Legal

Privacy Policy

This policy explains what data Stategram collects, why we collect it, and how we protect it. Stategram is operated by Ideevoog OÜ (reg. 16478761), Tallinn, Estonia. We are the data controller for the data described below; for data you submit to evaluate transitions, we act as a processor on your behalf.

1. What we collect

We collect only what we need to provide and improve Stategram:

We do not store the contents of business records (proposals, refunds, support tickets, customer PII) unless you explicitly include them in evidence fields.

2. Legal basis (GDPR)

3. How we use it

We do not sell your data. We do not use customer data to train AI models.

4. Sub-processors

We use a small set of vetted sub-processors. The current list is published on our Security & Trust page. We give 30 days' notice before adding or replacing a sub-processor.

5. Data location and retention

Data is stored in the EU (Hetzner, Falkenstein, Germany — network zone eu-central) by default. US residency is available on request for Enterprise customers. Account and service data is retained while your account is active. Receipts are retained per your plan's receipt history limit (90 days, 1 year, or longer for Enterprise). Backups are kept for 30 days. After deletion, data is purged from active systems within 30 days and from backups within 60 days.

6. Your rights

Under GDPR you have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. To exercise any of these, email [email protected]. We respond within 30 days. You also have the right to lodge a complaint with a supervisory authority — the lead authority for Stategram is the Estonian Data Protection Inspectorate (aki.ee).

7. Cookies

We use a minimal set of strictly-necessary cookies for authentication and security. We do not use third-party advertising or cross-site tracking cookies. We use first-party analytics only to measure landing-page performance (page views, session length, button clicks) — no profile is built across sessions.

8. Security

See Security & Trust for technical detail. In short: TLS 1.3 in transit, AES-256 at rest with envelope encryption, MFA for all employee access, and signed receipts you can independently verify.

9. Children

Stategram is not directed to children under 16. We do not knowingly collect data from children.

10. Changes

If we make material changes to this policy, we will notify account holders by email at least 14 days before the change takes effect. Non-material edits will be reflected by updating the "last updated" date below.

11. Contact

Last updated: 27 April 2026.