Privacy Policy
Who Controls Your Data
LAMX is a service operated by Iron Mind AB (org. nr. 559551-9181), a company registered in Sweden, EU. Iron Mind AB is the data controller for all personal data processed in connection with the LAMX service.
Contact for data protection matters: support@lamx.io
This policy explains what personal data we collect, why we collect it, how long we retain it, who we share it with, and what rights you have. We have written it to be readable, not just legally defensible.
What Data We Collect
We collect only what is necessary to provide the service. The table below lists every category of personal data we process.
| Data | Why We Collect It | Legal Basis (GDPR) |
|---|---|---|
| Email address | Account identity, login, transactional emails (billing alerts, welcome, service notices) | Contract performance |
| Password hash | Authentication. We store only a bcrypt hash — your plaintext password never touches disk. | Contract performance |
| SSH public keys | Injected into provisioned instances to give you SSH access. Public keys are not secret data. | Contract performance |
| Billing ledger | Credit purchase records, usage charges, and balance history. Required for invoicing and dispute resolution. | Contract performance; legal obligation (accounting) |
| Instance metadata | Instance name, GPU type, status, provisioning timestamps, port assignments. Needed to operate and bill your instances. | Contract performance |
| Payment method data | Processed entirely by Stripe. Cardholder data (card numbers, CVV) never reaches LAMX servers. We store only Stripe's customer and session identifiers. | Contract performance |
| IP address (login/API) | Security logging — detecting unauthorized access. Retained in server logs for 30 days. | Legitimate interest (security) |
What We Do Not Collect
We do not collect or inspect the contents of your GPU workloads, training data, models, or files stored on instance volumes. We do not profile you for advertising. We do not sell your data.
Cookies
The LAMX marketing site sets no cookies. The platform (when logged in) may use a session cookie strictly necessary for authentication — no tracking, analytics, or advertising cookies are set. We do not use third-party analytics scripts on this site.
How We Use Your Data
We use personal data for the following purposes only:
- Providing and operating the LAMX service (account management, instance provisioning, billing).
- Sending transactional emails: welcome on registration, low-balance alerts, instance stop/terminate notifications, and service announcements where required.
- Processing payments and maintaining accounting records.
- Investigating and resolving support requests.
- Detecting and preventing fraud or abuse of the platform.
- Complying with legal obligations (tax records, lawful data requests).
We do not use your data for marketing or advertising, nor share it with third parties for those purposes.
Third Parties and Data Processors
We share personal data with the following categories of third parties acting as data processors under our instruction:
Stripe — Payment Processing
Payments are processed by Stripe, Inc. When you purchase credits, you interact directly with Stripe's payment interface. Cardholder data is never transmitted to or stored on LAMX servers. Stripe's Privacy Policy applies to data you provide during checkout.
Infrastructure Providers — Compute
LAMX routes your instances to Tier-1 GPU infrastructure providers (currently RunPod; Nebius, Lambda Labs, and others planned). Your SSH public key and instance configuration are transmitted to the relevant provider to provision your hardware. Your workload data resides on hardware operated by that provider in EU datacenters.
Providers process workload data under their own terms. LAMX selects only providers operating in the EU to preserve EU data residency. We will publish the current active provider list in our documentation.
Mail Infrastructure
Transactional emails (billing notices, welcome mails, service alerts) are sent from our own mail infrastructure (noreply@lamx.io) running on EU-hosted servers. Email content includes only information necessary for the specific notification (e.g., remaining balance, instance name). We do not use third-party email marketing platforms.
No Other Sharing
We do not sell, rent, or broker personal data to any third party. We will disclose data to law enforcement only where required by a valid legal process and, where legally permitted, will notify you of such requests.
How Long We Keep Your Data
- Active account data (email, SSH keys, instance records): retained while your account is active.
- Billing/ledger records: retained for 7 years from the transaction date to comply with Swedish accounting law.
- Server access logs (IP addresses): retained for 30 days, then deleted.
- Terminated instance data (volumes, files): deleted within 24 hours of instance termination. This is permanent and irreversible — back up before terminating.
- Closed account data: account record and non-billing personal data deleted within 30 days of closure. Billing records retained for the statutory period above.
Your Rights Under GDPR
As an EU/EEA resident, you have the following rights regarding your personal data. To exercise any of them, contact support@lamx.io. We will respond within 30 days.
You also have the right to lodge a complaint with the Swedish supervisory authority: Integritetsskyddsmyndigheten (IMY) — imy.se.
Data Processing Agreement (DPA)
If you are an EU business using LAMX to process personal data on behalf of your customers (e.g., running inference on user data, training on datasets containing personal information), you may require a Data Processing Agreement under GDPR Article 28.
A GDPR-compliant DPA is available upon request. Contact support@lamx.io with the subject line "DPA Request". We will respond within 5 business days.
Security
We implement technical and organizational measures appropriate to the risk:
- Passwords stored as bcrypt hashes (plaintext never persisted).
- All API communication over TLS 1.2+.
- Internal services bound to localhost — no direct external exposure of the database or API layer.
- Stripe handles all cardholder data — PCI-DSS scope does not extend to our servers.
- Access to production systems restricted to authorized personnel.
No system is completely immune to attack. If you discover a security issue, please report it responsibly to support@lamx.io.
Data Residency and Transfers
All LAMX compute infrastructure runs in EU datacenters. Your workload data and instance volumes do not leave the EU.
Account data (email, billing records) is stored in our database hosted in the EU. Stripe, as a US-based company, processes payment data subject to EU-US Standard Contractual Clauses. We do not transfer personal data to non-EU countries except where Stripe's processing requires it under such SCCs.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced by email to the address on your account at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.
Non-material changes (clarifications, restructuring without changing substance) may be made without notice.
For privacy requests, DPA enquiries, or to exercise your GDPR rights:
Iron Mind AB, Sweden · lamx.io