Privacy Policy
Last updated: 8 September 2026
This policy explains how Paytend Europe UAB (“EURU”, “we”), a company registered in the Republic of Lithuania under company code 304730875, processes personal data in connection with the www.euru.io website and the EURU inference gateway. We are the controller for the data described below, except where we act as a processor on your behalf (see Data processing).
1. What we collect
Account and billing data
- Name, work email address, company name, role and country.
- Billing details, VAT number, and payment metadata received from our payment providers. We do not store full card numbers.
- Invoices, credit top-ups and consumption records.
Service data
- API request metadata: timestamp, model, token counts, latency, status code, key identifier and cost.
- Request and response bodies only where you have enabled logging for a key. Keys set to zero retention never have bodies written to persistent storage.
- IP address and user agent for security, abuse prevention and rate limiting.
Website data
- Standard server logs. This website sets no advertising or profiling cookies and does not embed third-party trackers.
- Messages you send through the contact form open in your own email client; the website itself stores nothing.
2. Why we process it, and on what basis
- To provide the Services — performance of a contract (GDPR Art. 6(1)(b)).
- To meter, bill and account — contract and legal obligation (Art. 6(1)(b), (c)).
- To secure the platform and prevent abuse — legitimate interests (Art. 6(1)(f)).
- To comply with tax, accounting and sanctions obligations — legal obligation (Art. 6(1)(c)).
- To send service and product email — legitimate interests, or consent where required. You can opt out of non-essential email at any time.
We do not sell personal data, and we do not use your prompts, completions or business data to train any model.
3. Sharing and sub-processors
To deliver a request we transmit its content to the model provider you selected. Providers act as our sub-processors under terms that prohibit training on your content where such terms are available. We also use infrastructure, payment and communication vendors. The current sub-processor list, naming each entity, its purpose and its location, is available on request from Ben@euru.io and is provided as an annex to the data processing agreement.
We disclose data to public authorities only where legally required, and we will notify you unless prohibited from doing so.
4. International transfers
Some model providers operate outside the European Economic Area. Where we transfer personal data outside the EEA we rely on an adequacy decision, or on the European Commission's Standard Contractual Clauses together with a transfer impact assessment. Keys can be restricted to providers serving from EU regions where you require EU-only processing.
5. Retention
- Account records: for the life of the account and 12 months after closure.
- Invoices and accounting records: 10 years, as required by Lithuanian law.
- Request metadata used for billing: 24 months.
- Request and response bodies, where logging is enabled: a retention window you choose between 0 and 30 days.
- Security logs: up to 12 months.
6. Security
Data is encrypted in transit with TLS and at rest. Access to production systems is limited to personnel who need it, protected by multi-factor authentication and logged. API keys are stored hashed. We maintain an incident response process and will notify affected customers and, where required, the supervisory authority without undue delay.
7. Your rights
Under the GDPR you may request access to your personal data, its rectification or erasure, restriction of or objection to processing, and portability. Where processing rests on consent you may withdraw it at any time. Write to Ben@euru.io; we respond within one month. You may also lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija) or with your local supervisory authority.
8. Data processing (customer content)
Where you send personal data inside prompts, you are the controller and EURU is your processor. We process that content only on your documented instructions — which is to say, to route and complete the request you submitted, and to meter it. A data processing agreement incorporating GDPR Art. 28 terms, the sub-processor annex and the Standard Contractual Clauses is available on request and can be signed before you go to production.
Under that agreement we commit to:
- process customer content only for the purpose of delivering the Services;
- impose confidentiality obligations on personnel with access;
- apply the technical and organisational measures described in section 6;
- give notice of intended sub-processor changes and allow reasonable objection;
- assist with data subject requests, impact assessments and breach notification;
- delete or return customer content on termination.
9. Children
The Services are intended for business use and are not directed to children under 18.
10. Changes
We may update this policy. Material changes are announced by email or in the dashboard before they take effect, and the date at the top of this page is revised.
11. Contact
Paytend Europe UAB, company code 304730875,
J. Savickio g. 4-7, LT-01108 Vilnius, Lithuania
Data protection enquiries: Ben@euru.io.