Privacy
Privacy policy
Last updated: September 28, 2026
This policy explains what personal information we collect when you visit staedra.ai, fill out the form to book a demo or leave your email to watch the interactive demo, how we use it, who we share it with and the choices you have.
1. Who we are
The website is operated by GenComply S.r.l., Via Privata Beltrame Cristiani 5, 20162 Milan (MI), Italy, VAT number IT14312740963, REA MI-2774549 (“Staedra”, “we”, “us”). Staedra is a product of GenComply S.r.l.
For any question about this policy or your information, email info@gencomply.ai.
2. HIPAA and patient data
This policy covers the website and the Staedra app (section 3). The website is not used to collect protected health information (PHI): the forms ask only for your professional contact details. Don’t enter health information or patient data in the forms or in emails to us.
Patient data that research sites process with the Staedra product is protected health information under the Health Insurance Portability and Accountability Act (HIPAA). For that data Staedra acts as a business associate of the site, under a Business Associate Agreement (BAA) and the HIPAA Privacy and Security Rules. That data is governed by the BAA and by the contract with the site, not by this policy.
3. The Staedra app
The app records audio you choose to record and keeps it on your device until you delete it. If you ask for a summary and allow it, the recording is sent to our servers and to a third-party AI provider in the United States to produce the summary, and our servers delete it immediately afterwards. The app is not intended for patient or health information. Product analytics are anonymous and never include recordings or summaries.
4. What information we collect
Information you give us
- Demo booking form (/book/): first name, last name, work email, job role and, if you choose, phone number.
- Information you type but don’t send. Once the email you typed in the form is valid, we save what you enter as you type, even if you don’t click “Continue”. We use it only to contact you about the demo. The form tells you this below the button.
- Call booking: the day and time you pick and your time zone. We use them to create the calendar event and send you the invite with the Google Meet link.
- Email for the interactive demo: the work email you leave before watching the demo.
- Emails and messages you send us and what you share during the call.
Information collected automatically
- Context sent with the form: page language, the page and button you came from, the referring site, campaign parameters (UTM) and the anonymous browsing ID assigned by PostHog.
- Usage analytics (PostHog): pages viewed, clicks, scrolling, heatmaps, clicks on elements that aren’t clickable, load times, technical page errors, the A/B test variants you see, device and browser type, IP address and approximate location (country and city) derived from the IP.
- Session recording (PostHog): a reconstruction of how you use the pages (mouse movements, clicks, scrolling). What you type in form fields is masked and not recorded.
- Campaign measurement (Meta Pixel): the pages you visit and some actions (for example sending the form, booking the call, watching the demo), to measure the results of our Facebook and Instagram campaigns.
When you leave us your email, we link the PostHog usage analytics collected on your browser to that email, so we know which pages you saw before and after your request. In analytics we only send the names of the form fields you fill in, never their content.
5. How we use your information
- To reply to your request, organize and run the demo and send you the invite.
- To contact you if you started the form without sending it.
- To send you up to three follow-up emails about the demo if you left your details without booking the call, or if you watched the interactive demo. The emails stop when you book the call or ask us to stop.
- To understand how the website is used and improve it, including through session recordings and A/B tests.
- To measure our advertising campaigns.
- To protect the website from spam and abuse.
- To comply with the law and defend our rights.
We don’t make decisions about you based solely on automated processing.
6. Who we share your information with
We don’t sell your information. We share it only with our team and with the service providers that help us run the website and the demo requests:
| Provider | What it does for us | Where |
|---|---|---|
| Google (Google Workspace, Google Tag Manager, Google Fonts) | Storage of the requests (Google Sheets), notification emails to the team, calendar and Google Meet invite, management of the website scripts, fonts | US and EU |
| PostHog Inc. | Usage analytics, session recording, A/B tests | US |
| lemlist SAS (lemlist and lemcal) | Sending the follow-up emails; backup booking calendar, used only if ours doesn’t load | EU (France) |
| unpkg / Cloudflare | Delivery of the JavaScript libraries and icons used by the pages (they receive your IP address when you load them) | Global |
| Cloudflare, Inc. | Hosting and delivery of the website, protection from attacks (it receives your IP address on every visit) | Global |
Meta Platforms receives the usage data collected by the Meta Pixel and may also use it for its own purposes, for example to show you ads. You can read how Meta uses data in Meta’s privacy policy and manage your ad settings in your Facebook or Instagram account.
We may also share information with advisers (for example lawyers and accountants), with a buyer if the company is sold, and with public authorities when the law requires it.
7. How long we keep your information
- Demo requests, bookings and emails for the interactive demo: 12 months from the last contact, unless you become a customer (then the contract’s retention periods apply).
- Information typed but not sent: 12 months.
- Session recordings: 30 days.
- Usage analytics: up to 48 months.
- Meta Pixel data: according to Meta’s retention periods.
If you ask us to stop emailing you, we keep only your email on a suppression list, so we don’t write to you again.
8. Cookies and tracking technologies
The website uses cookies and the browser’s local storage (localStorage and sessionStorage):
| Name | Provider | Purpose | Duration |
|---|---|---|---|
staedra_lang, staedra_booking_variant, staedra_cta_location | Staedra | Remember the language and which button opened the form, for the confirmation page | Until you clear them from the browser |
staedra_lead_email, staedra_lead_tracked | Staedra | Remember the email you already entered, so we don’t ask for it again before the demo, and avoid counting the same request twice | Until you clear them from the browser |
staedra_lead_id, staedra_demo_booked | Staedra | Link the form data to the same request and avoid counting the same booking twice | Until you close the tab |
ph_*_posthog | PostHog | Usage analytics, session recording, A/B tests | 1 year |
_fbp | Meta | Advertising campaign measurement | 3 months |
You can block or delete cookies and local storage in your browser settings. If you do, the website still works, but the form may ask for your email again.
Do Not Track. The website doesn’t currently respond to “Do Not Track” browser signals.
9. Your choices and rights
- Follow-up emails: reply to any of them asking us to stop, or write to info@gencomply.ai. We stop within 10 business days.
- Access, correction and deletion: you can ask us what information we hold about you, and ask us to correct or delete it.
- Targeted advertising: you can ask us not to use your information for the Meta Pixel.
Depending on the state you live in, you may have additional rights under state privacy law. Write to the address above: we’ll verify your request and reply within 45 days. We won’t discriminate against you for exercising your rights.
10. Children
The website is meant for clinical research professionals and is not directed at anyone under 18. We don’t knowingly collect information from children under 13. If you believe a child has sent us information, write to us and we’ll delete it.
11. Security
We protect your information with reasonable technical and organizational measures: encrypted connections (HTTPS), access limited to the team members who need it, and providers that offer security guarantees. No system is completely secure, so we can’t guarantee absolute security.
12. Changes to this policy
We may update this policy when the website, our providers or the law change. The date at the top shows the last update. If the changes are significant, we’ll point them out clearly on the website.