Privacy policy
Last updated 2026-10-05. Operated by Happi Hacking AB, org. nr 556912-2707, Sweden.
Who is responsible
Happi Hacking AB, org. nr 556912-2707, Sweden, is the controller for personal data handled by Eldrim Compute. Questions and requests: support@eldrim.ai.
What we collect, and why
- Account details: name, email address, company, and for each API key a hash of the key, the name you give it, who created it, and when it expires or was revoked. Used to provide the service and contact you about it. Legal basis: contract.
- Payment details: card payments are handled by Stripe. We receive the payer's name, billing address, VAT number and the amounts paid, not the card number. Used for billing and bookkeeping. Legal basis: contract and legal obligation.
- Usage metadata: for each API request, the time, which of the account's API keys made it (an internal id, never the key itself), model, provider, jurisdiction where it ran, token counts, price and response time. Used for billing, capacity planning and support. Legal basis: contract.
- Console sign-in: the email address and account identifier of the Google account you sign in to the console with, which Eldrim accounts it may act for, and your sign-in sessions with the times they started and were last used. Sign-ins and account changes are recorded by an internal user number, not by email address. Used to give you access to the console and to know who acted for an account. Legal basis: contract.
- Business enquiries and prospects: company and business-contact details, short conversation summaries, their source references, expected workloads, follow-up dates and draft pricing. We use these to answer enquiries and discuss potential services or partnerships. Information comes from our correspondence, introductions and relevant public company information. Access is restricted to named Eldrim administrators. You can ask us to correct or remove a record or stop contacting you.
- Signup requests: what you enter in the signup form, and the IP address it was sent from, used to answer you and to limit abuse. Legal basis: legitimate interest.
- Email we send: the recipient's address, the subject and the text of each message, and whether our mail relay accepted it. We send an invitation link to a person we invite. We tell an account's owners and its contact address when one of its API keys is created or revoked, and the contact address when someone links the account to a console sign-in, naming that person's email; a notice names the key, never the key itself. Used to deliver the message and to see whether it went out. Legal basis: contract for account notices, legitimate interest for invitations.
What we do not collect
We do not store the content of prompts or responses. They pass through our gateway to the provider that runs the model and are not written to our logs or database. The sales site sets no cookies, and none of our sites use analytics or tracking. The console at console.eldrim.net sets only the cookies sign-in needs: a short-lived one while Google signs you in, and a session cookie while you are signed in. The console does not keep your API key in your browser. Our web servers do not keep access logs with visitors' IP addresses.
Who processes data for us
- Bahnhof AB, Sweden: hosting of the website, API gateway and database.
- Stripe: payments. Stripe is also a controller for some payment data; see stripe.com/privacy.
- Google (Google Workspace): email. Console sign-in uses your own Google account; Google manages that account under its own terms and tells us its email address and identifier when you sign in.
- Compute providers: the prompt and response of each request pass through the provider that serves it, chosen within your residency policy and named in each response. During early access, models run on Happi Hacking's own hardware in Stockholm.
Stripe and Google may process data outside the EU/EEA, under the EU-US Data Privacy Framework or the EU standard contractual clauses.
How long we keep it
- Account details: while the account is open, and 12 months after it is closed.
- Billing records and the usage metadata they are based on: 7 years, as Swedish bookkeeping law requires.
- Signup requests that do not lead to an account: 12 months.
- Prospect records: kept while needed for the business discussion, with operator review of records inactive for 12 months. Operators can delete the record and its associated contacts, notes and draft prices from the active database. Existing database backups expire after 30 days.
- Console sign-in sessions: until you sign out, or at most 7 days, or 24 hours without use. A Google identity that is not a member of any Eldrim account is deleted once its sessions have ended; one that is a member is kept while it is.
- Email we send: the text is deleted once sending has ended, whether or not the message was delivered, and the record of the message 30 days after it was created.
Your rights
You may ask for access to, correction or deletion of your personal data, ask us to restrict its processing, object to it, or receive it in a portable format. Write to support@eldrim.ai. You may also complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se).