Data Security & Confidentiality
Last updated: 6 October 2026
Effective date: October 6, 2026
The documents you upload to Lodestellar, such as EPDs and LCA background reports, often hold confidential business data. This page sets out the rules that apply to every account. Customers whose IT, security or procurement teams need more can get it under an enterprise agreement, described below.
Every account
- Stored in the EU. Your documents, review results and account data are stored and backed up in the European Union.
- Encrypted. Data is encrypted in transit and at rest.
- Never used to train AI models. To review a document, we send its content to specialised providers for document conversion and AI analysis. They work under business terms that do not allow them to use your data to train their models, or for any purpose other than providing their service to us, and they keep it only for a limited time. Some of them process data in the United States. The current list of providers is available on request.
- Kept separate. Each organization’s data is kept separate from every other organization’s. Your documents are never used in another customer’s review.
- Seen only by the people who run the service. Only the people who operate Lodestellar, and the tools they run to do so, can reach your data, and only to keep the service running and to help you when you ask.
- Deleted. Reviews and their documents are deleted automatically, usually about a year after the review was run. Write to info@lodestellar.com to have a document, a review or your whole account deleted sooner. When your account is closed, its data is deleted.
- Told if something goes wrong. If a data breach puts your data at risk, we notify the affected customers within 72 hours of becoming aware of it, and tell you what happened and what we have done about it.
How we handle personal data, including transfers outside the EU, retention periods, your GDPR rights and breach notification, is set out in our Privacy Policy. Our Terms and Conditions are the contract for every account.
Enterprise agreements
Organizations with stricter requirements can get them met under an enterprise agreement: a written set of commitments, sent on request and agreed as part of the contract. Depending on what your policies require, it can include:
- a data processing agreement under GDPR Article 28, with a named list of sub-processors and notice before it changes;
- AI analysis run inside the EU, and no retention of your data by the AI provider, where the provider approves it for our account;
- answers to your security questionnaire, and our security measures in writing;
- deletion of your data at the end of the contract, confirmed in writing;
- shorter breach notification and other terms your policies require.
Enterprise pricing is agreed per customer. Contact us at info@lodestellar.com.
Questions
For security questions, a security questionnaire, or the list of providers that process your documents, contact us at info@lodestellar.com.