Privacy Policy

Last updated: 12 July 2026

Your privacy matters. This policy explains what data STEER collects, why, and your rights under GDPR, CCPA/CPRA and other applicable privacy law.

1. Data Controller & Privacy Contact

S.E. SMARTERS ENGINEERED LTD

Efesou 9, 5290 Paralimni, Famagusta, Cyprus

Company Reg.: HE465488 · VAT: CY60097979Z

Privacy contact: [email protected]

Person responsible: Sebastian Pardo, Director (acting privacy lead)

We have not yet appointed a formal Data Protection Officer under GDPR Article 37, as we are evaluating whether our processing meets the “large scale, regular, and systematic monitoring” threshold. We will appoint a DPO and update this page if and when that threshold is met.

2. What data we collect

When you use the STEER device and mobile application, we may collect:

  • Vehicle diagnostic data: VIN (Vehicle Identification Number), fault codes (DTCs), sensor readings (engine temp, RPM, speed), mileage
  • Account data: email address, hashed password, subscription status
  • Device metadata: iOS device model, app version, crash logs
  • Payment data: processed by Stripe; we never store full card numbers
  • Order & shipping data: name, shipping address, phone number and order details — needed to fulfil and ship your hardware order
  • Usage analytics: anonymised app interaction events to improve the product

2.1 Sensitive Data — special handling

The ST013B device does not collect biometric, health, racial, religious, political, union-membership or sexual-orientation data. The VIN, when combined with account information, identifies a specific vehicle and therefore indirectly its registered owner; we treat VIN as personal data under GDPR. The device does not collect precise GPS location. Speed, RPM and mileage readings are local vehicle measurements only and are not used to derive geographic location.

2.2 Cookies & Trackers

The steer.so website uses only strictly necessary cookies for session and checkout functionality (exempt from consent under ePrivacy Directive 2002/58/EC Article 5(3)). We do not use third-party advertising cookies, cross-site tracking pixels, or analytics cookies that require consent. The STEER mobile application does not use the IDFA advertising identifier and does not track users across other companies' apps or websites within the meaning of Apple's App Tracking Transparency framework.

If we add optional analytics or marketing cookies in the future, we will deploy a GDPR/ePrivacy-compliant consent management platform before doing so.

2.3 Children

STEER services are intended for adults aged 18 and over and are not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

3. Legal basis (GDPR Art. 6)

We process personal data on the following legal bases, mapped to specific purposes:

PurposeLegal basisRetention
Account creation, authentication, subscription managementContract — Art. 6(1)(b)Account life + 30 days
Vehicle diagnostic features and AI-assisted insightsContract — Art. 6(1)(b)Subscription duration + 12 months
Payment processingContract — Art. 6(1)(b); legal obligation — Art. 6(1)(c)10 years (Cyprus tax law)
Product improvement, fraud prevention, IT securityLegitimate interest — Art. 6(1)(f)24 months
Customer support communicationsContract — Art. 6(1)(b); legitimate interest — Art. 6(1)(f)3 years from last contact
Marketing emails / newslettersConsent — Art. 6(1)(a)Until withdrawal of consent
Tax records, accounting, statutory complianceLegal obligation — Art. 6(1)(c)10 years

Where we rely on legitimate interest, our interest is the secure, reliable operation and continuous improvement of the STEER service. We have performed a balancing test (Legitimate Interests Assessment) confirming this interest is not overridden by your rights and freedoms. You may object to such processing at any time — see Section 6.

Provision of account and device data is required to provide the STEER service. Without it we cannot deliver the contracted service. Provision of marketing-related data is voluntary.

4. How we use your data

  • Deliver diagnostic features and AI-assisted insights
  • Process subscriptions and payments
  • Provide customer support
  • Improve product reliability and accuracy
  • Detect and prevent abuse, fraud, or security incidents

5. Sub-processors & Data Sharing

We do not sell personal data. We use the following sub-processors, each bound by a written data processing agreement compliant with GDPR Article 28 and CCPA service-provider requirements:

Sub-processorPurposeLocationTransfer mechanism
Stripe Payments Europe Ltd / Stripe Inc.Card payments, billingIreland, USAEU-US Data Privacy Framework + SCCs
RevenueCat, Inc.Subscription state managementUSAEU-US Data Privacy Framework + SCCs
Anthropic PBC (Claude API)AI-assisted diagnostic insights — input data not used to train modelsUSAEU-US Data Privacy Framework + SCCs
Self-hosted Supabase (Hetzner Cloud)Database, authentication, file storageEU (Germany)No third-country transfer
Bunny CDNStatic asset deliveryEU primary, global edgeSCCs (where applicable)
Apple Inc. (App Store, IAP)App distribution, in-app purchasesUSA, IrelandEU-US Data Privacy Framework
Resend (Plus Five Five, Inc.)Transactional email delivery (order confirmation, sign-in codes) — processes your email addressUSAEU-US Data Privacy Framework + SCCs
Mintsoft Ltd & Scovia (3PL fulfilment)Order fulfilment and shipping — receives name, shipping address and phoneUK, USASCCs / UK IDTA

For transfers outside the EEA we rely, in this order of preference: (1) the European Commission's adequacy decision under the EU-US Data Privacy Framework (Decision (EU) 2023/1795) for U.S.-based DPF-certified recipients; and (2) the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, supplemented by encryption in transit and at rest. We have conducted a Transfer Impact Assessment (TIA) for each non-EEA transfer; a copy is available on request to [email protected].

We may also disclose data to legal authorities when required by binding law or court order, after assessment of the request's legality and proportionality.

6. Your rights under GDPR

If you are in the EU/EEA, you have the right to:

  • Access the data we hold about you (Art. 15)
  • Correct inaccurate or incomplete data (Art. 16)
  • Request deletion (“right to be forgotten”) (Art. 17)
  • Restrict processing in certain circumstances (Art. 18)
  • Object to processing based on legitimate interests, including profiling (Art. 21)
  • Receive your data in a structured, commonly used, machine-readable format and transmit it to another controller (Art. 20)
  • Withdraw any consent you have given, at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3))
  • Lodge a complaint with your local supervisory authority. In Cyprus this is the Office of the Commissioner for Personal Data Protection (Iasonos 1, 1082 Nicosia)

To exercise any right, email [email protected]. We will respond within one month (extendable by two further months for complex requests under Art. 12(3)).

6.1 Automated decision-making

The STEER app uses Anthropic's Claude large language model to translate diagnostic fault codes (DTCs) and sensor readings into plain-language explanations. This is a decision-support feature: it provides information to help you understand your vehicle, but it does not produce legal effects or significantly affect you within the meaning of GDPR Article 22. You always retain control of decisions about your vehicle. You may request human review of any AI-generated explanation by contacting [email protected].

7. US Residents — State Privacy Rights

If you are a resident of the United States, the following rights apply depending on your state of residence (including but not limited to California — CCPA/CPRA, Virginia — VCDPA, Colorado — CPA, Connecticut — CTDPA, Utah — UCPA, Texas — TDPSA, Oregon — OCPA, Montana — CDPA):

  • Right to know / access: categories and specific pieces of personal information we have collected, sources, purposes and recipients (12-month look-back, or all data under most state laws).
  • Right to delete: request deletion of personal information we have collected from you, subject to legal exceptions.
  • Right to correct inaccurate personal information.
  • Right to data portability in a structured, machine-readable format.
  • Right to opt out of sale or sharing (cross-context behavioural advertising). We do not sell personal information and do not share it for cross-context behavioural advertising as those terms are defined under CPRA.
  • Right to limit use of sensitive personal information. We do not collect precise geolocation, biometric identifiers, racial/ethnic origin, religious beliefs, union membership, health, sexual orientation, immigration status, or genetic data through the STEER service.
  • Right to non-discrimination for exercising any of the above rights — we will not deny you the service or charge a different price.

CCPA Notice at Collection — categories of personal information collected (last 12 months)

  • Identifiers (name, email, account ID, IP address, device IDs, VIN) — purpose: provide service, security, billing.
  • Commercial information (subscription status, purchase history) — purpose: subscription management.
  • Internet/network activity (app usage events, crash logs) — purpose: reliability, fraud prevention.
  • Geolocation data — approximate location inferred from IP address only; no precise GPS coordinates collected.
  • Inferences from vehicle telemetry (DTC categorisation, maintenance suggestions) — purpose: provide diagnostic features.

To exercise any state privacy right, email [email protected] with subject line “US State Privacy Request — [Right]”. We verify identity using your account email + a recent order or transaction reference. We respond within 45 days (extendable by 45 days for complex requests). You may also designate an authorised agent to make a request on your behalf in accordance with applicable state law.

8. Data retention

We retain personal data only as long as necessary to provide the service or comply with legal obligations. See the retention table in Section 3 for category-specific periods.

9. Security

STEER implements industry-standard technical and organisational measures including TLS encryption, encrypted databases, role-based access control, and regular security audits. The ST013B device complies with EN 18031-1 (cybersecurity) and EN 18031-2 (privacy) under EU Delegated Regulation (EU) 2022/30.

9.1 Data Breach Notification

In the event of a personal data breach that creates a risk to your rights and freedoms, we will notify the Cyprus Office of the Commissioner for Personal Data Protection within 72 hours of becoming aware of the breach (GDPR Art. 33). Where the breach is likely to result in a high risk to you, we will notify you directly and without undue delay (GDPR Art. 34). For US residents, we will comply with all applicable state breach notification statutes.

10. Changes to this policy

We may update this policy from time to time. Material changes will be announced in-app and via email. The “Last updated” date at the top of this page reflects the most recent revision.

11. Contact

S.E. SMARTERS ENGINEERED LTD

Efesou 9, 5290 Paralimni, Famagusta, Cyprus

Privacy queries: [email protected]

General support: [email protected]