Undergryd Privacy Policy
Last Updated: 2026-08-11
1. INTRODUCTION
1.1 This Privacy Policy explains how Tmanunet Technologies, UAB (“Undergryd”, “we”, “us” or “our”) collects, uses, processes, stores, transfers, protects and discloses personal data in connection with Undergryd and related websites, repositories, APIs, hosted interfaces, onboarding systems, hosted services, software distributions, applications and related systems operated or made available by us.
1.2 This Privacy Policy applies together with the Undergryd Terms of Service and any applicable product-specific terms.
1.3 Undergryd relies on third-party providers — for hosting, inference, and payments — which process certain data on our instructions or under their own terms. See §5.
1.4 We are committed to processing personal data in accordance with applicable privacy and data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”), UK GDPR, applicable United States privacy laws, Canadian privacy laws including PIPEDA, and other applicable legal frameworks.
1.5 “AI Systems” means artificial-intelligence systems, machine-learning systems, autonomous agents, orchestration systems, inference systems, generative systems and related computational technologies.
1.6 Tmanunet Technologies, UAB is a private limited liability company incorporated under the laws of the Republic of Lithuania. Undergryd is a product of Tmanunet Technologies, UAB, which acts as the controller for purposes of this Privacy Policy.
1.7 Our registered office is V. Nagevičiaus g. 3, 08237 Vilnius, Lithuania. Our VAT identification number is LT100015162112. You can contact us about anything in this Privacy Policy at info@undergryd.ai.
2. CATEGORIES OF DATA
2.1 We may process technical, operational and account-related information including usernames, identifiers, email addresses, wallet addresses, API identifiers, deployment metadata, telemetry information, logs, device information, IP addresses, infrastructure metadata, support communications, onboarding information and account-related data.
2.2 Our systems may additionally process prompts, operational inputs, orchestration metadata, workload metadata, AI interaction data, generated outputs and related computational information generated in connection with operation of hosted functionality or orchestration systems.
2.3 Certain systems may generate automated telemetry, diagnostics, runtime metrics, debugging information, operational logs, infrastructure availability information, security monitoring information and performance-related metadata.
2.4 While certain technical information may not inherently constitute personal data, such information may become personal data where linked to an identifiable individual, account, wallet, User or device. In such circumstances, we treat such information as personal data in accordance with applicable law.
2.5 Users may additionally provide information voluntarily through support requests, onboarding systems, repositories, community forums, communication channels or collaboration platforms.
2.6 Documents you upload. Where you upload a document, its contents are transmitted to our inference provider to be read and processed. Please do not upload documents containing personal information — yours or anyone else’s — such as names, contact details, identity documents, CVs, or health or financial records. You remain responsible for having a lawful basis for any personal data you submit about other people.
3. PURPOSES OF PROCESSING
3.1 We process personal data for purposes including operation of hosted infrastructure, onboarding, support, account administration, interoperability management, orchestration services, infrastructure diagnostics, analytics, debugging, testing, CI/CD infrastructure, security monitoring, abuse prevention, fraud prevention, legal compliance, sanctions compliance and protection of systems and Users.
3.2 We may additionally process technical and operational information to improve compatibility, reliability, security, APIs, orchestration systems, hosted infrastructure, interoperability systems and related functionality.
3.3 Personal data may additionally be processed to respond to support requests, maintain repositories, manage community engagement, protect infrastructure integrity and investigate malicious or unlawful activity.
3.4 Where applicable, we may process information in connection with compliance obligations including anti-money laundering obligations, sanctions obligations, fraud prevention obligations, dispute resolution or legal requests.
3.5 We seek to process personal data limited to what is reasonably necessary for the purposes described in this Privacy Policy.
4. LEGAL BASES
4.1 Processing may be based upon performance of contractual obligations, legitimate interests, compliance with legal obligations, cybersecurity obligations, fraud prevention, abuse prevention, infrastructure protection, operational requirements or consent where required by applicable law.
4.2 Legitimate interests pursued by us may include infrastructure protection, interoperability management, platform reliability, debugging, abuse prevention, analytics, fraud prevention, infrastructure security, system optimisation and protection of Users and services.
4.3 Operational telemetry may be processed for infrastructure security, interoperability, diagnostics, abuse prevention, reliability and operational integrity purposes based upon legitimate interests and operational necessity.
5. THIRD-PARTY PROCESSING
5.1 Undergryd relies on third parties to operate: infrastructure and hosting providers, an inference provider, the model providers reached through it, and a payment processor.
5.2 We choose those providers and instruct them. We remain the controller for the processing described in this Privacy Policy — meaning we are the party responsible to you for it, and the party you can hold to it.
5.3 Some of those providers determine aspects of their own processing under their own terms, including how long they retain data and how they secure it. We select providers on terms consistent with this Privacy Policy, and we restrict routing to exclude providers whose terms would permit training on your data (§6.5).
5.4 Operating these systems may involve international routing and processing outside the European Economic Area. See §7.
6. DATA SHARING
6.1 We may share information with infrastructure providers, hosting providers, cloud providers, support providers, analytics providers, legal advisers, auditors, regulators, payment processors, compliance providers or service providers where reasonably necessary for operation, compliance, infrastructure protection, abuse prevention or legal obligations.
6.2 We may additionally disclose information where required by applicable law, governmental request, court order, sanctions obligations, dispute resolution proceedings or regulatory requirements.
6.3 Users may voluntarily disclose information through repositories, community platforms, collaboration systems, issue trackers, forums or communication channels. Such disclosures are made at the User’s own discretion.
6.4 What happens to your prompts and uploads. To generate a response, we transmit your prompts — and the contents of any document you upload — to an inference provider, which routes them to a model provider operating the AI model that produces the response. Separately, your payment details are handled by our payment processor; we do not store card numbers ourselves.
6.5 Training. We do not permit model providers to use your data to train their models, and we configure our inference routing to exclude providers whose terms would allow it.
7. INTERNATIONAL TRANSFERS
7.1 Because of the international nature of the systems we use, information may be processed in multiple jurisdictions.
7.2 Our inference provider is established outside the European Economic Area, so prompts and the contents of uploaded documents are transferred outside the EEA to be processed. Where required by applicable law, we implement safeguards intended to support lawful international data transfers, including Standard Contractual Clauses or an adequacy decision where available.
8. USER RIGHTS
8.1 Subject to applicable law, you may have rights relating to access, rectification, erasure, restriction, objection, portability and withdrawal of consent. You also have the right to lodge a complaint with a supervisory authority. In Lithuania this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, “VDAI”), Vilnius. You may also complain to the supervisory authority in your own country of residence.
8.2 Certain rights may be limited where processing is necessary for legal compliance, infrastructure security, fraud prevention, dispute resolution or protection of infrastructure and Users.
8.3 Users located within jurisdictions providing additional privacy rights may exercise such rights in accordance with applicable law.
8.4 We do not sell personal data or share personal data for cross-context behavioural advertising purposes.
8.5 If such processing is introduced in the future, we may provide additional notices or controls where required by applicable law.
9. DATA RETENTION
9.1 We retain information for periods reasonably necessary to fulfil operational, legal, compliance, infrastructure protection, security, debugging, dispute-resolution and abuse-prevention purposes.
9.2 Retention periods may vary depending on operational requirements, legal obligations, infrastructure requirements, security considerations and the nature of the relevant systems or services.
9.3 How we decide how long to keep things:
| Data | How long we keep it |
|---|---|
| Account information | For as long as your account is open. If you ask us to close your account or to erase your data, we delete or anonymise it, except anything we must keep for billing, legal or dispute purposes |
| Prompts, generated outputs, and your workload data | For as long as your account is open; we remove them when we erase your account at your request |
| Uploaded documents | Files you upload stay in your storage until you delete them. We do not separately store the text extracted from them |
| Support communications | Until the matter is resolved, and for a reasonable period afterwards in case you contact us again about it |
| Billing and invoice records | 10 years, as required by Lithuanian accounting and tax law |
| Server and security logs | We keep them only for as long as needed for security, abuse-prevention and debugging |
Where a longer period is required by law, or where data is needed for an ongoing legal claim, dispute or investigation, we keep it for as long as that requires and no longer.
10. SECURITY
10.1 We implement reasonable technical and organisational measures intended to protect information against unauthorised access, disclosure, destruction, alteration or misuse.
10.2 Such measures may include access controls, network security controls, encryption, infrastructure monitoring, audit logging and operational security procedures.
10.3 Notwithstanding the foregoing, no distributed, internet-connected, AI-enabled or computational system can be guaranteed to be completely secure.
11. BREACH NOTIFICATION
11.1 Where required by applicable law, we shall make reasonable efforts to notify affected individuals and competent authorities regarding personal-data breaches within legally required timeframes.
11.2 Such notifications may include information concerning the nature of the incident, categories of potentially affected data and reasonable mitigation measures where appropriate.
11.3 Security concerns or suspected vulnerabilities may be reported to info@undergryd.ai.
12. CHILDREN’S DATA
12.1 Undergryd is not directed toward children under the age of 16.
12.2 We do not knowingly collect personal data from children under applicable minimum ages and may remove such information where reasonably identified.
13. COOKIES AND ANALYTICS
13.1 Our websites or hosted interfaces may use cookies, analytics technologies, session technologies or similar mechanisms intended to support authentication, security, diagnostics, analytics, interoperability or operational functionality.
13.2 Users may control certain cookie functionality through browser settings or applicable consent mechanisms.
13.3 Where required by applicable law, non-essential cookies, analytics technologies or similar tracking mechanisms shall be subject to applicable consent mechanisms.
14. ENTERPRISE PROCESSING
14.1 Certain enterprise or organisational Users may enter into separate contractual arrangements, including data-processing agreements or enterprise terms, governing particular processing activities.
14.2 Where required by applicable law or contractual arrangements, we may enter into separate data-processing agreements governing specific enterprise processing activities.
14.3 Unless expressly agreed otherwise in writing, Users remain solely responsible for evaluating suitability of our systems for regulated or enterprise environments.
15. OPEN-SOURCE LICENSING
15.1 Our software and applications may be distributed under open-source or permissive licences, including Apache License 2.0 and other applicable licences.
15.2 Additional licensing terms may apply to repositories, contributions, dependencies or software distributions.
16. CHANGES TO THIS PRIVACY POLICY
16.1 We may amend this Privacy Policy from time to time.
16.2 Updated versions become effective upon publication unless otherwise specified.
17. CONTACT
17.1 Questions, requests or notices relating to personal-data processing may be directed to info@undergryd.ai.
17.2 Nothing in this Privacy Policy limits mandatory rights available under applicable data-protection laws.