SUCH MUCH AI PRIVACY POLICY

Effective Date: 21 August 2026

This Privacy Policy explains how the legal entities operating under the Such Much AI brand collect, use, disclose, retain and otherwise process personal data when acting as controllers. It also explains the separate circumstances in which a Such Much AI entity processes personal data on behalf of a business, institutional or public-sector customer.

UAB Such Much AI, a private limited liability company incorporated in Lithuania, company code 306405204, registered address Bukčių g. 6-38, Vilnius, LT-04127, Lithuania, VAT number LT100017966319, is the principal operating company of the Such Much AI brand and the primary operator and administrator of the Such Much AI platform (the “Platform Operator”).

Depending on the relevant sales, procurement or service arrangement, SIA “Such Much AI” or Such Much AI, Inc. may act as an authorized supplier, reseller, contracting entity, invoicing entity or support provider. Section 2 explains which entity is responsible for particular processing.

We process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”), applicable Lithuanian and Latvian data-protection laws, and applicable rules on electronic communications, cookies and similar technologies.

Privacy contact: info@suchmuchai.com

1. Scope of This Policy

This Policy applies when you:

  • visit a Such Much AI website, including websites and related domains using suchmuchai.com, suchmuch.ai or rfpx.com;
  • create or use an account through a Such Much AI application or related application domain;
  • request information, a demonstration, proposal or quotation;
  • communicate with us about sales, procurement, onboarding, training, consulting, support or another business matter;
  • subscribe to marketing communications or manage communication preferences;
  • attend an event, webinar, training session or similar activity organized by us;
  • apply for a role or otherwise communicate with us about recruitment; or
  • otherwise interact with a Such Much AI entity in circumstances where that entity determines the purposes and means of processing your personal data.

This Policy describes controller-side processing. It does not replace:

  • the Such Much AI Terms of Service;
  • an applicable order form, procurement agreement, subscription confirmation or other service agreement (an “Order Form”);
  • the Data Processing Terms included in the Terms of Service or another applicable data-processing agreement (the “DPA”); or
  • a customer’s own privacy notice where personal data are contained in Customer Data and processed by us on that customer’s behalf.

The Services are intended primarily for business, professional, institutional and public-sector use. They are not directed to children as individual users.

2. Who Is the Controller?

2.1 UAB Such Much AI as Platform Operator

UAB Such Much AI is normally the controller for:

  • operation and administration of the public Such Much AI websites;
  • general website inquiries submitted directly to the Platform Operator;
  • administration and security of the shared Such Much AI platform, accounts and authentication environment, to the extent UAB Such Much AI determines the relevant purposes and means;
  • product-level security, service integrity, essential technical logs and platform administration carried out for UAB Such Much AI’s own legitimate purposes; and
  • brand-level communications or marketing campaigns organized by UAB Such Much AI.

If no other controller is identified when personal data are collected, UAB Such Much AI is the default controller for the controller-side processing described in this Policy.

2.2 Authorized Suppliers and Contracting Entities

The following entities may market, sell, resell, supply, invoice or support the Services:

  • SIA “Such Much AI”, registration number 40203701469, registered address Ropažu iela 7–8, Rīga, Latvia; and
  • Such Much AI, Inc., a corporation incorporated in the State of Delaware, United States.

The Such Much AI entity identified in an applicable Order Form, invoice, proposal, subscription confirmation or other relevant communication may act as a separate controller for personal data it processes for its own contracting, procurement, billing, taxation, customer-relationship management, support, compliance and legal purposes.

For example, if SIA “Such Much AI” is the supplier under a Latvian public-procurement agreement, SIA “Such Much AI” is normally the controller for the contact, procurement, contracting, invoicing and related business-administration data it processes for that engagement. UAB Such Much AI may separately process limited platform-account and security data as Platform Operator or may process data on SIA “Such Much AI”’s behalf, depending on the actual activity.

2.3 Separate Legal Entities

UAB Such Much AI, SIA “Such Much AI” and Such Much AI, Inc. are separate legal persons. Affiliation, common branding or technical cooperation does not by itself:

  • make every Such Much AI entity a controller of the same personal data;
  • give every Such Much AI entity access to personal data;
  • create joint controllership; or
  • make one entity responsible for another entity’s processing.

Where two entities jointly determine the purposes and means of a specific processing activity, they will act as joint controllers only for that activity and will make the essence of their respective responsibilities available as required by law.

In this Policy, the “Applicable Controller” means the Such Much AI entity that determines the purposes and means of the relevant controller-side processing. If you are unsure which entity is the Applicable Controller, contact info@suchmuchai.com. UAB Such Much AI will coordinate the request with the relevant entity.

3. Controller and Processor Roles

3.1 When We Act as Controller

A Such Much AI entity acts as controller when it determines why and how personal data are processed for its own purposes. Examples include website administration, account administration, business communications, sales, contracting, billing, taxation, recruitment, security and direct marketing.

3.2 When We Act as Processor

When a business, institution or public authority submits documents, prompts, recordings, files or other content to the Services and that content contains personal data (“Customer Data”), the customer normally acts as controller and the entity identified as the service provider in the applicable Order Form acts as processor.

Where the contracting service provider is not UAB Such Much AI and UAB Such Much AI operates or administers the platform on its behalf, UAB Such Much AI acts as an affiliated subprocessor for Customer Data. UAB Such Much AI is not a subprocessor where it is itself the contracting service provider.

Processor-side activities are governed by the applicable Order Form and DPA, not by this Policy alone. If your personal data appear in Customer Data, you should normally direct your request first to the customer that submitted the data, such as your employer, municipality, contracting authority or another organization. We will assist that customer as required by the DPA and applicable law.

3.3 No Automatic Affiliate Access

An Authorized Supplier or other affiliated entity does not receive access to Customer Data merely because it operates under the Such Much AI brand. In particular, Such Much AI, Inc. does not receive access to EEA-hosted Customer Data solely because it is affiliated with another Such Much AI entity. Any access must be necessary for an authorized purpose, permitted by the applicable agreement and protected by an appropriate transfer mechanism where required.

4. Personal Data We Collect

Depending on how you interact with us, we may process the following categories of personal data.

4.1 Identity and Business Contact Data

Name, surname, job title, organization, department, professional role, work address, work email address, telephone number and other business contact details.

4.2 Account and Organization Data

Account identifier, organization membership, user role, permissions, organization-administrator actions, invitations, account status, language preference and other account configuration information.

4.3 Authentication, Device and Network Data

Login events, IP address, approximate location derived from IP address, device type, operating system, browser type and version, session identifiers, authentication information and related access records. We do not intentionally collect your account password in readable form.

4.4 Usage, Diagnostics and Security Data

Feature use, timestamps, interaction events, system performance information, error data, audit logs, security events and information needed to detect misuse or maintain service integrity. Diagnostic records may contain limited contextual snippets where necessary to investigate an error, security event or support request, subject to access controls and minimization.

4.5 Communications and Support Data

Emails, messages, meeting notes, support tickets, feedback, survey responses, files you choose to send, and information exchanged during demonstrations, onboarding, consulting, training and support.

4.6 Commercial, Procurement and Relationship Data

Information about proposals, quotations, procurement procedures, tenders, negotiations, Order Forms, subscription plans, credits, contract contacts, purchase orders, relationship history and customer-management notes.

4.7 Billing, Payment and Tax Data

Billing contacts, invoice details, bank-transfer information, payment status, company registration information, VAT identification numbers, tax-residency information and related accounting records. Card payment details are normally processed directly by the applicable payment provider. We typically receive limited payment metadata rather than complete card details.

4.8 Marketing and Preference Data

Newsletter subscriptions, consent records, campaign interactions, event registrations, communication preferences, unsubscribe requests and suppression records maintained to respect your choices.

4.9 Cookie and Similar-Technology Data

Cookie identifiers, consent choices and information collected through essential, analytics, performance, monitoring or similar technologies as described in Section 10.

4.10 Recruitment Data

Contact details, curriculum vitae, work history, education, professional qualifications, portfolio information, interview notes, references and other information you choose to provide in connection with a role.

4.11 Customer Data

Documents, prompts, instructions, images, recordings, audio, video, transcripts, generated outputs and other content submitted by or for a customer may contain personal data. Except where we independently determine a lawful controller purpose, we process that information as a processor under the DPA.

4.12 Restricted Data

Customers and users must not submit special categories of personal data under Article 9 GDPR, criminal-offence data under Article 10 GDPR, classified information or similarly restricted information unless this is expressly authorized in writing and appropriate safeguards have been agreed.

5. How We Obtain Personal Data

We may obtain personal data:

  • directly from you, including through forms, account registration, contracts, communications, meetings, events and support requests;
  • from your organization or an organization administrator, including when an account is created or access is assigned for you;
  • automatically from your browser, device or use of the websites and Services;
  • from an Authorized Supplier or another Such Much AI entity where sharing is necessary for an identified and lawful business purpose;
  • from payment, communications, CRM, analytics, event-management and other service providers;
  • from referrals, business partners, professional networks and event organizers; and
  • from public sources, such as company websites, public procurement records and professional profiles, where collection and use are lawful and proportionate.

Where Article 14 GDPR applies because personal data were not obtained directly from you, we will provide the required information within the applicable period unless a lawful exception applies.

6. Why We Process Personal Data, Legal Bases and Retention

We process personal data only where a lawful basis applies. The categories below describe our principal controller-side purposes, legal bases and usual retention periods. A longer period may apply where necessary to comply with law, investigate security incidents, establish or defend legal claims, enforce an agreement or comply with a lawful retention hold.

6.1 Websites, Accounts and Service Operation

Purposes: provide websites and accounts; authenticate users; administer organizations, roles and permissions; deliver requested functionality; maintain essential technical operations; and respond to operational requests.

Legal bases: performance of a contract or steps requested before entering a contract under Article 6(1)(b) GDPR; and legitimate interests under Article 6(1)(f) GDPR in operating reliable B2B/B2G services.

Usual retention: for the lifetime of the relevant account or service relationship and generally up to 12 months after closure, termination or prolonged inactivity, unless a different period is required for security, legal or contractual reasons.

6.2 Sales, Procurement, Contracting and Customer-Relationship Management

Purposes: respond to inquiries; provide demonstrations, proposals and quotations; participate in procurement procedures; negotiate and administer agreements; maintain business relationships; and record relevant decisions and communications.

Legal bases: steps requested before entering a contract and performance of a contract under Article 6(1)(b) GDPR; and legitimate interests under Article 6(1)(f) GDPR in developing and managing professional relationships and documenting procurement and contracting activity.

Usual retention: for the duration of the relationship and generally up to 24 months after the last meaningful interaction where no contract is concluded. Contract records may be retained for the applicable limitation period and as required by procurement or public-record rules.

6.3 Billing, Payments, Accounting and Taxation

Purposes: issue and administer invoices; process payments; verify payment status; maintain accounting records; apply VAT and other tax rules; and comply with financial reporting obligations.

Legal bases: performance of a contract under Article 6(1)(b) GDPR and compliance with legal obligations under Article 6(1)(c) GDPR.

Usual retention: accounting, tax and supporting transaction records are generally retained for up to 10 years, or longer where required by applicable law or a lawful authority request.

6.4 Support, Onboarding, Consulting and Training

Purposes: answer questions; diagnose and resolve issues; conduct onboarding and training; deliver agreed professional services; and maintain service-quality records.

Legal bases: performance of a contract under Article 6(1)(b) GDPR and legitimate interests under Article 6(1)(f) GDPR in providing effective support and documenting service delivery.

Usual retention: for the duration of the service relationship and generally up to 24 months after the relevant request or engagement is closed, unless the content forms part of a contract record or is required for an unresolved issue.

6.5 Security, Fraud Prevention and Incident Response

Purposes: protect accounts, systems and data; detect unauthorized access, malicious activity, fraud and abuse; investigate incidents; preserve evidence; and comply with security obligations.

Legal bases: legitimate interests under Article 6(1)(f) GDPR in securing the Services and protecting users, customers and the Such Much AI entities; and compliance with legal obligations under Article 6(1)(c) GDPR where applicable.

Usual retention: routine security, audit and activity logs are generally retained for up to 180 days. Relevant records may be retained longer where needed for an active investigation, fraud prevention, dispute, legal hold or statutory obligation.

6.6 Analytics, Performance and Service Improvement

Purposes: understand website and feature use; diagnose performance; improve usability; measure adoption; plan capacity; and develop service improvements using aggregated or appropriately minimized information.

Legal bases: consent under Article 6(1)(a) GDPR for non-essential cookies or similar technologies where consent is required; and legitimate interests under Article 6(1)(f) GDPR for essential operational measurement, security and appropriately minimized service analytics that do not require consent.

Usual retention: according to the applicable tool configuration and consent settings, normally for no longer than reasonably necessary for the stated purpose. More specific periods should be presented through the cookie banner or settings where applicable.

6.7 Service Communications

Purposes: send account, security, billing, contractual, support, maintenance, feature-change and other non-promotional communications necessary for the relationship.

Legal bases: performance of a contract under Article 6(1)(b) GDPR and legitimate interests under Article 6(1)(f) GDPR in keeping customers and users informed about the Services.

Usual retention: for as long as needed to deliver and evidence the communication and, where relevant, for the related contract or legal retention period.

6.8 Marketing and Events

Purposes: send newsletters and promotional communications; manage event or webinar registrations; measure engagement; and invite relevant professional contacts to business events where permitted by law.

Legal bases: consent under Article 6(1)(a) GDPR where required; and, only where permitted by applicable electronic-marketing law, legitimate interests under Article 6(1)(f) GDPR in limited and proportionate B2B communications. You may unsubscribe or object at any time.

Usual retention: marketing subscription data are retained until consent is withdrawn or you unsubscribe. We may retain a minimal suppression record afterward so that we continue to respect your preference. Event records are generally retained for up to 24 months after the event unless a longer period is justified.

6.9 Legal Compliance, Corporate Administration and Claims

Purposes: comply with laws, court orders and authority requests; maintain corporate and compliance records; exercise or defend legal rights; conduct audits; manage insurance; and support a merger, investment, financing, restructuring or sale subject to appropriate safeguards.

Legal bases: compliance with legal obligations under Article 6(1)(c) GDPR and legitimate interests under Article 6(1)(f) GDPR in administering the business and establishing, exercising or defending legal claims.

Usual retention: for the period required by law and the applicable limitation period, plus any additional period required for an active proceeding or lawful hold.

6.10 Recruitment

Purposes: evaluate applications; communicate with candidates; conduct interviews; verify qualifications and references where lawful; and administer recruitment decisions.

Legal bases: steps requested before entering a contract under Article 6(1)(b) GDPR; legitimate interests under Article 6(1)(f) GDPR in recruiting personnel; legal obligations under Article 6(1)(c) GDPR; and consent under Article 6(1)(a) GDPR where specifically requested.

Usual retention: unsuccessful candidate records are generally retained for up to six months after the recruitment process, unless you consent to a longer talent-pool period or a longer period is justified by law or a claim. Records of successful candidates become part of the relevant personnel file.

7. Legitimate Interests

Where we rely on legitimate interests, those interests may include:

  • operating, securing and improving B2B/B2G websites and Services;
  • managing professional, customer, supplier and public-sector relationships;
  • preventing fraud, misuse and security incidents;
  • maintaining appropriate business, procurement and support records;
  • protecting legal rights and resolving disputes; and
  • conducting limited, proportionate business development permitted by law.

We consider the nature of the information, your reasonable expectations, the relationship between you and the Applicable Controller, and the potential impact on your rights. We apply safeguards such as access limitations, data minimization, retention controls and the right to object. You may request further information about a relevant legitimate-interest assessment by contacting us.

8. AI-Specific Privacy Commitments

8.1 No Model Training Without Express Opt-In

We do not use Customer Data or Outputs to train models for other customers or for general model improvement unless the relevant customer expressly opts in through a specific written agreement describing the scope, purposes and safeguards. We do not use controller-side personal data to train general-purpose models unless the personal data have first been rendered anonymous or another specific lawful basis and appropriate transparency apply. Use of aggregated and de-identified operational information does not authorize use of identifiable Customer Data for model training.

8.2 EEA Hosting by Default

Customer Data are hosted in the EEA by default unless the applicable Order Form and DPA expressly provide otherwise. The standard platform configuration uses Microsoft Azure for cloud infrastructure and, where applicable, AI services in the EEA.

8.3 External AI Services

In the standard configuration, Customer Data are not sent to an external third-party foundation-model API outside the approved Azure environment. A different arrangement applies only where it is expressly authorized in the applicable Order Form or DPA and protected by appropriate safeguards.

8.4 Human Review and Automated Decisions

Controller-side processing described in this Policy is not used to make solely automated decisions about you that produce legal or similarly significant effects. The Services may generate assistive outputs for customers, but the customer is responsible for determining its lawful use, providing human review and meeting any applicable transparency or automated-decision requirements.

9. Enterprise Process-Only Mode and Customer Data Retention

Some customers may agree in writing to a process-only or no-storage configuration. In that configuration, Customer Data are processed transiently and are not stored in the platform except to the limited extent necessary for immediate processing and authorized operational or security logging.

Without such an agreement, Customer Data and Outputs may be stored as needed to provide the Services. Unless an applicable Order Form or DPA states otherwise:

  • the customer receives a 30-day period to export Customer Data after termination;
  • Customer Data may be deleted from active systems after that export period; and
  • residual copies in backups are deleted through ordinary backup rotation within 90 days thereafter.

Mandatory retention, a lawful customer instruction or a legal hold may require limited continued storage. Retained data remain protected and are not used for another purpose merely because deletion is delayed.

10. Cookies and Similar Technologies

We use cookies and similar technologies to operate, secure and understand the websites and Services.

10.1 Essential Technologies

Essential technologies support authentication, session management, security, load balancing, fraud prevention, consent storage and other core functions. Where the law permits, they are used without consent because the requested service cannot be provided securely or effectively without them.

10.2 Analytics, Performance and Monitoring

Subject to consent requirements, we may use the following tools where enabled:

  • Google Analytics for website analytics;
  • Hotjar for user-experience analytics and session insights;
  • PostHog for product analytics; and
  • Sentry for error monitoring and technical diagnostics.

Some monitoring may be configured as essential where it is strictly necessary for security or service operation. Non-essential analytics and similar technologies are activated only in accordance with the choices presented through the cookie banner or settings where required.

10.3 Advertising Technologies

We do not use advertising cookies or pixels, such as Meta Pixel, LinkedIn Insight Tag or Google Ads tags, unless we clearly disclose the change and obtain consent where required.

10.4 Your Choices

You can accept, reject or manage non-essential technologies through the cookie banner or available settings. You may also use browser controls, although blocking essential technologies may prevent parts of the Services from functioning. Withdrawal of consent does not affect processing that occurred lawfully before withdrawal.

The cookie banner or settings may provide more specific and current information about individual technologies, providers, purposes and durations. If that information conflicts with a generic description in this Section, the more specific current cookie disclosure governs for the relevant technology.

11. Recipients and Sharing

We disclose personal data only where necessary for an identified purpose and subject to appropriate contractual, organizational and technical safeguards. Depending on the processing, recipients may include:

  • the Applicable Controller’s authorized personnel and contractors on a need-to-know basis;
  • UAB Such Much AI as Platform Operator or provider of shared platform, security and administration services;
  • SIA “Such Much AI”, Such Much AI, Inc. or another authorized supplier where required for the relevant sales, contracting, billing or support arrangement;
  • Microsoft Azure and related Microsoft entities for cloud infrastructure and, where applicable, AI services;
  • payment providers such as Stripe and relevant banks or payment institutions;
  • Attio for customer-relationship management;
  • Intercom and email or communications providers for support and service communications, where enabled and configured for the relevant use;
  • analytics, performance and monitoring providers identified in Section 10, subject to applicable consent requirements;
  • event, webinar and scheduling providers where you register or book a meeting;
  • legal, accounting, tax, audit, insurance and other professional advisers bound by confidentiality;
  • competent public authorities, courts, law-enforcement bodies or regulators where disclosure is required or legally permitted; and
  • prospective or actual investors, purchasers, successors or transaction advisers in connection with a financing, restructuring, merger or sale, subject to confidentiality and data-protection safeguards.

We do not sell personal data as a separate data asset.

This Section primarily describes recipients of controller-side data. It does not mean that every listed provider receives Customer Data. The processors and subprocessors authorized for Customer Data are determined by the applicable Order Form and DPA. In the standard platform configuration, Microsoft Azure is the external cloud and, where applicable, AI-services subprocessor. Where another Such Much AI entity is the contracting processor, UAB Such Much AI may also act as its affiliated platform subprocessor.

A current Customer Data subprocessor list is available upon request or through an applicable customer notice channel. Where required by the DPA, the contracting processor provides at least 30 days’ prior notice of a material addition or replacement where reasonably practicable, and customers may object on reasonable and substantiated data-protection grounds within the period stated in the DPA.

12. International Transfers

Customer Data are hosted in the EEA by default. Status as an affiliate, Authorized Supplier or contracting entity does not by itself authorize access from outside the EEA.

Controller-side data may be processed or accessed outside the EEA where a recipient, service provider or support function is located in another country. Where the GDPR restricts a transfer, the Applicable Controller uses a lawful transfer mechanism, which may include:

  • a European Commission adequacy decision;
  • the European Commission’s Standard Contractual Clauses together with appropriate supplementary measures;
  • binding corporate rules where applicable; or
  • a limited derogation under Article 49 GDPR only where its legal conditions are met.

You may request information about the relevant safeguard and, where legally available, a copy of it by contacting info@suchmuchai.com. Commercially sensitive or security-related information may be redacted where permitted.

13. Data Security and Breach Handling

We maintain technical and organizational measures appropriate to the nature and risk of processing. Depending on the relevant system and processing, these measures may include:

  • encryption in transit and appropriate encryption at rest;
  • individual accounts, authentication controls and role-based access;
  • least-privilege principles for administrative access;
  • logical separation of customer organizations and permissions;
  • security logging, monitoring and incident-response procedures;
  • vulnerability, patch and change-management processes;
  • backup, recovery and service-continuity measures; and
  • confidentiality and data-protection obligations for personnel and service providers.

No system can be guaranteed completely secure. You are responsible for protecting credentials, securely configuring your organization’s account and promptly reporting suspected unauthorized access.

Where the Applicable Controller becomes aware of a personal-data breach, it will investigate and take the actions required by applicable law. This may include notifying the competent supervisory authority without undue delay and, where Article 33 GDPR applies, within 72 hours after awareness, and notifying affected individuals where the breach is likely to result in a high risk to their rights and freedoms. When acting as processor, the relevant Such Much AI entity will notify the customer without undue delay in accordance with the DPA.

14. Your Data-Protection Rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  • obtain confirmation whether the Applicable Controller processes your personal data and request access to it;
  • correct inaccurate or incomplete personal data;
  • request erasure of personal data;
  • request restriction of processing;
  • receive personal data you provided in a structured, commonly used and machine-readable format and transmit it to another controller where the right to portability applies;
  • object to processing based on legitimate interests, including objecting at any time to direct marketing;
  • withdraw consent at any time where processing is based on consent, without affecting prior lawful processing;
  • receive information about safeguards used for restricted international transfers; and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where permitted by law with appropriate safeguards.

To exercise a right relating to controller-side processing, contact info@suchmuchai.com and describe the relevant interaction, account, organization or agreement. We may request information reasonably necessary to verify your identity and locate the relevant records.

We normally respond without undue delay and within one month. That period may be extended by up to two additional months where permitted because of the complexity or number of requests. Requests are normally handled free of charge, but a reasonable fee may be charged or a request may be refused where the GDPR permits this because it is manifestly unfounded or excessive.

If your personal data are contained in Customer Data submitted by a customer, contact that customer first. The customer is normally the controller and is responsible for responding to the request. We will assist the customer as required by law and the DPA.

15. Marketing Choices

You may unsubscribe from promotional email by using the link in the message or by contacting info@suchmuchai.com. We may continue to send non-promotional communications concerning an active account, contract, billing, security, support or material service changes.

If you object to direct marketing, we will stop using your personal data for that purpose. We may retain a minimal suppression record so that we do not contact you again contrary to your request.

16. Children

The websites and user accounts are intended for adult representatives of businesses, institutions and public authorities and are not directed to persons under 18. We do not knowingly invite a child to create an individual account or provide controller-side personal data directly to us.

The Services may process information concerning minors when such information is lawfully included in Customer Data by a customer. In that situation, the customer is responsible for the lawful basis, transparency and other controller obligations, and we process the information under the DPA.

17. Third-Party Websites and Social Media

Our websites and communications may link to third-party websites, platforms or services. Their privacy practices are governed by their own notices, and we are not responsible for processing they independently control.

When you interact with a Such Much AI page on a social-media platform, the relevant Such Much AI entity may receive profile and interaction information from that platform. The platform also processes information under its own privacy terms and may act as an independent or joint controller for certain activities. Review the platform’s privacy information and settings.

18. Complaints and Supervisory Authorities

Please contact us first at info@suchmuchai.com so that we can investigate and try to resolve your concern.

You also have the right to lodge a complaint with the supervisory authority in the EEA country of your habitual residence, place of work or the alleged infringement. Depending on the Applicable Controller, relevant authorities include:

Lithuania — State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI)

L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania

Website: vdai.lrv.lt

Latvia — Data State Inspectorate (Datu valsts inspekcija, DVI)

Elijas iela 17, Rīga, LV-1050, Latvia

Website: dvi.gov.lv

19. Changes to This Policy

We may update this Policy to reflect changes to the Services, entity structure, recipients, technology, law or processing practices. The current version will state its effective date.

Where a change materially affects your rights or the way we use personal data, we will provide appropriate notice through the websites, Services, email or another reasonable channel before the change takes effect, unless a shorter period is required for security, legal compliance or urgent service needs.

20. Contact Details

Privacy questions and requests may be sent to info@suchmuchai.com. Please use the subject line “Privacy Request” where practicable.

UAB Such Much AI — principal operating company and Platform Operator

Company code: 306405204

Registered address: Bukčių g. 6-38, Vilnius, LT-04127, Lithuania

VAT number: LT100017966319

Email: info@suchmuchai.com

SIA “Such Much AI” — authorized supplier and potential Contracting Entity

Registration number: 40203701469

Registered address: Ropažu iela 7–8, Rīga, Latvia

Email: info@suchmuchai.com

Such Much AI, Inc. — authorized supplier and potential Contracting Entity

State of incorporation: Delaware, United States

Notice address: the address identified in the applicable Order Form, invoice or subscription confirmation

Email: info@suchmuchai.com

If no Applicable Controller is identified in your records, UAB Such Much AI will receive the request and coordinate it with the relevant Such Much AI entity.