Last updated: 28 April 2026
Privacy Policy
This policy explains what personal data STRGY AI Oy collects when you use strgy.com, why we collect it, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Who we are
The data controller for personal data processed via strgy.com is STRGY AI Oy (Y-tunnus 3559076-8), Malagankatu 8 A 34, 00220 Helsinki, Finland.
For data protection questions, contact privacy@strgy.com.
2. What we collect
We collect the following categories of personal data:
- Email captures. When you submit your email to receive an analysis, request a demo, or contact us — we store the email address, the timestamp, and the company you asked about.
- Analysis requests. Company name, the requester's email, and any free-text context you provide.
- Technical data. IP address, user agent, and basic usage logs collected by our hosting and security infrastructure for the legitimate purpose of preventing abuse.
3. Why we use it (legal basis)
- Service delivery (contract / pre-contractual steps, Art. 6(1)(b)). To respond to your demo request and deliver the analysis you asked for.
- Legitimate interests (Art. 6(1)(f)). To monitor service health, prevent abuse, and improve the product in aggregate.
4. How long we keep it
We retain personal data only as long as needed for the purpose it was collected for:
- Email captures and analysis requests: for as long as needed to deliver the requested analysis, respond to follow-up questions, and operate our marketing relationship — or until you ask us to delete it.
- Technical logs: only as long as needed for service health, abuse prevention, and security monitoring.
5. Who we share it with (processors)
We use the following sub-processors. Each operates under a Data Processing Agreement (DPA) and only processes data on our instructions:
- Microsoft Azure — infrastructure.
- Plausible Analytics — analytics.
Prompts sent to Azure OpenAI are not used to train models.
6. International transfers
Where personal data is transferred outside the European Economic Area, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses, supplemented by additional safeguards where required.
7. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Have inaccurate data corrected (Art. 16).
- Request deletion (Art. 17), subject to legal retention obligations.
- Restrict or object to processing (Art. 18, 21).
- Receive your data in a portable format (Art. 20).
- Withdraw consent at any time, without affecting prior processing.
To exercise any of these, email privacy@strgy.com. You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).
8. Security
We protect personal data with industry-standard technical and organizational measures: encryption in transit and at rest, role-based access control, audit logs, and regular security review. No system is perfectly secure, but we treat your data with care.
9. Changes to this policy
We will update this policy as our practices evolve. Material changes will be communicated via the site or email. The "last updated" date at the top reflects the most recent revision.