Personal data processed via https://cortexforge.cloud is controlled by RASTELITA UAB, company code 308066375, registered at V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania ("CortexForge", "we", "us"). This notice explains what personal information we handle, the purposes we use it for, and how you can exercise your rights, in accordance with the EU GDPR.
1. What we collect
• Account information — your name, email address, hashed password and any API keys you create through the dashboard.
• Payment information — records of the token packs you purchase and the corresponding transactions. Actual card numbers are held by our payment providers rather than on our systems.
• Working material — the prompts, instructions, uploaded files, images and audio you submit (Input), together with everything the Service returns to you (Output).
• Technical and usage signals — which tools you launch, tokens consumed, IP address, browser details, operating system and an approximate geographic location inferred from IP.
• Support communications — any tickets you open and the exchanges you have with our team.
• Cookies — described separately in the Cookie Policy.
One general request: please keep sensitive categories of personal data — health information, biometric identifiers, government-issued numbers and similar — out of the material you submit to the tools.
2. Why we process it (GDPR legal bases)
• Operating the platform, converting your Input into Output and administering your account — performance of a contract.
• Processing payments and maintaining the tax and accounting records the law requires — contract combined with legal obligation.
• Providing support, ensuring security, preventing abuse and fraud, and improving the product — legitimate interests.
• Non-essential cookies and marketing messages — consent, which is freely revocable at any time.
Your Input and Output are not used to train, fine-tune or benchmark our own AI models — under any circumstances.
3. Sharing with third parties
In order to execute your requests, we forward Input to the third-party AI providers behind the tools you invoke (for instance, the operators of the reasoning, image, audio and video models we call). Beyond that, personal data reaches only those vendors that help us operate the platform — hosting, transactional email, analytics, customer support and payment processing — each of which acts as our processor under a written data processing agreement. We do not sell personal data. Public authorities receive information only where we are legally compelled to provide it.
4. Transfers outside the EEA
Where a processor is located outside the European Economic Area, transfers are covered by the safeguards recognised under GDPR — most often the EU Standard Contractual Clauses combined with a transfer impact assessment, or an adequacy decision applying to the destination country.
5. How long we keep it
Account data is retained while your account remains active and for a short wind-down period after closure. Invoicing and other accounting documentation is preserved for the period required by Lithuanian tax and company legislation (up to ten years). Content, telemetry and support logs are kept only for as long as they serve the purpose that justified collecting them in the first place.
6. Security
We apply industry-standard safeguards — encryption of data in transit and at rest, encrypted storage of secrets, role-based access control, logging and continuous monitoring. No online service is completely invulnerable; where a data breach affecting you occurs and notification is required by law, we will notify you and the competent supervisory authority within the deadlines set out in the GDPR.
7. Your rights
Under GDPR you have the right to request access to your personal data, rectification, erasure, restriction, portability, or to object to specific processing activities, and to withdraw any consent you have provided. Send such requests to [email protected] — we respond within one month. Complaints may be lodged with the State Data Protection Inspectorate of Lithuania (VDAI, https://vdai.lrv.lt) or with the data protection authority in the EU country where you live or work.
8. Children
The Service is designed for adults, and we do not knowingly collect personal data from anyone under 18. If a minor has submitted personal information to us, please contact us and we will delete it.
9. Updates to this notice
We update this notice as the platform and the surrounding legal framework evolve. The "Last updated" date on the cover reflects the current version, and material changes will be flagged in advance.
Contact
RASTELITA UAB · Company code 308066375 · V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania · +370 666 54163 · [email protected]