This is a draft, working document. It has not yet been reviewed by a lawyer and is not yet in force.
Privacy Policy
1. Who controls your data
We are finalizing our registered legal entity details (name, address, company and VAT registration numbers) and a dedicated data-protection contact, and will publish them here.
Controller/processor split. For your own business data and for the third-party personal data you upload or generate through the Service (leads, contacts, inbound email senders), you are the controller and we are the processor, acting on your documented instructions under a Data Processing Agreement. For your own account and administrator data, we are the controller. This notice covers both roles and flags which applies where.
2. What data we collect
We collect and process the following categories of data:
- Account data — admin name, email, credentials, and your billing/credit ledger, from your authorized users. We are the controller of this data.
- Tenant business data — drafts, documents, your ingested knowledge base, and agent-run records. We are the processor, acting on your instructions.
- Leads and contacts — names, emails, and other fields you or your CEO agent add. You are the controller of this third-party data; we are the processor.
- Conversation data — your chat transcript with the CEO agent.
- Voice and meeting data — spoken audio and its transcript during a CEO voice call or a hosted meeting, the CEO's synthesized voice reply, and live per-person meeting translation. This is processed to power the call in real time.
- Email content — outbound outreach and inbound email (from/to, subject, body, headers) sent and received through your own connected mailbox (Gmail, Microsoft 365, or Yandex Mail).
- Connected file-storage data — if you connect Google Drive, only the specific files you pick or create through Strady, never your whole Drive. See the Limited Use section below.
- Website-visitor chat data — if you embed our widget on your own website, the messages your visitors send through it.
- Payment and billing data — your purchase and subscription details for a credit top-up or package subscription, processed at checkout by our payment Merchant of Record, Polar.
- Technical and usage data — logs, audit trails, and agent-run records, collected automatically for security and operations.
3. Why we process your data
- Providing the Service you have subscribed to (performance of a contract).
- Processing leads and business data on your instructions, as your processor — you rely on your own legal basis for your own data.
- Billing, credit accounting, and fraud prevention.
- Security, audit logging, and abuse prevention (our legitimate interests).
- Service improvement and any marketing to prospects — the specific legal basis for these is still being finalized and will be published here.
4. Who else processes your data
We use a number of sub-processors to run the Service — Anthropic, Deepgram, ElevenLabs, Supabase, Hetzner, Resend, an S3-compatible backup provider, and our payment Merchant of Record, Polar. LiveKit, which carries live voice and video, is self-hosted and not an external recipient. Each sub-processor is engaged under a data-processing agreement and may only use your data to help us provide the Service.
5. International data transfers
Some of your data is processed by US-headquartered providers (Anthropic, Deepgram, ElevenLabs, Resend, and our payment Merchant of Record, Polar, for customer/subscription/payment data); all stored data stays in the EU (our database provider's EU region and our EU-based host), and live voice-call media is carried by our own self-hosted EU server. We use appropriate international-transfer safeguards — such as the EU Standard Contractual Clauses and, where available, the EU–US Data Privacy Framework — for each of these providers; the specific mechanism per provider will be published here once finalized.
6. How long we keep your data
We retain personal data only as long as needed for the purposes above, then delete or prune it. Transcripts, audit logs, and agent-run records are automatically time-pruned across your workspace after a configurable age. We are finalizing the exact retention period for each data category and will publish the specific day-counts here. When you close your account, see the offboarding section of our Terms of Service.
7. Your data-subject rights
You have the rights of access, rectification, erasure, restriction, portability, and objection over your personal data. We have built tools that let you, or your users, request a copy of personal data we hold, or ask us to erase it — erasure requests are confirmed in two steps before they take effect, and every request is logged. Because we are often the processor, a data subject's request usually goes to you (the controller), and we assist you in fulfilling it. We are finalizing the exact request channel, identity-verification steps, and response timeline, and will publish them here; by law, we respond within one month. You may also lodge a complaint with the Slovenian supervisory authority (Informacijski pooblaščenec) or your own local data-protection authority.
8. Automated decision-making and AI
The Service uses AI — the CEO agent and department agents — to generate drafts and suggestions. You review AI output before acting on it. We do not make any decision with a legal or similarly significant effect about you or your customers solely by automated means.
9. Security
We isolate each tenant's data with per-tenant schema isolation and row-level security, encrypt data in transit, encrypt backups, and restrict access through strict access controls and secrets management.
10. Cookies and tracking technologies
We are finalizing our cookie and tracking-technology policy and will publish it here.
11. Children
This is a business-to-business (B2B) service and is not directed at children. We are finalizing the specific age threshold and will publish it here.
12. Changes to this policy
We are finalizing how we will notify you of changes to this policy and when they take effect, and will publish that process here.
13. Google API Services User Data Policy — Limited Use
Where you choose to connect a Google account to the Service, Strady's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements. This applies to both Google-authorized connectors the Service offers:
- Google Drive — the requested scope is file-scoped access only, limited to the specific files you pick or create through Strady, never your whole Drive. Used solely to read and write those files as part of the AI-office functionality you requested — for example, drafting into a file, or ingesting a document into your knowledge base.
- Gmail — requested through the mail-connector OAuth flow. Used solely to send and receive email through the Service on your behalf — outreach you authorize, and inbound mail routing.
For data accessed through either scope, we:
- do not use it to serve advertisements, and do not permit any other party to do so;
- do not sell it, and do not transfer it except as needed to provide or improve user-facing features of the Service, to comply with applicable law, or as part of a merger, acquisition, or asset sale disclosed to you;
- do not use it to determine creditworthiness or for lending purposes;
- restrict human access to it to your own authorized users, and to our personnel only when it is necessary for a support request you have consented to, for security purposes, to comply with applicable law, or for internal operations that inherently require it — and even then, only for as long as necessary and never to build a user profile.