Skip to main content

Legal · Draft 1.0 · Effective [insert date]

Privacy Notice

How the Summa platform operator processes personal data for personal accounts and business workspaces. For employee content in business workspaces, the customer is controller and Summa acts as processor under the Data Processing Agreement.

1. Who we are

Summa is operated by Schmeitzke, a sole proprietorship (eenmanszaak) registered in the Netherlands, trading as Summa / Summa Labs. In this notice, "Summa", "we", "us" and "our" refer to Schmeitzke.

Address
Sint Annadal 12-D, 6214 PA Maastricht, the Netherlands
Chamber of Commerce (KVK)
91878381
VAT identification
NL004922078B10
General contact
info@summalabs.ai
Privacy contact
privacy@summalabs.ai
Security contact
security@summalabs.ai

2. Our privacy roles

For personal accounts, Summa determines the purposes and essential means of processing and acts as the data controller.

For prompts, responses, conversation content and other content processed for a business customer, the business customer generally acts as controller and Summa acts as processor under the applicable Data Processing Agreement. The business customer is responsible for informing its users about workplace processing.

Summa remains an independent controller for processing it determines for its own purposes, including account and identity administration, subscription and payment administration, platform security and abuse prevention, statutory administration, contract and consent records, and legal-claim and regulatory compliance.

3. Personal data we process

Depending on how the service is used, we may process account and identity data (name, email, external identity identifier, organisation and role, authentication events, preferences); waitlist and onboarding data; conversation and AI data (prompts, responses, titles, model information, custom instructions, token and usage statistics); business administration data; billing data; and technical, security and audit data (IP address, request identifier, timestamps, rate-limit and security events, encrypted audit details).

Passwords and authentication credentials are handled by the self-hosted identity service; we do not store readable passwords. Full payment-card details are processed by Stripe and are not stored in the Summa application database.

Users control what they enter. Do not submit personal data that is unnecessary for your request, and do not submit special-category data, government identifiers, passwords, or payment-card information into conversations.

4. Purposes and legal bases

PurposePrincipal legal basis
Creating and administering an accountPerformance of a contract, or steps requested before a contract
Providing conversations and AI responsesPerformance of a contract
Processing business content on customer instructionsCustomer's instructions under the DPA
Providing the waitlist and requested notificationsConsent, which may be withdrawn
Processing payments and subscriptionsPerformance of a contract and legal obligations
Maintaining invoices and statutory administrationCompliance with legal obligations
Securing the platform and preventing abuseLegitimate interests in security and fraud prevention
Maintaining audit and contract evidenceLegitimate interests and establishment/defence of legal claims
Sending marketing communicationsConsent
Complying with lawful authority requestsCompliance with legal obligations

We do not rely on consent where processing is objectively necessary to provide an account or the requested service. Where we rely on legitimate interests, a copy of the relevant balancing assessment may be requested where disclosure would not undermine security or third-party rights.

5. AI processing

  • The core application and AI inference are hosted on infrastructure in the Netherlands.
  • Prompts are transmitted from the Summa backend to private, self-hosted inference services; your browser does not connect directly to the model server.
  • Customer prompts and responses are not sent to an external commercial model provider as a fallback.
  • Customer content is not used to train or fine-tune the general Summa model unless a separate, explicit agreement is concluded.

The model may generate inaccurate, incomplete, biased or unsuitable output. You must independently verify important information.

6. Recipients and international transfers

Core application databases and AI inference are intended to remain in the Netherlands. Certain limited network-security, email and payment providers may process personal data in or from countries outside the European Economic Area. We do not claim that all personal data always remains in the Netherlands while these providers are in use.

Where required, we rely on an adequacy decision, a recognised transfer framework, European Commission standard contractual clauses, and/or supplementary measures. The current providers and safeguards are listed in the Provider and Subprocessor Register, which forms part of this notice. We do not sell personal data and do not use customer conversations for third-party advertising.

7. Retention

We retain personal data only for as long as necessary for the relevant purpose. Our intended standard periods are:

DataStandard retention
Pending waitlist entryUp to 12 months after the last interaction
Refused or expired waitlist entry90 days, unless needed for security or claims
Converted waitlist entryDeleted or minimised within 30 days after conversion
Conversation content30 days by default, unless deleted earlier or a business retention setting applies
Temporary chat contentUntil you close the chat, and in any case no longer than 24 hours after it starts; removed from active systems within minutes of either
Personal account and profileDuration of the account, then deletion/anonymisation within 30 days
Ordinary application security logsNormally 90 days
Business audit recordsNormally 12 months, unless the business agreement specifies otherwise
Contract, DPA and acceptance evidenceRelationship plus up to seven years where needed for evidence
Invoices and fiscal administrationSeven years or another legally required period
Encrypted production backupsAccording to the documented backup cycle, normally no longer than 35 days

When deletion from active systems has been completed, residual copies may remain in protected backups until the backup expires; they are not returned to ordinary use.

This applies to temporary chats too. A temporary chat is a short retention period, not zero retention: its content is processed in our ordinary systems while it is open, and a backup taken before it was removed can hold a copy until that backup expires.

8. Account deletion

You can initiate deletion through account settings or by contacting privacy@summalabs.ai. Deletion covers the account, workspace content controlled by you, the identity record, active-system caches and linked observability records, subject to records we must retain by law, limited contractual or security evidence, third-party rights, business-customer instructions, and protected backup cycles.

We record completion of each deletion and investigate any component that could not be deleted automatically. For business users, the organisation may control workspace retention; a business user can nevertheless contact us directly about processing for which Summa is independently responsible.

9. Security

We use risk-based technical and organisational measures, including encrypted transport, field-level encryption of selected sensitive data, secret management, role-based access, tenant separation, database row-level security, private model-serving networks, rate limiting, tamper-evident audit records, security monitoring, dependency and vulnerability management, and incident response.

Beta notice: the current closed beta has no off-cluster database backup or restore guarantee. A storage or cluster failure may permanently delete beta data, so do not use Summa as the only copy of important information. Backup and tested restoration will be in place before paid production launch.

10. Your rights

Depending on the circumstances you may request access, rectification, erasure, restriction, objection, portability, withdrawal of consent, information about safeguards, and review of a solely automated decision where applicable. The self-service export is a convenience and does not limit the broader right of access.

Requests may be sent to privacy@summalabs.ai. We may ask for proportionate verification and ordinarily respond within one month. You may also complain to the Autoriteit Persoonsgegevens or seek a judicial remedy; we encourage you to contact us first.

11. Automated decision-making and children

Summa generates content but does not use conversation output to make legal or similarly significant decisions about users. Business customers must not use Summa output as the sole basis for decisions concerning employment, credit, insurance, housing, healthcare, education, law enforcement or comparable rights.

The consumer service is intended only for persons aged 18 or older. We do not knowingly offer personal accounts to children.

12. Changes

We may update this notice when the service, providers or law change. Material changes will be communicated through the service or by email before they take effect where reasonably possible. Current and archived versions show their effective dates.