Privacy
Privacy notice
B2B notice · last updated 2026-08-20 · not indexed yet
This notice describes how Steinlog processes personal data for business customers evaluating or using the product. It is an operational summary for pilots and early access — not a substitute for a signed data processing agreement. For a pilot DPA PDF, write to privacy@steinlog.com. Roles below match the DPA page. Subprocessors and residency detail live on Security.
Who we are (controller vs processor)
Steinlog is operated by Dago Digital Michal Walpole-Skwarczynski (Polish JDG), NIP 9570839810, Lecha Kaczyńskiego 10E, 80-373 Gdańsk, Poland. Privacy contact: privacy@steinlog.com.
- Controller (Steinlog / Dago Digital) — we are controller for the Steinlog B2B customer account used to contract with us (legal/billing identity of the contracting party), billing and invoices, website visitors, and product telemetry we collect for our own purposes (platform security, reliability, optional PostHog analytics after consent). That is Steinlog's commercial relationship data — not your tenants' bid files. Support is split below — not a blanket “all support = controller.”
- Support (split by processing purpose) — roles follow the purpose of the processing, not the incidental content of a ticket field. Account, billing, and product-support processing that Steinlog runs for its own commercial relationship is controller processing. Diagnosing or remediating customer tenant / bid content under your organisation's instructions is processor processing (same Art. 28 path as other tenant content). One ticket may involve both purposes; each purpose keeps its own role.
- Processor (Steinlog / Dago Digital) — for customer bid/tender content and for end-user accounts inside your organisation's tenant (org members, invites, project access, assistant prompts/answers tied to that org), we act as processor under your organisation's instructions. Your organisation is the controller of that tenant content and of those org-user records. See the DPA page. We do not treat the same dataset as both controller and processor: B2B contracting / billing identity ≠ org end-users under your tenant.
Lawful bases (where Steinlog is controller)
GDPR Article 6 bases below apply only where Steinlog / Dago Digital is the controller. They do not apply to customer bid content or org end-user data we process as processor — for that processing, your organisation establishes the Article 6 basis; Steinlog follows documented Art. 28 instructions (signed DPA / product configuration). Art. 28 instructions are not themselves an Article 6 legal basis.
- Contract / pre-contract (Art. 6(1)(b)) — only where the individual is or will be the contracting party in their own name (e.g. a sole trader / JDG / personal contractor contracting personally with us). Used to create and run that person's Steinlog B2B account, authenticate them, bill them, and deliver the service they contracted for. We do not rely on Art. 6(1)(b) for employees or other negotiators acting for a company — they are not parties to the contract with us, even when they negotiate a pilot. Authorised employees/users of a customer organisation are not parties to that organisation's contract with us.
- Legitimate interests (Art. 6(1)(f)) — for authorised employees and other users of a customer organisation interacting with Steinlog's controller surfaces (e.g. account/billing support for Steinlog's commercial relationship, security/ops telemetry about platform use, abuse prevention, rate limits, reliability), for employee negotiators of a company pilot, for B2B enquiries, and for operating the public Vraag de Wet legal Q&A (store, cache, and publish as described below), where those interests are not overridden by the individual's rights. Where support's purpose is customer-content diagnosis under your organisation's instructions, or where the person appears only as an org end-user inside a tenant, Steinlog is processor and the customer's Art. 6 basis applies instead.
- Consent (Art. 6(1)(a)) — optional website analytics (PostHog) only after you accept the banner. Under Art. 13(2)(c) you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal — use the banner controls again, or clear analytics cookies / contact privacy@steinlog.com. Withdrawal stops further analytics collection; it does not delete already-collected analytics unless you also request erasure where applicable.
- Legal obligation (Art. 6(1)(c)) — where we must retain billing or tax records under Polish law.
What we process
- Steinlog B2B customer account & billing (controller) — contracting-party name, company, work email, market, invoices, and pilot contact details needed to run the commercial relationship.
- Org end-users & customer bid content (processor) — member/invite records inside your tenant, tender and bid documents you upload, project metadata, and assistant prompts/answers tied to that tenant, processed under your organisation's instructions.
- Independent ops telemetry (controller) — platform-level auth, error, and rate-limit logs that do not include tender/bid document contents, collected so we can secure and operate Steinlog for our own purposes.
- Support — customer-content diagnosis (processor) — when the purpose of support is to diagnose or remediate customer tenant / bid content under your organisation's instructions, that processing is processor processing. Processed only as needed for that purpose; not used for advertising or model training. Account / billing / product support that Steinlog runs for its own commercial relationship remains controller processing (above), even if the same conversation also mentions an organisation name.
- Optional analytics (controller) — PostHog (EU-hosted) only after you accept analytics in the banner. Decline and no analytics cookies are set. Analytics never carry tender/bid contents.
Where data lives and is processed
Processing is mixed across regions — storage, inference, and OCR/embeddings are not the same claim:
- Storage (EU-hard where pinned) — document object storage (Cloudflare R2) and Steinlog-operated per-tenant stores (TenantDb, BidRoom, ClarificationScout Durable Objects) use Cloudflare EU jurisdiction pins. Content is isolated per client.
- Assistant inference — xAI via the Ireland regional endpoint (eu-west-1.api.x.ai).
- Embeddings & OCR (US processing, not storage) — Voyage (embeddings) and Datalab (OCR for scanned files only) are disclosed US subprocessors. They may run inference / embedding / OCR processing in the United States. They are not where Steinlog stores your bid documents or tenant databases (those stay on EU-pinned Cloudflare R2 / Durable Object stores above).
Your tender and bid content is never used to train AI models. Full subprocessor table: Security.
International transfers
Voyage and Datalab process in the United States for embeddings and OCR only (and controller-side public surfaces such as Vraag de Wet Q&A where Voyage is used). That is a processing / inference transfer, not a relocation of Steinlog's document or tenant storage. Assistant inference stays on xAI Ireland (eu-west-1.api.x.ai). Operative Art. 46 transfer safeguards (e.g. SCCs) with Voyage and Datalab remain a product/legal open item — this page does not assert that SCCs are already executed. A customer DPA PDF is not the Art. 46 mechanism for those providers.
Analytics
We use PostHog, hosted in the EU, to understand which pages help — but only after you accept analytics in the banner. We don't run advertising or third-party trackers, and analytics never carry the contents of your tenders or bids.
Vraag de Wet (public legal Q&A)
Steinlog is controller for the public "Vraag de Wet" Q&A. Lawful basis: legitimate interests (Art. 6(1)(f)) in operating a free public Dutch procurement-law Q&A — storing questions and answers to serve cached responses, protecting the service (fair-use / abuse controls), and publishing screened, generally applicable Q&A as reference pages — with transparency on this page. Asking a question is not gated on a separate consent click; optional PostHog analytics remain consent-gated (above) and are independent of this processing. You may object to Art. 6(1)(f) processing as described under Your rights.
When you ask a question, we store the question and the generated answer for those purposes. Questions are screened so that names, company details or other personal data are never published; raw questions that are not published are deleted after 90 days. Your IP address is never stored — only a daily-rotating pseudonym used for fair-use limits. Independent of the analytics banner, we record service telemetry for this page (event counts, timings and refusal reasons under a random pseudonym — never the text of your question or your clear IP). Those pseudonymous identifiers may still be personal data under the GDPR; pseudonymisation is not the same as anonymous data. The page is protected against abuse with Cloudflare Turnstile, which processes limited device data to tell people from bots (see Cloudflare's Turnstile privacy policy). Questions are answered with the help of xAI (assistant inference in Ireland / EU) and Voyage AI (embeddings, which may leave the EU), as disclosed on Security.
Retention
- Steinlog B2B customer account & billing (controller) — kept while the organisation's commercial relationship is active. After a confirmed deletion request for that account, we aim to delete primary copies within 30 days. Billing/tax records may be kept longer where Polish law requires it. Operational backups and auth/error logs may lag primary deletion by up to about 90 days.
- Org end-users & customer bid content (processor) — retained while the customer tenant is active and per the customer's deletion instructions. After a confirmed customer deletion / export-and-close request, we aim to delete primary tenant copies within a commercially reasonable period (target 30 days); backups and diagnostic logs that touched that tenant may lag by up to about 90 days. There is no separate automated product retention window beyond tenant lifetime + deletion request today — contact privacy@steinlog.com or use in-product export where available.
- Independent ops telemetry (controller) — rolling operational logs retained as needed for security and reliability (typically on the order of weeks to a few months), then overwritten or deleted.
Your rights
Where GDPR applies, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. For Steinlog-controller data (B2B customer account, billing, independent ops telemetry, consent-gated analytics), contact privacy@steinlog.com. For org end-users and customer bid content in a tenant, your organisation is the controller — we will assist that organisation as processor. You may also lodge a complaint with a supervisory authority (for the Steinlog controller role: UODO in Poland).
Changes
We will update this page when the processing picture changes. Material changes for active
customers are communicated by email or in-product notice where practical. This page stays noindex until we deliberately publish legal
pages for broader traffic.
Steinlog