Skip to content

Privacy Policy

Last updated: 23 August 2026

Effective date: August 23, 2026

This Privacy Policy explains how Lodestellar OÜ (“Lodestellar”, “we”, “us”), an Estonian company (registry code 17374696, VAT EE102925300), with its registered address at Telliskivi tn 60a/5, Põhja-Tallinna linnaosa, Tallinn, 10412, Harju maakond, Estonia, collects, uses, and protects your personal data when you use the Lodestellar EPD quality review service at lodestellar.com (“the Service”).

By using the Service, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

Lodestellar OÜ is the data controller for all personal data processed through the Service. We have not appointed a Data Protection Officer as it is not required given the nature and scale of our processing. For privacy inquiries, contact us at [email protected].

2. Personal Data We Collect

Account data — when you register for an Account, we collect your name, email address, and organization name. We also look up basic public information about the company behind your email address, such as its name, its field of business and its size. This tells us the kind of organization we are serving.

Authentication data — session tokens and, if you use third-party login (such as Google or Microsoft), your OAuth identifiers. We do not store your third-party account passwords.

Uploaded documents — EPDs, LCA background reports, and supporting documents you submit for quality review. These may incidentally contain personal data such as author names or contact details.

Quality review results — the findings, verdicts, and reports generated by the Service for your uploaded documents.

What you write in the Service — the notes, comments and messages you write while working on a review, and the details you record about it, such as the name of the EPD developer. We keep these with the review they belong to.

Review remarks you offer as automatic checks — the wording of a remark you wrote yourself about one compliance point in a review, where you have explicitly offered it for this purpose, together with the clause reference that goes with it.

Email preferences — your choice of whether to receive product updates and other non-essential email from us.

Report requests — if you ask for a report or other resource on our website and tick the box consenting to hear from us, we collect the email address you give us, the record of that consent, and the time of the request. Ticking the box is optional and the resource opens either way; if you leave it unticked we do not keep your address at all. You do not need an Account for this.

We do not collect or store payment card information. All payment processing is handled by our payment provider (see Section 5).

3. How We Use Your Data

We process your personal data for the following purposes and legal bases:

To provide the Service (legal basis: contract performance, Art. 6(1)(b) GDPR)

  • Creating and managing your Account
  • Processing uploaded documents using AI to generate quality reviews
  • Delivering quality review results
  • Keeping the notes, comments and messages you write about a review, so that you and your colleagues can carry that review forward

To process payments (legal basis: contract performance and legal obligation, Art. 6(1)(b) and (c) GDPR)

  • Sharing necessary account information with our payment provider for billing and invoicing

To maintain security and prevent abuse (legal basis: legitimate interest, Art. 6(1)(f) GDPR)

  • Session management and authentication
  • Detecting and preventing misuse of the Service

To understand who our customers are (legal basis: legitimate interest, Art. 6(1)(f) GDPR)

  • Looking up basic public information about the company behind the email address you register with. Our interest is in knowing the kind of organization we serve, so that we can support it properly.

To send you research, product updates and personal messages about your use of the Service (legal basis: consent, Art. 6(1)(a) GDPR)

  • Writing to you occasionally about our EPD quality research, where you asked for a report or other resource on our website and ticked the optional consent box on that form
  • Sending product updates and occasional one-to-one messages from a Lodestellar founder about how your reviews are going
  • Preparing those messages from your Account data and your activity in the Service, with the help of an AI service provider (see Sections 4 and 5)
  • There are two consents behind this: one you give on the website form, and one you give when you create your Account. Both are off unless you turn them on, and we do not prepare or send these messages for anyone who has not given the matching consent.
  • You can withdraw your consent at any time, using the unsubscribe link in any such email or by writing to [email protected]. Withdrawing does not affect processing we carried out lawfully before you withdrew.

To improve the shared automated checks (legal basis: consent, Art. 6(1)(a) GDPR)

  • To improve the shared automated checks, using only a remark you wrote yourself about one compliance point in a review, and have explicitly approved for this purpose in the app.
  • We use the wording of the remark and the clause it cites, and nothing else from your review. To draft a general version of the check, we give that wording and clause reference to an AI service provider (see Section 5); a person at Lodestellar then decides whether to use it, edit it or drop it. The check that results does not identify you, your Organization or your documents.
  • You can withdraw a remark at any time before we have made that decision, and we then delete its wording. Withdrawing does not affect processing we carried out lawfully before you withdrew.

To comply with legal obligations (legal basis: legal obligation, Art. 6(1)(c) GDPR)

  • Retaining records where required by Estonian law

4. Automated Processing

The Service uses artificial intelligence to analyze documents and generate quality review results. That processing is performed on documents, not on individuals. We also use artificial intelligence for two smaller jobs. One is to look up the company behind the email address you register with. The other, where you have offered a remark as an automatic check, is to draft a general version of that check.

If you have consented to receive product updates by email, we also look at your own account activity for a second purpose: to judge whether it is a useful moment to write to you, and to draft the message. For that we use your Account data and a short summary of what you are working on, such as the name of a review and what it raised. Every draft is read by a person at Lodestellar, who edits, approves or discards it before anything is sent to you; no message reaches you without that decision.

The Service does not make automated decisions about individuals that produce legal or similarly significant effects. Quality review results are informational guidance only.

5. Data Sharing

We share your personal data only with the categories of service providers necessary to operate the Service:

Payment provider — processes all payments, invoicing, and tax compliance as our merchant of record. Handles your billing information directly. We share your email, name, and organization name for invoicing purposes. The payment provider acts as an independent data controller for payment data. See their privacy policy for details on how they handle your payment information.

Authentication provider — manages user registration, login, and session management on our behalf. Processes your email address and authentication events.

AI service providers — process the content you put into the Service to produce quality review results. That is your uploaded documents, together with the details you record about a review and the text you write while working on one. They also process the domain of the email address you register with, so that we can recognize the company behind it. Where you have consented to receive product updates by email, they process the Account and activity data described in Section 4, to draft those messages. Where you have offered a remark as an automatic check, they process its wording and the clause it cites, to draft the check. These providers are contractually bound not to use your data for model training or any purpose other than providing their services to us.

Email delivery provider — delivers the email the Service sends you, including account and quality review notifications and, where you have consented, product updates. Processes your name, email address, and the content of the message.

Cloud hosting provider — hosts the Service infrastructure where your data is stored and processed.

A list of specific sub-processors is available on request by contacting [email protected].

We do not sell your personal data, and we do not share it with anyone for their own marketing purposes. The providers above act only on our instructions.

6. International Data Transfers

Some of our service providers are located outside the European Economic Area (EEA), including in the United States. Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission or the EU-US Data Privacy Framework.

7. Data Retention

Uploaded documents, quality review results, and what you write in the Service are retained for up to one year and are deleted upon Account closure. You may delete your data at any time through the Service.

Account data is retained for the duration of your Account. Upon Account closure, account data is deleted within a reasonable period.

Email preferences and prepared messages — your choice about receiving email, including a later withdrawal of it, is retained for the duration of your Account so that we continue to honour it. A message prepared for you is deleted once it is clear it will not be sent, at the latest 12 months after we prepared it, and in any case on Account closure.

Remarks you offer as automatic checks — the wording of a remark you have approved for this purpose, and the clause it cites, are kept while the suggestion is waiting for our decision. They are deleted once we have decided, whether we use the remark or not, if you withdraw it before then, and on Account closure.

Copies of what we send to an AI service provider — where we send data to an AI service provider to prepare something for you, such as a message or a draft check, we keep a short-lived copy of what we sent, so that we can check afterwards what left our systems. It is deleted once we no longer need it for that, and within 90 days at the latest.

Report requests — an email address you give us on our website, with its consent record, is kept until you ask us to remove it, and is then deleted.

Some records may be retained beyond these periods where required by applicable law, such as financial record-keeping obligations.

8. Cookies

The Service currently uses only strictly necessary cookies for authentication and session management. These cookies are required for the Service to function and cannot be disabled.

We do not currently use any tracking, analytics, or marketing cookies. If we introduce non-essential cookies in the future, we will update this Privacy Policy and obtain your consent as required by applicable law.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including encryption of data in transit, access controls, and secure authentication mechanisms. While we take reasonable steps to protect your data, no method of transmission or storage is completely secure.

10. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate personal data
  • Erasure — request deletion of your personal data
  • Restriction — request that we restrict processing of your personal data
  • Data portability — request your personal data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interest
  • Withdraw consent — where we process your data on the basis of your consent, withdraw that consent at any time, without affecting processing carried out before the withdrawal
  • Object to direct marketing — tell us at any time to stop using your personal data to send you marketing, including the messages described in Section 3. We will stop, and you do not have to give us a reason

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):

11. Children’s Data

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it.

12. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours as required by GDPR. If the breach poses a high risk to you, we will also notify you without undue delay.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be posted at lodestellar.com/privacy-policy with a revised effective date. For material changes, we will provide reasonable advance notice by email.

14. Contact

For questions about this Privacy Policy or how we handle your data, contact us at:

Lodestellar OÜ
Telliskivi tn 60a/5, Põhja-Tallinna linnaosa, Tallinn, 10412, Harju maakond, Estonia
Registry code: 17374696
VAT: EE102925300
Email: [email protected]