Your financial records are yours
We process them as your processor, on your documented instructions, for the purpose of running the service. Not to build products for anyone else.
Almost everything Stratiri processes is your company’s financial data, held on your instructions. A much smaller amount is personal data about the people who use the product and the people we talk to. This notice separates the two, because the rules are different.
The sections below are the binding text. This is what they add up to, for anyone who needs the answer rather than the wording.
We process them as your processor, on your documented instructions, for the purpose of running the service. Not to build products for anyone else.
No sale of personal data, no sharing for cross-context advertising, no data brokers, and no advertising trackers on this website.
Questions asked in Shared Intelligence go to an inference provider under terms that exclude training and retention. Nothing about your business ends up in a general model.
Regional deployment options support groups operating across major markets. The appropriate setup and any permitted data flows are agreed before connections are made.
Customer data is deleted or returned within thirty days of the contract ending, other than what we are legally required to keep and can name.
privacy@stratiri.com reaches a person, not a queue. Rights requests are acknowledged inside five working days.
Stratiri provides a financial intelligence platform that sits above the systems a company already runs. This notice explains how Stratiri handles personal data across the marketing site, the product, and the conversations that lead to a contract.
It does not cover the websites of the ERP, banking or planning providers you connect to Stratiri. Those relationships remain yours, and their own notices apply.
Stratiri is a processor for the financial and operational records a customer connects. Receivables, payables, bank transactions, ledger entries and the personal data embedded inside them — a supplier contact, an account owner, an approver’s name — are processed on the customer’s documented instructions under a data processing agreement. The customer decides why that data exists and what happens to it. We do not use it for our own purposes.
Stratiri is a controller for a narrow set of personal data it decides about itself: the account details of the people who log in, the contact details of people who ask for a demo, support correspondence, and the technical logs needed to keep the service running and secure.
If you are an employee of a Stratiri customer and your question is about data inside your company’s workspace, your own employer is the controller. Ask them first; we will support their response but we cannot answer for them.
Only the last column changes what we are allowed to do with a category, so it is stated for each rather than summarised at the end.
| Category | What it includes | Lawful basis |
|---|---|---|
| Account data | Name, work email, organisation, role and the permissions granted to you inside a workspace. | Contract |
| Connected records | Financial and operating data drawn from the systems a customer connects, including any personal data those records contain. | Processor·customer’s basis |
| Usage and technical | Sign-in events, IP address, device and browser, pages viewed and actions taken, and application error traces. | Legitimate interests |
| Support and correspondence | Messages you send us, the context you attach, and our replies. | Contract·legitimate interests |
| Enquiries | The details you give when requesting a conversation, and notes from the calls that follow. | Legitimate interests |
| Billing | Contracting entity, billing contact, purchase order references and invoice history. | Contract·legal obligation |
We do not knowingly collect special category data, and the product is not designed to hold it. If it reaches us inside a connected record, tell us and we will remove it.
To provide the service: authenticate you, build and maintain the financial model from the records you connect, answer questions inside the product, and prepare the outputs you ask for.
To keep it working: monitor availability, investigate faults, detect abuse, and maintain the audit trail that lets a figure be traced back to the record it came from.
To support and improve it: respond to your questions, and understand in aggregate which parts of the product are used, so we invest in the right ones. Product analytics run on aggregated usage, not on the content of your financial records.
To run the business: contract, invoice, and meet accounting, tax and regulatory obligations.
Where we rely on legitimate interests, we have weighed those interests against your rights and can share that assessment. You can object at any time using the address in section 11.
Stratiri is designed for regional deployments across major markets. Depending on the agreed architecture and service availability, a customer may use a setup aligned to Europe, the United States or Asia-Pacific. Exact provider locations and permitted data flows are documented for the deployment before the first connection is made.
Where personal data crosses a legal boundary, the applicable transfer mechanism and safeguards are recorded in the contract and supporting data-processing documentation. Regional availability varies by service, so this notice does not promise every component in every geography.
| Connected records | For the term of the contract. Deleted or returned within thirty days of termination, on the customer’s instruction. |
|---|---|
| Account data | For as long as the account is active, then twelve months, so an accidental removal can be reversed. |
| Audit logs | For the term of the contract, then twelve months, because they are evidence for financial controls and are frequently needed after the fact. |
| Technical logs | Ninety days. |
| Enquiries and correspondence | Twenty-four months from the last contact. |
| Billing records | As required by accounting and tax law in the contracting jurisdiction, typically seven years. |
Backups age out on their own schedule, so a deleted record can persist in a snapshot for up to thirty days after deletion. Those snapshots are encrypted, and are not used to restore individual records.
Where Stratiri is the controller, you can ask for access to your data, correction of anything inaccurate, deletion, restriction of processing, portability of what you gave us, and you can object to processing based on legitimate interests. You can also withdraw consent where consent is what we relied on, without affecting what came before.
Write to privacy@stratiri.com. We acknowledge within five working days and respond within one month, and will say so early if a request is complex enough to need the two-month extension the law allows. We do not charge for this.
Where Stratiri is a processor, requests are forwarded to the customer who controls the workspace, and we assist them in responding. We will confirm to you that we have done so.
You can complain to a supervisory authority in the country where you live or work. We would rather you came to us first, but nothing here requires it.
Encryption in transit and at rest, tenant isolation enforced at the database rather than in application code, single sign-on with directory provisioning, audit logging of access and approvals, and time-boxed, logged support access. The full control set, the sub-processor list and the vendor review process are on the security page.
If we confirm a personal data breach affecting your data, we notify you in writing within twenty-four hours with what we know, what we do not yet know, and when the next update will come.
Material changes are notified to customer administrators by email at least thirty days before they take effect, and the version and effective date at the top of this page are updated every time. Superseded versions are kept and can be requested.
Privacy questions, rights requests and data processing agreement queries all go to privacy@stratiri.com. Security questions go to security@stratiri.com. Anything else, use the contact page.