Privacy Policy
We meter what your requests cost. We do not store what they say. This policy sets out exactly what that means, where everything runs, and what you can ask us for.
1 · Who we are
Sociaro Baltic OÜ, registry code 16252815, Karu tn 14-8, Kesklinna linnaosa, 10120 Tallinn, Estonia, is the controller for personal data described in this policy. Write to dpo@sociaro.com for anything concerning data protection.
Where we process data on your behalf as part of providing the gateway, we act as your processor and the Data Processing Agreement governs that processing.
2 · What we collect
Account
Your name, work email, company and the API keys issued to you. You give us this when you ask for access.
Billing
Billing name and address, VAT number where applicable, and your payment history. Card details go directly to Stripe and never reach our systems.
Request metadata
For every call through the gateway we record what it was and what it cost: the model, the provider, the region
it was served from, token counts, price, response status, latency, timestamp, and any attribution tag you attach
yourself with an X-Attr header. This is what your invoice and your usage reports are built from.
What we do not collect
We do not store the content of your requests. Prompts, system messages, reference images, audio and the text of model responses pass through the gateway to the provider and back to you, and are not written to our database.
One narrow exception, and it contains no content: for asynchronous image and video jobs we store the pricing parameters needed to bill the job correctly once it finishes — resolution, duration, number of images, whether audio was generated. These are numbers and flags, never prompts, URLs or free text.
Generated assets
Images and video you generate are stored in object storage so you can retrieve them. They belong to you, they are kept until you delete them, and we do not use them for anything other than delivering them back to you.
Website
This site is static and sets no cookies of its own. See the Cookie notice.
3 · Why we process it
- To provide the service — routing your requests, issuing and checking keys, enforcing budgets. Legal basis: performance of a contract.
- To bill you — metering usage and producing invoices. Legal basis: performance of a contract, and legal obligation for accounting records.
- To keep the service running and secure — rate limiting, abuse detection, diagnosing failures and preventing fraud. Legal basis: legitimate interest (Article 6(1)(f)). The interest is keeping a shared service available and unabused for every customer on it, and protecting ourselves against unpaid or fraudulent use. We use metadata rather than request content for this, which is what keeps the intrusion on you minimal.
- To answer you — support and account correspondence. Legal basis: performance of a contract.
We do not sell data and we run no advertising.
Do you have to give us this data?
Account and billing details are a contractual requirement: without an email address and billing information we cannot open an account, issue a key or invoice you, so we cannot provide the service. Request metadata is generated automatically by using the service and cannot be switched off while you use it — it is what the invoice is calculated from. Nothing else is required of you.
Automated decisions
We make no decisions about you by automated means that produce legal effects or similarly significantly affect you, within the meaning of Article 22. The service does apply automatic technical limits — a request is refused when a key is over its rate limit or an account is out of budget — but these follow the thresholds you or your administrator set, and they do not evaluate you as a person.
4 · Model training
We do not train models. We do not fine-tune models on your requests, and there is no setting that turns this on, because the content never reaches storage in the first place.
What a model provider does with a request once it reaches them is governed by their own terms. Their policies are linked from each entry on the sub-processors page — read them alongside this one, particularly if you are sending anything sensitive.
5 · Where it runs
The gateway, its database and all accounting run on servers in Helsinki, Finland. Network access reaches them through Cloudflare.
Inference is a separate choice. An account can run in EU-only mode, where requests are served exclusively by EU inference endpoints, or in global mode, which opens the full catalogue including providers outside the EU. The region a request was served from is recorded and visible in your usage data.
Transfers outside the EEA
In EU-only mode, request content is not transferred outside the EEA. In global mode it may be, because the provider you address may operate elsewhere — including countries for which the European Commission has not issued an adequacy decision.
Where we transfer personal data to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses under Article 46(2)(c) as the transfer mechanism, together with the provider's own supplementary measures. Some of our sub-processors are instead covered by an adequacy decision — Stripe and Resend operate under the EU–US Data Privacy Framework. Which mechanism applies to which sub-processor is listed on the sub-processors page.
You can obtain a copy of the safeguards we rely on by writing to dpo@sociaro.com. If you need transfers excluded entirely, ask us to set your account to EU-only.
6 · Who else sees it
The third parties that process data on our behalf are listed individually, with purpose, data and their own policies, on the sub-processors page. We share data with nobody else except where the law requires it.
7 · How long we keep it
- Account records — for as long as you have an account, and a short period afterwards to close it out.
- Request metadata and invoices — retained for the statutory accounting period under Estonian law, currently seven years.
- Generated assets — until you delete them, or until your account closes.
- Support correspondence — up to two years after the ticket closes.
8 · Your rights
Under the GDPR you can ask us for a copy of your data, correct it, delete it, restrict or object to processing, and receive it in a portable form. Write to dpo@sociaro.com and we will answer within one month.
If you think we have handled your data badly, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon ↗) or to the supervisory authority where you live.
9 · Security
Keys are stored hashed, never in plain text. Traffic is encrypted in transit. Administrative interfaces are not exposed publicly, and the catalogue served to clients is filtered so that upstream endpoints and credentials are not disclosed. More detail is on the security page.
If a personal data breach affects you, we will tell you without undue delay, and notify the supervisory authority within 72 hours as required by Article 33.
10 · Children
The service is sold to businesses and is not intended for anyone under 18. We do not knowingly collect data from children.
11 · Changes
When this policy changes we update the date at the top. For changes that materially affect you, we notify account holders by email before they take effect.
Sociaro Baltic OÜ · Registry code 16252815 · Karu tn 14-8, Kesklinna linnaosa, 10120 Tallinn, Estonia