal data only to the following categories of recipients, under appropriate contractual safeguards:

5.Data retention

We keep personal data only as long as necessary for the purposes above, then delete or de-identify it. Typical retention periods:

CategoryRetention
Account informationDuration the account is active, plus 7 years
Transaction & billing history7 years (tax and accounting compliance)
Communications records3 years from last contact
Technical & log data2 years (security and analytics)
De-identified / aggregated dataRetained indefinitely

6.Your rights

EEA / UK (GDPR)

California (CCPA/CPRA)

To exercise any right, contact us at privacy@tokentoken.club. We may need to verify your identity before acting.

7.International transfers

We may transfer personal data outside the EEA. Where we do, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and, where applicable, the EU–U.S. Data Privacy Framework.

8.Security

We apply commercially reasonable technical, administrative, and organisational measures to protect personal data against loss, misuse, and unauthorised access, disclosure, alteration, or destruction, including encryption in transit and access controls on a need-to-know basis. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9.Do Not Sell or Share My Personal Information

You may opt out of any “sale” or “sharing” of your personal information by emailing privacy@tokentoken.club. We process opt-out requests within 15 business days. If you later wish to opt back in, a 12-month waiting period may apply before we ask.

10.Changes & contact

We may update this Policy from time to time and will post the revised version here with a new “Last updated” date. Continued use of the Services after an update constitutes acceptance of the revised Policy.

Controller: tokentoken OÜ, Tallinn, Estonia. Privacy contact: privacy@tokentoken.club.