Privacy Policy
1. Who We Are and What We Do
Leil Storage OU ("the Company," "we," "us," or "our") (5 Tornimae, Tallinn 10145, Estonia) is the data controller responsible for personal data processed through ieilio.com (the "Service"). The Company builds and operates a distributed file system optimised for high-density SMR (shingled-magnetic-recording) hard drives. Our product is sold to AI infrastructure teams and machine-learning platform operators who use our software to store large-scale training datasets, run GPU checkpoint pipelines, and manage petabyte-scale data archives. Contact us at [email protected].
This Privacy Policy explains what personal data we collect when you visit ieilio.com or use our early-access program, why we collect it, how we use and protect it, and what rights you have under Estonian and EU data protection law (including the General Data Protection Regulation, EU 2016/679).
2. Personal Data We Collect
2.1 Data You Provide Directly
| Category | Examples | When Collected |
|---|---|---|
| Identity and contact data | Name, email address, company name, job title | Contact form, early-access request, account registration |
| Account credentials | Username, hashed password | Account creation and sign-in |
| Workload details | Approximate cluster size (TB), storage use case, current infrastructure stack | Early-access intake form -- technical qualification for our design-partner program |
| Support communications | Email threads, support tickets, pilot feedback | Ongoing support interactions during early-access program |
| Payment and billing data | Payment method type, last four digits, billing address (collected and processed via our payment provider) | Production or Enterprise subscription sign-up |
2.2 Data Collected Automatically
| Category | Examples | Source |
|---|---|---|
| Technical data | IP address, browser type, operating system, device type | Server logs |
| Usage data | Pages visited, time on page, click paths, referring URL | Analytics tools and server logs |
| Cookie and preference data | Cookie dismissal state, session identifiers | Cookies -- see our Cookie Policy |
2.3 Special Category Data
We do not intentionally collect special categories of personal data (Article 9 GDPR) such as health, racial or ethnic origin, religious beliefs, or biometric data. Please do not submit such information. If you inadvertently share it, we will delete it promptly.
3. How We Use Personal Data
We rely on the following legal bases under Article 6 GDPR:
| Purpose | Legal Basis (Art. 6 GDPR) |
|---|---|
| Respond to technical inquiries and contact form submissions | Legitimate interests (6(1)(f)) -- responding to prospective customers |
| Manage your account and deliver the Service | Contract performance (6(1)(b)) |
| Operate the early-access design-partner program (profile workloads, schedule onboarding, provide engineering support) | Contract performance (6(1)(b)) |
| Process payments and manage billing | Contract performance (6(1)(b)) |
| Send transactional emails (account notices, pilot updates) | Contract performance (6(1)(b)) |
| Improve the Service via anonymised usage analytics | Legitimate interests (6(1)(f)) -- understanding how AI infrastructure teams use our product |
| Security monitoring and fraud prevention | Legitimate interests (6(1)(f)) |
| Comply with legal and regulatory obligations (Estonian accounting and tax law, EU law) | Legal obligation (6(1)(c)) |
We do not sell personal data to third parties. We do not use personal data to train machine-learning models without your explicit written consent.
4. Data Sharing and Third-Party Processors
We share personal data only as described below, under appropriate Data Processing Agreements (Article 28 GDPR):
- Cloud hosting and infrastructure: servers and databases operated in EU data centers, under contractual data protection obligations;
- Payment processors: handle billing data under PCI-DSS standards; we do not receive full card numbers;
- Email service providers: used for transactional communications under EU-adequate data transfer safeguards;
- Analytics providers: anonymised and aggregated usage statistics only;
- Professional advisors: legal, audit, and accounting advisors bound by professional confidentiality obligations;
- Regulatory and law enforcement bodies: only when required by Estonian or EU law or a valid court order.
5. International Data Transfers
The Company is incorporated in Estonia and operates within the European Economic Area (EEA). Where any of our processors are located outside the EEA, we ensure an adequate level of protection by relying on European Commission adequacy decisions (Article 45 GDPR) or Standard Contractual Clauses (Article 46(2)(c) GDPR). You may request details of the transfer safeguards in place by writing to [email protected].
6. Data Retention
Personal data relating to the Leil Storage distributed filesystem service is retained only as long as necessary for the purposes described above or as required by Estonian and EU law.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account data (active users) | Duration of account, plus 2 years after closure | Contract / Legitimate interests |
| Financial and transaction records | 7 years from transaction date | Estonian Accounting Act, tax law |
| Support and pilot communications | 3 years from last interaction | Legitimate interests (claims defence) |
| Analytics and server logs | Up to 26 months | Legitimate interests |
| Deleted account data | Anonymised or purged within 90 days of deletion request | Data minimisation (Art. 5(1)(e) GDPR) |
7. Data Security
We apply technical and organisational security measures (Article 32 GDPR) including encryption of data in transit (TLS 1.2+) and at rest, role-based access controls, and incident response procedures. In the event of a personal data breach likely to result in risk to your rights, we will notify the Estonian Data Protection Inspectorate within 72 hours (Article 33 GDPR) and notify affected individuals where required by Article 34 GDPR.
8. Your Data Subject Rights
Under Articles 15-21 GDPR, as a data subject you have the following rights regarding personal data the Company holds about you:
- Right of Access (Art. 15): request a copy of the personal data we hold about you and information about how it is processed;
- Right to Rectification (Art. 16): request correction of inaccurate or incomplete data;
- Right to Erasure (Art. 17): request deletion of your personal data where there is no compelling reason for continued processing;
- Right to Restriction (Art. 18): request that we restrict processing in certain circumstances;
- Right to Data Portability (Art. 20): receive your personal data in a structured, machine-readable format and transmit it to another controller, where processing is based on consent or contract;
- Right to Object (Art. 21): object to processing based on legitimate interests, including profiling, and to direct marketing at any time;
- Rights regarding Automated Decisions (Art. 22): not be subject to solely automated decision-making producing legal or similarly significant effects;
- Right to Withdraw Consent: withdraw any consent at any time, without affecting the lawfulness of processing before withdrawal.
8.1 How to Exercise Your Rights
Send a request by email to [email protected] with the subject line "Data Subject Request," or by post to the address below. We will respond within 30 days. In complex cases we may extend this to 90 days, notifying you within the initial 30-day window. There is no charge for exercising rights unless requests are manifestly unfounded or excessive. We may need to verify your identity before processing your request.
8.2 Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the data protection supervisory authority. The lead supervisory authority for Leil Storage OU is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): www.aki.ee, Tatari 39, 10134 Tallinn, Estonia. You may also contact the supervisory authority in your own EU member state of habitual residence or workplace. We ask that you contact us first so we can try to resolve the concern directly.
9. Cookies
We use cookies on ieilio.com to operate the site and measure usage. See our Cookie Policy for full details.
10. Children's Privacy
Our Service is directed at AI infrastructure professionals and is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided data without parental consent, contact us at [email protected] and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this page. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
12. Contact
Leil Storage OU5 Tornimae, Tallinn 10145, Estonia
Email: [email protected]
Phone: +372 640 2200