1. Scope and controller
This Privacy Statement explains how SteadyOp, a Fyniche product (“SteadyOp,” “we,” “us,” or “our”), processes personal data when you visit our website, use the SteadyOp service, import business data, upload a document, use the operations mailbox, or contact us.
For customer workspace content, the customer normally determines why the data is processed and SteadyOp acts as its processor. For account administration, service security, billing, product operations, and our website, SteadyOp generally acts as controller.
2. Data we collect
- Account and organization data, such as name, email address, organization, role, authentication identifiers, mailbox handle, and account preferences.
- Imported business data, including spreadsheets, CSV files, PDFs, images, documents, contacts, schedules, and related metadata that you choose to upload.
- SteadyOp Native records, mailbox messages, prompts, drafts, approvals, agent results, schedules, inventory movements, OCR text, and audit history.
- Technical and usage data, such as IP address, device and browser information, timestamps, security events, feature activity, model/token usage, and diagnostic logs.
- Support, billing, and communications data you provide when contacting us or managing a subscription.
3. Workspace data and operations mail
SteadyOp stores business records and import metadata in a workspace scoped to the customer organization. Uploaded files are kept in private object storage and linked to the resulting records where appropriate.
The built-in operations mailbox uses Resend to send and receive mail for the organization-specific address. Incoming mail is routed by the recipient address, and outgoing mail is sent only after an authorized user or approved workflow requests it.
4. Why we use data
- Provide, personalize, and maintain the service and connected workflows.
- Authenticate users, enforce workspace permissions, and prevent fraud or abuse.
- Run requested AI analysis, document recognition, search, drafts, automations, and approved actions.
- Maintain source-linked records, audit trails, usage accounting, reliability, and support.
- Comply with law, enforce agreements, and protect users, SteadyOp, and third parties.
- Improve product quality using service telemetry and feedback. We do not sell personal data or use workspace content for targeted advertising.
5. Legal bases
Where the GDPR or similar law applies, we process personal data as necessary to perform our contract with you; based on legitimate interests in operating, securing, supporting, and improving the service; with consent where required; and to comply with legal obligations.
You may withdraw consent at any time, but withdrawal does not affect processing already performed lawfully.
7. AI and document processing
Prompts, authorized source context, and uploaded images or documents may be sent to configured AI providers to complete the task you request. We limit the data sent to what is reasonably needed and instruct document-reading systems to treat uploaded content as untrusted evidence rather than instructions.
AI output and extracted fields are presented for review where appropriate. Consequential actions are subject to workspace controls and approval rules.
8. Retention and deletion
We retain personal data for as long as needed to provide the service, maintain security and audit records, meet legal obligations, resolve disputes, and enforce agreements. Retention varies by data type and customer settings.
Unconfirmed private document uploads may be removed automatically after a limited review period. Registered records and their source documents remain until deleted under the workspace’s controls or an applicable request, subject to legal and security requirements.
9. Security
We use measures designed to protect data, including access controls, workspace scoping, server-side credentials, encrypted transport, private object storage, bounded uploads, rate limits, security headers, audit records, and confirmation gates. No method of storage or transmission is completely secure.
10. International transfers
SteadyOp and its providers may process data outside your country. Where required, we use recognized safeguards such as adequacy decisions, standard contractual clauses, or another lawful transfer mechanism.
11. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to complain to a supervisory authority. Workspace administrators may fulfill requests involving customer-controlled workspace data.
- Edit or delete imported workspace records using organization controls.
- Export operational records and the Work Ledger where available.
- Request account or personal-data assistance through privacy@steadyop.com.
- Object to direct marketing or unsubscribe using the link in a marketing message.
13. Children
SteadyOp is a business service and is not directed to children under 18. We do not knowingly collect personal data from children through the service.
14. Changes to this statement
We may update this Privacy Statement as the service or law changes. We will post the revised statement with a new effective date and provide additional notice for material changes where required.
15. Contact
Privacy questions and rights requests can be sent to privacy@steadyop.com. General support is available at support@steadyop.com or on our Support page.