We've raised €1.1M to fix AI coding drift
A vault room with cameras

■ Privacy

Privacy Policy

In addition to this Privacy Policy, Straion also has a Terms of Service

  1. Introduction

    The protection and privacy of personal data is very important to Straion FlexCo ("Straion", "we" or "us"). With this privacy policy (the "Privacy Policy") we inform you how we handle and process your personal data when you access our website, use our Straion Services or otherwise interact with us. In addition, we explain your rights and available options. Straion currently provides its services exclusively as Software-as-a-Service (SaaS) and plans to offer an optional on-premise deployment in the future. On-premise deployment means the software runs on the customer's own hardware; Straion will have only limited access as agreed in the contract and will not store customer source code or personal data from the on-premise environment on Straion systems, except where strictly necessary for support and only on the Customer's documented instructions. Terms not defined otherwise herein have the meaning set forth in our General Terms and Conditions available under www.straion.com/legal/terms-of-service/ ("Terms").

    Personal Data. Personal data means any information relating to an identified or identifiable natural person (data subject). A natural person is identifiable if they can be identified directly or indirectly, in particular by reference to an identifier such as name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

    Disclaimer. The Straion Services are not directed to individuals under the age of 16 years and are intended exclusively for use by business customers and their authorized representatives acting in the course of their trade, business or profession (B2B). We do not offer the Straion Services to consumers acting for purely private purposes. We do not knowingly collect personal information from individuals under the age of 16 years. When registering for the Straion Services, users must confirm that they are at least 18 years old and that they are acting on behalf of a business customer. If we become aware that an individual under the age of 16 years or a consumer using the Straion Services for private purposes has provided us with personal data, we will take steps to delete such information. If you become aware that an individual under the age of 16 years has provided us with personal data, please contact our support services.

  2. Application of this Privacy Policy

    1. When does this Privacy Policy apply?

      We process personal data from you in different ways:

      • From you as a Website Visitor. We process personal data (such as IP address, name, email address or contact information) you share with us when accessing our website or when interacting with us - either as a visitor, Customer or potential customer of our Straion Services.
      • From you as a Customer of our Straion Services. Our Straion Services are made available to our customers subject to our Terms, and can be accessed via multiple channels:
        • By signing up directly on our website
        • By entering into a custom contract or order form
        • Through third-party marketplaces, such as Azure, AWS, GCP, Claude, GitHub Marketplace

        In order to use the Straion Services, you - either directly or as an employee or other representative of our business customer and designated by our business customer - are required to provide personal data during the signup or contractual process. We process personal data of you as our Customer and when interacting with us as a Customer or prospective Customer of our Straion Services.

      • From you as an employee of our business partner. We work with many business partners, as described below. To work with these partners, we collect business contact information and other related data from relevant employees of those business partners.

      When we process such data we are a data controller. We process your data in compliance with the GDPR and this Privacy Policy.

      The exact type of data we collect depends on the relationship we have with you and the product or service you use. Applying your cookie management settings on our website, signing up for a newsletter, requesting to be contacted by our sales team, creating an account for our Straion Services, are all examples of actions you take that require you to share certain personal data with us that is specific to that particular interaction. For on-premise deployments, the customer is solely responsible for operation, security, updates, and backups. Straion will have access only for support or maintenance purposes and will not store personal data or source code permanently on Straion systems. In this context, Straion generally acts as a data processor or sub-processor based on the respective data processing agreement, and the Customer remains responsible for informing its users about the processing in the on-premise environment.

    2. When does this Privacy Policy not apply?

      This Privacy Policy does not apply when we process personal data on behalf of our Customer: Personal Data included in Customer Content. A customer of our Straion Services can upload and manage a variety of content, such as texts, images, videos or other files to and via our Straion Services. Typically, this is content not intended for publication but Customer Content may contain personal data. We process this personal data according to the contract with our Customer. In this context, Straion is a data processor and not the controller. Straion will only process such data pursuant to our agreement. In such case our Customer agrees to enter into and be bound by the Straion Data Processing Agreement and all attachments thereto, which shall govern the processing of personal data included or part of their Customer Content. This is in accordance with Art 28 GDPR and Straion only processes such data under documented instructions from the Customer and does not use Customer Content (including source code) for its own purposes.

  3. How do we protect your personal data?

    General. Protection of your data is extremely important to us. We use physical, technical and organizational safeguards designed to protect your information and strive to protect your data in the best possible way. All measures comply with Art 32 GDPR.

    Technical and organizational measures. We use appropriate technical and organizational security measures to protect your data against manipulation, loss, destruction and unauthorized access or use, in accordance with Art 32 GDPR. These measures include, where appropriate, encryption, pseudonymization, access controls, and regular reviews of our security practices. We limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know such data. They will only process your Personal Data on our instructions and they are subject to a duty of confidentiality. We use appropriate technology and invest in technology and infrastructure to protect personal data. Access to our Straion Services is password protected. You should be the only person with access to your account. You are responsible for safeguarding the credentials to your account. If your login information is compromised or used without your permission, you need to notify us immediately so we can take steps to secure your account. Straion does not know or store your account passwords in plain text, and customer source code is only accessible to authorized personnel on a strict need-to-know basis as required to provide the Straion Services or agreed support.

    Reviews. We conduct thorough screenings and reviews of our systems, services and infrastructure taking into account security and compliance best practices, current risks, threats, vulnerabilities, technology, and changes in applicable legal requirements.

    Trainings. Our staff has the obligation to secrecy in compliance with applicable law and undergoes regular training on data protection and confidentiality. Training includes GDPR obligations such as data subject rights and breach notification procedures.

  4. Personal Data We Process

    1. Website

      Our websites are made available to every internet user. We collect certain data when you visit our website and process data you, as a visitor, provide to us when accessing our website (www.straion.com).

      Data we collect automatically from our website

      Internet or other electronic network activity information - Log Files & Usage Information

      Data processed. When you visit our website for information purposes we collect data about your access to our servers on which our website is stored for retrieval via the Internet (so-called server log files). This access data includes:

      • Requested content, the name of the website accessed
      • File, date and time of access/request
      • GMT time zone difference
      • access status / HTTP status code
      • Amount of data transferred
      • Message about successful retrieval
      • browser type, version and language version
      • operating system
      • Referrer URL (the previously visited page)
      • IP address
      • the requesting provider
      • performance numbers such as latencies and caching
      • Source of the data. Website visitors.

      We process this data based on our legitimate interests (Art. 6(1)(f) GDPR) in monitoring and improving our website and services. For necessary cookies and similar technologies, processing is based on consent (Art. 6(1)(a) GDPR).

      Purpose. We need to process these log files in order to ensure the functionality, stability and security of our website, for troubleshooting, to optimize marketing activities and to adjust our offer and our information on the websites accordingly. We may also use these data in connection with forensic investigations in the event of a security incident or to create aggregate user statistics. Legal Basis. We process this data based on our legitimate interest in monitoring and improving our website and services. Third Party Service Providers. We use Hetzner for hosting of our website.

      Data you as our website visitor share directly with us

      Identifiers - Contact Information & communications

      Contact Form/Email inquiries

      Data Processed. When you contact us through our website or request information about our products or services, ask to be added to our email distribution list or Newsletter, we may collect your first name, last name, email address, country, phone number and other contact details to fulfill your request. When you do so in the course of a (potential) relationship between you, your organization, and us, we also collect your organization's/employer's name, industry, company size and your job title. When you communicate with us, we will receive and retain your communications and the information included in those messages. Source of the data. Website visitors, customer, potential customer.

      Purpose. We process Contact Information in order to offer, market, and sell our products and services to you or to reply to your request. We process your communications in order to communicate with you, to keep records of our communications with you, to enhance your experience, and to send you relevant information.

      Legal Basis.The legal basis for this processing is fulfillment of a contract (pre-contractual measures) and our legitimate interests in taking steps, at your request, to enter into a contract with you and the proper administration of our website, business and communication with our users.

      Third Party Service Providers. We use Pipedrive (see below) to manage the data received.

      Social Media. When you interact with social media, data may be transferred outside the EEA. We ensure adequate safeguards are in place such as Standard Contractual Clauses or rely on Privacy Shield / Data Privacy Framework where applicable.

      LinkedIn, operated by LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland Our site: https://www.linkedin.com/company/straion

      Data processed. If you interact with us on social media, we may also receive your user names on such social media platforms and associate such information with your other Contact Information.

      If you click on a plug-in included in our website and provided by these (social) media networks, such plug-in is activated, a connection will be established to the respective network's server and your data may be transmitted to such network. We have no control over the extent, and content, of personal data processed by the operator of the respective network following a click on the relevant plug-in. If you do not agree with the transfer of your data, please avoid activating any plug-ins.

      When interacting with our social media channels we may have access to your publicly visible data (e.g. name and profile picture when you make a public comment on our page). Please review your profile settings to check which data is publicly available and to change which data can be shared by the platform.

      When communicating with us via social media platforms we process data provided by you (e.g. posted articles, likes, direct messages, customer inquiries, comments, etc.). In addition to the data processing by us, other providers, in particular operators of social networks and platforms, also process personal user data. We have no influence on this data processing and are not responsible for it - the data processing takes place exclusively in the area of responsibility of the other providers.

      In addition, we receive anonymous statistics from the social media operators about the use and popularity of our social media pages. The following information are processed:

      • Total number of followers (i.e. person following our channel)
      • Reach: number of people who see a specific post; number of interactions with a specific post; this enables us to review which topics are of great interest to our community
      • Demographic data of users: age, gender, place of residence, language.
      • Ad performance: How many people were reached by a post or paid ad? How many people have interacted with it?

      Source of the data. Individuals contacting us via social media.

      Purpose.We collect this data in order to offer, market, and sell our products and services to you and to communicate with active customers, prospective customers and interested social media users about our Straion Services, products, services and other news and in order to improve our social media presence.

      Legal Basis. We process this data lawfully based on our legitimate interest.

      Third Party Service Providers.When you access such social media platforms, the general terms and conditions, as well as the privacy policies of these operators, additionally apply. We would like to point out that user data may also be processed outside the European Union. This can result in risks for users due to different legal frameworks (e.g. it could make it more difficult to enforce data subject rights).

      As part of the technical process of different social media platforms, these platforms will know when you click on content or a website you are visiting, if you are logged in to your social media account at the same time. Such information is collected by social media platforms and assigned to your social media accounts, regardless of whether you click on content of this platform or not. By logging out from your accounts, you may prevent such companies from associating the information collected with your accounts. The activities of those companies are not controlled by us and therefore, we do not assume any liability for damages that you may incur through the use of your data by these companies.

      For a detailed explanation of the respective processing and the possibilities of objection (opt-out) by providers of social media networks, we refer to the respective privacy policies of the providers (see below). In the case of requests for information and the assertion of data subject rights regarding data processing by other providers, we point out that these can be asserted with the below-mentioned providers. Only the providers have access to the data of the users and can directly take appropriate measures and give information.

    2. Customers

      We collect and process following personal data when you are a customer of our Straion Services, interact with us and access the Straion Services via straion.app.

      Data you as our Customer of the Straion Services share directly with us

      Account Information

      Data Processed. When you directly signup within our Straion Services, we will require you to enter your first name, last name, email address and a password. Straion creates user profiles including first name, last name, email address and profile picture. Passwords are not visible to Straion. Profiles may be personalized and can be deleted at any time by the customer. Customers also grant Straion access to source code exclusively for the purpose of using the Straion Services; the code remains the customer’s property, is not stored by Straion and may only be used for contractually agreed purposes. Within the Straion Services we process information on which users interact or collaborate with which other users, in which organizations, workspaces, projects or repositories and on the type and time of such interactions (e.g. comments, assignments, code reviews). This information forms part of your user profile and activity log and is used to enable collaboration, audit trails and traceability of changes. You also have the option of adding a username, and other details to your profile information to be displayed in our Straion Services. In case you use SSO we may only receive your unique identifier from the SSO provider instead of your email, depending on your configuration.

      Purpose. We process Account Information to operate the Straion Services, to provide our products and services to you, to ensure the privacy and security of our Straion Services, to manage our relationships with you, to communicate with you, to keep records of our communications with you, to send you our notifications, and to promote our products and services to our customers. We do not use customer source code or Customer Content to train generic models or for product development beyond what is necessary to provide, secure and improve the specific Straion Services used by the Customer, unless expressly agreed in writing.

      Legal Basis. The legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract; where you give your content we base processing on your consent or, we base processing, where applicable, on our legitimate interests in the proper administration of our Straion Services and the proper management of our customer relationships.

      Third Party Services. We use Pipedrive to manage data relating to your account. We may enrich your data with publicly available data or with data we receive from our service providers which structure publicly available information for us.

      Your Communications & Feedback

      Data Processed. The Straion Services may also include customer support, where you may choose to submit information regarding a problem you are experiencing with the Straion Service. The specific personal information requested will vary based on the purpose of the support. We may ask you for your contact information or also additional information to help us understand you and your support needs better.

      We might conduct surveys or polls in which you may choose to participate. We process the data you decide to submit to our surveys. The specific personal information requested on these surveys will vary based on the purpose of the survey. We may ask you for your contact information or also additional information to help us understand you better as a customer. Your participation in and completion of any surveys or questionnaires is always voluntary.

      The Straion Services may also include feature request forms or the option to give feedback, where you may choose to submit information regarding a feature or improvement you are suggesting for the Straion Services. We may ask you for your contact information or also additional information to help us understand you and your request better.

      Purpose. We process this information to find out how our customers or potential customers use our products and services; to provide support services to you; to improve our products and services; to provide better services to you, or other customers; to provide training to our staff and to develop and grow our business.

      Legal Basis. We process this data lawfully for the performance of our contract and based on our legitimate interest in the proper administration and performance of our Straion Services and business and communications with our users.

      Financial & Payment Information

      Data Processed. If you choose to purchase products or services from us, we collect your name, contact information, and your payment information (which may include your credit card provider and expiration date, and other related billing information). Credit card numbers are not visible to Straion and payment information does not touch any Straion systems. Our payment processor will share your billing address with us.

      Purpose. We process Financial and Payment Information in order to provide our products and services to you and to keep records of those transactions. We'll use your billing address for tax calculation and audit purposes.

      Legal basis. The legal basis for this processing is the performance of a contract between you and us and taking steps, at your request, to enter into such a contract and our legitimate interests in the proper administration of our Straion Services and business.

      Third Party Services. If you are a Self-Service customer we use Stripe to process payments; if you are an Enterprise Customer you may pay for our services via bank transfer; we share your data with BDO DigiTax which is used as accounting tool.

      Contact Information

      Data Processed. When you contact us or request information about our products or services, we may collect your first name, last name, email address, country, phone number and other contact details to fulfill your request. When you do so in the course of a (potential) relationship between you, your organization, and us, we also collect your organization's/employer's name, industry, company size and your job title. When you communicate with us, we will receive and retain your communications and the information included in those messages.

      Purpose. We process Contact Information in order to offer, market, and sell our products and services to you or to reply to your request. We process your communications in order to communicate with you, to keep records of our communications with you, to enhance your experience, and to send you relevant information.

      Legal Basis. The legal basis for this processing is fulfillment of a contract (pre-contractual measures) and our legitimate interests in taking steps, at your request, to enter into a contract with you and the proper administration of our Straion Services, business and communication with our users.

      Third Party Services. We use Pipedrive, Slack and Google Workspace where you may communicate with us.

      Data we collect automatically from our Straion Services

      Internet or other electronic network activity information - Log Files & Usage Information

      Data processed. When you access our app we collect data about your access to our servers on which our app is stored for retrieval via the Internet (so-called server log files). This access data includes:

      • Requested content, the name of the website accessed
      • File, date and time of access/request
      • GMT time zone difference
      • access status / HTTP status code
      • Amount of data transferred
      • Message about successful retrieval
      • browser type, version and language version
      • operating system
      • Referrer URL (the previously visited page)
      • IP address
      • the requesting provider
      • performance numbers such as latencies and caching
      • information about how you use the Straion Services (e.g. which features are used, frequency of use, click paths, error messages), where such information is linked to your account or device

      Purpose. We need to process these log files in order to ensure the functionality, stability and security of our app, for troubleshooting, to optimize marketing activities and to adjust our offer and our information on the websites/app accordingly. We may also use these data in connection with forensic investigations in the event of a security incident or to create aggregate user statistics. Where possible, we use aggregated or pseudonymised data for analytics.

      Legal Basis. We process this data based on our legitimate interest in monitoring and improving our website/app and services.

      Third Party Services. We share Log Files & Usage Information with our cloud provider Hetzner Online GmbH.

      Internet or other electronic network activity information - Cookies

      Data processed. When visiting our app we and our third-party partners, such as our advertising and analytics partners, use cookies and other tracking technologies (e.g., web beacons, device identifiers and pixels).

      When you visit & access our app for the first time, a cookie consent banner will pop up and ask you to customize your cookie preferences. If you decide to change your preferences later, you can easily do so by clicking on the "Cookie Settings" link on the bottom of our website/app. Please note that Essential Cookies cannot be disabled and if you decide to opt-out of Statistics Cookies, certain functionality of our app may be impacted. You can prevent the storage of cookies by adjusting your browser software accordingly. However, we would like to point out that in this case you may not be able to use all functions of our app to their full extent.

      Purpose. We collect this data to analyse and regularly improve the use of our website/app, to provide functionality, to recognize you across different services and devices, to enhance your experience and to improve our marketing efforts. We may use the statistics obtained to improve our offer and make it more interesting for you as a visitor and user.

      Legal Basis. The legal basis for processing of Essential Cookies is our legitimate interest to properly manage our website/app and improve our service. Statistical Cookies are processed based on your consent. For analytics and marketing we rely on your consent.

    3. Information we receive from other sources

      We receive information about you from other Service users, from third party services, related companies, and from our business and channel partners. We process this data lawfully.

      Third party service providers of business information & data enrichment

      We obtain business data from third parties. This information may include email addresses, the company an individual works for, job titles, phone numbers, and URLs of LinkedIn profiles. We obtain this information to expand our business through direct marketing, targeted advertising, and event promotion to business customers and prospects. We do not use such data to market to consumers acting for private purposes.

      Publicly available information

      We may also use publicly available information about you that we have gathered through services like LinkedIn, or we may obtain information about you or your company from your company's website URL or third party service providers (data enrichment). We use this information to help us understand our customer base better, such as your industry or the size of your company.

      Other users of the Services

      Other users of our Straion Services may provide information about you when they submit content through the Straion Services. We receive your email address from other Straion Service users when they provide it in order to invite you to the Straion Services. Similarly, an administrator may provide your contact information when they designate you as another administrator for an Organization. We use this information to contact you.

      Other services you link to your account

      We receive information about you when you or your administrator enable third-party apps, integrate or link a third-party service with our Straion Services. For example, if you create an account or log into the Straion Services using your Google credentials, we receive your name and email address as permitted by your Google profile settings in order to authenticate you. You or your administrator may also integrate our Straion Services with other services you use, such as to allow you to access, store, share and edit certain content from a third-party through our Straion Services. For example, you may authorize our Straion Services to access a third-party service within the Straion Services interface. Or you may authorize our Straion Services to sync a contact list or address book so that you can easily connect with those contacts within the Services or invite them to collaborate with you on our Services. The information we receive when you link or integrate our Straion Services with a third-party service depends on the settings, permissions and privacy policy controlled by that third-party service. You should always check the privacy settings and notices in these third-party services to understand what data may be disclosed to us or shared with our Services.

      Partners

      We work with a global network of partners who provide consulting, implementation, training and other services around our products. Some of these partners also help us to market and promote our products or generate leads for us etc.. We receive information from these partners, such as contact information, company name, what products you have purchased or may be interested in, evaluation information you have provided, what events you have attended, and what country you are in.

      Others

      We receive information about you and your activities on and off the Straion Services from third-party partners, such as advertising and market research partners who provide us with information about your interest in, and engagement with, our Straion Services and online advertisements. We use this information to market our services.

    4. Special Category Data

      We collect, process, and disclose Special Category Data only as required in the context of employment, as job applicants and employees would reasonably expect. We do not intentionally process Special Category Data of users of the Straion Services in their role as customers or end users.

    5. Other Processing Activities

      We may also process personal information when necessary for the following:

      • The establishment, exercise, or defense of legal claims, whether in court, administrative, or other proceedings. (The legal basis for this processing is our legitimate interest in the protection and assertion of our legal rights, your legal rights, and the legal rights of others.)
      • Obtaining or maintaining insurance coverage, managing risks, or obtaining professional advice (The legal basis for this processing is our legitimate interest in the proper protection of our business.)
      • Compliance with applicable laws (The legal basis for this processing is compliance with a legal obligation applicable to Straion.)
      • Compliance with a civil, criminal, or regulatory inquiry, investigation, subpoena, or summons by authorities and cooperation with law enforcement agencies concerning conduct or activity that we, a service provider, or a third party reasonably and in good faith believe may violate applicable law (The legal basis for this processing is compliance with a legal obligation applicable to Straion.)
      • Performing the tasks you have requested or to comply with your instructions or other contractual obligations between you and us;
      • Processing based on our legitimate interests

      All processing activities are limited to the minimum necessary, and documented in accordance with Art. 5(1)(c) and 24 GDPR.

    6. How long do we keep your personal data?

      Account Information

      We retain your account information until you delete or request the removal of your account. If your account is deactivated or disabled, some of your information and the content you have provided will remain in order to allow your team members or other users to make full use of the Straion Services. Retention periods comply with Art. 5(1)(e) GDPR. Data is anonymized or deleted once no longer necessary. Activity logs and audit trails may be retained for a longer period where required for security, compliance or auditing purposes and will be anonymized or pseudonymized where possible. For on-premise deployments, retention periods are determined by the Customer in its role as data controller.

      Financial Records

      Financial records have to be kept 7 years according to applicable law (e.g. § 132 BAO).

      Internet or other electronic network activity information - Automatically Collected Data

      Log Files & Usage Information: 30 days in its original form.

      Contact Form

      If you provide us with your data by using our contact form or chat, we will store your data until we have answered your request. Any data to defend against possible claims for damages are stored as necessary to safeguard your interests. The same applies to data for the enforcement of claims.

      Communication Data

      Communication data will be processed until your inquiry is completed or as long as (pre-) contractual obligations apply.

      Marketing Emails

      If you have chosen to receive marketing emails from us, we retain information about your marketing preferences unless you specifically ask us to delete such information.

      Legal Claims

      Any data to defend against possible claims for damages are stored as necessary to safeguard your interests. The same applies to data for the enforcement of claims.

      Cookies

      You may also delete cookies in your browser settings at any time.

    7. How to access and control your information

      Please contact Straion support.

  5. How we share Data

    1. Introduction

      We do not sell, rent, or share your personal data for money or anything else of value, and have not done so within the last 12 months. However, we do work together with other companies, contractors and service providers who help us run our business and operate our Straion Services. These companies provide services to help us deliver the Straion Services to you, provide you with customer support, process credit card payments, manage and contact you and other (potential) customers, provide marketing support, and otherwise improve our products and services. All data sharing is based on GDPR-compliant agreements with our processors (Art. 28 GDPR) and limited to the necessary purpose.

    2. Disclosure of Personal Data

      We may disclose (and have done so in the last 12 months) your personal data to the following categories of third parties:

      Corporate Affiliates

      We disclose personal information to our affiliates and with their respective officers, directors, employees, accountants, attorneys and agents. Affiliates will only use the information as described in this notice. Note that "affiliates" includes both parents and subsidiaries.

      Acquisitions and Similar Transactions

      We may transfer any information we collect under this privacy policy in connection with any merger, reorganization, sale of company assets, dissolution, financing, or acquisition of all or a portion of the Straion businesses to another company or other similar event. In such cases, data we process of you may be part of the assets transferred in connection with the due diligence for any such transaction.

      Legal Obligations and Rights

      We may share any personal information to comply with legal obligations. This includes sharing data with: attorneys-at-law; service providers in connection with the prevention of money laundering; tax consultants and auditors; banks and insurance companies; courts and authorities; or other legal processes. We may also share personal information in order to establish or exercise our legal rights, to defend against a legal claim, and to investigate, prevent, or take action regarding possible illegal activities, suspected fraud, safety of person or property, or a violation of contract.

      Professional Advisors

      We share personal information with our insurers and other professional advisors and consultants, including attorneys, accountants, consultants, and auditors, that need access to your information to provide operational or other support services on our behalf.

    3. Service Providers

      We disclose personal data to our service providers that help us to administer and provide the Straion Services; support our provision of products and services; send communications; provide technical support; and assist with other legitimate purposes. Straion does not share customer source code with any third parties. Access is strictly limited to management, support, or other purposes explicitly agreed upon in the contract. For on-premise deployments, customer source code and personal data remain within the customer’s environment; Straion may only access such data remotely for support purposes on the customer’s documented instructions.The tables below show the disclosures we have made within the last 12 months. We require all our service providers to undergo a thorough diligence process by our team to ensure that your data is adequately protected. This process includes a review of the data we plan to disclose to the service provider and the associated level of risk, the service provider's security policies, measures, certifications and third party audits, and whether the service provider has a mature privacy program in place that respects the rights of data subjects.

      International Transfers - Data Privacy Framework.

      For the EEA residents: Some of the service providers process your personal data, or have their seat, outside the European Economic Area. We may transfer your personal data outside the EEA. We take care to ensure our partners regardless of location have sufficient safeguards in place to process and protect your personal data in line with our own data protection and information security standards.

      Hetzner Online GmbH

      Cloud Infrastructure

      Industriestr. 25, 91710 Gunzenhausen, Deutschland

      www.hetzner.com

      www.hetzner.com/de/legal/privacy-policy

      OVH GmbH

      Cloud Infrastructure

      Oskar-Jäger-Str. 173/K6, 50825 Köln, Deutschland

      www.ovhcloud.com/

      www.ovhcloud.com/de/personal-data-protection/

      PostHog Inc

      Observability of Straion app usage

      2261 Market Street #4008, San Francisco, CA 94114

      www.posthog.com

      www.posthog.com/privacy

      Stripe Payments Europe, Ltd.

      Payments, Billing

      The One Building, 1, Lower Grand Canal Street, Dublin 2, Ireland

      stripe.com

      stripe.com/privacy

      LinkedIn Inc

      Networking

      605 W Maude Ave, Sunnyvale, CA 94085, USA

      www.linkedin.com

      linkedin.com/legal/privacy-policy

      Google Inc

      Productivity and collaboration tools, software and products

      1600 Amphitheatre Parkway Mountain View, CA 94043, USA

      workspace.google.com/

      policies.google.com/privacy

      Pipedrive Inc

      CRM

      530 Fifth Avenue, 8th floor, Suite 802 New York, NY 10036, USA

      www.pipedrive.com/

      www.pipedrive.com/en/privacy

      Slack Technologies Limited

      Communication and collaboration

      Salesforce Tower, 60 R801, North Dock, Dublin, Ireland

      www.slack.com

      slack.com/intl/en-gb/trust/privacy/privacy-policy

      GitHub Inc

      Ticket management

      88 Colin P. Kelly Jr. St. San Francisco, CA 94107, USA

      www.github.com

      docs.github.com/en/site-policy/privacy-policies/github-general-privacy-state

      Cloudflare Inc

      CDN

      101 Townsend St., San Francisco, California 94107, USA

      www.cloudflare.com

      www.cloudflare.com/privacypolicy

      Axiom Inc

      Observability

      1390 Market Street Suite 200 San Francisco, CA 94102, USA

      axiom.co

      axiom.co/privacy

      Groundcover

      Observability

      HaMasger 47, Tel Aviv, Israel

      www.groundcover.com

      www.groundcover.com/privacy

  6. Your Rights

    In accordance with privacy laws, you as a data subject may assert the following data protection rights against us, where we are controller:

    • Right to withdraw consent: You may withdraw any consent you have given us at any time. After withdrawal, we will no longer process your personal data based on that consent. Processing carried out before the withdrawal remains lawful.
    • Right to be informed: You have the right to be informed about the personal data we process about you, including the categories of personal data, sources, processing purposes, recipients, storage periods, and any transfers to third countries.
    • Right of access: You have the right to obtain access to the personal data and information we have collected about you.
    • Right to rectification: You have the right to request that inaccurate or incomplete personal data be corrected without undue delay.
    • Right to erasure (“right to be forgotten”): You have the right to request the deletion of the data we hold about you without undue delay, unless other statutory provisions (e.g. statutory retention obligations) prevent this or there is an overriding interest on our part (e.g. to defend our rights and claims).
    • Right to restriction of processing: You have the right to request restriction of processing under Art. 18 GDPR.
    • Right to data portability: You have the right to receive your personal data, which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to a different controller without hindrance from us.
    • Right to object (EU and EEA residents): You have the right to object at any time to the processing of your personal data based on Art. 6(1)(e) or (f), including profiling. Please provide reasons relating to your situation. We will stop processing unless compelling legitimate grounds exist that override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
    • Right to opt out: You have the right to opt out of the processing of the personal data for purposes of direct marketing, targeted advertising, the sale of personal data, profiling in furtherance of decisions that produce legal or similarly significant effects concerning you to the extent such rights are available under applicable data protection law.

    If you would like to register your complaint with the Austrian supervisory authority, please send your claim to: Österreichische Datenschutzbehörde, Barichgasse 40 - 42, 1030 Vienna, Austria, +43 1 52 152-0, dsb@dsb.gv.at

    How you can assert your rights

    If you have any questions related to this privacy policy, please contact legal@straion.com.

    Straion FlexCo, Hafenstraße 47-51, 4020 Linz, Austria

    Your request must: Provide sufficient information that allows us to verify you are the person about whom we collected personal information or an authorized representative of that person. Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

    We may, under applicable law, require additional proof of your identity. You may designate an authorized agent to make a request for you. If you use an authorized agent, we may require the agent to submit proof that they are authorized to act on your behalf. We will not discriminate against you for exercising these rights.

  7. Miscellaneous

    Links to other Websites. Our Privacy Policy also links to websites of third parties. We have no control over the content, or the data protection practices, of these websites. We recommend reading the data protection policies of any websites of third parties visited.

    Changes to this Privacy Policy. We may change this privacy policy from time to time. We will post any privacy policy changes on this page and, if the changes are significant, we will provide a more prominent notice by adding a notice on the Straion Services homepages, login screens, or by sending you an email notification. We will also keep prior versions of this Privacy Policy in an archive for your review. We will obtain your consent for any changes or adjustments to this privacy statement that can only be implemented with your consent as a data subject. Where changes significantly affect the way we process your personal data, we will notify you in advance, where feasible, so that you can review the updated Privacy Policy in time.

    Handling Disputes. If there ever should be any concern or dispute relating to our data protection practices, we hope to be able to resolve such disputes between us in an amicable and mutually beneficial way. If you have a concern or dispute with us, you can raise your concern or dispute by contacting us either via email or by mail to Straion at the email or physical address listed in the section above.

    If you are a visitor to our website you have the right to commence proceedings in a court of competent jurisdiction in accordance with applicable data protection laws. If you are our Customer and entered into our Terms, please see the relevant section on applicable law and jurisdiction of our Terms, which describes how disputes will be resolved between us.

  8. Last updated: December 5th, 2025

    For any questions about these terms, please contact legal@straion.com.