1. Scope and Roles
This Privacy Policy explains how Eachlabs Inc. ("Eachlabs", "we", "us") collects, uses, discloses, and protects personal data across our websites, developer console, APIs, software development kits (SDKs), and platform services (collectively, the "Services").
Controller vs. Processor Boundary
Under applicable data protection laws (including the EU General Data Protection Regulation (GDPR), UK GDPR, Swiss Federal Act on Data Protection (FADP), Turkish Law on Protection of Personal Data (KVKK), and United States federal and state privacy laws), Eachlabs operates in two distinct legal capacities:
- ·Eachlabs as an independent Controller: Eachlabs acts as an independent Controller for Account Data, including profile and registration details, commercial billing records, developer contact communications, website cookies and analytics, and technical API telemetry. This Privacy Policy governs our processing of personal data in our capacity as an independent Controller.
- ·Eachlabs as a Processor: In accordance with Section 14 of the Terms of Service, this Privacy Policy does not govern Customer Content (including prompts, input parameters, uploaded files, and generated outputs submitted to or processed through the Services). Customer Content is processed strictly as a Processor on Customer's documented instructions and is governed exclusively by our Data Processing Addendum (DPA).
2. Information We Collect
In our capacity as a Controller, Eachlabs collects the minimum personal information necessary to deliver, bill, secure, and operate the Services:
Account and Registration Information
When you create an account, register an organization, or generate API credentials, we collect your name, email address, password hash, organization name, and role. If you authenticate through third-party identity providers (such as Google OAuth or GitHub), we receive authentication identifiers and profile details authorized by your provider settings.
Billing and Transaction Information
Payment card processing and billing transactions are handled directly by our PCI-DSS compliant payment processor, Stripe. Eachlabs stores transaction records, invoice history, credit balances, and tokenized payment identifiers, but does not store raw payment card credentials (such as full card numbers or CVV/CVC codes).
Technical Telemetry and Usage Data
When you access our websites or make calls to the API, our servers automatically record technical telemetry and operational usage data. This technical telemetry includes request counts, timestamps, execution IDs, HTTP methods, endpoint routes, status codes, latency, client IP address, and browser or device user-agent information.
Customer Content Clarification
When you submit inputs, prompts, or files for inference, they constitute Customer Content and are processed in accordance with the DPA rather than this Privacy Policy.
3. How We Use Information and Legal Bases
We process personal data only for specific, lawful purposes. Under Article 13 of the GDPR and equivalent data protection regulations, we rely on the following legal bases for processing:
- ·Providing and operating the Services: To administer your account, authenticate users, provide developer console access, execute API requests, and deliver platform functionality (Performance of Contract - GDPR Art. 6(1)(b)).
- ·Billing and accounting: To calculate usage, process payments through Stripe, maintain invoice records, comply with statutory tax and accounting obligations, and prevent payment fraud (Performance of Contract and Legal Obligation - GDPR Art. 6(1)(b), (c)).
- ·Security and platform integrity: To protect our infrastructure, detect malicious activity or unauthorized access, mitigate DDoS attacks, and investigate suspected breaches of our Acceptable Use Policy (Legitimate Interests - GDPR Art. 6(1)(f)).
- ·Service communications: To send technical notices, security alerts, operational updates, administrative messages, and customer support responses (Performance of Contract and Legitimate Interests).
- ·Marketing communications: To share news about platform capabilities, developer features, and events (Consent - GDPR Art. 6(1)(a) where required by applicable law; you may opt out at any time).
4. AI Models and Model Training
Eachlabs Model Training Commitment
Eachlabs does not use Customer Content or Personal Data, or any copy, embedding, or derivative of them, to train, retrain, fine-tune, or improve any AI or machine-learning model, whether for Eachlabs, another customer, or any third party.
Third-Party Model Providers
When Customer directs Eachlabs to route requests to third-party AI models (e.g. OpenAI, Anthropic, Google Cloud), data handling, retention, and model practices are governed by the respective independent provider's terms and privacy policies, as set forth in DPA Section 5 and Terms of Service Section 9. Eachlabs makes no representation or warranty regarding upstream provider data handling or model training.
6. Service Providers and Subprocessors
Eachlabs engages trusted third-party service providers to deliver cloud infrastructure, developer authentication, payment processing, error tracking, and operational support. To maintain an authoritative single source of truth, our complete and current list of authorized subprocessors—including corporate entities, processing activities, and locations—is published in our Subprocessor Directory at eachlabs.ai/subprocessors and Schedule 3 of our Data Processing Addendum (DPA).
Infrastructure and Operational Categories
- ·Cloud Infrastructure: Scalable compute, encrypted object storage, managed relational databases, and edge networking located in AWS us-east-1 and global CDN points of presence.
- ·Authentication and Security: Developer identity management, OAuth authentication, DDoS mitigation, and web application firewall services.
- ·Billing and Support Tooling: Secure payment processing (Stripe), developer support ticketing, on-call incident alerting, and engineering issue management.
Customer-Directed Endpoints
Third-party AI model providers accessible through the Eachlabs API operate as independent Customer-Directed Endpoints under Section 5 of the DPA and Section 9 of the Terms of Service. When Customer selects or invokes a specific model endpoint (directly or through assisted model selection, routing, or fallback features), Customer affirmatively directs and instructs Eachlabs to route the relevant prompt and input data to that independent third-party provider for inference execution. These third-party AI model providers are invoked at Customer direction and do not form part of Eachlabs core infrastructure.
7. Data Retention
Eachlabs retains personal data and technical records only for as long as necessary to fulfill the purposes described in this policy, satisfy legal, tax, and accounting obligations, and deliver the Services in accordance with Schedule 1 of the DPA:
- ·Execution Records: Execution records (including prompts, inputs, outputs, parameters, and provider response metadata) are retained in secure cloud storage in AWS us-east-1 for the lifetime of Customer's organization to maintain workflow history, debugging, and billing auditability.
- ·Stored Media and Files: Uploaded files and media stored via the Storage API follow Customer-configured retention policies (default 180 days, configurable between 60 seconds and 365 days, or non-expiring).
- ·Account and Billing Records: Account and billing records are retained for the active life of the account plus statutory tax and accounting retention periods (typically 7 years).
- ·Backups: Automated database backups are retained for 14 days; versioned object storage backups are retained for up to 30 days. Backups are isolated and not used for ordinary processing.
8. Security Measures
Eachlabs implements commercially reasonable administrative, physical, and technical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorized access.
- ·Data in Transit: Web traffic and public API requests enforce modern encryption in transit via TLS.
- ·Data at Rest: Encryption at rest where supported in cloud storage and databases.
- ·Access Control: Role-based access control (RBAC) and least privilege principles governing internal access.
- ·Vulnerability Monitoring: Ongoing vulnerability monitoring, automated edge threat filtering, and structured incident response procedures.
9. International Data Transfers
Eachlabs operates infrastructure hosted primarily in the United States (AWS us-east-1). Where personal data originating in the European Economic Area (EEA), United Kingdom, Switzerland, Türkiye, Saudi Arabia, or the UAE is transferred to Eachlabs, such transfers are governed by appropriate legal transfer mechanisms:
- ·EEA Transfers: Standard Contractual Clauses (EU SCCs - Commission Implementing Decision (EU) 2021/914) incorporated into DPA Schedule 4.
- ·United Kingdom Transfers: UK International Data Transfer Addendum (Version B.1.0) issued by the ICO.
- ·Switzerland Transfers: Swiss Federal Act on Data Protection (FADP) adaptations to the EU SCCs.
- ·Türkiye Transfers: Turkish Personal Data Protection Law (KVKK No. 6698) Standard Contracts executed under DPA Schedule 4.D.
- ·Saudi Arabia and UAE: Controller-to-processor contractual safeguards complying with Saudi PDPL and UAE Federal Decree-Law No. 45/2021.
10. Your Privacy Rights
Depending on your jurisdiction, you may hold statutory rights regarding your personal data under the GDPR, UK GDPR, Swiss FADP, Turkish KVKK, or US State Privacy Laws (e.g. CCPA/CPRA):
- ·Right to Access & Portability: Request confirmation of processing and obtain a copy of your personal data.
- ·Right to Rectification: Request correction of inaccurate or incomplete personal data.
- ·Right to Erasure: Request deletion of personal data where statutory grounds apply.
- ·Right to Restriction & Objection: Restrict or object to processing based on legitimate interests.
- ·Right to Opt Out of Sale/Sharing: Opt out of personal data sharing for cross-context behavioral advertising (CPRA).
- ·Right to Lodge a Complaint: Lodge a complaint with a competent supervisory authority in your jurisdiction.
We respond to verifiable data subject requests within 30 days (or statutory deadline). To exercise any of these rights, please contact support@eachlabs.ai. (Note: Customer Content requests should be directed to the Customer/Controller; Eachlabs will assist the Customer in fulfilling data subject requests in accordance with our DPA).
11. Children's Privacy
The Services are designed and offered exclusively to businesses, organizations, and professionals aged 18 and older. The Services are not directed to individuals under 18. Eachlabs does not knowingly collect or solicit personal data from anyone under 18. If we learn that an account has been created by or personal data collected from an individual under 18, we will take prompt steps to terminate the account and delete associated data.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, platform functionality, or operational practices. Notice of material changes will be posted on our website or communicated to registered users via email. Continued use of the Services following notice constitutes acknowledgment of the updated policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us:
| Entity | Eachlabs Inc. (Delaware Corporation) |
| Address | 8 The Green, Suite A, Dover, Delaware 19901, USA |
| support@eachlabs.ai | |
| Support & Compliance | support@eachlabs.ai |