Privacy Policy
Version 1.6 · last updated 10 October 2026
This policy explains what happens to personal data when you visit platform.uprelic.com or api.uprelic.com, sign up for Strom, send us an enterprise enquiry, or use Strom as a customer. It is the information we owe you under Art. 13 and Art. 14 GDPR. For every processing activity it states what we process, why, on what legal basis, and for how long.
Strom is Uprelic's own decision model, fine-tuned by Uprelic from open model weights, and offered as an API. It runs on GPU servers operated for us in the EU (section 7). No third-party AI provider receives the content you send to Strom, and we never use that content to train any model (section 8).
This policy informs you; it is not part of any contract. Strom is offered to businesses only.
1. Who is responsible, and how to reach us
The controller within the meaning of Art. 4 No. 7 GDPR for the processing described in this policy is:
Uprelic GmbH Liebenwalder Straße 16 13347 Berlin Germany
Registered at Amtsgericht Berlin (Charlottenburg), HRB 288877 B.
Email: privacy@uprelic.com
For data protection matters, including any of the rights in section 17, please write to the address above.
Data protection officer: We are not required to designate a data protection officer (Art. 37 GDPR, § 38 BDSG). Please send data protection questions to the email address above.
2. Our two roles: controller and processor
We act in two different roles, and it matters which one applies.
Where we are the controller. We are the controller only for:
- accounts, billing, security and logs: our own websites, the former waitlist, user accounts and sign-in, billing and payments, the emails we send, product analytics on our websites and in the console, request metadata we need for billing and tax, backups, server logs and the security of our systems; and
- a limited review of request content to detect and handle abuse, security incidents and breaches of our Acceptable Use Policy, on the basis of Art. 6(1)(f) GDPR (section 7).
This policy describes that processing in full.
Where we are a processor. Apart from the limited review in point 2 above, the content a customer sends to Strom through the API or the console playground — the state (text or JSON), the question texts, images or image addresses, and the responses Strom returns — is processed by us on the customer's behalf and on its instructions. For that content, the customer is the controller and we are its processor under Art. 28 GDPR, governed by our Data Processing Agreement. Section 7 describes this processing briefly.
In no role do we use request content to train any model (section 8).
If your personal data appears in content that one of our customers sends to Strom, please contact that customer: it decides what is sent and how the results are used, and its own privacy information applies. If you contact us, we will refer you to the customer and support it in answering you.
3. Visiting our websites
3.1 Server logs
What. When your browser or an API client connects to platform.uprelic.com or api.uprelic.com, our web server and application write log entries containing your IP address and request metadata, such as the time, the requested address and the response status.
Why. To deliver the websites and the API, to keep them stable, and to detect, investigate and stop attacks, abuse and faults.
Legal basis. Art. 6(1)(f) GDPR. Our legitimate interest is operating a reliable and secure service. Where the request is part of using your account, the processing is also necessary to perform the contract, Art. 6(1)(b) GDPR.
Retention. 90 days, then deleted automatically.
3.2 Load balancer
All traffic to our websites and to the API reaches our servers through a load balancer operated by Scaleway (Scaleway SAS, France) in its data centres in France. The load balancer terminates the encrypted TLS connection and forwards the request to our servers over a private network. For this, Scaleway processes connection data including your IP address, on our behalf as our processor, in the EU. Our servers limit the rate of requests per IP address to protect the service against overload.
The DNS records of our domains are hosted by Cloudflare (Cloudflare, Inc., USA). Cloudflare answers the DNS lookups for our host names, which usually come from your internet provider's DNS resolver rather than from your device; your traffic to our websites and to the API does not pass through Cloudflare.
Legal basis. Art. 6(1)(f) GDPR. Our legitimate interest is delivering the service securely, protecting it against misuse and overload, and showing you the right version of our pages (section 3.3).
3.3 Choosing the page version and currency
To show you prices in a suitable currency and to decide whether to show you the European or the international version of our home page, our server derives your region from the country of your IP address, which it looks up in a geolocation database stored on our servers (IP geolocation by DB-IP, licensed under CC BY 4.0). This happens on our side when the page is delivered; your IP address is not sent to anyone for this. The result is not stored, except for the country on your account’s first visit to the console, which chooses the version of your welcome email and is kept with its copy (section 10), and the country of an earlier waitlist sign-up (section 4), and nothing is stored on or read from your device for this purpose.
Legal basis. Art. 6(1)(f) GDPR. Our legitimate interest is presenting prices and content that fit where you are.
3.4 Product analytics
We measure how our websites and the console are used with PostHog, an open-source analytics tool that we run ourselves on our own servers at Scaleway in France (section 13). PostHog Inc. receives no data.
Without your consent (the default). Until you accept in our cookie banner, and after you decline, we count page views and clicks without storing anything on your device or reading anything from it. To tell visits apart, our analytics server forms a hash from your IP address and your browser's user agent together with a secret value that changes every day. The IP address and the user agent are removed before anything is stored, and the hash cannot be traced back to you or linked across days. We record the page address, the referring page, your browser, operating system and screen size, and which elements you click; in the console we do not record the text of what you click. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is understanding which pages and functions are used, so that we can improve Strom. You can object at any time (section 18).
With your consent. If you click "Accept", we additionally store an identifier on your device (section 12), so that we can recognise your browser across visits. From your IP address we derive your approximate location (country, region, city and postal code); the IP address itself is then discarded. We also record your sessions (session replay): how the pages look and how you scroll, move and click. In recordings, everything you type is masked; in the console all text is masked, and the playground, demos, usage, API keys and admin pages are not recorded at all. Network requests are never recorded. If you are signed in to the console, we link this data to your account's internal identifier and to your email address. Legal basis: your consent, § 25(1) TDDDG and Art. 6(1)(a) GDPR. You can withdraw it at any time with effect for the future under "Cookie settings" at the bottom of every page.
What never reaches our analytics. The content of your requests to Strom, API keys, and anything in page addresses after the path, such as sign-in codes, payment references or unsubscribe links: we remove query parameters and fragments before anything is sent, except campaign tags beginning with utm_.
Retention. Analytics events 12 months, session recordings 30 days, then deleted. Analytics data is not included in our backups (section 11).
4. The former waitlist and enterprise enquiries
Until October 2026 Strom was in a private beta, and instead of signing up you could join a waitlist. Sign-up is now open to everyone, and the waitlist takes no new entries.
What. For entries made until then: the email address, the time of joining, the country of the IP address when joining (section 3.3) and, where we approved the entry, the time of approval.
Why. To manage access to the beta, to decide on admission, and to create accounts and notify people when they were approved.
Legal basis. Art. 6(1)(b) GDPR — steps taken at your request before entering into a contract. Where you joined on behalf of a business you work for, Art. 6(1)(f) GDPR — our legitimate interest in handling access requests from prospective business customers.
Retention. An approved entry is part of the account (section 5). Entries that were not approved are deleted 24 months after sign-up, or at any time earlier if you ask us.
Enterprise enquiries
You can leave your work email on our enterprise page so that we contact you about a dedicated deployment.
What. Your work email address, the language of the page and the time of the enquiry.
Why. To contact you about your enquiry and, if you wish, to prepare an offer. We store the enquiry, send it by email to our sales inbox and post a short notice with your email address to our internal team chat.
Legal basis. Art. 6(1)(b) GDPR — steps taken at your request before entering into a contract. Where you ask on behalf of a business you work for, Art. 6(1)(f) GDPR — our legitimate interest in answering prospective business customers.
Retention. 24 months after the enquiry, or at any time earlier if you ask us. If you become a customer, the contract data you give us is kept as stated in section 5.
5. Signing in and your account
What. Your email address, an optional display name, sign-in data (email, sign-in timestamps and the sign-in method used), your account balance and its currency, your Stripe customer ID, the API keys you create, and — for Uprelic staff only — an administrator flag.
How you sign in. Either with a one-time magic link sent to your email address, or — where this option is enabled and you choose it — with Google. If you use Google sign-in, Google confirms your identity to us and we receive the account identifier and the email address associated with your Google account (Art. 14 GDPR: we receive this data from Google, not from you). Google processes your sign-in under its own terms.
Why. To create and run your account, to authenticate you, and to provide the console and the API.
Legal basis. Art. 6(1)(b) GDPR where you are yourself our contracting party. Where you use Strom as an employee or on behalf of a business customer, Art. 6(1)(f) GDPR — our legitimate interest in providing the service we owe to that business customer to the people it authorises.
Do you have to provide this data? An email address is required: without it we cannot create an account or let you sign in. The display name is voluntary.
API keys. You create API keys yourself in the console. Keep them secret: anyone who holds a key can use Strom on your account.
Retention. For as long as the account exists. Within 30 days after the account is closed we delete its API keys, sign-in data, waitlist entry (if any), the content of stored requests and any other personal data not listed here. We keep contract and account data (company and contact details, records of your acceptance of our terms, account history) for three years after closure to establish or defend claims (§ 195 BGB), and then delete it. Invoices, bookings and payment records are kept longer, see section 9.
6. Using the console
In the console at platform.uprelic.com you can use the playground, manage API keys, view your usage and manage your balance and payments.
What. The account data in section 5, the usage and billing data in section 9, and — when you use the playground — the requests and responses described in section 7, which are stored in the same way as API requests. We also measure how the console is used, as described in section 3.4.
Legal basis. As in section 5. For playground content, see section 7.
7. API requests: the content sent to Strom
What we receive. Each request to Strom contains a state (text or JSON), up to 256 questions and up to 8 images. Images can be sent inline (as data URLs) or as http(s) addresses; for an address, our server downloads the image itself.
What we store. Standard API and playground requests are stored with their full input (the state and the question texts) and the full response, together with metadata: time, source (API or playground), the name of the key used, the model, the number of questions and images, tokens, cost and the exchange rate applied.
Zero data retention. For accounts enabled on request, calls to POST /v1/systemone/private retain only billing and operational metadata in our database. Customer content, including inputs, outputs, image URLs and content-bearing errors, is excluded from application request records and database backups, and is not available for retrospective content review. Backend exception logging excludes content. Infrastructure logging and operating-system memory handling retain their normal settings; model-server diagnostics, swap and crash dumps are outside this application-storage guarantee. Standard calls retain their normal policy. See Zero data retention.
Images. Images sent inline are redacted in the stored copy: we keep only their type and length, not the image. For images sent as an address, we store the address as sent; the downloaded image itself is not stored.
Our role. For the content of requests and responses, we act as processor on behalf of the customer (section 2), under the Data Processing Agreement. We use it to answer the request, to show the customer its request history, and to investigate errors. For the metadata we need for billing, tax and usage history, we are controller (section 9).
Limited review for abuse and security (as controller). Authorised Uprelic staff may review the content of individual requests where this is needed to detect and handle abuse, security incidents or breaches of our Acceptable Use Policy. For this review we act as an independent controller. The review is limited to the requests concerned and to what the purpose requires; we use the content for nothing else and never for training (section 8). Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is protecting the Service, our customers and third parties against misuse and attacks, and enforcing our Acceptable Use Policy. Retention: where a review confirms or reasonably suspects abuse, a security incident or a breach of the Acceptable Use Policy, we may keep the requests concerned, and only those, separately and with restricted access as evidence beyond the periods below: until the matter is closed and for no more than 12 months after the review, or longer only while legal proceedings or an authority's request require it (Art. 17(3)(e) GDPR). We never keep suspected child sexual abuse material as evidence; we report it and follow the authorities' instructions.
Where it is processed. Requests are processed on GPU servers in the EU, operated for us by a GPU cloud provider (section 13), Scaleway, in its data centres in France. The model servers have no route to the internet.
Retention.
- Content of requests and responses: 90 days, then deleted automatically. This standard period is the customer's documented instruction under the Data Processing Agreement. The customer can instruct us at any time to delete content earlier; we then delete it within 30 days.
- Metadata needed for billing, tax and usage history (time, counts, tokens, cost): for the lifetime of the account and, beyond that, as part of our booking records for 8 to 10 years (section 9).
Personal data in content. Customers decide what they send to Strom. If a customer sends personal data, it is responsible for having a legal basis to do so. Strom's outputs are predictions with probabilities; the customer decides how to act on them (see section 20).
8. No training on customer content
We never use customer inputs or outputs — requests, images, responses — to train, fine-tune or evaluate Strom or any other model. Not now, and not in anonymised form. We train our models on other data: public datasets, synthetic data and our own data.
No third-party AI provider receives customer content.
9. Payments and billing
How it works. Strom works with a prepaid balance. You top it up through Stripe Checkout, or automatically if you turn on automatic top-up. Stripe processes the payment, calculates tax and creates the invoice; you can enter a tax ID there. We never see or store your card or bank details. Invoices and billing details are held at Stripe, not in our database.
Free credit. A new account can get a one-time free credit by verifying a card in Stripe Checkout. The card is saved with Stripe and not charged. So that each card gets the credit only once, whatever the account, we store the card fingerprint Stripe gives us — an identifier of the card number from which the number cannot be recovered — with the account, the time and whether the credit was granted. The legal basis is Art. 6(1)(f) GDPR, our legitimate interest in preventing the free credit from being claimed repeatedly with the same card. We keep the fingerprint for the lifetime of the account and for three years after it is closed, so the card cannot claim the credit again on a new account; then we delete it.
Saved payment method and automatic top-up. The payment method you use in Stripe Checkout is saved with Stripe, so that automatic top-up can charge it; you can remove it in the Stripe customer portal. If you turn automatic top-up on, Stripe charges that payment method the amount you chose whenever your balance falls below the threshold you set. We store whether automatic top-up is on, the threshold, the amount and, if a payment fails, the reason Stripe gives, for the lifetime of the account. We still never see your card or bank details.
What we process. Your Stripe customer ID, your balance and its currency, the top-ups you make, your automatic top-up settings, the card fingerprint if you claim the free credit, the payment confirmations Stripe sends us (stored in full, to be able to trace payment problems), and the request metadata in section 7 on which each charge is based.
Stripe's role. Stripe acts as our processor for payment handling. For some processing — in particular fraud prevention and compliance with its own legal obligations as a payment service provider — Stripe acts as an independent controller under its own privacy policy.
Legal basis. Art. 6(1)(b) GDPR for taking payment and keeping your balance; Art. 6(1)(c) GDPR for keeping accounting and tax records; Art. 6(1)(f) GDPR for storing the payment confirmations, our legitimate interest being to trace and resolve payment problems.
Retention. Invoices, bookings and payment confirmations, including the stored Stripe payment notifications and the request metadata that underlies charges, are kept for as long as German law requires: 8 years for accounting vouchers such as invoices and 10 years for books and records (§ 147 AO, § 257 HGB), counted from the end of the calendar year. Then we delete them.
10. Emails we send
What. We send the emails the service needs: sign-in links, a welcome email when you first open the console after signing up, and notices about your account, such as a warning that your balance is low. You can turn the low-balance warning off or change when it is sent under Settings → Notifications in the console. For this we process your email address and the content of the message.
Copies. We keep a copy of the welcome email and of each notice about your account (the message, when it was sent and whether delivery succeeded), so we can answer questions about it. Copies are deleted 12 months after sending, or when your account is closed, and are included in your data export.
Transport. Emails are sent through Amazon SES (Amazon Web Services EMEA SARL) in the eu-central-1 region (Frankfurt, Germany), acting as our processor.
Legal basis. Art. 6(1)(b) GDPR, or Art. 6(1)(f) GDPR where you act for a business customer (see section 5).
Product updates. Now and then we email you about new features of Strom, such as a new endpoint. For this we process your email address and the language of your console, which we store when you use the console, and keep a copy of each message as described above. You can object to these emails at any time and free of charge, with the unsubscribe link in each of them or under Settings → Notifications in the console. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in telling customers about our own similar services, together with § 7(3) of the German Unfair Competition Act (UWG).
No tracking. Our emails contain no tracking pixels and no click tracking. Beyond product updates, we do not send a newsletter.
11. Backups
What. Our whole database — and with it the data described in sections 4 to 9 — is backed up daily. Backups are encrypted before they leave our servers and are stored in Scaleway Object Storage (Scaleway SAS) in Amsterdam, Netherlands (stored and processed in the EU); Scaleway holds no key.
Why. To be able to restore the service and your data after a failure or an attack.
Legal basis. Art. 6(1)(f) GDPR — our legitimate interest in the availability and integrity of the service; Art. 32 GDPR requires us to be able to restore data. For customer content, the backups are part of our processing on the customer's behalf.
Retention. We keep 14 daily, 8 weekly and 12 monthly backups. Data deleted from the live database therefore disappears from all backups within 12 months at the latest.
12. Cookies and local storage
Without your consent, we store only what our websites need to work as you requested. On platform.uprelic.com:
| Name / type | What it holds | Purpose | Duration |
|---|---|---|---|
| Sign-in session (local storage) | Your sign-in session | Keeps you signed in to the console | Until you sign out or the session ends |
| Language choice (local storage) | The language you chose | Shows the site in your language | Until you change it or clear your browser storage |
| Cookie choice (local storage) | Whether you accepted or declined analytics | Remembers your choice, so that we don't ask again | Until you change it or clear your browser storage |
Only if you accept analytics (section 3.4):
| Name / type | What it holds | Purpose | Duration |
|---|---|---|---|
ph_…_posthog (cookie, local storage and session storage) |
A random identifier for your browser and the current session | Product analytics and session replay | Cookie: 1 year; otherwise until you withdraw your consent or clear your browser storage |
Without your consent we set no cookies, and we never read your browser's time zone or language settings on your device.
When we ask for consent. Under § 25(1) TDDDG, storing information on your device or accessing information already stored there requires your consent — unless, under § 25(2) No. 2 TDDDG, it is strictly necessary for us to provide a service you have explicitly requested. Your sign-in session, the language you chose and your cookie choice are strictly necessary for functions you request, so we store them without asking. The analytics identifier is not; we set it only after you accept in our cookie banner. Without your consent, our analytics store nothing on your device and read nothing from it (section 3.4). The currency and page version are chosen on our side from your IP address (section 3.3); nothing is stored on or read from your device for this. Where personal data is involved, the legal basis is Art. 6(1)(f) GDPR, as set out in sections 3.3 and 5, and for analytics as set out in section 3.4.
No advertising, no third-party tracking. We use no advertising cookies, no third-party analytics or tracking services and no tracking pixels. Our analytics run on our own servers (section 3.4).
13. Recipients and processors
Inside Uprelic, only people who need access to do their job have it.
We use the following service providers, each for a defined purpose:
- GPU cloud provider — Scaleway SAS (France): operates the servers that run Strom, our analytics (section 3.4) and the load balancer in front of them, in its data centres in France, and stores our encrypted backups in Amsterdam, Netherlands.
- Cloudflare, Inc. (USA), under Cloudflare's Data Processing Addendum — DNS hosting for our domains (section 3.2).
- Stripe Payments Europe, Ltd. (Ireland) — payments, invoices, tax calculation, customer portal; partly an independent controller (section 9).
- Amazon Web Services EMEA SARL — Amazon SES in Frankfurt for sending emails (section 10).
- Google Ireland Limited / Google LLC — only if you choose Google sign-in (section 5); Google acts as an independent controller.
The current list, with each provider's role and location, is on our Subprocessors page.
We use no AI model providers and no third-party analytics providers: our analytics tool runs on our own servers (section 3.4).
Beyond this, we disclose data to tax advisers, auditors or public authorities only where we are legally required to or where it is necessary to establish, exercise or defend legal claims.
14. Transfers outside the EU/EEA
Some of our service providers — Cloudflare, Stripe, Amazon Web Services and Google — belong to groups based in the United States or operate globally, so personal data may be processed or accessed outside the EU/EEA.
We allow such a transfer only where at least one of the following applies:
- the European Commission has decided that the country ensures an adequate level of protection (Art. 45 GDPR) — for the United States, this covers recipients certified under the EU-US Data Privacy Framework; or
- we or our processor have agreed the European Commission's standard contractual clauses with the recipient (Art. 46(2)(c) GDPR), with additional safeguards where necessary.
The mechanism used for each provider is stated on the Subprocessors page. You can request a copy of the safeguards from us at the contact address in section 1.
15. Retention at a glance
| Data | How long |
|---|---|
| Server and security logs | 90 days |
| Region derived from your IP address | Not stored |
| Analytics events | 12 months |
| Session recordings (with your consent) | 30 days |
| Sign-in session, language choice, cookie choice (in your browser) | Until you sign out, change or clear them |
| Analytics identifier (in your browser, with your consent) | Until you withdraw consent or clear it; the cookie expires after 1 year |
| Waitlist entry (approved, until October 2026) | Becomes part of the account |
| Waitlist entry (not approved, until October 2026) | 24 months after sign-up; earlier on request |
| Enterprise enquiry | 24 months after the enquiry; earlier on request |
| Copies of the welcome email and of notices about your account (e.g. low balance) | 12 months after sending; at once when the account is closed |
| Contract and account data | Lifetime of the account, then 3 years after closure (§ 195 BGB) |
| Card fingerprint for the free credit | Lifetime of the account, then 3 years after closure |
| Other personal data of a closed account | Deleted within 30 days after closure |
| Content of requests and responses | Standard calls: 90 days, or earlier on the customer's instruction. Private endpoint: no content retained in application request records |
| Requests kept as evidence of abuse | Until the matter is closed, at most 12 months after review, unless proceedings are pending |
| Request metadata (time, counts, tokens, cost) | Lifetime of the account, then as booking records (8–10 years) |
| Invoices, bookings, payment confirmations (incl. stored Stripe notifications) | 8–10 years (§ 147 AO, § 257 HGB) |
| Backups | Up to 12 months |
16. Where your data comes from
We receive most data directly from you. Exceptions: if you use Google sign-in, your account identifier and email address come from Google (section 5); payment status comes from Stripe (section 9).
17. Your rights
You have the following rights regarding your personal data. Exercising them is free of charge.
- Access (Art. 15 GDPR) — to know whether we process data about you, and to receive a copy of it together with the information in this policy.
- Rectification (Art. 16 GDPR) — to have inaccurate data corrected and incomplete data completed.
- Erasure (Art. 17 GDPR) — to have data deleted where one of the grounds in Art. 17(1) applies and no legal retention duty stands in the way. Where we must keep something, such as accounting records, we will tell you what and why.
- Restriction (Art. 18 GDPR) — to have us keep data without using it, for example while its accuracy is disputed.
- Data portability (Art. 20 GDPR) — to receive the data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection (Art. 21 GDPR) — see section 18.
Only analytics with an identifier on your device and session replay (section 3.4) are based on your consent. You can withdraw it at any time with effect for the future (Art. 7(3) GDPR), under "Cookie settings" at the bottom of every page.
To exercise your rights, write to the contact address in section 1. We answer within one month; where a request is complex, we may extend this by two further months and will tell you within the first month (Art. 12(3) GDPR). If we have reasonable doubts about your identity, we may ask for the information needed to confirm it.
For content a customer has sent to Strom, please address your request to that customer (section 2).
18. Your right to object
Right to object under Art. 21 GDPR
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data that we carry out on the basis of Art. 6(1)(f) GDPR. In this policy, that is: the server logs and the load balancer (sections 3.1 and 3.2), the choice of page version and currency (section 3.3), product analytics without your consent (section 3.4), the limited review of request content for abuse and security (section 7), the former waitlist where you joined for a business and enterprise enquiries you send for a business (section 4), account and sign-in data where you act for a business customer (section 5), stored payment confirmations and the card fingerprint for the free credit (section 9), emails where you act for a business customer (section 10), and backups (section 11).
If you object, we will no longer process the data concerned, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
We do not process your data for direct marketing. If we ever do, you may object to it at any time, without giving reasons, and we will stop.
To object, write to the contact address in section 1.
19. Right to complain to a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your habitual residence, your place of work or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit Alt-Moabit 59–61, 10555 Berlin, Germany Telephone: +49 30 13889-0 Email: mailbox@datenschutz-berlin.de
You are welcome to contact us first, but you do not have to.
20. No automated decision-making about you
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Access to the beta is decided by a person at Uprelic.
Strom itself produces predictions with probabilities for our customers. Those predictions can be wrong. It is the customer, not Uprelic, who decides whether and how to act on them — for example with thresholds or human review. Our terms do not allow customers to use Strom as the sole basis for decisions with legal or similarly significant effects on people without human review.
21. Security
We protect personal data with technical and organisational measures appropriate to the risk (Art. 32 GDPR). Among them:
- all connections to our websites and the API are encrypted (TLS); traffic reaches our servers only through the load balancer, over a private network;
- the model servers have no route to the internet, and customer content is not passed to any third-party AI provider;
- images sent inline are redacted before a request is stored;
- request contents are deleted after 90 days;
- backups are encrypted before they leave our servers;
- our analytics run on our own servers; session recordings mask what you type and all console text, and pages with request content or API keys are not recorded;
- API keys are stored only as a SHA-256 hash;
- rate limits per account and per IP address protect against abuse;
- access to personal data within Uprelic is limited to the people who need it.
No system is perfectly secure. If a personal data breach occurs, we will act as Art. 33 and Art. 34 GDPR require.
22. Changes to this policy
We update this policy when Strom, our service providers or the law change. The date at the top shows when it was last updated. Where a change is significant — for example a new purpose, a new category of recipient or a new transfer outside the EU/EEA — we will inform account holders in advance, by email or in the console.