1. Who we are
Soteria ("Soteria", "we", "us", "our") provides a Financial Leakage Intelligence platform for finance teams — invoice-line analysis, spend benchmarking, contract control and payment-integrity support. This Privacy Policy explains how we handle personal data in connection with our website and our services.
The data controller for the purposes described in Section 3 (website and marketing) is:
[SOTERIA LEGAL NAME], [REGISTERED ADDRESS], company number [COMPANY NUMBER]. Contact: [PRIVACY EMAIL]. Data protection contact: [DPO CONTACT].
2. Our two roles: controller and processor
It is important to distinguish two different situations, because our responsibilities differ in each.
When we are a data controller. For personal data relating to our website visitors, prospects, demo requesters and marketing contacts, Soteria decides why and how the data is processed. This Privacy Policy governs that processing.
When we are a data processor. When a customer uses the Soteria platform, they upload or connect business data such as invoices, contracts, supplier master data and payment records. That data may contain personal data (for example, names, contact details or bank details of the customer's suppliers, vendor representatives or employees). For this data, the customer is the data controller and Soteria acts only as a data processor, processing it on the customer's documented instructions under a separate Data Processing Agreement (DPA). We do not use customer platform data for our own purposes, and we do not sell it. If you are an employee, supplier or contact of a Soteria customer and have questions about that data, please contact the relevant customer (the controller) in the first instance.
3. Personal data we collect as controller
Contact and demo-request data: name, work email, company, role and any message you submit through our forms.
Communications data: correspondence when you contact us or we contact you.
Usage and device data: IP address, browser type, pages viewed, referring source and similar analytics data collected via cookies and similar technologies (see Section 9).
Marketing preferences: your consent and communication choices.
We do not intentionally collect special categories of personal data through our website, and we ask that you do not submit them via free-text fields.
4. Purposes and lawful bases
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Respond to demo requests and enquiries | Performance of a contract / steps prior to a contract, and our legitimate interests |
| Provide, secure and improve our website | Our legitimate interests in operating and protecting our business |
| Send marketing communications about Soteria | Consent, or legitimate interests where permitted for existing business contacts |
| Analytics and website measurement | Consent (where required for non-essential cookies) |
| Comply with legal, tax and accounting obligations | Compliance with a legal obligation |
| Establish, exercise or defend legal claims | Our legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights. You may ask us for more information about that assessment.
6. International transfers
Where personal data is transferred outside the European Economic Area, we rely on an appropriate transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary measures where necessary. Details are available on request.
7. Retention
We keep personal data only as long as necessary for the purposes above, then delete or anonymise it. Demo and enquiry data is typically retained for the duration of our discussions and for a reasonable period afterwards to manage the relationship and meet legal requirements; marketing data is kept until you unsubscribe or object. Customer platform data is retained and deleted in accordance with the applicable DPA and customer instructions.
8. Security
We maintain appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, logical separation of customer data, least-privilege access, logging and auditability, and regular review of our controls. No system is perfectly secure, but we work to protect your data and to detect and respond to incidents.
10. Your rights
Subject to conditions and exemptions under applicable law, you have the right to: access your personal data; have it rectified; have it erased; restrict or object to processing; data portability; and withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with your supervisory authority — in our case, [SUPERVISORY AUTHORITY] in [EU MEMBER STATE], or the authority in your country of residence.
To exercise any right, contact [PRIVACY EMAIL]. We will respond within the timeframes required by law. If your request concerns data we process on behalf of a customer (as processor), we will refer you to, or coordinate with, the relevant customer.
11. Children
Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from children.
12. Changes to this Policy
We may update this Policy from time to time. We will post the updated version here and revise the "Last updated" date. Material changes will be communicated where appropriate.
13. Contact
Questions or requests: [PRIVACY EMAIL]. Data protection contact: [DPO CONTACT]. Postal: [SOTERIA LEGAL NAME], [REGISTERED ADDRESS].