Last updated: June 22, 2025
At [Company Name], we recognize that trust begins with transparency. This Data Handling and Security page outlines how LLMtel manages, stores, protects, and secures your data throughout its lifecycle, in accordance with our Privacy Policy and Terms of Use.
1. Data Collection and Processing
We collect and process user data only as necessary to deliver and improve the LLMtel Service. Types of data collected include:
- Account Data: Name, email, hashed passwords, preferences, billing info.
- Query and Report Data: Prompts submitted by users and the responses returned by third-party language models.
- Usage and Device Data: IP addresses, device/browser type, timestamps, clickstreams, and session duration.
All data is processed for specific purposes such as delivering LLM reports, improving our AI-powered features, ensuring platform integrity, and meeting legal obligations.
2. Data Encryption and Transmission
To protect your information in transit and at rest:
- HTTPS encryption is enforced across all platform interactions.
- All sensitive information, including passwords and tokens, is hashed or encrypted using modern, industry-standard algorithms (e.g., bcrypt, AES-256).
- Connections to third-party LLMs are conducted via secure, authenticated API endpoints.
3. Data Access Controls
Access to personal or sensitive data is tightly restricted:
- Role-based access controls (RBAC) are enforced internally to limit access to only authorized personnel.
- All access to production systems is logged, monitored, and audited.
- Engineering and support staff must pass security training and adhere to confidentiality agreements.
4. Storage and Retention
- Data is stored in ISO 27001 or SOC 2 certified cloud environments (e.g., AWS, GCP).
- Query and report data are retained only as long as needed for feature functionality or user access, subject to user deletion or retention preferences.
- Account-related information is retained in compliance with tax, billing, and legal obligations.
We regularly assess data retention schedules to minimize storage duration and exposure.
5. Use of Third Parties
We use trusted third-party service providers for:
- LLM query processing (e.g., OpenAI, Anthropic)
- Cloud hosting and infrastructure
- Payment processing
- Analytics and performance monitoring
All vendors are vetted for their security posture and must agree to appropriate data protection agreements (including Standard Contractual Clauses where applicable).
6. Incident Response
In the event of a data breach or security incident:
- We follow a documented Incident Response Plan, including containment, investigation, notification, and remediation.
Affected users will be notified without undue delay if their data is at risk, as required by applicable laws.
7. User Controls and Data Rights
You retain control over your data:
- You may review, update, export, or delete your account information via your dashboard.
- You may delete specific prompts, queries, or reports at any time.
- You can contact us to request restrictions, corrections, or erasure where applicable under law (e.g., GDPR, CCPA).
For more information, see our Privacy Policy.
8. Security Standards and Practices
We adhere to industry best practices, including:
- Regular penetration testing and vulnerability scanning
- Security patching of all production systems
- Use of Web Application Firewalls (WAF) and DDoS protection
- Continuous monitoring and alerting for suspicious activities
We are actively working toward compliance with relevant frameworks such as SOC 2 Type II and ISO/IEC 27001.
9. International Data Transfers
Data may be processed or stored in jurisdictions outside your home country. Where applicable, we rely on:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions
- Vendor-specific compliance mechanisms
By using LLMtel, you consent to such transfers, consistent with our Privacy Policy.
10. Contact and Questions
For any questions or requests regarding data handling and security, please contact:
[Company Name]
Email: security@[company].com
Address: [Company Address]
Support Portal: [URL if applicable]
By using the Service, you acknowledge and agree to the practices described in this Data Handling and Security page.