OpenLake Technologies Privacy Policy
16th February 2026
This Privacy Policy explains how Concierge AI, Inc (Operator of OpenLake Technologies) (“OpenLake,” “we,” “us,” or “our”) collects, uses, stores, discloses, and deletes personal data when you use our websites, console, accounts, application programming interfaces, hosted inference services, support channels, and related services (collectively, the “Services”).
This policy applies whether you access OpenLake directly or through an approved router, marketplace, reseller, or integration partner. A partner may provide its own privacy notice for its separate processing.
1. Scope and who we are
1.1 Controller and processor roles. For direct Accounts and our own business operations, OpenLake generally determines why and how relevant personal data is processed. When OpenLake processes personal data for an enterprise customer or routing partner under a data-processing agreement, OpenLake may act as that party’s processor or service provider. The applicable agreement controls where it assigns a specific role.
1.2 Contact details. Privacy questions and requests may be sent to contact@theopenlake.com.
1.3 Relationship to other documents. This policy should be read with the OpenLake Terms of Service, any applicable Data Processing Addendum, data policy, cookie notice, order form, and model specific disclosures.
2. Personal data we collect
2.1 Account and profile data. We collect information such as your name, email address, organization, display name, authentication identifiers, account settings, and records of acceptance of our terms and policies.
2.2 Prompts, completions, and other Customer Content. We process and store prompts, messages, files, images, tool definitions, instructions, model responses, completions, feedback, and other content submitted to or produced by the Services. This content may contain personal data depending on what you submit.
2.3 API and usage data. We collect API key or credential identifiers, model identifiers, request and response timestamps, token counts, cache usage, rate limit events, latency, throughput, status and error codes, request identifiers, feature flags, and similar metering and performance information.
2.4 Device, network, and security data. We may collect IP addresses, browser or device information, operating-system information, approximate location inferred from IP address, authentication events, security events, fraud signals, and diagnostic logs.
2.5 Billing and transaction data. We collect subscription, credit, invoice, tax, payment-status, and transaction information. Payment-card details may be collected directly by our payment processor rather than stored by OpenLake.
2.6 Communications and support data. We collect information you provide in support requests, emails, surveys, feedback, incident reports, and other communications with OpenLake.
2.7 Data received from partners. If you access OpenLake through a router, marketplace, reseller, enterprise administrator, or other integration partner, we may receive prompts, completions, request metadata, pseudonymous user or workspace identifiers, billing or entitlement information, safety signals, and other information necessary to provide and secure the Services.
3. How we use personal data
3.1 Provide the Services. We use personal data to authenticate users, process inference requests, return outputs, maintain conversation or request records where supported, administer Accounts, provide support, and operate requested features.
3.2 Metering and billing. We use usage and transaction information to calculate charges, reconcile token counts, apply credits, invoice customers or routing partners, and resolve billing disputes.
3.3 Security, safety, and abuse prevention. We use data to secure Accounts and infrastructure, detect credential compromise, prevent fraud and abuse, investigate prohibited activity, enforce rate limits and policies, respond to incidents, and protect users, OpenLake, and others.
3.4 Reliability and service improvement. We use Usage Data and diagnostic information to monitor uptime, latency, throughput, errors, capacity, and product performance; troubleshoot problems; improve the operation of the Services; and plan infrastructure.
3.5 Legal and corporate purposes. We use data to comply with law and binding process, preserve evidence, establish or defend legal claims, enforce agreements, conduct audits, complete corporate transactions, and maintain required records.
3.6 No model training. OpenLake does not use prompts, completions, files, images, or other Customer Content to train or fine tune any artificial intelligence or machine learning model. This prohibition applies to content received directly and through approved routing or marketplace partners.
3.7 Aggregated and de-identified information. We may create and use aggregated or de-identified information that does not identify you and does not contain identifiable Customer Content for analytics, benchmarking, capacity planning, security, and lawful business purposes. We will not attempt to reidentify information that applicable law treats as de-identified.
4. Legal bases for processing
Where applicable law requires a legal basis, OpenLake relies on one or more of the following:
Performance of a contract, including providing requested inference, account, billing, and support services.
Legitimate interests, including security, fraud prevention, reliability, service administration, legal claims, and responsible business operations, balanced against your rights.
Compliance with legal obligations, including tax, accounting, sanctions, regulatory, and lawful-request requirements.
Consent, where we specifically request it and where consent is the appropriate legal basis, including parental or guardian authorization where required.
Protection of vital interests or other grounds permitted by applicable law in exceptional circumstances.
5. How we disclose personal data
5.1 Service providers and subprocessors. We may disclose personal data to vendors that provide cloud infrastructure, storage, authentication, payment processing, monitoring, security, communications, customer support, analytics, professional services, and other functions necessary to operate the Services. They may process data only for authorized purposes and subject to appropriate contractual obligations.
5.2 Routers, marketplaces, and enterprise customers. We may exchange prompts, completions, request metadata, usage information, and status information with an approved routing partner, marketplace, reseller, or enterprise administrator where necessary to fulfill a routed request, administer access, reconcile billing, investigate incidents, or comply with the applicable agreement.
5.3 Third-party models and services. If you select a model or feature that depends on a third-party provider, we may disclose the information necessary to provide that model or feature. We will identify material third-party model terms or disclosures in the relevant documentation.
5.4 Legal, safety, and enforcement disclosures. We may disclose information when reasonably necessary to comply with law or binding legal process; respond to emergencies; protect rights, safety, and systems; investigate fraud, abuse, or security incidents; or enforce agreements. Where legally permitted and appropriate, we will seek to notify the affected customer.
5.5 Corporate transactions. Personal data may be disclosed in connection with a financing, merger, acquisition, reorganization, bankruptcy, asset sale, or similar transaction, subject to appropriate confidentiality protections and applicable law.
5.6 Sale and targeted advertising. OpenLake does not sell personal data for monetary consideration. OpenLake does not use Customer Content for advertising.
5.7 Subprocessor list. Current subprocessors and processing locations can be requested through contact@theopenlake.com.
6. Prompt storage, retention, and deletion
6.1 Prompt and completion storage. OpenLake stores prompts, completions, and related request records. We retain this information to preserve records necessary for legal compliance, establish or defend legal claims, resolve disputes, investigate security, fraud, and abuse, enforce agreements, and support documented operational requirements.
6.2 No indefinite retention. We do not retain identifiable personal data indefinitely merely because it may be useful. We retain data only for a disclosed period or while reasonably necessary for a specific purpose, then delete or de-identify it unless a longer period is required or permitted by law.
6.3 Deletion requests. You may request deletion of personal data by emailing contact@theopenlake.com. We may verify your identity, authority, Account, or relevant request identifiers before acting. Where you use OpenLake through a routing partner or enterprise customer, we may direct the request to that party or assist it in responding.
6.4 Deletion exceptions. We may retain limited information where reasonably necessary to comply with law, maintain tax or transaction records, preserve evidence, establish or defend legal claims, resolve disputes, detect fraud or abuse, protect security, honor prior opt-outs, or complete a documented backup deletion cycle. We will restrict retained information to the applicable purpose and delete it when the exception ends.
6.5 How deletion works. Approved deletion requests remove or de-identify covered data from active systems. Residual copies may remain temporarily in encrypted or access restricted backups until overwritten through the normal backup cycle. Deleted data may persist in aggregated or de-identified form that does not reasonably identify you.
7. International data transfers and locations
7.1 Processing locations. OpenLake and its service providers may process personal data in multiple countries which vary by model, capacity, customer configuration, or routing arrangement and will be disclosed where required.
7.2 Transfer safeguards. Where required, we use recognized safeguards for international transfers, such as adequacy decisions, standard contractual clauses, data-processing agreements, contractual commitments, or another lawful transfer mechanism. You may contact us for information about applicable safeguards.
8. Security
8.1 Safeguards. We maintain administrative, technical, and organizational measures reasonably designed to protect personal data against unauthorized access, use, alteration, loss, and disclosure. Measures may include encryption in transit, access controls, credential protection, monitoring, logging, network protections, vulnerability management, backups, and incident-response procedures.
8.2 Shared responsibility. You are responsible for protecting your Account and API credentials, limiting access, configuring Customer Applications securely, and avoiding submission of unnecessary sensitive information.
8.3 No absolute security. No system or transmission method is completely secure. If you believe an Account, credential, or personal data may have been compromised, contact contact@theopenlake.com promptly.
9. Your privacy rights and choices
9.1 Available rights. Depending on your location and the context, you may have rights to request access to or a copy of personal data; correction; deletion; restriction; objection; portability; withdrawal of consent; an appeal of a request decision; or information about categories, sources, purposes, recipients, and retention.
9.2 How to exercise rights. Submit a request to contact@theopenlake.com. Describe your request and provide information reasonably necessary to locate the relevant records. We may verify identity and authority before responding.
9.3 Authorized agents and parents. Where permitted, an authorized agent, parent, or legal guardian may submit a request. We may require proof of authorization, identity, and the relationship to the person concerned.
9.4 Response and appeal. We will acknowledge and respond within the period required by applicable law. If we deny a request in whole or in part, we will explain the reason where required and provide an appeal or complaint route where applicable.
9.5 No discrimination. We will not unlawfully discriminate against you for exercising a privacy right.
9.6 Regulatory complaints. You may have the right to complain to a privacy or data-protection authority in your location. We encourage you to contact us first so we can try to address the concern.
10. Children and minors
10.1 Lawful access. Minors may use the Services where permitted by applicable law. Where law requires parental or guardian authorization before we process a minor’s personal data, that authorization must be provided through an appropriate mechanism before the relevant processing.
10.2 Minimization and protection. We seek to collect only information reasonably necessary to provide the requested Service and apply safeguards appropriate to the user, information, and context. We do not use a minor’s prompts or completions for model training or targeted advertising.
10.3 Parent and guardian rights. A parent or legal guardian may contact us to review, correct, or request deletion of a minor’s personal data and to withdraw further authorization where applicable. We may verify identity and authority before responding.
10.4 Contact. If you believe we processed a minor’s personal data without authorization required by law, contact us at contact@theopenlake.com. We will investigate and delete or restrict the information where required.
11. Cookies and similar technologies
11.1 Technologies used. Our websites and console may use cookies, local storage, pixels, SDKs, and similar technologies for authentication, security, preferences, functionality, diagnostics, and analytics.
12. Third-party services and links
12.1 Separate practices. The Services may link to or interoperate with third-party websites, models, applications, payment providers, authentication providers, routers, marketplaces, and services. Their privacy practices are governed by their own notices except where they process data solely on OpenLake’s behalf.
12.2 Partner access. If you use OpenLake through a partner or another intermediary, review that intermediary’s privacy policy. The intermediary may independently collect account, payment, routing, and usage information that OpenLake does not control.
13. Changes to this Privacy Policy
13.1 Updates. We may update this Privacy Policy to reflect changes in law, technology, Services, or data practices. The updated version will state a new effective date.
13.2 Notice. If a change materially affects how we use personal data, we will provide notice through the Services, Account, email, website, or another appropriate channel and obtain consent where required by law.
14. Contact and complaints
14.1 Privacy contact. Questions, requests, and complaints may be sent to contact@theopenlake.com.