Ce document est fourni en anglais. Si une traduction est proposée, la version anglaise fait foi.

Privacy Policy

Effective date: 6 October 2026

This Privacy Policy explains how Zelvimo OÜ, the Estonian operator of Zelvimo ("we", "us" or "our"), handles personal data when you visit our website, create an account, make a payment, contact us or use our dashboard and API (together, the "Service"). Please read it together with our Terms of Service, Cookie Policy.

We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation or "GDPR"), the Estonian Personal Data Protection Act and other applicable data protection law.

1. Who is responsible for your data

Zelvimo OÜ is an Estonian private limited company with registry code 17582420 and registered office at Harju maakond, Tallinn, Haabersti linnaosa, Paldiski mnt 199a-4, 13517, Estonia. Zelvimo is the name of the website and AI API platform we operate. Contact us about privacy at [email protected].

We are the controller for personal data used to manage our website, accounts, billing, security and communications, because we determine the purposes and means of that processing.

Where a business customer sends personal data about its users through our API and determines the purposes of that processing, we act as a processor to the extent that we handle that data on the customer's documented instructions. An Article 28 GDPR data processing agreement must be in place before such data is submitted. Contact us to arrange it. That agreement governs instructions, confidentiality, security, subprocessors, assistance with rights and incidents, deletion or return and compliance verification. This Privacy Policy does not replace it. The customer's privacy notice must explain its own processing.

2. Information we collect

CategoryWhat it may includeHow we receive it
Account and sign-in informationEmail address, account identifier, authentication information, and any name or profile details you provideFrom you or, if you choose Google sign-in, from Google
Billing and transaction informationTop-up amount and currency, resulting USD balance, exchange rate shown at checkout, payment status, transaction references, refunds and invoice detailsFrom you, our payment service provider and our own transaction records
API request metadataModel selected, usage units such as input and output tokens, charge, timestamp, API key identifier, IP address and request statusGenerated when you use the Service
Technical and security informationIP address, browser or device information, session information and security eventsFrom your device and our systems
Settings and preferencesAPI key names and spending limits, language and currency preferences, and whether you enabled request loggingFrom your account settings and use of the Service
Support communicationsMessages you send us, any documents you provide in support of a request, and our repliesFrom you and our support records
Request contentPrompts, files, parameters and model responsesFrom API requests you make or that are made using your account

An email address or a supported Google sign-in is needed to create an account. Payment details are needed to add paid balance. API request metadata is needed to deliver and bill requests. If you do not provide information needed for one of these purposes, we may be unable to provide that part of the Service. Support messages and optional profile details are voluntary.

Card payments are handled by a third-party payment service provider. We do not request or store your full payment-card number. The payment provider sends us information needed to confirm and administer the transaction. It may also perform its own fraud and payment checks under its privacy notice.

3. Prompts, responses and logging

When you select a model, we transmit the content of your request to the provider operating that model so it can generate a response. This transmission occurs whether or not request logging is enabled.

By default, we do not store the content of your prompts or responses as a request history. We store request metadata for billing, account history, security and support. If you enable request logging in your dashboard, we store the content of requests and responses so you can review it. Turning logging off stops the creation of new content logs; it does not by itself change how a Model Provider handles data it has already received.

We do not use your prompts or responses to train models. The current inference provider, DeepInfra, processes request content to return a response. Its published terms provide for no retention beyond the processing needed for the request, subject to limited exceptions for authorised support, legal obligations, fraud, security and abuse investigations. Its Terms of Service, Privacy Policy and any applicable data processing agreement describe that processing. Review the information about the selected provider before sending sensitive content. Do not submit special-category or criminal-offence data unless its processing has been expressly agreed with us and the applicable GDPR conditions and safeguards have been satisfied. A general contractual permission to use the API does not establish those conditions.

4. Why we use personal data

We use personal data to:

  • register and authenticate accounts, manage API keys and settings, forward requests to the selected Model Provider and return responses;

  • display usage, calculate charges, process top-ups and refunds, and issue receipts or invoices;

  • answer questions, investigate support requests and communicate service or account changes;

  • keep the Service secure, detect fraud or abuse, enforce our Terms and comply with applicable sanctions and other legal requirements;

  • maintain business, tax and accounting records and establish, exercise or defend legal claims; and

  • operate necessary website and account features and honour the privacy choices available on the Service.

For processing for which we are the controller, we rely on the following GDPR legal bases, according to the purpose and circumstances:

PurposeLegal basis
Creating an account, delivering requests, maintaining a prepaid balance and providing requested supportContract necessity (Article 6(1)(b)) for individual customers; legitimate interests (Article 6(1)(f)) in managing the relationship when dealing with a business customer's representatives
Tax and accounting records, and compliance with legal requirements that apply to usCompliance with a legal obligation (Article 6(1)(c))
Security, fraud prevention, abuse investigations, service administration and the defence of claimsLegitimate interests (Article 6(1)(f)) in protecting the Service, users and legal rights, subject to your interests and fundamental rights; legal obligation where a specific duty applies
Request content logging that you choose to enableContract necessity (Article 6(1)(b)) for an individual customer's requested feature, or legitimate interests (Article 6(1)(f)) in providing it to a business customer's representatives. End-user content processed on a customer's behalf is governed by that customer's lawful instructions and the data processing agreement.
Optional cookies or direct marketing, if introduced and where consent is requiredConsent (Article 6(1)(a)), which you can withdraw at any time

When we process a business customer's end-user data on its behalf, that customer is responsible for identifying the legal basis for its own use of the data and for giving any required notices to its users. Our processing for that customer is subject to the applicable data-processing arrangements.

We may use automated security and fraud signals relating to sign-ups, payments and requests. Payment providers may also perform their own checks. Where a proposed decision would be based solely on automated processing and have legal or similarly significant effects on you, we will make it only where Article 22 GDPR permits and provide the required information and safeguards. Where applicable, you may obtain human intervention, express your position and contest the decision by contacting [email protected].

5. Who receives personal data

We disclose personal data only as needed for the purposes above, to the following classes of recipients:

  • Model Providers: the provider of the model you select receives request content and the technical information needed to process it. The current inference provider is Deep Infra Inc. (DeepInfra), based in the United States, which runs the models available on the Service. The model developer and the inference provider are not necessarily the same company; using a model does not mean its developer receives your request. We will update the recipient information before routing request content to a new provider. Where a provider acts as a processor, its processing is subject to an appropriate data processing agreement; any separate controller processing must have its own lawful basis and notice.

  • Service providers: companies that provide hosting, technical infrastructure, payment processing, authentication, email delivery or customer-support services. They receive only the information needed for their role.

  • Google: if you choose Google sign-in, information is exchanged to authenticate your account.

  • Professional advisers and transaction parties: lawyers, accountants, auditors and, if relevant, a purchaser or successor to our business, subject to appropriate protections.

  • Public authorities and other parties: where disclosure is required by law, necessary to protect legal rights or needed to respond to a valid legal request.

We do not sell personal data or disclose it for cross-context behavioural advertising.

6. International transfers

Zelvimo OÜ is established in Estonia. Some recipients, including DeepInfra in the United States, may process personal data outside the European Economic Area (EEA). Processing location depends on the provider and the services used; a model's name or developer's location does not by itself identify where a request is processed.

Before transferring personal data outside the EEA, we must ensure that Chapter V GDPR requirements are met. Depending on the recipient, this means an applicable European Commission adequacy decision or appropriate safeguards, such as the Commission's standard contractual clauses, together with a transfer assessment and supplementary measures where necessary. An EU-US Data Privacy Framework adequacy decision can be used only for a recipient with a valid certification covering the relevant processing. We do not assume that a recipient is certified merely because it is based in the United States.

If the necessary protection cannot be established, we will not make the transfer. We do not treat acceptance of our Terms or ordinary use of the API as consent to an otherwise unlawful transfer, and we do not use exceptional consent derogations as the routine basis for transfers.

You may request information about the destination countries, recipients and safeguards relevant to your data, including a copy of the applicable safeguards, by emailing [email protected]. Necessary redactions may be made to protect confidential information or other people's rights.

7. How long we keep data

We keep personal data for the time needed for the purpose for which it was collected, taking account of the account's status, the need to provide the Service, security investigations, refunds, disputes and legal obligations. We then delete or anonymise it unless another lawful reason requires us to keep it. In particular:

DataRetention approach
Account information and settingsWhile the account is open, then only as long as needed to complete closure, resolve outstanding matters or meet a legal duty
Request metadataAs needed to show usage, calculate charges, investigate errors or abuse and handle disputes; no longer than necessary for those purposes
Request content when logging is offProcessed to fulfil the request; not stored by us as a request history
Request content when logging is onKept while needed for the history feature you enable; you may request deletion of existing logs. Turning logging off stops new content logs. Limited records may be retained for a specific unresolved security or legal matter where lawful
Security logs and support communicationsFor as long as needed to investigate security events, respond to you, resolve disputes or protect legal rights
Business and accounting recordsAccounting source documents and related transaction records are retained for seven years from the end of the relevant financial year under the Estonian Accounting Act; longer where required for long-term obligations, another legal duty or a specific unresolved claim

Model Providers and payment service providers have their own retention practices. Their privacy notices may apply to information they receive. Turning off request logging or closing your Zelvimo account does not itself delete records held by those independent providers.

8. How we protect data

We use technical and organisational measures designed to protect personal data against unauthorised or accidental access, processing, loss or misuse. These include controls over who can access data and protections for data transmitted over the network. We review access and security events as appropriate. No internet service can guarantee absolute security. If a security incident affects personal data, we will investigate and give notices required by applicable law.

Keep your password and API keys confidential. If you suspect a key has leaked, revoke it in your dashboard and contact [email protected] promptly, as explained in our Terms of Service.

9. Your choices and rights

You can manage API keys, spending limits and request logging in your dashboard and ask to close your account. Subject to the GDPR's conditions and exceptions, you have the following rights:

  • Access: obtain confirmation of processing, access to your personal data and a copy.

  • Rectification: correct inaccurate data and complete incomplete data.

  • Erasure: request deletion where there is no overriding lawful reason for continued retention.

  • Restriction: ask us to limit processing in the circumstances specified by law.

  • Portability: receive data you provided in a structured, commonly used, machine-readable format and request transmission to another controller where processing is automated and based on consent or a contract.

  • Objection: object, for reasons relating to your situation, to processing based on legitimate interests. We must stop unless we demonstrate overriding grounds or need the data for legal claims. You may object to direct marketing at any time.

  • Withdrawal of consent: withdraw consent at any time without affecting the lawfulness of earlier processing.

  • Automated decisions: exercise the protections described in section 4 where Article 22 GDPR applies.

Send requests to [email protected] or the registered address in section 1. If we have reasonable doubts about your identity, we may request information necessary to verify it. We respond without undue delay and within one month of receipt. For complex or numerous requests, we may extend that period by up to two further months and will explain the extension within the first month.

Requests are normally free. We may charge a reasonable administrative fee or refuse a manifestly unfounded or excessive request only where the GDPR permits, and we must justify that decision. If we cannot fulfil a request, we will explain why and tell you about complaint and court remedies.

You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at www.aki.ee/en, or to a supervisory authority in the EU/EEA country of your habitual residence, workplace or the alleged infringement. You may contact an authority without first obtaining our approval.

Where we act as a processor for a business customer, we will assist that customer with rights requests and direct you to the relevant controller where appropriate. This does not affect your rights concerning processing for which we are the controller.

10. Cookies

Cookies and similar technologies support account sign-in, security and site preferences. Our Cookie Policy explains the technologies used, their purposes and the controls available to you. If we use optional technologies that require consent under applicable law, we will ask for that consent before using them and provide a way to change your choice.

11. Children

The Service is for people aged 18 or older. We do not knowingly offer accounts to children. If you believe a child has created an account or submitted personal data, email [email protected] so we can investigate and take appropriate steps, including deletion where required and permitted by law.

12. Changes to this policy

We may update this Policy to reflect changes to the Service, recipients or legal obligations. We will publish the updated version with a new effective date. Where a change materially affects the processing of your personal data, we will give clear notice before it takes effect where required by law. We will obtain new consent where required; a policy update alone does not create consent.

13. Contact

Zelvimo OÜ
Operator of Zelvimo
Registry code: 17582420
Registered office: Harju maakond, Tallinn, Haabersti linnaosa, Paldiski mnt 199a-4, 13517, Estonia
Privacy requests and complaints: [email protected]