Scope of this policy
This policy covers this website only. Data that customers send through the Situra service (model requests, keys, usage) is governed by the data processing agreement (DPA), under which Situra acts as processor. We summarise this at the end, in Data processed by the Situra service.
Controller
| Controller | Syntheris Advisory S.L.U. (operator of Situra) |
|---|---|
| Tax ID (NIF) | [NIF pending] |
| Address | [Registered office pending] |
| Privacy contact | privacy@situra.ai |
| Data protection officer | [DPO: name and contact, if appointed] |
Beta and contact form
| Data | Name, organisation, email, role, sector, residency needs and expected volume if you provide them, and your message. |
|---|---|
| Purpose | Answering your request, assessing participation in the private beta and, where relevant, preparing an offer or contract. |
| Legal basis | Steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR). When you write on behalf of an organisation, our legitimate interest in answering business communications (Art. 6(1)(f) GDPR). |
| Retention | Proposed: up to 12 months after the last contact, unless a contract is signed, in which case the data is governed by the contractual relationship and the applicable statutory periods. |
| Is it mandatory? | Fields marked as required are needed to reply. If you prefer not to use the form, you can write directly to privacy@situra.ai. |
Live demo and status page
If you use the live demo (when enabled), the message you type is sent to Situra’s gateway with a public test key and answered by a sandbox, without calling any model or third party. As for any project, the gateway records only request metadata (model, tokens, latency, status, route); the content is not stored. Please do not enter personal data in the demo. The status page fetches a technical summary of the service and sends no data about you.
Server logs
Like any website, the server hosting it records technical data for each request: IP address, date and time, page requested, response code and user agent. These are used only for the security and operation of the site (detecting abuse and errors), on the basis of legitimate interest (Art. 6(1)(f) GDPR), and are not combined with other data or used for analytics.
| Hosting provider | [website hosting provider] |
|---|---|
| Log retention | [period, e.g. 30 days] |
What we do not do
- We use no cookies or tracking technologies. See the cookie policy.
- We use no web analytics, advertising pixels or session-recording tools.
- We load no third-party fonts, scripts or images: everything is served from this domain, so your browser contacts no one else when you visit.
- We do not sell or share personal data, and we make no automated decisions with legal effects on you.
Recipients and transfers
We do not disclose your data to third parties unless legally required. The following access it as processors, under contract:
- The provider that receives form submissions: [form provider, if any].
- The website hosting provider: [website hosting provider].
- The email provider we reply with: [email provider].
If any of them processes data outside the European Economic Area, we will state it here together with the applicable safeguard (adequacy decision or standard contractual clauses).
Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability by writing to privacy@situra.ai and stating which right you are exercising. If we cannot identify you from the data we hold, we may ask for additional information. We will reply within one month, extendable in the cases provided for by the GDPR.
If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or the supervisory authority where you live.
Data processed by the Situra service
When an organisation uses Situra, it is the controller of the data it sends and Situra acts as processor under the DPA. In short: by default only request metadata is logged (who, model, tokens, cost, latency, status); prompt and response logging is opt-in per project and encrypted under the customer’s data key; Situra staff have no access to content. The model and infrastructure providers involved are listed in the sub-processor list, and the technical detail is in Residency & compliance and Security.
Changes
If we change this policy, we will publish the new version on this page with its update date. If a change materially affects data we already hold, we will let you know.