llmax.ai
← Back
Legal

Data Processing Agreement

Last updated: August 10, 2026
Preliminary version published during the pre-launch phase; it may be updated before the service opens. It applies from the moment the Service becomes available.

1. Who this is for

If you use llmax.ai as an individual and only send your own data, you do not need this document: your relationship with us is covered by the Privacy Policy.

This agreement (the "DPA") applies when you use the Service as an organisation and, in doing so, send us personal data of third parties — your customers, your employees, the users of your product. In that case the law splits the roles: you decide what is processed and why, so you are the controller; we merely execute, so we are the processor (Art. 28 GDPR).

It is entered into between you (the "Customer") and HEGUZ CAPITAL, S.L., registered office at Calle Lepant 270, 08013 Barcelona, Spain, trading as llmax.ai ("we", "us" or "our", the processor). It forms part of the Terms of Use and is accepted at the same time as them; no signature is needed for it to bind us, though we will sign a copy if your procurement process requires it — write to legal@llmax.ai.

2. What we do with your data, and what we do not

We process personal data only on your documented instructions. Your instructions are, in practice, the API calls you send us: each request tells us what to process. We add nothing of our own.

Two commitments define this service and therefore this agreement:

  • We do not store the content. Prompts and responses are processed in memory and discarded when the request ends. We keep no copy, no log of content and no backup of it. What we cannot store, we cannot lose, hand over or be forced to produce.
  • We do not train on it. Your content is never used to train, fine-tune or evaluate any model, ours or anyone else's.

If we ever believed an instruction of yours infringed data protection law, we would tell you before acting on it.

3. Confidentiality

Anyone with access to personal data processed on your behalf is bound by an obligation of confidentiality that survives the end of their relationship with us. Access is granted on a need-to-know basis and is removed when it is no longer needed.

4. Security

We apply the technical and organisational measures described in Annex II, appropriate to the risk under Art. 32 GDPR. The main one is architectural rather than procedural: content is not persisted, which removes the largest category of risk instead of mitigating it.

5. Sub-processors

You give us general authorisation to use the sub-processors listed in Annex III. Each is bound by data protection obligations equivalent to those in this DPA.

Inference runs on dedicated servers we rent from several hosting providers established in the European Union, and operate ourselves: we install and run the whole inference stack, and no provider accesses your prompts or the model's responses or processes them for any purpose of its own. Because the machines and the datacenters are theirs, they are nonetheless sub-processors, and Annex III lists them as a category. We will tell you which providers we currently use if you ask — write to legal@llmax.ai — so that the right of objection below is real and not merely formal. The remaining providers in Annex III support the website, transactional email and, optionally, sign-in.

If we intend to add or replace a sub-processor, we will announce it on this page at least 30 days in advance. If you object on reasonable data protection grounds within that period, you may terminate the affected part of the Service without penalty, with a refund of the unused portion already paid.

6. Helping you meet your obligations

  • Data subject rights: since we do not store the content of your requests, there is normally nothing for us to retrieve, rectify or erase — the data lives in your systems. Where a request does concern data we hold (your account data), we will assist you within the applicable deadline.
  • Breach notification: we will inform you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the information you need for your own notification under Art. 33.
  • Impact assessments: we will provide the information within our reach so you can carry out a data protection impact assessment or a prior consultation, where the nature of your processing requires one.

7. Deletion at the end

When the Service ends, we delete the account data associated with you within 90 days, except where the law requires us to keep it (invoicing and tax records). There is no content to return or delete, because none was stored.

8. Audits

We will make available the information needed to demonstrate compliance with this DPA. You may audit us, or appoint an independent auditor bound by confidentiality, at most once a year, with reasonable prior notice, during business hours and without disrupting the service. Any extraordinary audit prompted by a security incident affecting you is not subject to that limit.

9. International transfers

Inference stays within the European Union at all times. Some auxiliary sub-processors in Annex III are companies based in the United States; where a transfer occurs, it relies on standard contractual clauses and, where applicable, the EU–US Data Privacy Framework. No such transfer involves the content of your requests.

10. Liability and duration

This DPA takes effect when you accept the Terms of Use and remains in force for as long as we process personal data on your behalf. Liability is governed by the limits in the Terms of Use, without prejudice to the rights data subjects hold directly under the GDPR.

Annex I — Details of the processing

Subject matterProvision of inference over open-source language models via an OpenAI-compatible API.
DurationFor as long as the subscription is in force.
Nature and purposeProcessing requests in memory to generate a response, and managing the subscription.
Types of dataWhatever you decide to include in your requests — we neither select nor inspect it. Plus account data: name, email, sign-in identifier and billing details.
Categories of data subjectsDetermined by you. Typically your customers, your users or your staff.
Special categoriesThe Service is not designed to process special categories of data (Art. 9) and we advise against sending them. If you do, you remain solely responsible for the lawfulness of that decision.

Annex II — Security measures

  • No persistence of content: prompts and responses are processed in memory and discarded at the end of the request. They are not written to disk, logs or backups.
  • Encryption in transit: TLS on every connection to the website and the API.
  • Authentication and access control: per-customer API keys, revocable at any time; administrative access restricted and individually attributed.
  • Isolation: separation between customers' workloads and between environments.
  • Minimisation: we record only the usage metadata needed to bill and to apply the agreed limits, never content.
  • Physical location: dedicated servers rented inside the European Union, across more than one location, running a stack we operate. We may add or move between EU locations as capacity requires; processing never leaves the Union.
  • Availability: monitoring of infrastructure and recovery procedures for the account and billing data, which is the only data that persists.

Annex III — Sub-processors

Sub-processorPurposeLocation
Hosting providers (several)Dedicated servers running the inference stack. No access to prompts or responses. The current list of providers is available on request at legal@llmax.ai.European Union
Cloudflare, Inc.Website and API hosting, DNS, sign-up databaseUnited States, with infrastructure in the EU
Scaleway SASTransactional email (account and service notices)France
GitHub, Inc.Optional sign-in, only if the user chooses itUnited States

Creem is not on this list: as merchant of record it acts as an independent controller of billing data, not as our sub-processor.

Contact

For anything concerning this agreement, to request a signed copy or to raise an objection under section 5, write to legal@llmax.ai.

llmax.ai Made in the EU · by developers for developers · © 2026 Privacy Policy Terms of Use DPA