Effective Date: 21 August 2026
This Privacy Policy explains how the legal entities operating under the Such Much AI brand collect, use, disclose, retain and otherwise process personal data when acting as controllers. It also explains the separate circumstances in which a Such Much AI entity processes personal data on behalf of a business, institutional or public-sector customer.
UAB Such Much AI, a private limited liability company incorporated in Lithuania, company code 306405204, registered address Bukčių g. 6-38, Vilnius, LT-04127, Lithuania, VAT number LT100017966319, is the principal operating company of the Such Much AI brand and the primary operator and administrator of the Such Much AI platform (the “Platform Operator”).
Depending on the relevant sales, procurement or service arrangement, SIA “Such Much AI” or Such Much AI, Inc. may act as an authorized supplier, reseller, contracting entity, invoicing entity or support provider. Section 2 explains which entity is responsible for particular processing.
We process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”), applicable Lithuanian and Latvian data-protection laws, and applicable rules on electronic communications, cookies and similar technologies.
Privacy contact: info@suchmuchai.com
This Policy applies when you:
This Policy describes controller-side processing. It does not replace:
The Services are intended primarily for business, professional, institutional and public-sector use. They are not directed to children as individual users.
UAB Such Much AI is normally the controller for:
If no other controller is identified when personal data are collected, UAB Such Much AI is the default controller for the controller-side processing described in this Policy.
The following entities may market, sell, resell, supply, invoice or support the Services:
The Such Much AI entity identified in an applicable Order Form, invoice, proposal, subscription confirmation or other relevant communication may act as a separate controller for personal data it processes for its own contracting, procurement, billing, taxation, customer-relationship management, support, compliance and legal purposes.
For example, if SIA “Such Much AI” is the supplier under a Latvian public-procurement agreement, SIA “Such Much AI” is normally the controller for the contact, procurement, contracting, invoicing and related business-administration data it processes for that engagement. UAB Such Much AI may separately process limited platform-account and security data as Platform Operator or may process data on SIA “Such Much AI”’s behalf, depending on the actual activity.
UAB Such Much AI, SIA “Such Much AI” and Such Much AI, Inc. are separate legal persons. Affiliation, common branding or technical cooperation does not by itself:
Where two entities jointly determine the purposes and means of a specific processing activity, they will act as joint controllers only for that activity and will make the essence of their respective responsibilities available as required by law.
In this Policy, the “Applicable Controller” means the Such Much AI entity that determines the purposes and means of the relevant controller-side processing. If you are unsure which entity is the Applicable Controller, contact info@suchmuchai.com. UAB Such Much AI will coordinate the request with the relevant entity.
A Such Much AI entity acts as controller when it determines why and how personal data are processed for its own purposes. Examples include website administration, account administration, business communications, sales, contracting, billing, taxation, recruitment, security and direct marketing.
When a business, institution or public authority submits documents, prompts, recordings, files or other content to the Services and that content contains personal data (“Customer Data”), the customer normally acts as controller and the entity identified as the service provider in the applicable Order Form acts as processor.
Where the contracting service provider is not UAB Such Much AI and UAB Such Much AI operates or administers the platform on its behalf, UAB Such Much AI acts as an affiliated subprocessor for Customer Data. UAB Such Much AI is not a subprocessor where it is itself the contracting service provider.
Processor-side activities are governed by the applicable Order Form and DPA, not by this Policy alone. If your personal data appear in Customer Data, you should normally direct your request first to the customer that submitted the data, such as your employer, municipality, contracting authority or another organization. We will assist that customer as required by the DPA and applicable law.
An Authorized Supplier or other affiliated entity does not receive access to Customer Data merely because it operates under the Such Much AI brand. In particular, Such Much AI, Inc. does not receive access to EEA-hosted Customer Data solely because it is affiliated with another Such Much AI entity. Any access must be necessary for an authorized purpose, permitted by the applicable agreement and protected by an appropriate transfer mechanism where required.
Depending on how you interact with us, we may process the following categories of personal data.
Name, surname, job title, organization, department, professional role, work address, work email address, telephone number and other business contact details.
Account identifier, organization membership, user role, permissions, organization-administrator actions, invitations, account status, language preference and other account configuration information.
Login events, IP address, approximate location derived from IP address, device type, operating system, browser type and version, session identifiers, authentication information and related access records. We do not intentionally collect your account password in readable form.
Feature use, timestamps, interaction events, system performance information, error data, audit logs, security events and information needed to detect misuse or maintain service integrity. Diagnostic records may contain limited contextual snippets where necessary to investigate an error, security event or support request, subject to access controls and minimization.
Emails, messages, meeting notes, support tickets, feedback, survey responses, files you choose to send, and information exchanged during demonstrations, onboarding, consulting, training and support.
Information about proposals, quotations, procurement procedures, tenders, negotiations, Order Forms, subscription plans, credits, contract contacts, purchase orders, relationship history and customer-management notes.
Billing contacts, invoice details, bank-transfer information, payment status, company registration information, VAT identification numbers, tax-residency information and related accounting records. Card payment details are normally processed directly by the applicable payment provider. We typically receive limited payment metadata rather than complete card details.
Newsletter subscriptions, consent records, campaign interactions, event registrations, communication preferences, unsubscribe requests and suppression records maintained to respect your choices.
Cookie identifiers, consent choices and information collected through essential, analytics, performance, monitoring or similar technologies as described in Section 10.
Contact details, curriculum vitae, work history, education, professional qualifications, portfolio information, interview notes, references and other information you choose to provide in connection with a role.
Documents, prompts, instructions, images, recordings, audio, video, transcripts, generated outputs and other content submitted by or for a customer may contain personal data. Except where we independently determine a lawful controller purpose, we process that information as a processor under the DPA.
Customers and users must not submit special categories of personal data under Article 9 GDPR, criminal-offence data under Article 10 GDPR, classified information or similarly restricted information unless this is expressly authorized in writing and appropriate safeguards have been agreed.
We may obtain personal data:
Where Article 14 GDPR applies because personal data were not obtained directly from you, we will provide the required information within the applicable period unless a lawful exception applies.
We process personal data only where a lawful basis applies. The categories below describe our principal controller-side purposes, legal bases and usual retention periods. A longer period may apply where necessary to comply with law, investigate security incidents, establish or defend legal claims, enforce an agreement or comply with a lawful retention hold.
Purposes: provide websites and accounts; authenticate users; administer organizations, roles and permissions; deliver requested functionality; maintain essential technical operations; and respond to operational requests.
Legal bases: performance of a contract or steps requested before entering a contract under Article 6(1)(b) GDPR; and legitimate interests under Article 6(1)(f) GDPR in operating reliable B2B/B2G services.
Usual retention: for the lifetime of the relevant account or service relationship and generally up to 12 months after closure, termination or prolonged inactivity, unless a different period is required for security, legal or contractual reasons.
Purposes: respond to inquiries; provide demonstrations, proposals and quotations; participate in procurement procedures; negotiate and administer agreements; maintain business relationships; and record relevant decisions and communications.
Legal bases: steps requested before entering a contract and performance of a contract under Article 6(1)(b) GDPR; and legitimate interests under Article 6(1)(f) GDPR in developing and managing professional relationships and documenting procurement and contracting activity.
Usual retention: for the duration of the relationship and generally up to 24 months after the last meaningful interaction where no contract is concluded. Contract records may be retained for the applicable limitation period and as required by procurement or public-record rules.
Purposes: issue and administer invoices; process payments; verify payment status; maintain accounting records; apply VAT and other tax rules; and comply with financial reporting obligations.
Legal bases: performance of a contract under Article 6(1)(b) GDPR and compliance with legal obligations under Article 6(1)(c) GDPR.
Usual retention: accounting, tax and supporting transaction records are generally retained for up to 10 years, or longer where required by applicable law or a lawful authority request.
Purposes: answer questions; diagnose and resolve issues; conduct onboarding and training; deliver agreed professional services; and maintain service-quality records.
Legal bases: performance of a contract under Article 6(1)(b) GDPR and legitimate interests under Article 6(1)(f) GDPR in providing effective support and documenting service delivery.
Usual retention: for the duration of the service relationship and generally up to 24 months after the relevant request or engagement is closed, unless the content forms part of a contract record or is required for an unresolved issue.
Purposes: protect accounts, systems and data; detect unauthorized access, malicious activity, fraud and abuse; investigate incidents; preserve evidence; and comply with security obligations.
Legal bases: legitimate interests under Article 6(1)(f) GDPR in securing the Services and protecting users, customers and the Such Much AI entities; and compliance with legal obligations under Article 6(1)(c) GDPR where applicable.
Usual retention: routine security, audit and activity logs are generally retained for up to 180 days. Relevant records may be retained longer where needed for an active investigation, fraud prevention, dispute, legal hold or statutory obligation.
Purposes: understand website and feature use; diagnose performance; improve usability; measure adoption; plan capacity; and develop service improvements using aggregated or appropriately minimized information.
Legal bases: consent under Article 6(1)(a) GDPR for non-essential cookies or similar technologies where consent is required; and legitimate interests under Article 6(1)(f) GDPR for essential operational measurement, security and appropriately minimized service analytics that do not require consent.
Usual retention: according to the applicable tool configuration and consent settings, normally for no longer than reasonably necessary for the stated purpose. More specific periods should be presented through the cookie banner or settings where applicable.
Purposes: send account, security, billing, contractual, support, maintenance, feature-change and other non-promotional communications necessary for the relationship.
Legal bases: performance of a contract under Article 6(1)(b) GDPR and legitimate interests under Article 6(1)(f) GDPR in keeping customers and users informed about the Services.
Usual retention: for as long as needed to deliver and evidence the communication and, where relevant, for the related contract or legal retention period.
Purposes: send newsletters and promotional communications; manage event or webinar registrations; measure engagement; and invite relevant professional contacts to business events where permitted by law.
Legal bases: consent under Article 6(1)(a) GDPR where required; and, only where permitted by applicable electronic-marketing law, legitimate interests under Article 6(1)(f) GDPR in limited and proportionate B2B communications. You may unsubscribe or object at any time.
Usual retention: marketing subscription data are retained until consent is withdrawn or you unsubscribe. We may retain a minimal suppression record afterward so that we continue to respect your preference. Event records are generally retained for up to 24 months after the event unless a longer period is justified.
Purposes: comply with laws, court orders and authority requests; maintain corporate and compliance records; exercise or defend legal rights; conduct audits; manage insurance; and support a merger, investment, financing, restructuring or sale subject to appropriate safeguards.
Legal bases: compliance with legal obligations under Article 6(1)(c) GDPR and legitimate interests under Article 6(1)(f) GDPR in administering the business and establishing, exercising or defending legal claims.
Usual retention: for the period required by law and the applicable limitation period, plus any additional period required for an active proceeding or lawful hold.
Purposes: evaluate applications; communicate with candidates; conduct interviews; verify qualifications and references where lawful; and administer recruitment decisions.
Legal bases: steps requested before entering a contract under Article 6(1)(b) GDPR; legitimate interests under Article 6(1)(f) GDPR in recruiting personnel; legal obligations under Article 6(1)(c) GDPR; and consent under Article 6(1)(a) GDPR where specifically requested.
Usual retention: unsuccessful candidate records are generally retained for up to six months after the recruitment process, unless you consent to a longer talent-pool period or a longer period is justified by law or a claim. Records of successful candidates become part of the relevant personnel file.
Where we rely on legitimate interests, those interests may include:
We consider the nature of the information, your reasonable expectations, the relationship between you and the Applicable Controller, and the potential impact on your rights. We apply safeguards such as access limitations, data minimization, retention controls and the right to object. You may request further information about a relevant legitimate-interest assessment by contacting us.
We do not use Customer Data or Outputs to train models for other customers or for general model improvement unless the relevant customer expressly opts in through a specific written agreement describing the scope, purposes and safeguards. We do not use controller-side personal data to train general-purpose models unless the personal data have first been rendered anonymous or another specific lawful basis and appropriate transparency apply. Use of aggregated and de-identified operational information does not authorize use of identifiable Customer Data for model training.
Customer Data are hosted in the EEA by default unless the applicable Order Form and DPA expressly provide otherwise. The standard platform configuration uses Microsoft Azure for cloud infrastructure and, where applicable, AI services in the EEA.
In the standard configuration, Customer Data are not sent to an external third-party foundation-model API outside the approved Azure environment. A different arrangement applies only where it is expressly authorized in the applicable Order Form or DPA and protected by appropriate safeguards.
Controller-side processing described in this Policy is not used to make solely automated decisions about you that produce legal or similarly significant effects. The Services may generate assistive outputs for customers, but the customer is responsible for determining its lawful use, providing human review and meeting any applicable transparency or automated-decision requirements.
Some customers may agree in writing to a process-only or no-storage configuration. In that configuration, Customer Data are processed transiently and are not stored in the platform except to the limited extent necessary for immediate processing and authorized operational or security logging.
Without such an agreement, Customer Data and Outputs may be stored as needed to provide the Services. Unless an applicable Order Form or DPA states otherwise:
Mandatory retention, a lawful customer instruction or a legal hold may require limited continued storage. Retained data remain protected and are not used for another purpose merely because deletion is delayed.
We use cookies and similar technologies to operate, secure and understand the websites and Services.
Essential technologies support authentication, session management, security, load balancing, fraud prevention, consent storage and other core functions. Where the law permits, they are used without consent because the requested service cannot be provided securely or effectively without them.
Subject to consent requirements, we may use the following tools where enabled:
Some monitoring may be configured as essential where it is strictly necessary for security or service operation. Non-essential analytics and similar technologies are activated only in accordance with the choices presented through the cookie banner or settings where required.
We do not use advertising cookies or pixels, such as Meta Pixel, LinkedIn Insight Tag or Google Ads tags, unless we clearly disclose the change and obtain consent where required.
You can accept, reject or manage non-essential technologies through the cookie banner or available settings. You may also use browser controls, although blocking essential technologies may prevent parts of the Services from functioning. Withdrawal of consent does not affect processing that occurred lawfully before withdrawal.
The cookie banner or settings may provide more specific and current information about individual technologies, providers, purposes and durations. If that information conflicts with a generic description in this Section, the more specific current cookie disclosure governs for the relevant technology.
We disclose personal data only where necessary for an identified purpose and subject to appropriate contractual, organizational and technical safeguards. Depending on the processing, recipients may include:
We do not sell personal data as a separate data asset.
This Section primarily describes recipients of controller-side data. It does not mean that every listed provider receives Customer Data. The processors and subprocessors authorized for Customer Data are determined by the applicable Order Form and DPA. In the standard platform configuration, Microsoft Azure is the external cloud and, where applicable, AI-services subprocessor. Where another Such Much AI entity is the contracting processor, UAB Such Much AI may also act as its affiliated platform subprocessor.
A current Customer Data subprocessor list is available upon request or through an applicable customer notice channel. Where required by the DPA, the contracting processor provides at least 30 days’ prior notice of a material addition or replacement where reasonably practicable, and customers may object on reasonable and substantiated data-protection grounds within the period stated in the DPA.
Customer Data are hosted in the EEA by default. Status as an affiliate, Authorized Supplier or contracting entity does not by itself authorize access from outside the EEA.
Controller-side data may be processed or accessed outside the EEA where a recipient, service provider or support function is located in another country. Where the GDPR restricts a transfer, the Applicable Controller uses a lawful transfer mechanism, which may include:
You may request information about the relevant safeguard and, where legally available, a copy of it by contacting info@suchmuchai.com. Commercially sensitive or security-related information may be redacted where permitted.
We maintain technical and organizational measures appropriate to the nature and risk of processing. Depending on the relevant system and processing, these measures may include:
No system can be guaranteed completely secure. You are responsible for protecting credentials, securely configuring your organization’s account and promptly reporting suspected unauthorized access.
Where the Applicable Controller becomes aware of a personal-data breach, it will investigate and take the actions required by applicable law. This may include notifying the competent supervisory authority without undue delay and, where Article 33 GDPR applies, within 72 hours after awareness, and notifying affected individuals where the breach is likely to result in a high risk to their rights and freedoms. When acting as processor, the relevant Such Much AI entity will notify the customer without undue delay in accordance with the DPA.
Subject to the conditions and exceptions in applicable law, you may have the right to:
To exercise a right relating to controller-side processing, contact info@suchmuchai.com and describe the relevant interaction, account, organization or agreement. We may request information reasonably necessary to verify your identity and locate the relevant records.
We normally respond without undue delay and within one month. That period may be extended by up to two additional months where permitted because of the complexity or number of requests. Requests are normally handled free of charge, but a reasonable fee may be charged or a request may be refused where the GDPR permits this because it is manifestly unfounded or excessive.
If your personal data are contained in Customer Data submitted by a customer, contact that customer first. The customer is normally the controller and is responsible for responding to the request. We will assist the customer as required by law and the DPA.
You may unsubscribe from promotional email by using the link in the message or by contacting info@suchmuchai.com. We may continue to send non-promotional communications concerning an active account, contract, billing, security, support or material service changes.
If you object to direct marketing, we will stop using your personal data for that purpose. We may retain a minimal suppression record so that we do not contact you again contrary to your request.
The websites and user accounts are intended for adult representatives of businesses, institutions and public authorities and are not directed to persons under 18. We do not knowingly invite a child to create an individual account or provide controller-side personal data directly to us.
The Services may process information concerning minors when such information is lawfully included in Customer Data by a customer. In that situation, the customer is responsible for the lawful basis, transparency and other controller obligations, and we process the information under the DPA.
Our websites and communications may link to third-party websites, platforms or services. Their privacy practices are governed by their own notices, and we are not responsible for processing they independently control.
When you interact with a Such Much AI page on a social-media platform, the relevant Such Much AI entity may receive profile and interaction information from that platform. The platform also processes information under its own privacy terms and may act as an independent or joint controller for certain activities. Review the platform’s privacy information and settings.
Please contact us first at info@suchmuchai.com so that we can investigate and try to resolve your concern.
You also have the right to lodge a complaint with the supervisory authority in the EEA country of your habitual residence, place of work or the alleged infringement. Depending on the Applicable Controller, relevant authorities include:
Lithuania — State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI)
L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania
Website: vdai.lrv.lt
Latvia — Data State Inspectorate (Datu valsts inspekcija, DVI)
Elijas iela 17, Rīga, LV-1050, Latvia
Website: dvi.gov.lv
We may update this Policy to reflect changes to the Services, entity structure, recipients, technology, law or processing practices. The current version will state its effective date.
Where a change materially affects your rights or the way we use personal data, we will provide appropriate notice through the websites, Services, email or another reasonable channel before the change takes effect, unless a shorter period is required for security, legal compliance or urgent service needs.
Privacy questions and requests may be sent to info@suchmuchai.com. Please use the subject line “Privacy Request” where practicable.
UAB Such Much AI — principal operating company and Platform Operator
Company code: 306405204
Registered address: Bukčių g. 6-38, Vilnius, LT-04127, Lithuania
VAT number: LT100017966319
Email: info@suchmuchai.com
SIA “Such Much AI” — authorized supplier and potential Contracting Entity
Registration number: 40203701469
Registered address: Ropažu iela 7–8, Rīga, Latvia
Email: info@suchmuchai.com
Such Much AI, Inc. — authorized supplier and potential Contracting Entity
State of incorporation: Delaware, United States
Notice address: the address identified in the applicable Order Form, invoice or subscription confirmation
Email: info@suchmuchai.com
If no Applicable Controller is identified in your records, UAB Such Much AI will receive the request and coordinate it with the relevant Such Much AI entity.