STEAV
Book a Demo →
Products
CIDEnd-to-end, cryptographically verified AI infrastructureAmplifyComing soonMonolithComing soon
Solutions
HealthcareHIPAA · FDA AI/MLFinancial ServicesFFIEC · NYDFS 500GovernmentNDAA §1513InsuranceFairness · Rate filingsEnterpriseAll other industries
Managed Services
STEAV DataSTEAV EvalSTEAV Test
Company
AboutOur CaseSecurityNewsContactPartnership Program
Resources
DocumentationGuidesSafety
Legal
TermsPrivacyCookiesAcceptable Use
Trust, made verifiable
Legal
Overview and scopeInformation we collectHow we use Personal Information, and our legal basesDisclosure of Personal InformationCookiesData retentionInternational data transfersYour rightsData securityChildren's privacyRegion-specific disclosuresChanges to this PolicyContact usDefinitions
STEAV

Privacy Policy


Last updated: August 2026
01

Overview and scope

1.1 This Privacy Policy (this "Policy") describes how STEAV collects, uses, discloses, and otherwise processes Personal Information in connection with the Sites and our business relationships. STEAV develops CID, verifiable artificial-intelligence infrastructure for regulated industries.

1.2 This Policy applies solely to Personal Information for which STEAV acts as a controller. It does not apply to Personal Information that STEAV processes on behalf of, and on the instructions of, its customers within the CID platform, which processing is governed by the applicable customer agreement and Data Processing Agreement ("DPA") and not by this Policy.

1.3 CID runs one pipeline with two training modes — centralized and federated. In federated (self-hosted) deployments, a customer's raw training data remains within the customer's own environment and is not transmitted to STEAV; in centralized deployments, training data is processed on the platform under the applicable customer agreement and DPA.

02

Information we collect

We collect the following categories of Personal Information:

2.1 Information you provide. When you submit an inquiry through a form on the Sites, we collect the information you enter, namely your (a) name; (b) email address; (c) company; (d) industry; and (e) reason for your inquiry. If you correspond with us directly, we also collect the information contained in your communications.

2.2 Information collected automatically. When you access the Sites, we and our infrastructure providers automatically collect certain technical information, including (a) your Internet Protocol (IP) address; (b) browser and device type; (c) referring pages; and (d) access dates and times, in each case recorded in server logs and used to operate and secure the Sites.

2.3 Cookies. We use only strictly necessary Cookies, as described in Section 5 and in our Cookie Policy.

2.4 What we do not collect. We do not knowingly collect through the Sites: (a) payment-card information; (b) information via self-service account registration (which we do not offer); or (c) special categories of data or sensitive Personal Information (such as government identifiers, health information, or precise geolocation).

03

How we use Personal Information, and our legal bases

3.1 We use Personal Information for the following purposes: (a) to respond to and follow up on your inquiries, and to communicate with you regarding our products and your potential use of them; (b) to operate, maintain, secure, and improve the Sites; (c) to comply with applicable legal obligations and enforce our agreements; and (d) to protect the rights, safety, and property of STEAV, our users, and others.

3.2 Where the GDPR applies, we rely on the following legal bases, as applicable to each purpose in Section 3.1: (a) our legitimate interests in responding to inquiries, operating and securing the Sites, and conducting our business; (b) the taking of steps at your request prior to entering into a contract; (c) compliance with a legal obligation to which we are subject; and (d) your consent, where we specifically request it. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

04

Disclosure of Personal Information

4.1 We do not sell your Personal Information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA.

4.2 We disclose Personal Information only to the following categories of recipients: (a) Service Providers that process it on our behalf to operate our business, including infrastructure/hosting and email-delivery providers, and that are permitted to use it solely to provide services to us; (b) legal and governmental recipients, where required by applicable law, legal process, or governmental request, or where necessary to protect rights, safety, or property; and (c) parties to a corporate transaction, such that, in connection with any merger, acquisition, financing, reorganization, or sale of assets, Personal Information may be disclosed or transferred as part of that transaction, subject to this Policy.

05

Cookies

5.1 The only Cookies we set are strictly necessary — those required for the Sites to load, function, and remain secure. We do not use advertising or third-party tracking Cookies, and we do not track you across other websites.

5.2 We use Vercel Web Analytics to measure aggregate traffic to the Sites. It is provided by our hosting provider, Vercel Inc., is served from our own domain, and does not set Cookies or any other identifier on your device. Because it is not strictly necessary, it is loaded only where you have consented; if you have not chosen, or have declined, it is not loaded at all. You may withdraw consent at any time from the Cookie settings panel. Where your browser sends a Global Privacy Control signal, it is not loaded regardless of any stored preference.

5.3 Should we introduce further analytics or similar technologies, we will update this Policy and provide any notice and choices required by applicable law before doing so. For further detail, see our Cookie Policy.

06

Data retention

6.1 We retain Personal Information only for as long as necessary to fulfill the purposes described in this Policy, including (a) to respond to and follow up on your inquiries; (b) to comply with applicable legal, accounting, or reporting obligations; and (c) to establish, exercise, or defend legal claims.

6.2 When Personal Information is no longer required, we delete or anonymize it. The applicable retention period depends on the nature of the Personal Information and the purpose for which it is processed.

07

International data transfers

7.1 STEAV is based in the United States and operates as a distributed organization. Personal Information may therefore be processed in the United States and in other jurisdictions in which we or our Service Providers operate, which may afford different protections than those of your jurisdiction.

7.2 Where we transfer Personal Information subject to the GDPR outside the European Economic Area (the "EEA") or the United Kingdom, we implement an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with any supplementary measures necessary to protect such Personal Information.

08

Your rights

8.1 Subject to applicable law, you may have the following rights with respect to your Personal Information: (a) access — to obtain confirmation of, and a copy of, the Personal Information we hold; (b) rectification — to correct inaccurate Personal Information; (c) erasure — to request deletion; (d) portability — to receive it in a portable format; (e) restriction and objection — to limit or object to certain processing (GDPR); (f) withdrawal of consent — where processing is based on consent; (g) opt out of sale or sharing (CCPA), noting that we do not sell or share Personal Information; (h) limit the use of sensitive Personal Information (CCPA), noting that we do not collect sensitive Personal Information for purposes that would give rise to this right; and (i) non-discrimination — we will not treat you differently for exercising your rights.

8.2 To exercise any right in Section 8.1, contact us at privacy@steav.io. We may need to verify your identity before responding, and you may use an authorized agent to submit a request where permitted by applicable law. We will respond within the timeframes required by applicable law.

8.3 Individuals in the EEA or the United Kingdom additionally have the right to lodge a complaint with their competent supervisory authority.

09

Data security

9.1 We maintain reasonable technical and organizational measures designed to protect Personal Information against unauthorized access, use, alteration, and destruction, including encryption, access controls, and audit logging. Additional information is available on our Security page.

9.2 No method of transmission or storage is entirely secure, and we cannot guarantee absolute security.

10

Children's privacy

10.1 The Sites and our products are intended for businesses and are not directed to children. We do not knowingly collect Personal Information from children. If you believe a child has provided us Personal Information, contact us and we will take appropriate steps to delete it.

11

Region-specific disclosures

11.1 California (CCPA/CPRA). During the preceding twelve (12) months, we have: (a) collected the categories of Personal Information described in Section 2 (identifiers such as name and email address; professional or employment-related information such as company and industry; and internet or other electronic network activity information); (b) used them for the purposes in Section 3; and (c) disclosed them only to the categories of recipients in Section 4. We do not sell or share Personal Information and do not collect sensitive Personal Information for purposes requiring the right to limit its use. California residents may exercise the rights in Section 8.

11.2 EEA / United Kingdom (GDPR). The controller of your Personal Information is STEAV. Our legal bases are described in Section 3, and you may exercise the rights in Section 8, including the right to lodge a complaint with your supervisory authority.

12

Changes to this Policy

12.1 We may amend this Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide more prominent notice. Your continued use of the Sites after the effective date of a revised Policy means the revised Policy applies, to the extent permitted by applicable law.

13

Contact us

13.1 For questions or requests regarding this Policy or your Personal Information, contact:

STEAV Inc. · Privacy: privacy@steav.io

14

Definitions

The following terms are used throughout this Policy:

14.1 "Personal Information" (used interchangeably with "personal data") means information that identifies, relates to, or could reasonably be linked with an identified or identifiable individual, and has the meaning given under applicable data-protection laws, including the EU/UK General Data Protection Regulation ("GDPR") and applicable U.S. state privacy laws (including the California Consumer Privacy Act, as amended, the "CCPA").

14.2 "Sites" means the websites located at steav.io and any associated subdomains operated by STEAV.

14.3 "Service Providers" means third parties that process Personal Information on STEAV's behalf and on its instructions.

14.4 "STEAV," "we," "us," or "our" means STEAV Inc.

STEAV
Trust, made verifiable
Products
CIDAmplifySoonMonolithSoon
Managed Services
STEAV DataSTEAV EvalSTEAV Test
Company
SecurityAboutOur CaseNewsContactPartnership Program
Solutions
HealthcareFinancial ServicesGovernmentInsuranceEnterprise
Resources
DocumentationGuidesSafety
Legal
TermsPrivacyCookiesAcceptable Use
© 2026 STEAV Inc. All rights reserved