Privacy policy
Last updated: 20 June 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) is:
IP Strategy UG (haftungsbeschränkt), trading as “Siyaya Digital” (product: SteelX), Niederrheinstraße 46f, 41472 Neuss, Germany. Represented by Managing Director Ilya Piontek. Email: info@siyaya-digital.com.
No data protection officer is appointed; there is currently no obligation to appoint one under Art. 37 GDPR or § 38 BDSG. For data protection questions, please use the address above.
2. Scope and legal bases
This notice applies to the steelx.app website and the SteelX application. We process personal data solely in accordance with the GDPR, the BDSG and the German Telecommunications-Digital-Services Data Protection Act (TDDDG).
Depending on the processing, the legal bases are: Art. 6(1)(b) GDPR (contract/use), Art. 6(1)(a) GDPR (consent), Art. 6(1)(c) GDPR (legal obligation) and Art. 6(1)(f) GDPR (legitimate interest, in particular security and operation).
3. Hosting and infrastructure (EU)
The application is operated in the European Union; data is held in the EU region of Frankfurt am Main.
Vercel (hosting/CDN)
The frontend and server functions are provided via Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. A data processing agreement under Art. 28 GDPR is in place; any US transfers rely on Standard Contractual Clauses (Art. 46 GDPR) and — where certified — the EU-US Data Privacy Framework. Legal basis: Art. 6(1)(f) GDPR.
Supabase (database, storage, authentication)
Database, file storage (uploaded photos) and authentication run on Supabase (Supabase Inc., USA), hosted in the EU region of Frankfurt (AWS eu-central-1). A data processing agreement under Art. 28 GDPR is in place; third-country transfers rely on Standard Contractual Clauses (Art. 46 GDPR). Tenant isolation is enforced technically via Row-Level Security (RLS).
4. Server log files
When the website is accessed, technically necessary access data transmitted by your browser is processed:
- requested URL and referrer
- date and time of access
- browser type and operating system
- IP address (for delivery and attack prevention)
Processing serves the delivery, stability and security of the service. The legal basis is Art. 6(1)(f) GDPR. Data is stored only as long as necessary for these purposes.
5. Cookies and consent management
We use technically necessary cookies (session/sign-in, language and theme settings, and storage of your cookie consent). Storing or reading this information is strictly necessary and exempt from consent under § 25(2) TDDDG.
Non-necessary cookies (e.g. statistics, marketing) are set only with your consent under § 25(1) TDDDG together with Art. 6(1)(a) GDPR. Via the cookie banner you can consent or object per category; you can change or withdraw your choice at any time via “Cookie settings” in the footer.
No statistics or marketing services are currently active; the corresponding categories are kept available and are only activated after your consent.
6. Fonts
The fonts used are served locally from our server (self-hosting). No connection to Google Fonts or other third parties takes place; in particular, your IP address is not transmitted to third parties for font delivery.
7. User account, sign-in and registration
To use SteelX an account is created. We process name, email address, role, company/tenant membership, language setting and sign-in/security metadata (incl. sign-in times, two-factor status). Passwords are stored only as a cryptographic hash by our authentication provider (Supabase).
Registration via Google or Apple (OAuth)
When you self-register, you can sign in with your Google or Apple account. You are redirected to the respective provider; after a successful sign-in we receive your email address and display name. Providers are Google Ireland Ltd. (Ireland) and Apple Distribution International Ltd. (Ireland). The provider's privacy notice applies additionally. The legal basis is Art. 6(1)(b) GDPR (establishing the use relationship).
Where two-factor authentication (TOTP) is set up, it serves account security. The legal basis is Art. 6(1)(b) and (f) GDPR (performance of the use relationship and account security).
8. Processing of uploaded photos and label text recognition (OCR)
The core function of SteelX is counting steel-tube bundles from photos. Uploaded photo files and the counting and inventory data derived from them are stored tenant-scoped in the EU (see section 3).
Counting the tubes happens entirely in your browser (client-side image processing). No image is transmitted to third parties for this purpose.
Optionally, you can photograph a bundle's shipping/inventory label to read it automatically. Only for this text recognition is the label photo transmitted server-side to the Claude API of Anthropic PBC, 548 Market Street, San Francisco, CA 94104, USA. Anthropic acts as a processor (Art. 28 GDPR); a data processing agreement is in place, and the US transfer relies on Standard Contractual Clauses (Art. 46 GDPR). Under the API terms, transmitted content is not used to train the models and is retained only transiently for operational and safety purposes.
The API key is a server-only secret; AI processing is tenant-scoped and logged per company (model, token usage, cost). The legal basis is Art. 6(1)(b) GDPR. Please do not photograph personal data that is not required for the inventory check.
9. Improving recognition (corrections / learning loop)
Corrections that users make to the automated count or label recognition may be used to improve recognition. Before any cross-tenant use, the data is de-identified; identifying information is removed. The cross-tenant master dashboard shows only metrics — never photo or label content. The legal basis is Art. 6(1)(f) GDPR; you can object under Art. 21 GDPR.
10. Payment processing (Stripe)
For paid self-service plans we process payments via Stripe (Stripe Payments Europe Ltd., Ireland, and Stripe, Inc., USA). Stripe processes the payment data (e.g. card or bank details) on its own responsibility as a payment service provider; full card details are not transmitted to us. We receive/store billing-related data such as plan, subscription status and Stripe customer/subscription identifiers.
The legal basis is Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(c) GDPR (tax/commercial obligations). US transfers rely on Standard Contractual Clauses (Art. 46 GDPR). Stripe's privacy notice applies additionally.
11. Email delivery
Transactional emails (e.g. signup confirmation, account and security notices) are sent via the “Private Email” service of Namecheap, Inc. (USA), acting as a processor (Art. 28 GDPR); our contact mailbox (info@siyaya-digital.com) is also hosted there. We process your email address and the respective message trigger. US transfers rely on Standard Contractual Clauses (Art. 46 GDPR). The legal basis is Art. 6(1)(b) GDPR.
12. No solely automated decision-making
The automated count and label recognition are proposals that are reviewed, corrected and released by a human. There is no solely automated decision producing legal effects within the meaning of Art. 22 GDPR.
13. Recipients / processors
We disclose personal data only where necessary. Service providers used:
- Vercel Inc. (USA) – hosting/CDN, server functions (EU region).
- Supabase Inc. (USA) – database, file storage, authentication (hosting EU/Frankfurt).
- Anthropic PBC (USA) – label text recognition (Claude API).
- Stripe Payments Europe Ltd. (Ireland) / Stripe, Inc. (USA) – payment processing (own responsibility).
- Google Ireland Ltd. / Apple Distribution International Ltd. (Ireland) – sign-in via Google/Apple, only when used.
- Namecheap, Inc. (USA) – email hosting and delivery (Private Email).
Data processing agreements under Art. 28 GDPR are in place with the processors. No disclosure for third parties' own advertising purposes takes place.
14. Transfers to third countries
Processing may take place in the USA (see section 13). Where data is processed outside the EU/EEA, we ensure an adequate level of protection through the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) and — where the recipient is certified — through the EU-US Data Privacy Framework (Art. 45 GDPR).
15. Retention and deletion
We store personal data only as long as necessary for the stated purposes or to meet statutory retention obligations. Account, photo, counting and inventory data is stored for the duration of the use relationship and deleted after it ends. Billing records (e.g. invoices) are retained for up to 10 years due to commercial and tax-law obligations (§ 147 AO, § 257 HGB). Thereafter the data is deleted or restricted.
16. Your rights
Under the GDPR you have the following rights:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- withdrawal of consent with effect for the future (Art. 7(3) GDPR)
To exercise your rights, a message to info@siyaya-digital.com is sufficient.
17. Right to lodge a complaint
Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Postfach 20 04 44, 40102 Düsseldorf (https://www.ldi.nrw.de).
18. Data security
We take appropriate technical and organisational measures (Art. 32 GDPR): transport encryption (TLS/HTTPS), tenant isolation via Row-Level Security, role-based access control, server-side secret management (no third-party keys in the browser) and optional two-factor authentication.
19. Status and changes
Status of this privacy policy: 20 June 2026. We will update this notice if the processing or the legal situation changes.