Effective 2 August 2026
Privacy policy
A clear account of what Stepmine collects, why it is needed, who receives it, and the choices you have.
1. Scope and controller
This policy covers stepmine.com, the Stepmine web application, account and organization administration, transactional email, and early-access requests.
Daniel Balastegui Julian operates Stepmine and is the data controller established in Spain. Contact [email protected] for any privacy question or request.
2. Data we collect and where it comes from
Most data comes directly from you. Technical data is generated when you use Stepmine. If someone invites you to an organization, the inviter provides your email address, assigned role, and organization name.
- Early access and communications
- Email address, language, request identifier, correspondence, and any information you choose to include in a message. The privacy-policy acknowledgement is required to send the request but is not retained.
- Account and profile
- Display name, email, protected authentication data, email-verification status, optional phone number and avatar, language, timezone, account timestamps, and the accepted Terms and Privacy policy versions with their acceptance timestamps.
- Organization and access
- Organization name, membership, role, invitations, inviter, selected organization, and security-sensitive changes.
- Device and security
- Session identifiers and timestamps, browser and device information, source IP and derived security identifiers, request identifiers, performance and diagnostic data, abuse-prevention counters, and network or device signals needed to deliver and protect the service.
3. Why we use data and our legal bases
Email, display name, password, timezone, and acceptance of the current Terms of use are required to create and secure an account. Without them, we cannot provide the account. Phone and avatar are optional. The early-access checkbox requires confirmation that you saw this policy; it is not retained and is not consent to marketing.
- Requested steps and service
- We answer early-access requests, register and verify accounts, authenticate users, manage sessions, organizations, memberships and invitations, save preferences, deliver requested account functions, and send essential service messages under GDPR Article 6(1)(b).
- Security and reliable operation
- We prevent abuse, protect accounts, investigate security events, maintain audit history, diagnose failures, and defend legal claims under our legitimate interests in a secure and dependable service, GDPR Article 6(1)(f).
- Legal compliance
- We respond to lawful requests and meet applicable legal and regulatory duties under GDPR Article 6(1)(c).
- Consent
- Current Stepmine processing does not depend on consent. If an optional feature later does, we will ask separately and you may withdraw consent at any time without affecting earlier lawful processing.
4. Cookies and local storage
Stepmine currently uses only technology needed for preferences, authentication, and abuse prevention. We do not use analytics or advertising cookies, or cross-site behavioral tracking. If we introduce non-essential analytics, we will update this policy and ask for consent before storing or accessing it on your device where required.
- Appearance preference
- Stores light, dark, or system appearance for up to 12 months.
- Language preference
- Stores the selected English or Spanish language for up to 12 months.
- Account session
- A strictly necessary cookie keeps the account signed in for a maximum of 30 days. Inactive sessions end after 7 days.
- Abuse prevention
- A security provider may use strictly necessary signals, cookies, or local storage when a protected form or sign-in action must distinguish people from automated abuse.
5. Recipients and international transfers
Access is limited to people and providers that need the data for the purposes above. We may also disclose the minimum necessary data to professional advisers, authorities, or a successor in a genuine corporate transaction when lawfully required.
Some hosting, security, and email providers may process data in the United States. For restricted transfers we use an applicable adequacy decision, including the EU-US Data Privacy Framework where valid, or the European Commission Standard Contractual Clauses with supplementary safeguards. You may request the current processor list and a copy or summary of the applicable safeguard at [email protected].
- Hosting and network security provider
- Hosts the public site, delivers content, protects the network, limits abusive requests, and verifies human interaction. It receives the network, device, request, and challenge data needed for those services.
- Email delivery provider
- Transactional and early-access email delivery. It receives recipient address, message content, locale, organization name when relevant, and delivery identifiers.
- European storage provider
- Stores account avatars in a selected European Economic Area region. It receives avatar files, storage identifiers, and request metadata.
- Business mailbox provider
- Receives early-access requests, privacy requests, and correspondence sent to Stepmine. A current processor list is available on request.
6. How long we keep data
We keep personal data only for the shortest period needed for its purpose, then delete or de-identify it. A longer period applies only where law, a dispute, or a legal claim requires it.
- Early-access requests
- Unanswered requests are deleted within 12 months. Active correspondence remains only while relevant to the request or relationship.
- Registration and recovery
- Incomplete registrations and password-reset links expire after 30 minutes. Unconfirmed avatar uploads expire after 1 hour.
- Operational delivery records
- Completed email-delivery records are removed after 7 days, failed delivery records after 30 days, and duplicate-action prevention records after 24 hours. Accepted, revoked, or expired invitations are removed after a further 30 days.
- Account and organization data
- Kept while the account or organization is active, then handled as described under Account deletion.
- Sessions
- Maximum 30 days, ended after 7 days of inactivity, and removed within 30 days after revocation.
- Security and abuse records
- Security audit events are kept for up to 12 months. Ephemeral rate-limit and login-failure counters normally expire after 15 minutes.
7. How we protect data
Stepmine applies technical and organizational controls appropriate to the risk, including encryption in transit, restricted access, separation between organizations, secure authentication and session management, protected credentials and service communications, monitoring, data minimization, and bounded retention.
No system is perfectly secure. If an incident creates a legally reportable risk, we will notify the competent authority and affected people as required.
8. Your rights and choices
Depending on the circumstances, you may request access, a copy, correction, deletion, restriction, or portability of your data; object to processing based on legitimate interests; and withdraw any consent if we ever ask for it.
Email [email protected]. We normally respond within one month. We may request proportionate information to verify identity and may limit a request only where law permits, including to protect another person's rights.
- Access and copy
- Learn whether we process your data and receive a copy with key details.
- Correction
- Correct inaccurate data or complete data that is materially incomplete.
- Deletion
- Delete data when no lawful reason requires continued processing.
- Restriction
- Temporarily limit how disputed data is used in qualifying cases.
- Portability
- Receive eligible data you supplied in a structured, machine-readable form.
- Objection
- Object to processing based on legitimate interests for reasons relating to your situation.
- Complaint
- Complain to the Spanish Data Protection Agency (AEPD) or the supervisory authority where you live or work.
9. Account deletion
You can permanently delete your account from Settings after confirming the account email. Shared organizations must retain another owner before deletion can proceed.
Deletion revokes sessions, removes memberships, queues the avatar for deletion, and replaces direct profile identifiers with a de-identified disabled record. A minimal technical tombstone, legal acceptance record, and security audit may remain for integrity, compliance, and legal claims; the audit expires within 12 months and the tombstone is not used to identify or contact you.
10. No sale, advertising, or automated decisions
We do not sell personal data, share it for cross-context behavioral advertising, or use it to build advertising profiles.
Stepmine does not make decisions producing legal or similarly significant effects through solely automated processing and does not perform user profiling.
The service is intended for professional use and is not directed to children. Contact us if you believe a child supplied personal data and we will investigate and delete it where required.
11. Changes, contact, and complaints
We may update this policy when the service, providers, or law changes. Material changes will be highlighted in the service or sent to the account email before they take effect where appropriate.
Questions and rights requests: [email protected]. Please do not send passwords, credentials, or identity documents unless we specifically request a secure verification method.
You can complain to the AEPD or another competent supervisory authority without first contacting us.