How the Summa platform operator processes personal data for personal accounts and business workspaces. For employee content in business workspaces, the customer is controller and Summa acts as processor under the Data Processing Agreement.
1. Who we are
Summa is operated by Schmeitzke, a sole proprietorship (eenmanszaak) registered in the Netherlands, trading as Summa / Summa Labs. In this notice, "Summa", "we", "us" and "our" refer to Schmeitzke.
- Address
- Sint Annadal 12-D, 6214 PA Maastricht, the Netherlands
- Chamber of Commerce (KVK)
- 91878381
- VAT identification
- NL004922078B10
- Contact
- info@summalabs.ai — for general questions, privacy and GDPR requests, and security or vulnerability reports
2. Our privacy roles
For personal accounts, Summa determines the purposes and essential means of processing and acts as the data controller.
For prompts, responses, conversation content and other content processed for a business customer, the business customer generally acts as controller and Summa acts as processor under the applicable Data Processing Agreement. The business customer is responsible for informing its users about workplace processing.
Summa remains an independent controller for processing it determines for its own purposes, including account and identity administration, subscription and payment administration, platform security and abuse prevention, statutory administration, contract and consent records, and legal-claim and regulatory compliance.
3. Personal data we process
Depending on how the service is used, we may process account and identity data (name, email, external identity identifier, organisation and role, authentication events, preferences); waitlist and onboarding data; conversation and AI data (prompts, responses, titles, model information, custom instructions, token and usage statistics); business administration data; billing data; and technical, security and audit data (IP address, request identifier, timestamps, rate-limit and security events, encrypted audit details).
Passwords and authentication credentials are handled by the self-hosted identity service; we do not store readable passwords. Full payment-card details are processed by Stripe and are not stored in the Summa application database.
Users control what they enter. Do not submit personal data that is unnecessary for your request, and do not submit special-category data, government identifiers, passwords, or payment-card information into conversations.
4. Purposes and legal bases
| Purpose | Principal legal basis |
|---|
| Creating and administering an account | Performance of a contract, or steps requested before a contract |
| Providing conversations and AI responses | Performance of a contract |
| Processing business content on customer instructions | Customer's instructions under the DPA |
| Placing an account on the waitlist and emailing you when access opens | Performance of a contract, or steps requested before a contract |
| Measuring whether our advertising on X leads to sign-ups (the optional X pixel) | Consent, which may be withdrawn at any time |
| Processing payments and subscriptions | Performance of a contract and legal obligations |
| Maintaining invoices and statutory administration | Compliance with legal obligations |
| Securing the platform and preventing abuse | Legitimate interests in security and fraud prevention |
| Maintaining audit and contract evidence | Legitimate interests and establishment/defence of legal claims |
| Sending marketing communications | Consent |
| Complying with lawful authority requests | Compliance with legal obligations |
We do not rely on consent where processing is objectively necessary to provide an account or the requested service. Where we rely on legitimate interests, a copy of the relevant balancing assessment may be requested where disclosure would not undermine security or third-party rights.
5. AI processing
- The core application and AI inference run on Leafcloud infrastructure in the Netherlands. The model is self-hosted on Leafcloud GPU servers in the Netherlands, and inference does not run anywhere else.
- Prompts are transmitted from the Summa backend to the private, self-hosted inference service; your browser does not connect directly to the model server.
- Customer prompts and responses are not sent to an external commercial model provider as a fallback.
- Customer content is not used to train or fine-tune the general Summa model unless a separate, explicit agreement is concluded.
The model may generate inaccurate, incomplete, biased or unsuitable output. You must independently verify important information.
6. Recipients and international transfers
Leafcloud B.V. is our only infrastructure provider. The core application, databases, file storage, backups and AI inference all run on Leafcloud infrastructure in the Netherlands. Our other subprocessors are Mailjet for email (European Union), Linkup for web search when you use the web-search feature (France), and Stripe for payments. Stripe may process personal data in or from countries outside the European Economic Area, including the United States.
Where required, we rely on an adequacy decision, a recognised transfer framework, European Commission standard contractual clauses, and/or supplementary measures. The current providers and safeguards are listed in the Provider and Subprocessor Register, which forms part of this notice. We do not sell personal data and do not use customer conversations for third-party advertising.
Some features connect Summa to a third-party service you choose to use: Sign in with Google and importing files from Google Drive (Google), importing from OneDrive and Microsoft 365 or Teams work features (Microsoft), the CRM connector for business workspaces (Salesforce), and importing files or repositories from Dropbox, GitHub and GitLab. These providers are not our subprocessors; each acts under its own terms and privacy policy, and data flows to or from them only when you use the feature. They may process personal data outside the European Economic Area.
Only if you accept it, the X (Twitter) pixel sends X — Twitter International Unlimited Company in Ireland, and X Corp. in the United States — details of your visits to our public pages and, once you complete signup, a signup event identified by a random account number. No name, email address or conversation content is sent. X uses this under its own privacy policy and may process it in the United States. The Cookie Notice describes the pixel and how to withdraw consent.
7. Retention
We retain personal data only for as long as necessary for the relevant purpose. Our standard periods are:
| Data | Standard retention |
|---|
| Pending waitlist entry | Up to 12 months after the last interaction |
| Refused waitlist entry | 90 days, unless needed for security or claims |
| Converted waitlist entry | Deleted or minimised within 30 days after conversion |
| Conversation content | Until you delete it or your account is closed, unless a business retention setting applies; a deleted chat is permanently removed from active systems within 24 hours |
| Temporary chat content | Until you close the chat, and in any case no longer than 24 hours after it starts; removed from active systems within minutes of either |
| Personal account and profile | Duration of the account, then deletion/anonymisation within 30 days |
| Ordinary application security logs | Normally 90 days |
| Business audit records | Normally 12 months, unless the business agreement specifies otherwise |
| Contract, DPA and acceptance evidence | Relationship plus up to seven years where needed for evidence |
| Invoices and fiscal administration | Seven years or another legally required period |
| Production database backups | According to the documented backup cycle, normally no longer than 35 days |
When deletion from active systems has been completed, residual copies may remain in protected backups until the backup expires; they are not returned to ordinary use.
This applies to temporary chats too. A temporary chat is a short retention period, not zero retention: its content is processed in our ordinary systems while it is open, and a backup taken before it was removed can hold a copy until that backup expires.
8. Account deletion
You can initiate deletion through account settings or by contacting info@summalabs.ai. Deletion covers the account, workspace content controlled by you, the identity record, active-system caches and linked observability records, subject to records we must retain by law, limited contractual or security evidence, third-party rights, business-customer instructions, and protected backup cycles.
We record completion of each deletion and investigate any component that could not be deleted automatically. For business users, the organisation may control workspace retention; a business user can nevertheless contact us directly about processing for which Summa is independently responsible.
9. Security
We use risk-based technical and organisational measures, including encrypted transport, field-level encryption of selected sensitive data, secret management, role-based access, tenant separation, database row-level security, private model-serving networks, rate limiting, tamper-evident audit records, security monitoring, dependency and vulnerability management, and incident response.
Beta notice: database backups are kept in Leafcloud object storage in the Netherlands, but the current closed beta carries no restore guarantee. A storage or cluster failure may permanently delete beta data, so do not use Summa as the only copy of important information. Tested restoration will be in place before paid production launch.
10. Your rights
Depending on the circumstances you may request access, rectification, erasure, restriction, objection, portability, withdrawal of consent, information about safeguards, and review of a solely automated decision where applicable. The self-service export is a convenience and does not limit the broader right of access.
Requests may be sent to info@summalabs.ai. We may ask for proportionate verification and ordinarily respond within one month. You may also complain to the Autoriteit Persoonsgegevens or seek a judicial remedy; we encourage you to contact us first.
11. Automated decision-making and children
Summa generates content but does not use conversation output to make legal or similarly significant decisions about users. Business customers must not use Summa output as the sole basis for decisions concerning employment, credit, insurance, housing, healthcare, education, law enforcement or comparable rights.
The consumer service is intended only for persons aged 18 or older. We do not knowingly offer personal accounts to children.
12. Changes
We may update this notice when the service, providers or law change. Material changes will be communicated through the service or by email before they take effect where reasonably possible. Current and archived versions show their effective dates.