Privacy Policy
Version: Launch Suite vL1 (rev. 8.1) · Effective date: 29 September 2026
Document title: Privacy Policy
Governing law: England & Wales Controller: Steelo Labs Ltd
Plain-English Overview
What this policy says in brief: Steelo Labs Ltd ("Steez", "we", "us") operates the Steez platform. This policy tells you what personal information we collect when you use Steez, why we collect it, who we share it with, how long we keep it, and what rights you have. Steez's paid services are offered in the UK and US at launch; depending on where you live, additional local data-protection rights may apply, and this policy explains those too (see sections 3, 3A and 3B). It is a legal document; it has been written as plainly as possible, but if anything is unclear, please contact us using the details in section 2.
1. Who We Are
Controller: Steelo Labs Ltd (incorporated in England & Wales) Registered office: Steelo Labs Ltd, 3 Harebell Close, Hamilton, Leicester, England, LE5 1UX Company number: 15553648 ICO registration number: ZB826048 Company domain: steelo.io Product domain: steez.space (preferred for user-facing references)
Steelo Labs Ltd is the data controller for personal data processed through the Steez mobile application and associated web services. Where Stripe, Inc. processes identity and banking data as part of its Know Your Customer (KYC) verification for Creator payout accounts, Stripe acts as an independent controller for that processing (see section 11.2 and section 7.4).
2. Privacy Contact and Data Protection Complaints
Privacy contact: privacy@steez.space General support: support@steez.space Legal: legal@steez.space Post: Privacy, Steelo Labs Ltd, 3 Harebell Close, Hamilton, Leicester, England, LE5 1UX
Note on Data Protection Officer: We have not appointed a formal Data Protection Officer at this stage. We are not legally required to appoint one in the UK on our current processing profile. We have instead designated a named privacy contact (privacy@steez.space) responsible for data-protection queries and complaints. This position will be reviewed as the platform scales or if our processing of special-category data grows.
How to make a data protection complaint to us: You may submit a complaint by email or post to the contact details above. We will acknowledge your complaint within 30 days and respond without undue delay, as required by the Data Protection Act 2018 s.164A (in force since 19 June 2026).
ICO complaint: You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at any time: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Telephone: 0303 123 1113 Website: ico.org.uk
If you are in the EU/EEA, you may also complain to your local supervisory authority (see section 3A). We encourage you to contact us first so we can try to resolve your concern.
3. Scope of This Policy and Geographic Posture
This policy applies to:
- All visitors to steez.space and steelo.io ("the Website");
- All users of the Steez mobile application ("the App"), whether fans or creators;
- Processing of personal data of individuals who connect third-party social media accounts to Steez.
This policy does not apply to third-party websites or platforms we link to. Those platforms have their own privacy policies.
3.1 Where Steez is available
Steez's paid services are offered in our supported territories — the UK and US at launch — expanding as we complete each territory's requirements (Terms of Service §2.1). Wherever you access Steez from, your data is processed in accordance with this policy and with UK data protection law as our baseline standard.
3.2 Local mandatory-rights saver
Where the law of your country of residence grants you data-protection or privacy rights that cannot be excluded or limited by agreement, those local mandatory rights prevail over anything in this policy to the extent of any conflict. Nothing in this policy removes or reduces a right you have under your local law that cannot lawfully be waived. The UK GDPR standard described here is our global baseline; where local law requires more, we apply the higher standard for users in that jurisdiction.
3A. EU / EEA Users (GDPR and DSA)
If and when Steez is made available in the EU/EEA (not at launch — see Terms of Service §2.1), the EU General Data Protection Regulation (Regulation (EU) 2016/679) will apply to our processing of EU/EEA residents' personal data under Article 3(2) GDPR, in addition to the UK GDPR baseline.
3A.1 Your EU GDPR rights
If you are in the EU/EEA, you have the rights set out in section 9 (access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and rights in relation to automated decision-making) as guaranteed by Articles 15–22 of the EU GDPR. You also have the right to lodge a complaint with the supervisory authority of your EU/EEA member state of residence, place of work, or place of the alleged infringement.
3A.2 EU representative (Article 27 GDPR)
If and when we offer Steez to EU/EEA residents, we will, as a controller established outside the EU/EEA, be required to designate a representative in the Union under Article 27 GDPR.
Current position. Steelo Labs does not offer paid services to or target the EEA at launch. Before any EEA launch, Steelo Labs will complete the applicable EU GDPR, consumer, tax, payments, copyright and Digital Services Act work, including any representative appointment required on the final facts. If you are in the EU/EEA and access Steez, you can exercise all of your rights and raise any data-protection matter by contacting us directly at privacy@steez.space, and we will deal with it directly. This does not limit any of your rights under the EU GDPR.
3A.3 Digital Services Act (DSA)
For online-intermediary and content-moderation obligations under the EU Digital Services Act (Regulation (EU) 2022/2065), including our notice-and-action mechanism, statement-of-reasons duties, and EU legal representative, see the Terms of Service and the Moderation, Complaints & Appeals Procedure.
The DSA notice-and-action mechanism, statement-of-reasons process, and EU legal representative are being stood up. Articles 16-18 DSA are hosting-service duties and are not displaced by the Article 19 micro/small-enterprise exemption for online-platform Section 3 duties. Article 24(5) is the transparency-database provision for statements of reasons; while the Article 19 exemption applies, submission to that database is voluntary for us rather than mandatory, although Article 24(3) recipient-number reporting on request still applies. Cross-references will be finalised when those mechanisms go live.
3A.4 EU international transfers
Where we transfer EU/EEA personal data outside the EU/EEA, we rely on the transfer mechanisms in section 10 (EU-US Data Privacy Framework certification where available; EU Standard Contractual Clauses as a fallback), applying the EU GDPR adequacy and safeguard standard to those transfers. The transfer safeguards and hosting-region statements in sections 10 and 11 apply equally to EU/EEA transfers.
3B. United States Users (CCPA / CPRA-style rights)
If you are a resident of a US state with a comprehensive consumer-privacy law (for example California under the CCPA/CPRA, and comparable statutes in other states), you may have the following rights in respect of your personal information, subject to the conditions and exemptions of your state's law:
- Right to know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties with whom we share it;
- Right to delete personal information we have collected from you, subject to legal exceptions;
- Right to correct inaccurate personal information;
- Right to opt out of any "sale" or "sharing" of personal information and of targeted advertising;
- Right to limit the use of sensitive personal information;
- Right to non-discrimination for exercising your rights.
We do not sell your personal information and we do not "share" it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. You may exercise any of the rights above using the contact details in section 2; we will verify your identity (section 9.1) before responding and will not discriminate against you for exercising a right.
Notice at collection and opt-out preference signals. The categories of personal information we collect, the sources, our purposes, our retention periods, and the third parties to whom we disclose them are set out in sections 5, 6, 8 and 11 of this policy, which together serve as our notice at collection. Because we do not sell or share personal information, there is no sale or share for an opt-out preference signal (such as Global Privacy Control) to opt you out of; if our practices ever change, we will update this policy first and will honour opt-out preference signals as required by applicable state law.
4. Children
Steez provides social access to users aged 13 and over with child-protection measures, while commerce, creator payouts and specified adult-restricted features are for users aged 18 and over (Terms of Service §3). Under-13s may not use Steez, and we do not knowingly collect their personal data. Because we permit 13–17-year-olds social access, we treat those users as children under the ICO's Age-Appropriate Design Code (Children's Code) and design our processing accordingly.
If you are a parent or guardian and believe we may hold data about your child, or wish to request removal of a child's account or a refund of a purchase made by a known minor, please contact us at the address in section 2 and we will handle your request. Known under-18s cannot make purchases, become creators, or access adult-restricted features; we do not knowingly provide those features to under-18s.
During beta we apply additional child-safety measures (Terms of Service §3.3): stranger direct messages and Villages are disabled; every upload is pre-moderated while volume is low; reporting and blocking are live; creators are 18+ and verified through Stripe Connect identity checks; and purchases sit behind an 18+ declaration and our payment controls. Age is recorded from your age declaration at sign-up; proportionate age assurance is applied where a genuinely adult-restricted feature justifies it (we do not otherwise verify age by document or estimation — see the age-inference note in section 6).
5. Personal Data We Collect
We collect the following categories of personal data about you:
5.1 Account and identity data
| Data field | Source | Notes |
|---|---|---|
| Display name | You | Provided at sign-up |
| Email address | You | Sign-up and communications |
| Profile photograph | You | Optional |
| Date of birth | You | |
| Age-assurance data | You / assurance provider | |
| Phone number | You | Optional; collected for contact-discovery features only on opt-in (see 5.3) |
| Referral code | You / platform-generated | Used to track referrals |
| Unique user identifier (Firebase UID) | Platform-generated | Assigned at account creation |
5.2 Payment and financial data
| Data field | Source | Notes |
|---|---|---|
| Stripe subscription ID | Stripe | Stored in Firestore users/{uid}/subscriptions |
| Payment method type (for example card or digital wallet) | Stripe / You | Source field stored on subscription and collection records. Every purchase is made through Stripe's secure checkout, reached from our website, whichever device you use |
| Transaction amounts and timestamps | Stripe | Stored on collection, subscription, and Steez purchase records |
| Stripe Connect account ID (creators only) | Stripe | Stored in creators/{creatorId} |
| Billing address entered at checkout (used for the country and, for US users, state) | You, through Stripe | Collected by Stripe at checkout; the country and state are read to confirm the purchase is from a supported territory (Terms of Service §2.1) |
What we do not store: Full card numbers, CVV codes, or raw bank account details. Payment card data is entered on Stripe's checkout page and processed directly by Stripe. The Steez apps do not take payments and we do not receive purchase data from Apple or Google. Neither full card nor bank account data ever reaches our servers.
5.3 Contact discovery data (opt-in only)
| Data field | Source | Notes |
|---|---|---|
| SHA-256 hashed email addresses | You (on opt-in) | Used to find contacts who are also on Steez |
| SHA-256 hashed phone numbers | You (on opt-in) | Used to find contacts who are also on Steez |
| `allowContactDiscovery` preference | You | Opt-in by explicit consent — off unless you actively turn it on |
Contact discovery is opt-in. We only process your hashed contacts for contact-matching after you give explicit consent through a dedicated consent screen; the feature is off by default. You can withdraw this consent at any time, after which we stop processing your contacts for matching.
Lawful basis for non-user contact data. The identifiers you submit for matching may include people who are not Steez users. Your consent covers your own decision to use the feature, but it cannot provide a lawful basis for processing the personal data of those non-users. For that non-user data we rely on legitimate interests (Article 6(1)(f) UK/EU GDPR) — connecting you with people you already know — supported by a legitimate-interests assessment (LIA) and, because we do not notify those non-users individually, the Article 14(5) disproportionate-effort assessment. Contact matching occurs only after opt-in. Contact identifiers are normalised and SHA-256 hashed before they are used for matching; we do not retain your plaintext contacts for this feature. We use the hashed values only for a single matching operation, do not use non-user contacts for invitations or marketing, and delete any unmatched values immediately, retaining nothing about people who are not Steez users. A match does not reveal that a particular user uploaded another person's contact details.
5.4 Content and usage data
| Data field | Source | Notes |
|---|---|---|
| Posts, videos, captions, and other content you create | You | Subject to the content licence in the Creator Terms & Earnings Agreement |
| Comments, chat messages, Village posts | You | Community communications; subject to community rule engine (see section 15.2) |
| Subscription, collection, and Steez records | Platform | Records of content you have purchased, subscribed to, or unlocked. A "Steez" is a personal key — personal, non-transferable, and non-resellable — a licence to access only what a creator explicitly offers (Mosaic exclusives, Village community, creator-picked Perks); it is not a financial asset, security, investment, e-money, stored value, deposit, trust asset, ownership interest, or share of creator/platform revenue. We keep records of first-hand Steez purchases |
| Following and follower lists | Platform | Your social graph on Steez |
| FCM device tokens | Platform / Firebase | Used to deliver push notifications; deleted on account erasure |
5.5 Technical and device data
| Data field | Source | Notes |
|---|---|---|
| Device manufacturer, model, OS version | Your device | Collected by our Mosaic performance analytics system and Crashlytics |
| App version and build number | Your device | Collected by our Mosaic performance analytics system |
| Platform (iOS / Android) | Your device | Collected by our Mosaic performance analytics system |
| Connection type | Your device | Sent to Mux video player for adaptive streaming |
| Firebase Analytics event data | Your device | First-party records of in-app events such as onboarding steps, page views, feature use; off by default and collected only under your consent (see §6 and §18 for the lawful basis — we do not rely on the DUAA first-party-statistics exemption) |
| Crash reports and stack traces | Your device | Collected by Firebase Crashlytics as minimised fault diagnostics; includes device info and app state at crash time (see §6 for the lawful basis) |
| Session identifiers | Platform-generated | Used in performance analytics; tied to Firebase UID |
| IP address (web) | Your device | Processed by Cloudflare as network infrastructure |
5.6 Mux viewer telemetry
When you watch video content on Steez, the Mux video platform collects the following data on our behalf:
| Data field | Notes |
|---|---|
| Firebase UID (viewer_user_id) | Sent to Mux Data SDK to associate playback with your account |
| Device name and category | For quality-of-experience analytics |
| Operating system family and version | For quality-of-experience analytics |
| App version | For quality-of-experience analytics |
| Connection type | For adaptive streaming |
| Viewer plan | For content personalisation analytics |
| View session ID | For playback session tracking |
This data is processed by Mux, Inc. under a Data Processing Agreement with us (see Processors Annex, section 11). Mux viewer telemetry is not covered by the DUAA first-party-statistics exemption; see §6 for its lawful basis.
5.7 Connected accounts data (third-party platforms)
If you connect a third-party social media account to Steez (for publishing or identity features), we collect and store the data described in section 12 (Connected Accounts).
5.8 Data collected from third parties
If you connect a social platform, we may receive data about you from that platform. Full details are in section 12.
6. How and Why We Use Your Data (Lawful Basis)
We are required by data protection law to have a lawful basis for every processing activity. The table below maps each purpose to its lawful basis under the UK GDPR; the equivalent EU GDPR bases apply to EU/EEA users (Article references are common to both regimes).
| Purpose | Data used | Lawful basis | Notes |
|---|---|---|---|
| Creating and managing your account | Account & identity data | Contract (Art 6(1)(b)) — necessary to provide the service | |
| Age assurance and eligibility (13+ social; 18+ for commerce and adult-restricted features) | Age-declaration and age-assurance data | Contract (Art 6(1)(b)) for age-conditioned access to paid features and legitimate interests (Art 6(1)(f)) — safeguarding and platform safety, including child protection under the ICO Children's Code | |
| Processing payments, subscriptions, and content purchases | Payment data, email, UID | Contract (Art 6(1)(b)) + Legal obligation (Art 6(1)(c)) — financial record-keeping | Includes first-hand Steez purchases |
| Processing creator payouts via Stripe Connect | Connect account data, earnings records | Contract (Art 6(1)(b)) + Legal obligation (Art 6(1)(c)) | |
| HMRC digital-platform reporting (SI 2023/817) | Creator earnings data, TIN | Legal obligation (Art 6(1)(c)) | We process creator earnings data and tax-identification information where required to identify and report reportable sellers after the due-diligence and classification steps required by the Regulations. Reporting is not automatic for every payout. |
| Sending transactional emails (welcome, renewal, payout, OTP) | Email address | Contract (Art 6(1)(b)) | Not marketing; required to perform the service |
| Sending push notifications (service alerts, activity) | FCM token, UID | Contract (Art 6(1)(b)) for service-critical notifications; Consent for marketing/re-engagement notifications | Consent collected at OS permission prompt |
| Marketing communications (email, push) | Email, FCM token | Consent (Art 6(1)(a) + PECR reg 22) | Explicit unticked opt-in at sign-up; soft opt-in only for purchasers; opt-out in every message |
| Contact discovery (matching you with known contacts) | Hashed phone/email | Consent (Art 6(1)(a)) | Opt-in only: processed only after explicit consent via a dedicated consent screen; off by default; withdrawable at any time |
| First-party audience analytics (in-app usage statistics) | First-party Firebase Analytics events, device data | Consent (Art 6(1)(a)) | Off by default: Firebase Analytics does not initialise until you give prior opt-in consent at the first-run consent screen or in Settings → Data & Privacy, and consent is withdrawable as easily as it was given. We do not rely on the DUAA first-party-statistics exemption or on legitimate interests to run these analytics without your consent. |
| Mosaic video performance analytics | Device data, UID, session data | Consent (Art 6(1)(a)) | Not within the DUAA first-party-statistics exemption. This SDK is off by default: it does not initialise until you give prior opt-in consent at the first-run consent screen or in Settings → Data & Privacy, and consent is withdrawable at any time. We do not rely on legitimate interests to run this SDK without your consent. |
| Crash diagnostics (Crashlytics) | Crash logs, device data | Legitimate interests (Art 6(1)(f)) for the processing, plus the PECR strictly-necessary / technical-fault detection exception (as clarified by the Data (Use and Access) Act 2025) for device storage/access | Minimised fault diagnostics only: used solely to detect and remedy technical faults and protect security — not for advertising, audience measurement, product analytics or model training. Advertising IDs, Google Signals and analytics linking are disabled; payload is minimised; short retention applies; a recorded balancing test (LIA) supports the Art 6(1)(f) reliance. Identifiers are two-mode. If you have not opted in to crash diagnostics, we attach only a pseudonymous, app-scoped installation identifier — never your account ID — so that we can tell one device crashing repeatedly from many devices crashing once. If you have opted in, we may attach your account ID so we can connect a crash to your support request and tell you when it is fixed. On by default; you may object. Crash diagnostics run by default and you may object at any time in Settings → Data & Privacy — this is an objection under Article 21, not a consent toggle, and we will stop unless we have compelling legitimate grounds. Where the documented production configuration meets the PECR technical-fault exception, we rely on that exception for device storage/access; if that configuration is not verified, crash diagnostics stay off until you consent. |
| Mux viewer telemetry | UID, device data, playback data | Consent (Art 6(1)(a)) | Not within the DUAA first-party-statistics exemption; Mux is a separate processor (see §5.6, §11.3). The Mux Data SDK is off by default: it does not send any telemetry until you give prior opt-in consent at the first-run consent screen or switch on Video analytics in Settings → Data & Privacy, and consent is withdrawable at any time — video playback itself is unaffected if you do not consent. We do not rely on legitimate interests to run this SDK without your consent. |
| Firebase Performance Monitoring (where used) | Device data, network timing, UID/session | Consent (Art 6(1)(a)) | Not within the DUAA first-party-statistics exemption. Firebase Performance Monitor is off by default: it does not initialise until you give prior opt-in consent at the first-run consent screen or in Settings → Data & Privacy, and consent is withdrawable at any time. We do not rely on legitimate interests to run this SDK without your consent. |
| Safety, fraud prevention, and legal defence | Account data, communications, moderation logs | Legitimate interests (Art 6(1)(f)) — fraud prevention and safeguarding | |
| Moderation of community chat (automated rule engine) | Chat messages | Legitimate interests (Art 6(1)(f)) — platform safety | Rule engine only; posts and videos are NOT automatically scanned. Where moderation review (whether of community chat or, on report, a direct message) surfaces special-category data, see §6.1 for the Article 9 condition |
| Content recommendation (discovery feed, mosaic) | Usage patterns, content preferences | Legitimate interests (Art 6(1)(f)) — personalised experience | See section 15 (automated processing) |
| Complying with legal obligations (tax, money-laundering, court orders) | As required | Legal obligation (Art 6(1)(c)) | |
| Responding to law-enforcement requests | Account data, communications | Legal obligation (Art 6(1)(c)) / Legitimate interests (Art 6(1)(f)) | See section 13 |
| Retaining financial records | Payment, subscription, earnings data | Legal obligation (Art 6(1)(c)) | 6-year retention under Companies Act 2006 / HMRC requirements — see §8 for the rationale |
| Connected-account OAuth publishing (creators) | OAuth tokens, content, UID | Consent (Art 6(1)(a)) — explicit per-platform consent at connection | See section 12 |
| Connected-account identity features (planned) | OAuth tokens, taste-profile data | Consent (Art 6(1)(a)) |
Note — age-inference / audience-age analytics removed: Earlier drafts listed an "age inference for audience analytics" purpose relying on a stored date of birth. Because DOB collection is unverified in production, we do not assert any age-inference or audience-age processing in this policy. This purpose will only be reinstated — with its own lawful basis and DPIA — if and when DOB collection is confirmed and the feature is built.
6.1 Special-category data and moderation (Article 9)
Our community-chat rule engine and our human moderation team may, in the course of safety and moderation work, encounter content that reveals special-category data (Article 9 UK/EU GDPR) — for example data revealing racial or ethnic origin, political opinions, religious beliefs, health, sex life, or sexual orientation — where a user has included such content in a message, or where a user reports a direct message to us for review.
Where we process special-category data in this context, we rely on the Article 9(2) conditions of:
- Article 9(2)(g) — substantial public interest (safeguarding users, preventing and detecting unlawful acts, and protecting users from harmful or illegal content), read with the relevant Schedule 1 conditions of the Data Protection Act 2018 (including safeguarding and the prevention/detection of unlawful acts), for which we maintain an Appropriate Policy Document; and
- Article 9(2)(e) — where the data has manifestly been made public by the user (for example, posted to a public channel).
We do not routinely scan the content of private direct messages; human review of a DM occurs on a report or where we are legally compelled. Automated scanning is limited to community-chat messages as described in §15.2.
6.2 Criminal-offence data (Article 10)
Where our moderation, safety, and fraud-prevention work produces records that relate to criminal convictions or offences, or to related unlawful conduct — for example a record of suspected illegal content, fraud, or other criminal activity, or of the action we took in response — we process that criminal-offence data under Article 10 UK/EU GDPR. We rely on the conditions in Schedule 1, Part 3 of the Data Protection Act 2018 that permit processing of such data for these purposes, including the prevention and detection of unlawful acts and the protection of the public against dishonesty, malpractice, or other seriously improper conduct. As required by the Data Protection Act 2018, we maintain an Appropriate Policy Document for this processing.
7. Sharing Your Data
We do not sell your personal data. We share it only as described below.
7.1 Processors acting on our behalf
We use service providers who process data only on our instructions under written Data Processing Agreements. These are listed in the Processors Annex (section 11).
7.2 Other users
Your display name, profile photo, published content, and follower/following counts are visible to other Steez users as part of the normal operation of the platform. Content you post to public channels is visible to all users.
7.3 Creators you subscribe to or purchase from
If you subscribe to a creator or purchase or unlock their content (including acquiring a Steez key), that creator can see that you are a subscriber/purchaser/holder. Your display name is shared. Your payment details, email address, and other personal data are not shared with creators.
7.4 Stripe (as independent controller for KYC)
When a creator connects a Stripe Express payout account, Stripe independently collects and processes that creator's identity documentation and banking details for KYC purposes. In this context, Stripe is an independent controller subject to Stripe's own privacy policy: stripe.com/gb/privacy. Steelo Labs Ltd does not have access to or control over the KYC data Stripe holds.
7.5 Law enforcement and regulators
See section 13.
7.6 Business transfers
If we undergo a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity as part of that transaction. You will be notified of any such transfer where required by law.
8. Retention Schedule
We keep your data for as long as necessary for the purposes described in this policy. The table below sets out our retention periods by category.
| Category | Retention period | Legal basis for retention |
|---|---|---|
| Account and identity data (active account) | Life of account | Contract performance |
| Account and identity data (after deletion) | 30-day grace period, then permanent deletion | UK GDPR Art 17; see section 14 for deletion blockers |
| Account-deletion re-link token (preserved Steez Key / content-unlock entitlement) | Single-use token retained for 6 years — the same period as financial-record retention — so that a preserved entitlement can be redeemed on a new account; see Data Deletion Policy §4.2 and §12.2 | Contract — supports paid entitlements you chose to preserve on deletion |
| Payment, subscription, and transaction records (incl. first-hand Steez transactions) | 6 years from the end of the financial year as the baseline; where VAT One-Stop-Shop (OSS) records apply, or a record is connected to Online Safety Act complaint-handling duties, the required period may be longer — up to 10 years — see Data Deletion Policy §6.2 (pseudonymised + access-restricted after deletion; remains personal data) | Legal obligation — corporation-tax (FA 1998 Sch 18) and VAT (VAT Act 1994 s.58) record rules, extended by OSS/foreign-law and OSA record-keeping duties where applicable; the Companies Act 2006 s.388 accounting minimum is 3 years |
| Creator payout records | accounting copy 6 years; DPR due-diligence record 5 years (pseudonymised + access-restricted after deletion) | Legal obligation — SI 2023/817 HMRC DPR (5yr) + corporation-tax/VAT (6yr) |
| Published content (posts, videos) | Deleted or anonymised/pseudonymised on account deletion, subject to ongoing licence grants, paid-content / Steez-access survival, moderation actions, and legal-hold exceptions | Contract; see the Terms of Service and Data Deletion Policy |
| Public comments, community chat messages and reactions | May remain visible in context after account deletion but are pseudonymised and attributed to "Deleted User"; removed where directly harmful, legally required, or subject to moderation | Contract / legitimate interests; see Data Deletion Policy §5.3 |
| Private messages (DMs) | Erased on permanent account deletion unless a legal hold applies | Contract |
| Moderation logs and ban history | 6 years from the date of the moderation action | Legitimate interests — statutory limitation period (Limitation Act 1980, s.2/s.5) |
| Firebase Analytics event data (first-party audience analytics) | Up to 14 months (event-level data; configurable in the Firebase console); collected only where you consent | Consent (Art 6(1)(a)) |
| Crashlytics crash reports (minimised fault diagnostics) | 90 days (short retention) | Legitimate interests (Art 6(1)(f)); PECR technical-fault exception |
| Mosaic performance analytics (Firestore `_analytics`) | 90 days rolling | Consent (Art 6(1)(a)) |
| Mux viewer telemetry | Pseudonymised view-level data retained by Mux for up to 100 days, then deleted (Mux's standard Data retention period) | Consent (Art 6(1)(a)) |
| FCM push notification tokens | Deleted on account erasure | Contract |
| Connected-account OAuth tokens (Firestore) | Deleted immediately on disconnect | Consent |
| Connected-account OAuth tokens (scheduler database) | Deleted on disconnect via ON DELETE CASCADE | Consent |
| Contact-discovery hashes | Deleted when contact discovery is turned off or consent is withdrawn | Consent |
| YouTube authorised data | Refreshed or deleted within 30 calendar days of last authorisation, per YouTube Developer Policies §III.E.4.c | Consent / contractual (platform terms) |
| Spotify taste-profile data | Deleted immediately on Spotify account disconnect | Consent / contractual (Spotify Developer Policy §I.1.b) |
Why we keep financial records for 6 years: UK tax and accounting law requires financial records to be kept for 6 years — principally the corporation-tax record requirement (Finance Act 1998 Sch 18 para 21) and the VAT record requirement (VAT Act 1994 s.58). The Companies Act 2006 s.388 minimum for private-company accounting records is 3 years; we retain for the longer 6-year tax period. Where VAT One-Stop-Shop (OSS) or other applicable foreign-law rules require a longer period, or a record is connected to Online Safety Act complaint-handling duties, we retain it for that longer period (up to 10 years) instead — see the table above and Data Deletion Policy §6.2. After your account is deleted, these records are pseudonymised and access-restricted — your name is removed but they remain personal data, retaining the transaction data required for our legal obligations.
9. Your Rights
Under UK data protection law (and, for EU/EEA users, the EU GDPR — see section 3A) you have the following rights in relation to your personal data. US-state residents have the rights in section 3B. To exercise any right, contact us at the address in section 2.
| Right | What it means | Time limit |
|---|---|---|
| Access (Art 15) | Obtain a copy of the personal data we hold about you and information about how we use it. To exercise this right, contact us at the address in section 2. | We will respond within one month of verifying your identity. |
| Rectification (Art 16) | Ask us to correct inaccurate data. | One month. |
| Erasure (Art 17) | Ask us to delete your personal data. Subject to blockers and retention obligations — see section 14. To exercise this right, contact us at the address in section 2. | One month (or we will inform you of any applicable exemption). |
| Restriction (Art 18) | Ask us to stop processing your data temporarily in certain circumstances. | One month. |
| Portability (Art 20) | Receive your data in a structured, machine-readable format for data you gave us on the basis of consent or contract. To exercise this right, contact us at the address in section 2. | One month. |
| Object (Art 21) | Object to processing based on legitimate interests, including direct marketing. | We will stop unless we have compelling legitimate grounds. |
| Withdraw consent (Art 7(3)) | Withdraw any consent you have given at any time (including contact discovery and marketing). Withdrawal does not affect lawfulness of processing before withdrawal. | Immediate effect. |
| Not to be subject to solely automated decisions (Art 22) | See section 15 for how automated processing affects you. | — |
9.1 Identity verification
To protect your data, we must verify your identity before responding to a Data Subject Access Request or erasure request. We will ask for information that lets us confirm you are the account holder. We will not require more information than is reasonably necessary for this purpose (DUAA 'reasonable and proportionate' scope).
9.2 No charge
Responding to your rights requests is free of charge. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse — and if we do, we will tell you why.
9.3 Erasure propagation
When we delete your account, we will also request deletion of data held by processors where technically feasible:
- Mux: Mux video assets uploaded by your account will be deleted. Mux viewer telemetry will be deleted to the extent permitted by Mux's DPA.
- Firebase/Google: Firebase Auth account, Analytics data, and Crashlytics reports associated with your UID will be subject to deletion per Google/Firebase's data practices.
- Stripe: Stripe retains transaction data under its own legal obligations. Steelo Labs will request removal of data Stripe holds solely as our processor; KYC data held by Stripe as independent controller is subject to Stripe's own privacy policy.
9.4 DPA s.164A complaint route
If you are not satisfied with how we have handled a data protection matter, you may submit a formal complaint to us by email or post (section 2). We will acknowledge within 30 days. If you remain dissatisfied, you may complain to the ICO (section 2 above) or, if you are in the EU/EEA, to your local supervisory authority (section 3A).
10. International Transfers
Some of our processors are based in, or process data in, the United States and other countries. Data protection law requires that transfers of personal data outside the UK (and, for EU/EEA users, outside the EU/EEA) are protected by an appropriate safeguard. We rely on the following mechanisms.
10.1 EU-US Data Privacy Framework (DPF) and UK Extension
For each international transfer, we use the transfer mechanism applicable to the relevant provider, entity, and service, as recorded in our current processor and transfer register. For several of our US-based processors — including Google/Firebase, Stripe, and Mux — the mechanism is certification under the EU-US Data Privacy Framework and its UK Extension, which we check against the official register and keep under review. Because a provider may be certified for one service or entity and not another, the register records the position for each flow; where certification does not cover a particular flow, we rely on the fallback in section 10.2. Current provider and mechanism details are available on request.
10.2 IDTA / SCC fallback
Where a processor is not DPF-certified, or DPF certification lapses, transfers are protected by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (for UK transfers), and by the EU Standard Contractual Clauses (for EU/EEA transfers), as incorporated into the relevant processor's Data Processing Agreement. A transfer risk assessment is maintained internally where required.
10.3 Other jurisdictions
For users outside the UK and EU/EEA, your data is processed under this policy with UK GDPR as our baseline standard, supplemented by any local mandatory rights that apply to you (section 3.2). Where your local law requires a specific transfer mechanism or localisation, we apply it for users in that jurisdiction.
10.4 Processor-specific notes
- Stripe DTA: Stripe's Data Processing Addendum incorporates the UK Addendum and EU SCCs as fallback mechanisms. Reference: stripe.com/legal/dta.
- Mux DPA: Mux's Data Processing Agreement incorporates standard contractual clauses. Reference: mux.com/dpa.
- Google/Firebase: the Google Cloud Data Processing Addendum covers Firebase services.
11. Processors Annex
The following third-party processors handle personal data on our behalf under written Data Processing Agreements. We are responsible for their processing under Art 28 UK GDPR (and the EU GDPR equivalent for EU/EEA data).
11.1 Google LLC / Firebase (Google Cloud Platform)
| Detail | Information |
|---|---|
| Purpose | Cloud hosting (Cloud Functions, Firestore, Firebase Auth), push notifications (FCM), first-party audience analytics (Firebase Analytics), crash reporting (Crashlytics), performance monitoring, file storage |
| Data processed | All personal data stored on the platform (account data, content, payment metadata, analytics events, crash logs, device data) |
| Transfer mechanism | EU-US DPF and UK Extension; IDTA / EU SCC fallback |
| Primary region | Firestore and Cloud Functions are deployed in europe-west1 (Belgium). Some Firebase services (Authentication, Analytics, logging, backups) are not necessarily confined to this region; we state the position service-by-service in our internal processing matrix |
| DPA reference | Google Cloud Data Processing Addendum |
11.2 Stripe, Inc.
| Detail | Information |
|---|---|
| Purpose | Payment processing (card, subscription, first-hand Steez transactions), Connect payout disbursement |
| Data processed | Payment method tokens, subscription records, transaction amounts, email for receipt delivery |
| Note | For Stripe Connect KYC (creator identity verification and bank-account data), Stripe acts as an independent controller — not our processor. See section 7.4 and Stripe's own privacy policy. |
| Contracting entity | Stripe Payments Europe Ltd (Ireland); Stripe Payments UK Ltd applies additionally where UK Financial Services Terms apply |
| Transfer mechanism | EU-US DPF and UK Extension; UK Addendum / EU SCC fallback via Stripe DTA |
| DPA reference | stripe.com/legal/dta |
11.3 Mux, Inc.
| Detail | Information |
|---|---|
| Purpose | Video transcoding, content delivery (CDN), viewer telemetry and quality-of-experience analytics |
| Data processed | Video assets, Firebase UID (as viewer_user_id), device telemetry (device name, category, OS, app version, connection type), view session identifiers |
| Transfer mechanism | EU-US DPF and UK Extension; standard contractual clauses fallback via Mux DPA |
| DPA reference | mux.com/dpa |
11.4 Microsoft Corporation (Microsoft 365 / Outlook)
| Detail | Information |
|---|---|
| Purpose | Transactional email delivery (welcome, subscription renewal, password reset OTP, payout notifications) |
| Data processed | Email addresses and email content of transactional messages |
| Note | Email is sent via Microsoft Outlook using OAuth2 credentials. No marketing email-service provider (e.g. SendGrid) is in use. |
| Transfer mechanism | EU-US DPF and UK Extension; Microsoft DPA / SCCs |
11.5 Cloudflare, Inc.
| Detail | Information |
|---|---|
| Purpose | Content delivery network (CDN), DDoS protection, web analytics for steez.space |
| Data processed | IP addresses, page-view data, request metadata for web visitors |
| Note | Cloudflare may set the `__cf_bm` cookie on web visitors for bot detection. See the Cookie & Tracking Policy for further detail. |
| Transfer mechanism | EU-US DPF and UK Extension; Cloudflare DPA / SCCs |
11.6 Apple Inc. (app distribution and Sign in with Apple)
| Detail | Information |
|---|---|
| Purpose | Distribution of the iPhone app through the App Store; Sign in with Apple, if you choose to use it |
| Data processed | If you use Sign in with Apple: the Apple account identifier and the name and email address (or Apple relay address) that you choose to share. We do not sell through Apple's in-app purchase system and receive no purchase or payment data from Apple |
| Note | Apple acts as an independent controller for App Store distribution and Sign in with Apple (not a Steelo processor) and processes that data under its own terms and privacy policy. |
| Transfer mechanism | Apple's standard contractual mechanisms as described in Apple's privacy policy |
12. Connected Accounts
Steez allows you to connect third-party social media accounts for content publishing (creators) and for identity/profile features (all users). This section describes data flows for each supported platform. Where an integration is not yet available, it is offered only once live; the data described below applies when you choose to connect that account.
12.1 General
When you connect a social media account:
- You are shown the exact permissions we are requesting before authorising;
- We store OAuth access and refresh tokens, encrypted at rest using AES-256-GCM;
- Access tokens are stored in our Firestore database (server-side only; not accessible to client-side code);
- You can disconnect any connected account at any time from your account settings. Disconnecting immediately revokes our access at the provider level and deletes stored tokens.
12.2 YouTube (Google API Services)
Disclosure required by YouTube API Terms of Service:
The Steez application uses YouTube API Services. By using the YouTube connection feature, you also agree to be bound by YouTube's Terms of Service.
Google Privacy Policy: Our use of YouTube API Services is subject to Google's Privacy Policy.
What data we collect from YouTube:
| Data | Purpose | Retention |
|---|---|---|
| YouTube channel ID and display name | Confirm the connected channel belongs to you | Deleted on disconnect |
| OAuth access token and refresh token | Publish content on your behalf | Deleted on disconnect; refreshed every 30 days or less per YouTube Developer Policy §III.E.4.c |
| Upload confirmations / video IDs | Confirm successful publishing | Retained as part of your post record for the life of the post |
What we do with YouTube data: We use your YouTube authorisation exclusively to publish content you create on Steez to your YouTube channel, at your direction. We do not use YouTube data for advertising, do not share it with third parties, and do not use it for any purpose beyond operating the publishing feature.
Revoking access: You may revoke Steez's access to your YouTube account at any time:
- Within the Steez app: Settings > Connected Accounts > YouTube > Disconnect
- Directly via Google: https://security.google.com/settings/security/permissions
Google API Services User Data Policy: Our use of data obtained through YouTube API Services adheres to the Google API Services User Data Policy, including the Limited Use requirements.
12.3 Meta (Instagram and Facebook)
What data we collect from Instagram / Facebook:
| Data | Purpose | Retention |
|---|---|---|
| Instagram/Facebook user ID and handle | Display connected account identity | Deleted on disconnect |
| OAuth access and refresh tokens | Publish content on your behalf | Deleted on disconnect |
| Page ID (for Facebook Pages connected by creators) | Publishing to Facebook Pages | Deleted on disconnect |
Meta Platform Data: We process data received from Meta platforms ("Platform Data") only to develop, improve, and operate the Steez content-publishing feature. We do not use Platform Data to target advertising, do not share it with data brokers, and do not use it for any purpose not described in this policy.
You may revoke Steez's access to your Meta account:
- Within the Steez app: Settings > Connected Accounts > Instagram/Facebook > Disconnect
- Via Facebook: Settings & Privacy > Settings > Apps and Websites
12.4 TikTok
What data we collect from TikTok:
| Data | Purpose | Retention |
|---|---|---|
| TikTok user ID and username | Display connected account identity | Deleted on disconnect |
| OAuth access and refresh tokens | Publish content on your behalf | Deleted on disconnect |
How we use TikTok data: We use TikTok data only to develop, maintain, and support the Steez app. We do not use TikTok Information for commercial solicitation, do not overlay Steez branding on TikTok-origin content, and comply with TikTok's Developer Terms §III.
Revoking access: You may revoke Steez's access to your TikTok account:
- Within the Steez app: Settings > Connected Accounts > TikTok > Disconnect
- Via TikTok: Profile > Settings > Security > Authorized apps
12.5 Spotify
What data we intend to collect from Spotify:
| Data | Purpose | Retention |
|---|---|---|
| Spotify user ID | Link account to your Steez profile | Deleted on disconnect |
| Top genres | Music taste profile for content discovery | Deleted on disconnect |
| Top artist IDs and names | Music taste profile for content discovery | Deleted on disconnect |
| OAuth access token | Retrieve taste data | Deleted on disconnect |
Spotify disconnect and deletion: When you disconnect your Spotify account, we immediately delete all Spotify-derived personal data from our systems. We do not retain Spotify data after disconnect.
No AI training: We do not use Spotify content or data to train or improve any machine learning or artificial intelligence model. This carve-out applies to all Spotify-derived data.
Revoking access: You may revoke Steez's access to your Spotify account:
- Within the Steez app: Settings > Connected Accounts > Spotify > Disconnect
- Via Spotify: Account > Manage Apps
Attribution: Where we display music metadata or cover art sourced from Spotify, we attribute it in accordance with Spotify's branding requirements and link back to Spotify where required.
13. Law Enforcement and Regulatory Disclosures
13.1 Recipient categories
We may disclose personal data to the following categories of recipients in connection with legal obligations or proceedings:
- UK law enforcement agencies (police forces, National Crime Agency) — in response to lawful production orders, search warrants, or voluntary disclosure requests under DPA 2018 Schedule 2 para 2;
- HM Revenue & Customs (HMRC) — for statutory digital-platform reporting (SI 2023/817) and tax investigations;
- The Information Commissioner's Office (ICO) — in response to regulatory investigations or audits;
- Ofcom — in response to Online Safety Act information notices (OSA ss.100–110);
- EU/EEA and other foreign authorities — where we are lawfully required to respond given our multi-territory availability, subject to applicable law and any conflict-of-laws safeguards;
- Courts and tribunals — in compliance with court orders or legal proceedings;
- Other competent authorities — where required by applicable law.
13.2 Voluntary law-enforcement disclosures
Where we receive a voluntary request (without a court order) from law enforcement, we assess each request individually. We require a written, signed request and disclose only where we reasonably believe refusal would prejudice the prevention or detection of crime. We document every disclosure decision.
13.3 Notice to you
In most cases we will tell you before disclosing your data to law enforcement. However, where a court order, statutory instrument, or the Investigatory Powers Act 2016 prohibits us from doing so (or where notification would prejudice the investigation), we may be legally required to keep the disclosure confidential. We will notify you as soon as we are legally permitted to do so.
13.4 Steez as a telecommunications operator; interception position
Because Steez operates chat and direct messaging services, we may be a telecommunications operator under the Investigatory Powers Act 2016 (IPA) (s.261). As such:
- We are subject to lawful interception and lawful-access provisions of the IPA and will comply only where served with valid lawful authority (for example a targeted interception warrant under Part 2, a communications-data authorisation/notice, or a technical-capability notice). We do not intercept the content of your communications other than as permitted by the IPA — including the limited business-purpose monitoring permitted by the IPA s.46 / the Investigatory Powers (Interception by Businesses etc.) Regulations for the operation and security of our own systems and for our automated community-chat rule engine (§15.2).
- Where interception or disclosure under the IPA is subject to a non-disclosure obligation, we are legally prohibited from notifying you (see §13.3).
- Any special-category data encountered in moderation or lawful-access work is processed under the Article 9 condition stated in §6.1.
14. Account Deletion and the Right to Erasure
14.1 How to delete your account
You may request deletion of your account through the account-deletion option in your in-app Settings. Alternatively, and in any case where any part of the in-app flow is not yet live, you may exercise your right to erasure simply by contacting us at the address in section 2.
14.2 Grace period
After you request deletion you may choose immediate, irreversible deletion (an Article 17 erasure request, actioned without undue delay) or an optional 30-day recovery period (your account is suspended and you can reactivate it; after 30 days deletion is permanent and irreversible). Under either route, public display, recommendation, analytics and marketing stop immediately.
14.3 Conditions before deletion can complete
You may request erasure of your account and personal data at any time. Exercising that right is never blocked. However, completing the deletion may require certain matters to be cancelled, settled, or subject to limited retention first, and in some cases a portion of your data must be retained under legal obligation (see §14.5). In particular:
- If you have an active paid subscription (fan), it must be cancelled before deletion completes; cancelling it does not affect your right to make the request;
- If you are a creator with unsettled earnings, those payouts must be settled before deletion completes; contact support to arrange this.
For the step-by-step process, see the Data Deletion Policy (listed in section 21, Related Documents).
14.4 What is deleted
The following is deleted permanently after the grace period:
- Your Firebase Auth account and login credentials
- Your profile data (display name, photo, bio, and date of birth where stored — see §5.1)
- Direct messages (DMs), unless a legal hold applies
- Follower/following data and FCM tokens
- Your connected-account OAuth tokens (from both Firestore and the scheduler database where applicable)
- Your Spotify taste profile and connected-accounts data
- Your contact-discovery hashes
14.5 What is retained
The following is retained after account deletion:
- Financial records (transaction amounts, dates, de-identified identifiers, including first-hand Steez transactions): retained for 6 years under legal obligation (see §8);
- Subscription, purchase, payout, tax, and accounting records: pseudonymised and access-restricted, not deleted immediately, and retained only for the legal periods described in §8 and the Data Deletion Policy;
- Public comments, community chat messages and reactions: may remain visible in context but are pseudonymised and attributed to "Deleted User"; removed where directly harmful, legally required, or subject to moderation;
- Moderation logs and ban history: retained for 6 years from the date of the action under legitimate interests (legal-claims limitation period);
- Creator earnings reports submitted to HMRC: retained per HMRC reporting obligations.
Note: the access a Steez key grants may survive or terminate independently of account deletion in certain circumstances (for example creator exit or insolvency) — see the Terms of Service and Creator Terms. This policy governs only the personal-data aspects of deletion.
15. Automated Processing
15.1 What automated processing means
Automated processing means using computer systems — without meaningful human review — to analyse your data and make decisions about you.
15.2 Community chat rule engine
Steez operates an automated content rule engine that reviews messages posted in community chat channels. This engine applies rules to detect content that may violate our Community Guidelines (such as illegal content, harassment, or spam). The rule engine may automatically remove content or flag it for human review by our moderation team.
Important: The rule engine applies only to community chat messages. Posts, videos, images, and captions are not automatically scanned by any rule engine.
Where moderation review surfaces special-category data, we rely on the Article 9 condition in §6.1.
The effect of the rule engine on you: if a message you post is removed by the rule engine, you will be notified. You may challenge that decision by contacting us through our Moderation, Complaints & Appeals Procedure (see clause 6.3 of that Procedure on the status of the appeals route).
15.3 Content recommendation (discovery feed and mosaic)
We use automated systems to personalise the content you see in your discovery feed and mosaic. These systems analyse your usage patterns (what you play, for how long, what you interact with) and your music taste profile (where provided) to suggest relevant content.
This is a personalisation decision, not a decision that significantly affects your legal rights. However, you have the right to object to processing of your personal data on the basis of legitimate interests (section 9 above).
15.4 No solely-automated decisions with legal or significant effects
We do not make decisions that produce legal effects on you — such as account suspension, access restrictions, or moderation bans — based solely on automated processing without human involvement. Moderation actions resulting in account suspension or bans involve human review.
16. Data Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction. These include:
- OAuth access tokens are encrypted at rest using AES-256-GCM;
- Firebase Auth handles user authentication and credential security;
- Access to production data is restricted by role-based IAM policies;
- API keys and secrets are managed via Google Secret Manager;
- Our payment flows tokenise card data directly via Stripe — card data never reaches our servers.
16.1 Breach notification
If we suffer a personal data breach, we will:
- Notify the ICO (and, for EU/EEA data, the relevant supervisory authority) within 72 hours of becoming aware, where the breach is likely to result in risk to individuals (UK GDPR / EU GDPR Art 33);
- Notify you without undue delay if the breach is likely to result in a high risk to your rights and freedoms (Art 34) — for example, exposure of private messages or payment-linked identity data;
- Log all breaches internally, even those not requiring notification (Art 33(5));
- Require our processors (Stripe, Mux, Google/Firebase, Microsoft, Cloudflare) to notify us without undue delay of any breach affecting our data under their processor agreements.
Where encryption or other mitigation measures make it unlikely that a breach will result in risk to individuals, we may be exempt from notifying you individually — but we will consider each incident on its facts.
17. Marketing Communications
What this section says: We will only send you marketing messages if you have actively opted in. You can opt out at any time.
Basis: We rely on your explicit consent (UK GDPR Art 6(1)(a) + PECR reg 22) to send marketing emails, push notifications, and in-app marketing messages.
Opt-in: We collect marketing consent via an unticked opt-in checkbox at sign-up. For users who have made a purchase, we may rely on the soft opt-in under PECR reg 22 (marketing of similar services to existing customers) — but only where an opt-out was clearly offered at the point of sale and remains available.
Opt-out: Every marketing communication includes a clear unsubscribe or opt-out mechanism. You may also withdraw marketing consent at any time in your app settings.
Push notifications: Push notification marketing is treated identically to email marketing — it requires prior consent. Service-critical push notifications (e.g. subscription renewal alerts, payout notifications) are sent on the basis of contract performance and do not require separate marketing consent.
18. Cookies and Tracking (Summary)
Cookies and tracking on the Steez website (steez.space / steelo.io) and in-app SDKs are described in full in the Cookie & Tracking Policy. Key points:
- We use Cloudflare infrastructure cookies (`__cf_bm`) for security and bot-detection — these are technically necessary;
- First-party audience analytics (Firebase Analytics first-party usage statistics), Mosaic performance analytics, Firebase Performance Monitoring and Mux viewer telemetry are off by default and operate only under your prior opt-in consent, collected at first launch and adjustable at any time in Settings → Data & Privacy; we do not rely on the DUAA first-party-statistics exemption for any of them;
- Crash diagnostics (Crashlytics) run as minimised fault diagnostics under our legitimate interests and, where the documented production configuration meets PECR's technical-fault detection exception, under that exception for device storage/access; they are not used for advertising, audience measurement or product analytics. They are on by default and you may object at any time in Settings → Data & Privacy (an Article 21 objection, not a consent toggle). Identifiers are two-mode: a pseudonymous, app-scoped installation identifier if you have not opted in, or your account ID if you have. If that configuration is not verified, crash reporting stays off until you consent. See §6 and the Cookie & Tracking Policy;
- No advertising or cross-context tracking cookies are currently in use on our web properties;
19. Changes to This Policy
We will update this policy when our data practices change. If changes are material (for example, we start a new processing activity, change our lawful basis, or change the types of data we share with third parties), we will:
- Update the version number and effective date at the top of this policy;
- Notify you by email or in-app notification before the change takes effect;
- Where required by law (for example, where we are relying on consent), obtain your fresh consent before the new processing begins.
20. Definitions
| Term | Meaning |
|---|---|
| Controller | The entity that decides how and why personal data is processed — Steelo Labs Ltd |
| Processor | An entity that processes personal data on behalf of the controller |
| Personal data | Any information relating to an identified or identifiable natural person |
| Special-category data | The categories of personal data listed in Article 9 GDPR (e.g. data revealing health, sex life, sexual orientation, racial/ethnic origin, religious or political beliefs) |
| Processing | Any operation performed on personal data (collection, storage, use, sharing, deletion) |
| Steez (key) | A personal licence ("key"), non-transferable and non-resellable, to access only what a creator explicitly offers (Mosaic exclusives, Village community, creator-picked Perks); not a financial asset, security, investment, e-money, stored value, deposit, trust asset, ownership interest, or share of creator/platform revenue |
| Anonymised data | Data rendered such that it can no longer be attributed to an identified or identifiable person, even with additional information; truly anonymised data is outside the scope of the GDPR |
| Pseudonymised data | Data that can no longer be attributed to you without additional information held separately and protected (for example, transaction records keyed to an internal identifier after your name is removed); pseudonymised data remains personal data and stays subject to the GDPR. Where this policy says financial records are "de-identified" after deletion, that process may amount to pseudonymisation rather than full anonymisation, and we treat such records as personal data accordingly |
| UK GDPR | The UK General Data Protection Regulation, as retained in UK law by the European Union (Withdrawal) Act 2018 and amended by the Data Protection, Privacy and Electronic Communications Regulations 2019 |
| EU GDPR | Regulation (EU) 2016/679 (the EU General Data Protection Regulation) |
| DSA | The EU Digital Services Act (Regulation (EU) 2022/2065) |
| CCPA / CPRA | The California Consumer Privacy Act, as amended by the California Privacy Rights Act, and comparable US state consumer-privacy laws |
| DPA 2018 | Data Protection Act 2018 |
| DUAA | Data (Use and Access) Act 2025 |
| IPA | Investigatory Powers Act 2016 |
| PECR | Privacy and Electronic Communications (EC Directive) Regulations 2003 (SI 2003/2426, as amended) |
| ICO | Information Commissioner's Office — the UK data protection regulator |
| DPF | EU-US Data Privacy Framework and UK Extension |
| IDTA | UK International Data Transfer Agreement |
| SCCs | EU Standard Contractual Clauses |
| DSAR | Data Subject Access Request |
| Steez | The Steez platform operated by Steelo Labs Ltd |
| App | The Steez mobile application (iOS and Android) |
| Website | steez.space and steelo.io |
| Creator | A user who publishes content on Steez; used here in the wider data-processing sense, irrespective of whether the Creator Terms & Earnings Agreement has yet been accepted |
| Fan | A user who subscribes to, purchases, unlocks, or otherwise engages with creator content on Steez |
| Platform Data | Data received from a third-party social media platform (e.g. Meta, Google) under that platform's developer terms |
21. Related Documents
This policy should be read alongside the following documents, which form part of our full legal framework:
- Terms of Service — your contract with Steelo Labs Ltd as a fan or general user
- Creator Terms & Earnings Agreement — additional terms for creators
- Cookie & Tracking Policy — full detail on cookies, SDKs, and tracking on web and in-app
- Acceptable Use & Community Guidelines — rules for content and conduct
- Data Deletion Policy — step-by-step guide to deleting your account and data
- Refund & Cancellation Policy — how refunds and cancellations work
- Copyright & Takedown Policy — how to report infringing content and how we respond
- Website Terms of Use — terms for visitors to steez.space / steelo.io who do not create an account
- Moderation, Complaints & Appeals Procedure — how content moderation decisions are made and appealed (includes the DSA notice-and-action mechanism for EU/EEA users)
England & Wales (global baseline). For questions, contact: privacy@steez.space