← Back to Steppica AI
Privacy Policy
Last Updated: September 2025 | Version: 1.1
1Introduction
Steppica AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website steppica.com or use our AI-powered newsroom platform services.
2Information We Collect
2.1 Personal Information
- Name and contact information (email, phone)
- Company/organization details
- Professional role and industry information
- Demo request preferences
2.2 Technical Information
- IP address and browser information
- Device and operating system details
- Website usage analytics (pages visited, time spent)
- Cookies and similar tracking technologies
2.3 Content and Usage Data
- News content processed through our AI modules
- API usage statistics and performance metrics
- User interaction data with our platform
3How We Use Your Information
We use collected information for:
- Providing and improving our AI newsroom services
- Processing demo requests and customer support
- Personalizing user experience and content
- Analyzing usage patterns to enhance our platform
- Sending marketing communications (with consent)
- Complying with legal obligations
4Legal Basis for Processing (GDPR)
We process personal data based on:
- Consent: For marketing communications and non-essential cookies
- Contract: To provide our services and fulfill agreements
- Legitimate Interest: For analytics, security, and service improvement
- Legal Obligation: For compliance with applicable laws
5Data Sharing and Disclosure
We may share your information with:
- Service Providers: AWS (hosting), Formspree (form processing), analytics providers
- Business Partners: Astana Hub, technology integration partners
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with mergers or acquisitions
We never sell your personal data to third parties.
6International Data Transfers
Your data may be processed in:
- Kazakhstan (our headquarters)
- European Union (GDPR-compliant processing)
- United States (with appropriate safeguards via AWS)
All international transfers are protected by appropriate safeguards including Standard Contractual Clauses.
7Data Security
We implement industry-standard security measures:
- SSL/TLS encryption for data transmission
- Secure cloud infrastructure (AWS)
- Access controls and authentication
- Regular security audits and monitoring
- Employee training on data protection
8Data Retention
- Marketing data: Until consent is withdrawn
- Customer data: For the duration of our business relationship + 7 years
- Analytics data: 26 months maximum
- Legal obligations: As required by applicable law
9Your Rights
Under GDPR and other privacy laws, you have the right to:
- Access: Request copies of your personal data
- Rectification: Correct inaccurate information
- Erasure: Delete your data ("right to be forgotten")
- Portability: Transfer data to another service
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: For consent-based processing
10Cookies and Tracking
We use the following types of cookies:
- Essential: Required for website functionality
- Analytics: To understand website usage (Google Analytics)
- Marketing: For targeted advertising (with consent)
You can manage cookie preferences through our cookie banner or browser settings.
11Children's Privacy
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal information from children under 16.
12Region-Specific Provisions
12.1 Kazakhstan
We comply with the Law of the Republic of Kazakhstan "On Personal Data and their Protection."
12.2 California (CCPA)
California residents have additional rights including the right to know what personal information is sold and to opt-out of sale.
13Updates to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or website notice. Continued use of our services after changes constitutes acceptance.
This Privacy Policy is designed to comply with GDPR, CCPA, and Kazakhstan data protection laws. For specific legal advice, please consult with a qualified attorney.