Last updated: 30 July 2026 Status: draft pending counsel and management approval Proposed effective date: on approved publication Version: 1.2-draft
This source is not approved for publication or customer reliance. The legal identity fields, provider reviews, transfer posture, retention periods, mailbox routing, and counsel decisions identified below must be completed before the status or noindex controls are removed.
This Privacy Policy explains how the entity operating under the LLM Machines name ("LLM Machines", "we", "us", or "our") processes personal data under Regulation (EU) 2016/679 (the GDPR) and applicable Croatian privacy and electronic-communications law. The exact legal entity name must be verified from the Croatian court register before publication. Other European laws, including the EU AI Act, the Data Act, and Croatian law transposing NIS2, apply only where their scope and the facts of a specific activity make them applicable.
1. Who we are and our role
Legal name: Pending verification from a Croatian court-register extract before publication Registered office: To be inserted from a verified Croatian court-register extract before publication Court register and registration number: To be inserted from the verified extract before publication Tax / VAT identifier: To be inserted where legally required before publication Website: llm-machines.com Privacy contact: privacy@llm-machines.com Security contact: security@llm-machines.com
No data protection officer is identified in this draft. Whether appointment is required remains subject to the recorded DPO applicability assessment and counsel approval.
We act in two distinct roles depending on the processing activity:
- Controller. When we collect personal data through our website, marketing channels, sales discussions, and recruitment, we determine the purposes and means of processing and act as the controller. This Policy describes that processing.
- Processor. When Customer-authorised support requires us to process personal data on behalf of a Customer, we act as a processor to the extent established by the facts and the signed Data Processing Agreement (DPA). The Customer is generally the controller of its End User and business data.
If you are an End User of a Customer's Appliance and you have questions about how your employer or service provider uses the system, please contact your employer's privacy team. If you have questions about how we support that processing as a processor, the contact details above remain valid.
2. Categories of personal data we process
2.1 Website visitors
When you visit llm-machines.com:
- the GitHub Pages hosting service receives standard request and service-usage data, which may include your IP address, requested URL, date and time, browser or user-agent information, operating system information, and referrer information where your browser sends it;
- the site reads and writes the first-party
llm-consent-v1local-storage record only to remember your site preference and the time of your choice; - if you opt in to functional assets, your browser requests Google Fonts, the Unicorn Studio runtime through jsDelivr, and Unicorn Studio media from
assets.unicorn.studio; those providers receive standard HTTP request data, including an IP address and browser headers; - the site does not currently load analytics or advertising tools; and
- the contact page creates a pre-filled draft in your own email application. The website does not submit the form payload to a relay. If you send the email, your email provider, our forwarding provider, and our final mailbox provider process the sender details, message content, and any attachments.
2.2 Prospects and sales contacts
If you contact us, attend a demo, or are introduced to us as a business contact, we may process:
- business contact data (name, role, business email, business phone, employer, country);
- a record of our interactions with you (calls held, emails exchanged, materials shared, meeting notes);
- information available from your employer, a referral, public company registers, company websites, or public professional profiles, together with the source and date where required.
2.3 Customers and Customer personnel
When a Customer engages us, we process:
- contact and contractual data for the Customer's authorised representatives, IT contacts, administrators, and billing contacts;
- time-limited support access grants when explicitly authorised by the Customer;
- support correspondence, ticket history, and any operational data needed to investigate issues.
2.4 End User data processed on behalf of Customers (processor role)
Nothing leaves your infrastructure. Within the supported Core Appliance boundary, prompts, model responses, tool arguments, tool results, request and response bodies, operational metadata, and audit records remain inside the Customer-controlled deployment. LLM Machines does not operate a hosted model-inference service for that workload. Remote support is disabled by default; any support access requires explicit, time-limited Customer authorisation and is logged. Processing during an authorised support session is governed by the signed DPA and support terms.
2.5 Recruitment
If you apply for a role with us, we process your CV, contact details, the contents of your application, interview notes, and references you provide.
2.6 Special-category data
We do not seek special-category data (Article 9 GDPR) and ask you not to provide it. If you do, we will delete it unless retention is strictly necessary and lawful.
3. Why we process personal data, and on what lawful basis
| Processing purpose | Categories of data | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Serving and securing the website | Hosting request and service-usage data | Legitimate interests (Art. 6(1)(f)) in operating, securing, and diagnosing the public website |
| Remembering your site preference | llm-consent-v1 local-storage record |
Legitimate interests (Art. 6(1)(f)); the terminal-storage exemption for storage strictly necessary to remember the service choice requested by the visitor |
| Loading optional fonts and visual assets | Standard HTTP request data sent to the selected providers | Consent (Art. 6(1)(a)), withdrawable at any time |
| Responding to email enquiries and demo requests | Contact data and message content sent by email | Pre-contractual steps at your request where you are personally party to the prospective contract (Art. 6(1)(b)); otherwise legitimate interests in B2B communication (Art. 6(1)(f)) |
| Outbound B2B contact with prospects | Business contact data, public-source data | Legitimate interests (Art. 6(1)(f)), subject to balancing test and easy opt-out |
| Negotiating and administering customer contracts | Customer contact and contractual data | Contract performance where the individual is personally party (Art. 6(1)(b)); otherwise legitimate interests in managing B2B relationships (Art. 6(1)(f)) and applicable legal obligations (Art. 6(1)(c)) |
| Providing Customer-authorised support | Support-session data (as processor) | Customer's lawful basis, instructed via the DPA |
| Invoicing, accounting, tax compliance | Customer contact, financial data | Legal obligation (Art. 6(1)(c)) |
| Security monitoring, incident response, audit logging | Technical and access data | Legitimate interests (Art. 6(1)(f)); contract; and legal obligation (Art. 6(1)(c)) only where a specific law applies |
| Recruitment | Application data | Pre-contractual steps (Art. 6(1)(b)); consent for retention beyond a closed application |
| Defending or asserting legal claims | All relevant data | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
We do not engage in profiling, scoring, or fully automated decision-making producing legal or similarly significant effects on you (Article 22 GDPR).
4. Sources of personal data
We obtain personal data:
- directly from you when you visit the website, send us an email, attend a meeting, or sign a contract;
- from your employer, where you are introduced as a representative or End User of a Customer;
- from referrals and public sources such as company websites, professional profiles, public registers, and business directories where we conduct proportionate B2B outreach.
5. Recipients and disclosure
Depending on the activity, personal data may be disclosed to:
- GitHub Pages, which hosts and delivers the public website;
- Google Fonts, jsDelivr, and Unicorn Studio services, but only when you opt in to functional assets;
- email-routing and mailbox providers when you send an email to one of our published addresses;
- processors or subprocessors approved for a defined business or Customer support activity;
- our professional advisers (legal, tax, audit) bound by professional confidentiality;
- public authorities or courts where required by applicable law;
- a successor entity in the event of a merger, acquisition, or restructuring, with prior notice to affected individuals where required.
We do not sell personal data and we do not share it with advertisers.
The current draft classification, review status, and unresolved provider facts are recorded at llm-machines.com/trust/subprocessors.
6. Customer-data subprocessors
No third party is currently approved in this draft as a customer-data subprocessor. Website and ordinary business providers are classified separately because their processing of website or business contact data does not, by itself, make them subprocessors for Customer appliance data.
Before a third party processes Customer personal data or accesses a Customer environment on our behalf, its role, security, privacy terms, transfer posture, and approval must be completed. Any customer notice and objection procedure is the one stated in the applicable signed DPA. The public register does not create a separate contractual right.
7. International transfers
Customer Appliances are deployed inside infrastructure controlled by the Customer. Within the supported Core Appliance boundary, LLM Machines-managed components do not transfer Customer workload content outside that infrastructure.
Website, email, sales, recruitment, and other business providers may process data outside the EEA. The applicable provider entity, processing locations, legal role, retention period, and transfer safeguard must be confirmed for each approved provider before this draft is published. Where Chapter V of the GDPR applies, we will use an available lawful transfer mechanism and provide information about the relevant safeguard on request.
The EU Data Act provisions concerning third-country government access are applied only where they cover the relevant service and data. This draft does not treat them as a blanket certification or transfer mechanism.
8. Retention
We keep personal data only for as long as necessary for the stated purpose, a signed contract, a legal obligation, an active legal hold, or the establishment, exercise, or defence of legal claims. The current retention schedule is a draft and must be approved and technically evidenced before exact public periods are stated.
- Website hosting and functional-provider logs: controlled in part by the relevant provider. Exact provider retention must be verified before publication.
- Site preference: the
llm-consent-v1record expires in the browser 12 months after the choice, or earlier if the visitor changes the choice or clears browser storage. - Email enquiries and prospect records: the draft internal target is 24 months after the last meaningful business interaction, subject to approval, an earlier valid deletion request, or a lawful reason to retain the record.
- Customer contact, contract, accounting, and tax records: retained for the engagement and the period required by the approved schedule and applicable Croatian law. Exact statutory periods require counsel and accounting confirmation.
- Customer operational metadata: retained inside the Customer-controlled deployment according to the supported configuration, Customer policy, and signed agreement.
- Customer workload content: not retained by LLM Machines-managed components within the supported Core Appliance boundary.
- Recruitment data: retained for the recruitment process and any separately approved talent-pool period. The current draft target for unsuccessful applications is 12 months and remains subject to approval.
- Authorised support-session data: retained or deleted as instructed by the Customer and specified in the DPA and support terms.
9. Security
We select technical and organisational measures appropriate to the risk and to the supported deployment. Current measures and contract controls include, as applicable:
- Customer-controlled deployment of the Core Appliance and local workload processing;
- remote support disabled by default and enabled only through explicit, time-limited Customer authorisation;
- access controls, authentication, logging, encryption, network segmentation, vulnerability handling, and incident procedures defined for the applicable release and engagement;
- operational records designed to exclude prompts, model responses, tool arguments, tool results, and request and response bodies; and
- supplier review before a provider receives Customer data or Customer environment access.
When we act as controller, the GDPR personal-data-breach assessment and any required supervisory-authority notice follow Articles 33 and 34. When we act as processor, we notify the controller without undue delay as required by Article 33(2) and the signed DPA. NIS2 and Croatian cybersecurity reporting clocks apply only if LLM Machines is determined to be an in-scope entity and the event meets the applicable significant-incident threshold.
Nothing in this Policy claims SOC 2 attestation or ISO certification. Any control, report, or certification claim requires the corresponding completed evidence and approval.
10. AI processing transparency (EU AI Act)
The Core Appliance exposes documented Models and Chat Completions APIs so Customers can connect their preferred applications and harnesses to Customer-selected models inside their infrastructure.
Roles under the EU AI Act depend on the facts and the statutory definitions, including who develops, places on the market, puts into service, substantially modifies, or deploys a particular AI system. A contract label does not replace that assessment. The applicable responsibilities for LLM Machines, the Customer, model providers, application providers, and other operators must be assessed for each use case.
Within the supported Core Appliance boundary, we do not use Customer prompts, outputs, or workload content to train shared models.
11. Your rights
Subject to the conditions and exceptions in the GDPR, you have the right to:
- Access: obtain confirmation as to whether we process your personal data and a copy of it (Article 15);
- Rectification: correct inaccurate or complete incomplete data (Article 16);
- Erasure: request deletion of your data where one of the grounds in Article 17 applies;
- Restriction: restrict processing in the circumstances of Article 18;
- Portability: receive your data in a structured, commonly used, machine-readable format and transmit it to another controller (Article 20);
- Object: object to processing based on legitimate interests, including direct marketing (Article 21);
- Withdraw consent: at any time, without affecting the lawfulness of prior processing (Article 7(3));
- Not to be subject to automated decisions: we do not engage in such decision-making, but you may exercise this right under Article 22 if circumstances change;
- Lodge a complaint with the supervisory authority: the Croatian Personal Data Protection Agency (AZOP, azop.hr) or the supervisory authority of your habitual residence or place of work.
To exercise any of these rights, contact us at privacy@llm-machines.com. We will respond without undue delay and within one month at the latest, with a possible extension of two further months for complex requests, of which we will inform you within the first month.
We may need to verify your identity before responding. We will not discriminate against you for exercising any right.
12. Browser storage and optional third-party assets
As of the date of this draft:
- the first-party site does not set analytics or advertising cookies;
- the site uses the first-party
llm-consent-v1local-storage record to remember whether functional assets are allowed; - the record is necessary to remember the choice and expires after 12 months;
- Google Fonts, jsDelivr, and Unicorn Studio media remain off until functional consent is given; and
- the footer preference link can be used to change the choice at any time.
The preference interface lists each active optional provider and domain. If a new analytics, marketing, or other optional provider is introduced, the code, notice, provider register, and consent version must be updated before that provider is loaded.
13. Children
Our website and Service are directed at business users. We do not knowingly process personal data of children under the age of 16. If you believe we hold such data, contact us and we will delete it.
14. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top of this Policy reflects the date of the most recent change. Material changes will be communicated to Customers in writing and prominently posted on the website. Where consent was the lawful basis for an existing processing activity, we will not extend that activity in a way materially inconsistent with the original consent without obtaining a fresh consent.
15. Contact
For any privacy-related question, request, or complaint:
LLM Machines Legal entity, registered office, and register details: pending verified company extract before publication Email: privacy@llm-machines.com Website: llm-machines.com
The email-routing and mailbox-provider review must be completed before this address is relied on as the sole public rights-request channel.
You also have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) at azop.hr, or with the supervisory authority of your habitual residence or place of work in the EEA.
Related documents
- Terms and Conditions
- Data Processing Agreement (provided to Customers on request)
- Third-party and subprocessor register: llm-machines.com/trust/subprocessors
- Trust Center: llm-machines.com/trust
Draft for business-to-business review. This document is not effective, approved for publication, or a legal opinion. Qualified Croatian counsel and an authorised management approver must complete the open fields and approval record before publication.