Skip to main content
Request early accessRun free audit

Privacy Policy

Last Updated: June 16, 2026

Sturnix Labs, Corp. ("Sturnix", "we", "us", or "our") operates sturnix.com (the "Service"). This Privacy Policy describes how we collect, use, disclose, and protect information, including personal data, collected through our website, application workflows, and communications.

1. Who We Are and How to Contact Us

Sturnix Labs, Corp. is a Delaware corporation.

Data Controller: Sturnix Labs, Corp.

Contact: For all privacy inquiries, access requests, or data deletion forms, contact our compliance team directly at hello@sturnix.com.

Because we do not maintain a physical establishment or dedicated local representative in the United Kingdom or European Union, all global data protection inquiries are handled centrally by our US compliance team.

2. Information We Collect and Lawful Grounds

Data CategorySpecific ElementsSourcePurposeLawful Basis (GDPR)
Audit Metadata & DatasetsUploaded ad platform performance files (spend metrics, impression counts, clicks, CTR, and campaign identifiers).Direct User UploadGeneration of spend efficiency diagnostics.Consent (Art. 6(1)(a))
Brand ContextResponses provided during optional programmatic workflow Q&As.Direct User InputTailoring diagnostic variables to your operational mix.Consent (Art. 6(1)(a))
Communication PIINames, corporate email addresses, and message contents."Talk to Us" Forms / Email InquiriesResponding to sales, technical support, or platform requests.Legitimate Interest or Contract (Art. 6(1)(f)/(b))
Technical Network LogsIP addresses, browser agent strings, request paths, response codes, and timestamps.Automated CollectionMaintaining platform infrastructure security and rate-limiting.Legitimate Interest (Art. 6(1)(f))

3. Cookies, Tracking Technologies, and Global Privacy Control (GPC)

We utilize cookies, pixels, and local storage tokens to preserve session states, analyze user journeys, execute retargeting campaigns, and run tracking features on our website.

  • Essential Session Tokens: We utilize a locally stored browser token to associate your optional diagnostic Q&As and audit results with your anonymous session. This token persists until you clear your browser cache.
  • Analytics & Performance Cookies: We deploy standard analytics cookies (such as PostHog / Google Analytics) to track conversion metrics, monitor platform health, and evaluate user traffic. These cookies track pseudonymous interaction data.
  • Advertising & Retargeting Pixels: We deploy marketing pixels and conversion tags (including but not limited to the Meta Pixel and Google Ads tracking tags). These technologies track your interactions across our site to deliver relevant, targeted advertisements to you on third-party platform networks and measure the effectiveness of our marketing campaigns.
  • Opt-Out Preference Signals: Our platform recognizes and respects Global Privacy Control (GPC) signals. If your browser broadcasts a GPC signal, our systems programmatically restrict non-essential tracking mechanisms.

4. How We Use Your Information & Model Training

We process your datasets under the following strict boundaries:

  • To generate, render, and compile your cross-channel spend efficiency audit.
  • Marketing & Re-engagement: To deliver, target, and measure our cross-site advertising and retargeting campaigns across external networks.
  • Algorithmic Optimization: We reserve the right to utilize pseudonymized, de-identified metrics to train, tune, and optimize our machine learning diagnostic models. Because structural identifying metadata is permanently hashed at ingestion, the models process purely abstract mathematical relationships. No tenant-specific intellectual property can be exposed, leaked, or reverse-engineered by other customers. This processing is conducted under our Legitimate Business Interest to improve platform precision (Art. 6(1)(f) GDPR).
  • No Selling of Raw Data: We do not sell, rent, or distribute your un-hashed, proprietary marketing data streams to third parties for commercial gain.

5. Data Retention Boundaries

We enforce strict automated deletion schedules to limit our data footprint:

  • Uploaded Ad Performance Files: Permanently purged from our cloud object storage systems within 48 hours of successful ingestion.
  • Generated Audit Reports: Retained in an encrypted environment for 30 days to permit user viewing, after which they are converted into a permanently aggregated, non-identifiable statistical baseline.
  • Communication Logs & PII: Contact information collected via inbound forms is retained for as long as necessary to service your request or maintain our active business relationship, up to a maximum of 2 years from last contact unless contractually required otherwise.
  • Network Logs: Rotated and permanently deleted on a rolling 30-day cycle.

6. Third-Party Infrastructure (Subprocessors)

We do not sell, rent, or distribute personal data to third parties for commercial gain. To execute our services, we share restricted data layers with contractually bound third-party subprocessors who manage our cloud infrastructure (such as Amazon Web Services or Google Cloud Platform). All subprocessors are vetted for security competency and operate under strict Data Processing Addendums (DPAs).

7. Global Rights and Regulatory Commitments

European Union & United Kingdom (GDPR/UK GDPR)

You possess comprehensive statutory rights under Articles 13–15 of the GDPR:

  • Core Rights: You maintain the right to access, rectify, restrict processing of, object to, or command the erasure of your personal data.
  • Right to Complain: You possess an absolute legal right to lodge a formal complaint regarding our processing frameworks with a recognized supervisory authority in your member state or country of residence.
  • International Cross-Border Transfers: Because Sturnix infrastructure is based in the United States, your data is transferred internationally. We secure these transactions by executing approved Standard Contractual Clauses (SCCs) to ensure equivalent legal protections.

California (CCPA/CPRA Aligned)

  • Categorical Disclosure: In the preceding 12 months, we have collected standard identifiers (IP addresses, corporate email if provided) and commercial performance metadata for business optimization. We do not sell or share personal data.
  • Right to Non-Discrimination: We strictly prohibit any discriminatory pricing, latency tiers, or service reductions against users who choose to exercise their privacy rights.
  • Authorized Agents: You may designate an authorized agent to execute a privacy request on your behalf by providing formal documentation or verifiable legal verification.

8. Request Verification for Anonymous Profiles

Because our core diagnostic tool operates on an account-free, anonymous profile system keyed to local browser data, you must provide verifiable proof of ownership to execute an Access, Portability, or Erasure request.

To verify your identity, you must submit your request via our secure portal at /legal/data-deletion while utilizing the specific browser and device containing the active local session token, or provide the exact cryptographically generated transaction token issued upon your file upload. We cannot fulfill requests for data layers we cannot definitively link to your session.

9. Forward-Looking Automated Decision-Making (ADMT) Notice

Sturnix offers diagnostic insights. In product versions where users voluntarily authenticate active API access to execute real-time automated budget reallocations or optimization workflows, please note the following frameworks:

  • California Residents: Pursuant to the California Privacy Protection Agency (CPRA) regulations, automated updates to commercial advertising accounts are excluded from the definition of "Significant Decisions" impacting consumer access, employment, housing, or healthcare.
  • EU/UK Residents: Where automated execution layers are deployed that fall within the scope of GDPR Article 22, Sturnix implements human-in-the-loop validation tools or requires explicit contract execution to ensure users retain human override capabilities over algorithmic workflows.

10. Children's Privacy

Our platform is structured entirely for business professionals managing commercial advertising budgets. We do not knowingly capture data from anyone under 13 (or 16 within the EEA).

11. Updates to This Policy

We reserve the right to modify this policy to adapt to new regulatory changes. The "Last Updated" timestamp at the top of this document will dictate the active revision date.