Privacy Policy
Last updated: 21 July 2026
1. Who we are
This website and our marketing are operated by Statera FZCO (“Statera”, “we”, “us”, “our”), a Free Zone Company incorporated in the United Arab Emirates.
- Registered office: 101 IFZA Dubai – Building A2, Dubai Silicon Oasis, DDP, Dubai, United Arab Emirates.
- What we do: we build and market software products — Vettd (AI-assisted recruitment), Archon SEO & GEO, Cortex AMSES (email-marketing analytics), and Statera Resolve (customer-support software).
Statera is the data controller responsible for the personal data described in this policy.
We are based outside the United Kingdom, but because we market to and contact people in the UK, our processing of UK individuals’ personal data is subject to the UK GDPR and the Data Protection Act 2018. (Appointing a UK representative, below, does not mean Statera is established in the UK.)
We have not appointed a Data Protection Officer, as we are not required to; you can reach our privacy contact and our UK representative using the details in Section 14.
Our UK representative (UK GDPR Article 27)
Because Statera is established outside the UK, under Article 27 of the UK GDPR we have appointed a UK representative whom individuals in the UK and the Information Commissioner’s Office (ICO) can contact on any matter relating to our processing of personal data:
- Representative:Daniel Vasilescu (Statera’s UK GDPR Article 27 representative)
- Address: Capital House, 25 Chapel Street, London NW1 5DH, United Kingdom
- Email: privacy@stateratech.io
You can contact our representative instead of, or as well as, contacting us directly.
2. What this policy covers
This policy explains what personal data we collect, why, who we share it with, how long we keep it, how we protect it, and the rights you have. It covers:
- Visitors to our website
www.stateratech.io; - People who contact us or request a demo of our products;
- People who subscribe to our updates, newsletters or resources;
- Business contacts we reach out to as part of our business-to-business (B2B) marketing;
- Marketing consultants and agencies we contact about joining our affiliate (partner) programme; and
- Affiliate partners who join that programme.
It does not cover the personal data that customers process inside our products (where the customer is the controller and Statera acts as their processor) — that is governed by the relevant product terms and data-processing agreement. It also does not cover third-party websites we link to.
3. The personal data we collect
Depending on how you interact with us, we collect:
| You are… | Personal data we collect |
|---|---|
| A website visitor | Technical and usage data — IP address, device/browser type, pages viewed, time spent on pages, referring site, and other analytics data collected via cookies and similar technologies (see Section 7). |
| Someone who contacts us or requests a demo | The details you submit on our forms: your name, work email address, the product you’re interested in, and (optionally) your company, role/job title, country, and a short description of what you’re hoping to achieve. |
| A subscriber | Your name and email address, and your subscription preferences. |
| A business prospect we contact | Business contact details — your name, business email address, job title, and employer/company — together with related professional information used to assess relevance (for example, company size or industry). This also covers marketing consultants and agencies we contact about our affiliate programme. |
| An affiliate partner | Your name and business email; the account identifier our affiliate-tracking and payment providers assign to you; and records of the referrals, commissions and payouts under our affiliate agreement. Depending on how our payment provider is configured, the identity, bank and tax details needed to pay you are collected either by that provider under its own terms, or by us to administer the programme and meet our tax and accounting obligations. |
We do not intentionally collect special-category data (such as health, ethnicity, or political opinions), and we do not knowingly collect data from children (see Section 12).
Filling in our forms is voluntary — you don’t have to give us your details. But if you don’t provide the information a form asks for, we won’t be able to respond to your enquiry or set up a demo for you.
4. Where we get your data
We obtain personal data:
- Directly from you — when you fill in a form, request a demo, subscribe, email us, or otherwise interact with us or our website.
- From your device — automatically, through cookies and similar technologies (Section 7).
- From third-party sources, for our B2B outreach and affiliate-partner recruitment — where we contact business prospects, or marketing consultants and agencies about our affiliate programme, we obtain business contact details from reputable third-party business-data providers (for example, Apollo) and from publicly accessible professional and business sources (such as company websites and professional networking profiles).
Where we obtain your data from these third-party sources, we provide you with this privacy information at the latest when we first contact you — normally by linking to this policy in that first message.
5. How and why we use your data — and our lawful bases
We only use your personal data where the law allows. Our purposes and lawful bases are:
| What we do | Why | Lawful basis (UK GDPR) |
|---|---|---|
| Respond to your enquiry or demo request; set up and run the demo | To give you what you asked for | Article 6(1)(b) — steps taken at your request before entering a contract; and/or Article 6(1)(f) legitimate interests (responding to enquiries). |
| Send you our newsletter/updates you signed up for | To keep you informed as you asked | Article 6(1)(a) — consent (which you can withdraw at any time). |
| Contact business prospects about our products (B2B marketing) | To promote our products to relevant businesses | Article 6(1)(f) — legitimate interests in marketing to relevant business contacts, subject to a legitimate-interests balancing assessment we carry out and maintain for each product. |
| Contact marketing consultants and agencies to invite them to join our affiliate (partner) programme (we use automated relevance scoring, reviewed by a person, to decide who is a good fit to contact — this does not by itself make any decision with legal or similarly significant effect about you, see Section 15) | To recruit partners who refer our products to their own clients | Article 6(1)(f) — legitimate interests in recruiting affiliate partners, subject to a legitimate-interests balancing assessment we carry out and maintain. |
| Administer our affiliate programme for partners who join — track referrals and commissions, and make payouts | To operate the affiliate partnership | Article 6(1)(b) — performing our agreement with you; and, to keep the tax and accounting records we are required to keep and to establish or defend legal claims, Article 6(1)(f) legitimate interests. |
| Understand and improve our website and campaigns | To operate and improve our marketing | Article 6(1)(f) — legitimate interests, and, for non-essential cookies, consent under PECR (Section 7). |
| Keep records of opt-outs / unsubscribes | To honour your choices and prove we did | Article 6(1)(f) — legitimate interests (we keep a suppression record so we can continue to respect your objection; we rely on the Article 17(3) exemption from erasure to retain it — see Section 8). |
| Comply with our legal obligations; establish or defend legal claims | Compliance and protecting our rights | Article 6(1)(c) legal obligation; Article 6(1)(f) legitimate interests. |
Where we rely on legitimate interests, you have the right to object (Section 10); where we rely on consent, you can withdraw it at any time.
6. Direct marketing and your right to object
When we send you B2B marketing or affiliate-recruitment email, we tell you — at the latest in our first message — why we are contacting you, where we obtained your details, and how to object or opt out. You have an absolute right to object to direct marketing at any time: if you object or unsubscribe, we will stop sending you marketing, and we keep a record of your request so we can honour it (Section 8).
We take steps to direct our business-to-business marketing at corporate subscribers (companies, LLPs and public bodies), for whom the Privacy and Electronic Communications Regulations (PECR) permit business marketing email, and to screen out individual subscribers (such as sole traders or non-LLP partnerships) where we can identify them. Because we contact people before we hold a relationship with them, we cannot always tell an individual subscriber apart from a company, so some of our marketing may reach an individual subscriber in error. If that happens, you have an absolute right to object and to unsubscribe at any time (see above), and we will stop.
7. Cookies and similar technologies
Our website uses cookies and similar technologies, including for analytics (to understand how the site is used). Cookies that are strictly necessary to provide the site work without consent. Whether we ask for your consent before setting non-essential (analytics) cookies depends on where you are: if you are in the UK, the EEA, Brazil or the UAE, we ask for your consent through our cookie banner and analytics stays off until you agree; if you are elsewhere, we set analytics cookies by default and you can opt out at any time (and we respect a Global Privacy Control signal where your browser sends one). You can change or withdraw your choice at any time using the cookie settings control on the site.
Full details of the specific cookies we use, their purpose and duration, and the third parties involved are in our Cookie Policy at https://www.stateratech.io/cookies.
8. Who we share your data with, and how long we keep it
Who we share it with. We do not sell your data. We share it only with:
- Service providers (processors) who help us run our website and marketing, under contracts that require them to protect your data and use it only on our instructions — including providers of website hosting and content delivery, product analytics, email delivery, customer/marketing data storage, email-outreach tooling, and — for our affiliate programme — affiliate-programme management and payment processing. Where our payment provider collects identity, bank and tax information from affiliates to make payouts, it may act as an independent controller of that information under its own privacy terms.
- Professional advisers, regulators and authorities where we are required to, or need to, share data for legal, regulatory or compliance reasons; and
- A buyer or successor if we sell or reorganise our business, subject to appropriate protections.
How long we keep it. We do not keep personal data for longer than we need it. Because the right retention period depends on why we hold the data, we set retention against the criteria below and review what we hold on a regular, scheduled basis, deleting or anonymising data we no longer need.
| Category of data | How long we keep it |
|---|---|
| Prospect / cold B2B marketing data (business contact details we have sourced or collected to assess whether our products are relevant to you, or to invite you to our affiliate programme) | We review this data regularly and delete records that show no engagement for 12 months (for example, no reply, meeting, or expression of interest). We keep a prospect record for at most 24 months where there is ongoing, documented business relevance. We delete or anonymise sooner if the data is inaccurate, irrelevant, or no longer needed. |
| Affiliate partner records (commission and payment records, and the identity linked to them, for people who join our affiliate programme) | For the life of the partnership and then for the period we are required to keep tax and accounting records (currently up to 7 yearsfrom the end of the relevant year), after which we delete or anonymise them — unless a longer period is needed to establish or defend a legal claim. Identity, bank and tax details used to pay affiliates are — depending on how our payment provider is configured — collected either by that provider under its own privacy terms, or by us to administer the programme and meet our tax and accounting obligations (Section 8, “Who we share your data with”). |
| Enquiry and demo records (where you contact us, book a demo, or start an evaluation) | For the duration of our discussions and for up to 24 months after our last meaningful contact — unless a longer period is required to perform a contract or meet a legal obligation. |
| Newsletter / marketing subscribers | For as long as you remain subscribed. If you unsubscribe we stop marketing to you immediately and move you to our suppression list (below); we also periodically remove long-inactive subscribers. |
| Website analytics data (e.g. PostHog usage and event data) | This data is pseudonymous — we discard IP addresses and do not link it to your identity. We delete a visitor’s analytics records, including their events, once they have been inactive for more than 14 months, through an automated monthly process (and may aggregate older data into anonymous statistics). Analytics associated with a demo or enquiry is retained under the enquiry/demo period above. |
| Suppression / do-not-contact records | We keep a minimal suppression record for as long as we operate — only the details needed to make sure we do not contact you again (for example, a hashed identifier and the date and scope of your opt-out). We keep this specifically to honour your request, relying on our legitimate interest in respecting your preferences, and we do not delete it in response to an erasure request, because doing so could mean we contact you again by mistake. |
We may keep data for longer only where we have a specific, documented and lawful reason (such as an ongoing contract, a dispute, or a legal obligation), and for no longer than that reason requires.
9. Transfers of your data outside the UK
Statera FZCO is established in the United Arab Emirates. The UAE is not currently covered by a UK “adequacy” decision. Where UK data protection law applies to our processing of your personal data, we handle international transfers as follows.
When you give us your information directly.When you submit your details to us directly — for example through a form on our website, or by replying to one of our emails — you are sending that information to us in the UAE yourself. Under UK guidance that step is not a “restricted transfer”, because there is no separate UK-based organisation transferring your data on your behalf. We protect the information you send us with appropriate technical and organisational safeguards, and we handle any onward transfers to our service providers as described next.
When we use service providers outside the UK.To run our website, communications and systems we use trusted service providers, some of which are located in, or store data in, the United States (for example, hosting, content delivery, transactional email, database and infrastructure providers). Where we transfer personal data protected by UK law to these providers, we rely on the UK-approved standard data protection clauses — the UK International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the EU Standard Contractual Clauses — as incorporated into those providers’ data processing agreements, backed by a transfer risk assessment as required by UK data protection law.
Providers in the UK, the EEA, or another adequate country.Some providers store data within the European Economic Area (for example, our product-analytics provider on its EU-hosted service), or contract through an entity in another country the UK recognises as “adequate”. Transfers to the EEA or to another adequate country are not “restricted transfers” under UK law, so no additional transfer safeguard is required for them.
What “safeguards in place” means.Where we say safeguards are “in place”, we mean that the relevant standard contractual clauses are incorporated into our agreements with those providers and that we have assessed the transfer; it does not mean any country involved has been formally recognised as “adequate” by the UK. You can ask us for more information about the safeguards that apply to a particular transfer using the contact details in Section 14.
10. Your rights
Under UK data protection law you have the right to:
- be informed about how we use your data (this policy);
- access the personal data we hold about you;
- ask us to correct inaccurate data or complete incomplete data;
- ask us to erase your data in certain circumstances;
- ask us to restrict our use of your data in certain circumstances;
- object to our processing based on legitimate interests (we will stop unless we can show compelling legitimate grounds to continue), and to direct marketing at any time (this objection is absolute — once you object to marketing, we stop);
- ask us to port certain data to another provider; and
- withdraw consent at any time where we rely on consent (this does not affect processing already carried out).
There is usually no charge, and we aim to respond within one month. To exercise any right, contact us (Section 14). We may need to verify your identity first.
11. How we protect your data
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse — including access controls, encryption of data in transit, and contractual and security controls on the service providers we use. No system is perfectly secure, but we take these obligations seriously and keep our measures under review.
12. Children
Our website and products are intended for businesses and professionals, not children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. We do not sell or share your personal information
Statera does not sell your personal information, and does not “share” it for cross-context behavioural advertising, as those terms are used under United States state privacy laws (including the California Consumer Privacy Act). Our use of analytics is a first-party business purpose and is not “selling” or “sharing”.
14. How to contact us, and how to complain
To contact us about your privacy or to exercise your rights:
- Email: privacy@stateratech.io
- Post: Statera FZCO, 101 IFZA Dubai – Building A2, Dubai Silicon Oasis, DDP, Dubai, United Arab Emirates.
Our UK representative (for individuals in the UK): Daniel Vasilescu, Capital House, 25 Chapel Street, London NW1 5DH, United Kingdom — privacy@stateratech.io.
Complaints. If you have a concern about how we handle your data, please contact us first — we will try to resolve it. You also have the right to complain to the UK supervisory authority, the Information Commissioner’s Office (ICO) (which is being reconstituted as the Information Commission): ico.org.uk/make-a-complaint, helpline 0303 123 1113.
15. Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.
16. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top shows when. Where changes are significant, we will take reasonable steps to bring them to your attention.