개인정보 처리방침

Privacy Policy

MAX — Unified API Platform for Frontier AI Models

Stellar Apex Tech Limited

시행일: December 28, 2025최종 업데이트: May 9, 2026
본 개인정보 처리방침은 영문판을 기준으로 합니다. 아래는 영문 원문입니다.

This Privacy Policy explains how Stellar Apex Tech Limited (“we”, “us”, “our” or the “Company”) collects, uses, shares, retains, and protects personal data when you visit our website, use the MAX developer dashboard, or make calls to our application programming interface (the “Service”), and the rights and choices available to you. It is designed to meet our obligations under the EU and UK General Data Protection Regulations, the California Consumer Privacy Act (as amended by the CPRA), and other applicable privacy laws. Please read it together with our Terms of Service.

1.Introduction and Scope

1.1 What This Policy Covers. It applies to personal data processed through our public website, developer dashboard, online documentation, and the API gateway we operate.

1.2 What It Does Not Cover. It does not cover (a) the applications you build or the data you collect from your own end users, for which you are the controller; or (b) data that a Model Provider collects independently under its own privacy policy when a request reaches its systems. We encourage you to review the Model Providers’ policies.

1.3 Our Two Roles. We act as a data controller for information relating to your account, billing, and use of our website and dashboard. We act as a data processor for the content you send through the API (your prompts, files, and the returned outputs), which we process only on your documented instructions.

2.Data Controller and Contact

2.1 Controller. The data controller is Stellar Apex Tech Limited, registered at UNIT 11, 9/F THE CLOUD NO.111 TUNG CHAU ST TAI KOK TSUI HONG KONG, with company/registration number 81332298.

2.2 Data Protection Officer. Our data protection contact can be reached at privacy@link-io.cloud (or dpo@link-io.cloud). We welcome questions and requests at any time.

3.Personal Data We Collect

3.1 Categories. The table below summarises the categories and examples of personal data we may collect.

Category
Identity and contact
Examples
Name, work email, organisation, job title, country.
Category
Account and credentials
Examples
Username, hashed password, security settings, account preferences.
Category
Verification (KYC/KYB)
Examples
Business registration, tax identifiers, and, only where required, identity documents (encrypted and access-restricted).
Category
API and technical data
Examples
API-key identifiers (prefixes only; secrets are hashed), request timestamps, model called, token counts, status codes, latency, rate-limit data, IP address.
Category
API content (Customer Data)
Examples
Prompts, inputs, uploaded files and context, and the generated outputs, processed on your behalf as processor.
Category
Billing and payment
Examples
Billing address, tax information, and payment records; full card details are handled by our payment processor and are not stored by us.
Category
Device and online data
Examples
IP address, browser and device type, operating system, referring URLs, pages viewed, and website/dashboard analytics.
Category
Communications
Examples
Support tickets, emails, chat messages, survey responses, and feedback.

3.2 Sensitive Data. We do not ask you to provide special categories of personal data (such as health, biometrics, racial or ethnic origin, political opinions, or precise location) or other regulated data. If you choose to submit such data through the API, you do so under Section 10.6 of the Terms and remain responsible for having a lawful basis.

4.How We Collect Personal Data

4.1 Directly From You. When you register, verify your account, add credits, configure routing, contact support, or communicate with us.

4.2 Automatically. When you use our website or dashboard, through server logs and cookies and similar technologies.

4.3 From Third Parties. From payment processors, verification providers, referral partners, and limited metadata returned by Model Providers.

4.4 Generated by Us. Usage metering, aggregated statistics, and security and reliability telemetry we derive.

5.How We Use Personal Data and Legal Bases

5.1 Purposes and Bases. Where the GDPR or UK GDPR applies, we rely on the following legal bases.

Purpose
Create and manage accounts; authenticate users.
Legal basis (GDPR)
Performance of a contract – Art. 6(1)(b).
Purpose
Operate the API; route requests; return outputs.
Legal basis (GDPR)
Performance of a contract – Art. 6(1)(b).
Purpose
Meter usage; calculate and collect Fees; prevent payment fraud.
Legal basis (GDPR)
Contract and legitimate interests – Art. 6(1)(b), (f).
Purpose
Secure the Service; detect abuse, attacks, and policy violations.
Legal basis (GDPR)
Legitimate interests – Art. 6(1)(f).
Purpose
Provide customer and technical support.
Legal basis (GDPR)
Contract and legitimate interests – Art. 6(1)(b), (f).
Purpose
Comply with KYC/KYB, sanctions, export-control, tax, and other legal obligations; respond to authorities.
Legal basis (GDPR)
Legal obligation and legitimate interests – Art. 6(1)(c), (f).
Purpose
Maintain reliability and capacity using aggregate/metadata (not API content).
Legal basis (GDPR)
Legitimate interests – Art. 6(1)(f).
Purpose
Send marketing or newsletters; set non-essential analytics cookies.
Legal basis (GDPR)
Consent – Art. 6(1)(a); withdrawable at any time.
Purpose
Process API content on your behalf.
Legal basis (GDPR)
As processor under the contract and your documented instructions (DPA).

5.2 Special Categories. We do not intentionally process special categories of personal data as a controller. If such data is contained in API content, we process it only on your instructions, and you must ensure a condition under Article 9(2) applies (for example, explicit consent).

6.API and AI Request Data

6.1 How Requests Flow. When you call the API, your request passes through our gateway and is forwarded to the selected Model Provider’s official endpoint; the generated output is returned to you. The Model Provider performs the inference.

6.2 No Training by Default. We do not use API content (prompts, files, or outputs) to train our own models or any third-party model. By default we process content only to route and fulfil the request.

6.3 Temporary Processing and Logging. Content is processed transiently for transmission and reliability. We do not persistently store API content by default. Security and debugging logs generally contain metadata (not full content) and are retained for a short period, typically 30 days or less. Content logging occurs only if you enable it through your settings.

6.4 Model Provider Data Policies. After a request reaches a Model Provider, its handling is governed by that provider’s policy, which may permit retention or, in some cases, training. We use reasonable efforts to display each model’s data policy, including zero-data-retention (“ZDR”) status, on the relevant model page. These indicators are indicative and not a substitute for the provider’s policy.

6.5 Your Controls. Where supported, you can (a) restrict routing to providers that do not retain or train on data (for example, a ZDR or “data_collection: deny” setting), enforced account-wide, per model, or per request; (b) choose specific providers and regions; and (c) disable content logging. We will not route a request to an endpoint that conflicts with an active restriction.

6.6 Processor Terms. For API content we are the processor and you are the controller. We handle, return, and delete that content according to your instructions, the DPA, and applicable law, and we assist with data-subject requests and security incidents.

6.7 Aggregated Telemetry. We may produce aggregated, de-identified statistics (such as total token volume, error rates, or latency distributions) that do not contain API content and cannot identify you, for operations, capacity planning, and reliability.

7.Cookies and Similar Technologies

7.1 Use. Our website and dashboard use cookies and similar technologies to operate, secure, and improve the experience. Core API calls do not rely on advertising cookies.

7.2 Categories. The categories are summarised below.

Category
Strictly necessary
Purpose and examples
Authentication, session and CSRF tokens, and security; required to log in.
Category
Functional
Purpose and examples
Remembering preferences such as language or dashboard settings.
Category
Analytics (consent)
Purpose and examples
Privacy-friendly statistics on how the site is used, set only with consent.

7.3 Your Choices. You can manage non-essential cookies through our consent banner and control or delete cookies via your browser settings. Disabling strictly necessary cookies may prevent login or dashboard use.

8.How We Share Personal Data

8.1 Recipients. We share personal data only as necessary to operate the Service, under appropriate contracts, and with the categories of recipients below. We do not sell personal data.

Recipient category
Model Providers (official endpoints)
Purpose
Perform inference and return outputs.
Typical location
Per model (often US; some EU/global).
Recipient category
Cloud and hosting providers
Purpose
Host, compute, and operate the gateway and dashboard.
Typical location
APAC / US / EU.
Recipient category
Payment processors
Purpose
Process top-ups and recurring payments.
Typical location
Global.
Recipient category
Identity/verification providers
Purpose
KYC/KYB and fraud checks, where applicable.
Typical location
Global.
Recipient category
Email, support, and CRM providers
Purpose
Deliver notices and manage support.
Typical location
Global.
Recipient category
Analytics and error-monitoring providers
Purpose
Reliability, debugging, and site analytics.
Typical location
Global.
Recipient category
Professional advisers
Purpose
Legal, accounting, audit, and insurance.
Typical location
Global.
Recipient category
Authorities and regulators
Purpose
Where required by law or legal process.
Typical location
As required.
Recipient category
Transaction counterparties
Purpose
In a merger, acquisition, financing, or asset sale.
Typical location
Global.

8.2 Providers’ Roles. For content sent to a Model Provider, that provider’s own terms and privacy policy apply; some act as independent controllers. Our sub-processors are bound by data-processing terms and confidentiality obligations.

8.3 Current List and Notice. We provide notice of material changes and an opportunity to object where the DPA requires.

9.International Data Transfers

9.1 Global Operations. Because the Service is global, personal data may be processed in countries other than your own, including where Model Providers or our infrastructure are located (often the United States).

9.2 Transfer Mechanisms. For transfers out of the EEA or the UK we rely, as appropriate, on: (a) European Commission adequacy decisions (including for recipients certified under the EU–US Data Privacy Framework); (b) the EU Standard Contractual Clauses under Implementing Decision (EU) 2021/914 (with the UK International Data Transfer Addendum where relevant); and (c) other legally permitted safeguards.

9.3 Processor Transfers. Our DPA incorporates the relevant standard-contract-clause modules for processor and sub-processor transfers and requires onward recipients to protect the data.

9.4 Copies. You may request a copy of the applicable transfer safeguards by contacting privacy@link-io.cloud, subject to redaction of commercial terms.

10.Data Retention

10.1 Retention Periods. We keep personal data only as long as necessary for the purposes described or as required by law, generally as follows.

Data
Account and profile data
Retention
While the account is active and for approximately 30 days after closure, subject to legal holds.
Data
Billing and tax records
Retention
For the period required by tax and accounting law (commonly 7 years).
Data
API content
Retention
Not persistently stored by us by default; where you enable logging, per that setting; transient caches are cleared within a short period.
Data
Security and debug logs
Retention
Typically 30–90 days; longer if needed for an incident or legal matter.
Data
Marketing and consent records
Retention
Until consent is withdrawn, plus records of consent as required.
Data
Customer Data (processor)
Retention
Per your instructions and the DPA; deletion or return within 30 days, with backup cycles of approximately 90 days.

10.2 Legal Obligations. We may retain data for longer where needed to comply with law, legal process, or regulatory requests, or to establish, exercise, or defend legal claims, in which case we limit use to those purposes.

11.Data Security

11.1 Technical and Organisational Measures. We protect the Service using measures that may include encryption of data in transit (TLS) and at rest, secure key management, role-based least-privilege access, network isolation and segmentation, multi-region deployment, logging and monitoring, vulnerability scanning and penetration testing, personnel training, and a documented incident-response process.

11.2 API Keys. Secrets are stored using cryptographic protection; only key prefixes are displayed in the dashboard, and full keys are shown once at creation.

11.3 Breach Response. We investigate suspected incidents promptly. Where a breach is likely to result in a risk to rights and freedoms, we notify the competent supervisory authority within the time required by law (under the GDPR, generally within 72 hours) and, when required, notify affected persons. When processing for you, we notify you without undue delay after becoming aware of a breach affecting your data.

11.4 No Absolute Guarantee. No method of transmission or storage is completely secure; while we work to protect personal data, we cannot guarantee absolute security.

12.Your Privacy Rights

12.1 EU and UK Rights. Where the GDPR or UK GDPR applies, you may: access your personal data; obtain rectification of inaccurate data; request erasure (“right to be forgotten”); restrict or object to processing; request data portability; withdraw consent at any time; and not be evaluated solely on automated processing producing legal or similarly significant effects, except as permitted.

12.2 How to Exercise Them. Email privacy@link-io.cloud with sufficient information to verify your identity. We generally respond within one month and do not charge a fee for manifestly unfounded or excessive requests except as allowed by law.

12.3 California (CCPA/CPRA). California residents have the right to know the categories and specific pieces of personal data collected, to delete, to correct inaccurate data, to opt out of any sale or sharing for cross-context behavioural advertising, to limit the use of sensitive personal information, and not to receive discriminatory treatment for exercising these rights. We do not sell or share personal data for cross-context behavioural advertising. Requests may be made through an authorised agent who is properly authorised.

12.4 Other Regions. Users in other jurisdictions (for example under Singapore’s PDPA, Australia’s Privacy Act, or Canada’s PIPEDA) may have equivalent rights to access, correct, or withdraw consent; we provide the same level of protection and will honour rights to the extent required.

12.5 Requests About API Content. Because we process API content as a processor on your behalf, requests from your end users should generally be directed to you; we will promptly assist you in responding as described in the DPA.

12.6 Supervisory Authorities. You have the right to lodge a complaint with a data-protection authority, for example in your EEA member state of residence or, in the UK, the Information Commissioner’s Office.

13.Children’s Privacy

13.1 No Directed Use. The Service is a business-to-business developer platform and is not directed to children. We do not knowingly collect personal data from persons under the applicable age (generally 16 for account-related data, or as local law requires).

13.2 If You Become Aware. If a child’s data has been submitted without a lawful basis, contact privacy@link-io.cloud and we will delete it. You must not process children’s data through the API except in compliance with applicable law.

14.Sensitive Data and Do-Not-Track

14.1 Sensitive Personal Information. We limit our use and processing of sensitive personal information to what is necessary to provide the Service and do not use it to infer characteristics about you. See Sections 3.2 and 10.6 of the Terms.

14.2 Do-Not-Track Signals. Some browsers transmit Do-Not-Track signals. We do not engage in cross-site tracking or cross-context behavioural advertising of our own, and we do not change our core data practices in response to such signals.

15.Changes to This Policy

15.1 Updates. We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. We will post the updated version on this page, revise the “Last Updated” date, and, for material changes, provide notice through the Service or by email. Continued use after the effective date constitutes acceptance where permitted.

16.Contact and Complaints

16.1 Contact. For privacy questions or to exercise rights, contact Stellar Apex Tech Limited at UNIT 11, 9/F THE CLOUD NO.111 TUNG CHAU ST TAI KOK TSUI HONG KONG, or email privacy@link-io.cloud. General support: support@link-io.cloud.

16.2 Complaints. If you are not satisfied with our response, you may complain to your local supervisory authority or seek a remedy under applicable law, as described in Section 12.6.