Legal
Privacy Policy
How Headframe processes account data and the limited telemetry needed to operate ToTheCent.
Effective: 24 August 2026
1. Controller and scope
Headframe Sp. z o.o., ul. Stanisława Leszczyńskiego 4/77, 50-078 Wrocław, Poland (KRS 0001227801, NIP 8971969073) is the controller of personal data used to operate the ToTheCent website, administer customer accounts, and respond to enquiries. Privacy questions and requests may be sent to contact@tothecent.ai.
Where ToTheCent processes operational data on a customer's instructions to provide the service, Headframe acts as that customer's processor. A Data Processing Agreement describing that relationship is available on request.
2. Data we process
Account data is limited to information needed for a business relationship, such as a user's name, business email address, organisation, role, account identifiers, support correspondence, and limited billing identifiers received from Paddle. Headframe does not receive or store complete payment-card details.
To provide AI-spend analytics, the service processes usage and cost telemetry such as token counts, model identifiers, prices, timestamps, provider usage records, invoice values, hashes, and customer-supplied business labels. ToTheCent does not ingest or store the content of AI prompts or model completions. Customers must not place prompt content, credentials, or unnecessary personal data in labels or uploaded metadata.
3. Purposes and legal bases
We use account and service data to provide contracted software access, authenticate users, reconcile and analyse costs, answer support requests, protect the service, meet accounting and legal obligations, and improve reliability. The principal GDPR legal bases are performance of a contract, compliance with legal obligations, and Headframe's legitimate interests in operating and securing a business software service. We do not sell personal data, use it for behavioural advertising, or use customer data to train AI models.
4. Storage, recipients, and transfers
Customer usage and cost telemetry is processed and stored in EU-resident application infrastructure. Access is restricted according to operational need. Service providers may process limited data for hosting, security, authentication, support, and report generation under contractual protections. If a recipient outside the EEA is used, Headframe applies an available lawful transfer mechanism and data-minimisation safeguards.
Paddle acts independently as Merchant of Record for purchases and processes payment and billing information under its own privacy terms. Headframe receives only the transaction information needed to provision and support the subscription.
5. Retention and security
Data is retained only for as long as needed for the customer relationship, service operation, dispute handling, security, and applicable accounting or legal duties. It is then deleted or anonymised. Security measures include encrypted transport, access controls, least-privilege administration, and separation of customer records. No internet service can promise absolute security, so customers should also protect credentials and report suspected account misuse promptly.
6. Your rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, objection, or portability of their personal data. Where processing depends on consent, consent may be withdrawn without affecting earlier processing. Requests can be sent to the role mailbox above. Individuals may also complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), or another competent EEA supervisory authority.
7. Changes
We may update this policy as the service, suppliers, or legal requirements change. The effective date shown on this page identifies the current version. Material changes will be communicated through the service or by email where appropriate.