Privacy Policy
Last updated: 19 July 2026 · Version 1.0
This policy explains how Stegi ("we", "us") processes personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and Cyprus Law 125(I)/2018. Stegi is operated from the Republic of Cyprus. Contact for all privacy matters: support@stegi.app. We have not appointed a Data Protection Officer, as we are not required to; the contact above reaches the person responsible for data protection.
1. Our two roles
Controller — landlord accounts. For the personal data of account holders (name, email, phone, language preference, login and security data, and the records you create), we determine the purposes and means of processing and act as controller.
Processor — tenant data.For personal data that landlords enter about other people (tenant names, contact details, identity numbers, tenancy and payment records, maintenance reports), the landlord is the controller and we process solely on the landlord's documented instructions, as their processor, under Article 28 GDPR. This policy, together with the Terms of Service, constitutes the data-processing agreement between us and each landlord: we process tenant data only to provide the Service, apply the security measures described below, engage only the sub-processors listed below, assist with data-subject requests, and delete the data on account deletion.
2. What we process, why, and on what legal basis
- Account and profile data (name, email, phone, language) — to provide the Service. Basis: contract (Art. 6(1)(b)).
- Property, tenancy, financial, and maintenance records— to provide the Service's core features. Basis: contract; for tenant data, the landlord's instructions.
- Transactional emails(rent reminders, account notices) — to perform the Service. Basis: contract; for reminder content concerning tenants, the landlord's instructions.
- Professional (contractor) requests — your contact details and the issue description are shared with our operations team and, where a job is arranged, with the contractor. Basis: contract / legitimate interest in fulfilling your request.
- Security and technical logs (IP address, timestamps) — to keep the Service secure and prevent abuse. Basis: legitimate interest (Art. 6(1)(f)).
We do not sell personal data, run advertising or tracking cookies, profile tenants, or make automated decisions with legal effect.
3. Cookies
Only strictly necessary cookies are used, which require no consent banner:
- Authentication cookies (names beginning
sb-) — keep you logged in; session lifetime. stegi_lang— remembers your language; 12 months.
Analytics. We measure aggregate page views and referrers using Vercel Web Analytics, which sets no cookies, builds no profile of you, and does not track you across other websites. It records the page visited, a coarse country, and the referring site. Basis: legitimate interest (Art. 6(1)(f)) in understanding which pages are useful.
4. Recipients and sub-processors
- Supabase — database, authentication, storage (Postgres hosted in the EU).
- Vercel — application hosting, content delivery, and cookieless page-view analytics.
- Resend — transactional email delivery.
- Independent maintenance contractors — only the details needed to carry out a job you requested.
Sub-processors are bound by data-processing agreements. Where processing involves transfers outside the EEA (for example by our hosting or email providers' infrastructure), transfers are safeguarded by the EU Standard Contractual Clauses and supplementary measures. We will give account holders notice before adding a sub-processor that processes tenant data.
5. Retention
- Account and records data — for as long as your account exists. Deleting your account (Settings → Delete account) erases all records immediately and permanently.
- Encrypted backups — expire automatically on the backup rotation schedule (up to 30 days after deletion).
- Security logs — up to 12 months.
- Emails to support — up to 24 months for accountability.
6. Your rights
Under the GDPR you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection. Two are built into the product: export everything (Settings → Download my data) and erase everything (Settings → Delete account). For anything else, email support@stegi.app; we respond within one month. If you are a tenant, please direct requests to your landlord, who is the controller of your data — we assist landlords in fulfilling them and will pass your request on where you contact us directly.
You may lodge a complaint with the supervisory authority: Commissioner for Personal Data Protection, 15 Kypranoros Street, 1061 Nicosia, Cyprus (dataprotection.gov.cy), or with the authority of your EU country of residence.
7. Security
Measures include: encryption in transit (TLS) and at rest; per-account isolation enforced with database row-level security; unguessable tokens for tenant links; least-privilege service credentials; security headers; and EU-hosted infrastructure. No system is perfectly secure; if a breach is likely to result in a risk to your rights, we will notify the Commissioner within 72 hours and affected users without undue delay, as the GDPR requires.
8. Children
The Service is for adults managing tenancies and is not directed at children under 18; we do not knowingly process children's data as controller.
9. Changes
Material changes to this policy will be notified to account holders by email or in-app before they take effect. The date above always identifies the current version.