LAMX
  • Infrastructure
  • GPU Plans
  • Deploy
  • FAQ
  • Docs
Deploy Now
  • Infrastructure
  • GPU Plans
  • How It Works
  • FAQ
  • Docs
  • Deploy Now
    Legal — Data & Privacy

    Privacy Policy

    Effective: June 10, 2026  ·  Last updated: June 10, 2026
    Operational draft — pending formal legal review. Material changes will be announced by email.
    Section 01

    Who Controls Your Data

    LAMX is a service operated by Iron Mind AB (org. nr. 559551-9181), a company registered in Sweden, EU. Iron Mind AB is the data controller for all personal data processed in connection with the LAMX service.

    Contact for data protection matters: support@lamx.io

    This policy explains what personal data we collect, why we collect it, how long we retain it, who we share it with, and what rights you have. We have written it to be readable, not just legally defensible.

    Section 02

    What Data We Collect

    We collect only what is necessary to provide the service. The table below lists every category of personal data we process.

    Data Why We Collect It Legal Basis (GDPR)
    Email address Account identity, login, transactional emails (billing alerts, welcome, service notices) Contract performance
    Password hash Authentication. We store only a bcrypt hash — your plaintext password never touches disk. Contract performance
    SSH public keys Injected into provisioned instances to give you SSH access. Public keys are not secret data. Contract performance
    Billing ledger Credit purchase records, usage charges, and balance history. Required for invoicing and dispute resolution. Contract performance; legal obligation (accounting)
    Instance metadata Instance name, GPU type, status, provisioning timestamps, port assignments. Needed to operate and bill your instances. Contract performance
    Payment method data Processed entirely by Stripe. Cardholder data (card numbers, CVV) never reaches LAMX servers. We store only Stripe's customer and session identifiers. Contract performance
    IP address (login/API) Security logging — detecting unauthorized access. Retained in server logs for 30 days. Legitimate interest (security)

    What We Do Not Collect

    We do not collect or inspect the contents of your GPU workloads, training data, models, or files stored on instance volumes. We do not profile you for advertising. We do not sell your data.

    Cookies

    The LAMX marketing site sets no cookies. The platform (when logged in) may use a session cookie strictly necessary for authentication — no tracking, analytics, or advertising cookies are set. We do not use third-party analytics scripts on this site.

    Section 03

    How We Use Your Data

    We use personal data for the following purposes only:

    • Providing and operating the LAMX service (account management, instance provisioning, billing).
    • Sending transactional emails: welcome on registration, low-balance alerts, instance stop/terminate notifications, and service announcements where required.
    • Processing payments and maintaining accounting records.
    • Investigating and resolving support requests.
    • Detecting and preventing fraud or abuse of the platform.
    • Complying with legal obligations (tax records, lawful data requests).

    We do not use your data for marketing or advertising, nor share it with third parties for those purposes.

    Section 04

    Third Parties and Data Processors

    We share personal data with the following categories of third parties acting as data processors under our instruction:

    Stripe — Payment Processing

    Payments are processed by Stripe, Inc. When you purchase credits, you interact directly with Stripe's payment interface. Cardholder data is never transmitted to or stored on LAMX servers. Stripe's Privacy Policy applies to data you provide during checkout.

    Infrastructure Providers — Compute

    LAMX routes your instances to Tier-1 GPU infrastructure providers (currently RunPod; Nebius, Lambda Labs, and others planned). Your SSH public key and instance configuration are transmitted to the relevant provider to provision your hardware. Your workload data resides on hardware operated by that provider in EU datacenters.

    Providers process workload data under their own terms. LAMX selects only providers operating in the EU to preserve EU data residency. We will publish the current active provider list in our documentation.

    Mail Infrastructure

    Transactional emails (billing notices, welcome mails, service alerts) are sent from our own mail infrastructure (noreply@lamx.io) running on EU-hosted servers. Email content includes only information necessary for the specific notification (e.g., remaining balance, instance name). We do not use third-party email marketing platforms.

    No Other Sharing

    We do not sell, rent, or broker personal data to any third party. We will disclose data to law enforcement only where required by a valid legal process and, where legally permitted, will notify you of such requests.

    Section 05

    How Long We Keep Your Data

    • Active account data (email, SSH keys, instance records): retained while your account is active.
    • Billing/ledger records: retained for 7 years from the transaction date to comply with Swedish accounting law.
    • Server access logs (IP addresses): retained for 30 days, then deleted.
    • Terminated instance data (volumes, files): deleted within 24 hours of instance termination. This is permanent and irreversible — back up before terminating.
    • Closed account data: account record and non-billing personal data deleted within 30 days of closure. Billing records retained for the statutory period above.
    Section 06

    Your Rights Under GDPR

    As an EU/EEA resident, you have the following rights regarding your personal data. To exercise any of them, contact support@lamx.io. We will respond within 30 days.

    Access
    Request a copy of all personal data we hold about you.
    Rectification
    Request correction of inaccurate or incomplete personal data.
    Erasure
    Request deletion of your personal data, subject to our legal retention obligations (billing records).
    Portability
    Request your account data in a structured, machine-readable format.
    Restriction
    Request that we restrict processing of your data in certain circumstances.
    Object
    Object to processing based on legitimate interests.

    You also have the right to lodge a complaint with the Swedish supervisory authority: Integritetsskyddsmyndigheten (IMY) — imy.se.

    Section 07

    Data Processing Agreement (DPA)

    If you are an EU business using LAMX to process personal data on behalf of your customers (e.g., running inference on user data, training on datasets containing personal information), you may require a Data Processing Agreement under GDPR Article 28.

    A GDPR-compliant DPA is available upon request. Contact support@lamx.io with the subject line "DPA Request". We will respond within 5 business days.

    Section 08

    Security

    We implement technical and organizational measures appropriate to the risk:

    • Passwords stored as bcrypt hashes (plaintext never persisted).
    • All API communication over TLS 1.2+.
    • Internal services bound to localhost — no direct external exposure of the database or API layer.
    • Stripe handles all cardholder data — PCI-DSS scope does not extend to our servers.
    • Access to production systems restricted to authorized personnel.

    No system is completely immune to attack. If you discover a security issue, please report it responsibly to support@lamx.io.

    Section 09

    Data Residency and Transfers

    All LAMX compute infrastructure runs in EU datacenters. Your workload data and instance volumes do not leave the EU.

    Account data (email, billing records) is stored in our database hosted in the EU. Stripe, as a US-based company, processes payment data subject to EU-US Standard Contractual Clauses. We do not transfer personal data to non-EU countries except where Stripe's processing requires it under such SCCs.

    Section 10

    Changes to This Policy

    We may update this Privacy Policy from time to time. Material changes will be announced by email to the address on your account at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.

    Non-material changes (clarifications, restructuring without changing substance) may be made without notice.

    Data Protection Contact

    For privacy requests, DPA enquiries, or to exercise your GDPR rights:

    support@lamx.io

    Iron Mind AB, Sweden  ·  lamx.io

    LAMX
    • Docs
    • Status
    • Terms
    • Privacy
    • Contact
    © 2026 LAMX — Dedicated GPU Infrastructure