Privacy Policy
Last updated: July 2026
This English text is a translation provided for convenience. The Spanish-language version is the legally binding one; in case of any discrepancy, the Spanish version prevails.
1. Controller
Standard 21, S.A.
Tax ID (NIF): ESA22623508
Registered office: Paseo de la Habana, Madrid, Spain
Contact email: legal@standard21.com.
Data Protection Officer (DPO): Standard 21, S.A. has not appointed a Data Protection Officer, as none of the circumstances set out in Article 37 of the GDPR that make such an appointment mandatory apply. For any question regarding the processing of your personal data or the exercise of your rights, you may get in touch through the contact email indicated above.
2. Scope
This policy applies to the two channels through which Standard 21, S.A. provides the SatsIntel service:
- The website satsintel.io and all of its subdomains.
- The SatsIntel mobile app for iOS and Android, distributed through the App Store and Google Play.
A good part of the service can be used without registering. Only the features that require storing information associated with a person — synchronised portfolio, alerts and notifications — require creating an account.
3. Data we collect
We collect only the data that the user voluntarily provides to us or that is strictly necessary to provide the requested service.
a) Without an account: browsing and newsletter
- Email address, if the user subscribes to the newsletter.
- Browsing data collected through cookies (see section 9).
b) Account data
- Email address and internal user identifier.
- Sign-in method used: magic link sent to the email address, or sign-in with Google. We do not store passwords: SatsIntel does not use them.
- Sign-up date and technical session data required to maintain access.
c) Content the user creates in the service
- Portfolio: the assets and amounts that the user chooses to record. In the mobile app, additionally, the purchase price and date and a free-text note associated with each position, if the user writes one.
- Alerts: the company, the type of condition and the threshold configured by the user.
This data is entered by the user and is visible only to them. SatsIntel is not connected to any broker, exchange or financial institution: we do not read real positions and we do not have access to investment accounts.
d) Push notifications (mobile app only)
- The device's push notification token, the platform (iOS or Android) and the delivery preference. The token is generated by the operating system, identifies the installation of the app — not the device permanently — and is only recorded if the user grants the notifications permission.
4. Purpose and legal basis of the processing
- Provision of the account service: authentication, synchronisation of the portfolio between the Website and the App, and management of alerts. Legal basis: performance of the contract (Art. 6.1.b of the GDPR).
- Sending push notifications: notifying about the alerts configured by the user themselves. Legal basis: consent, given through the operating system's permission, revocable at any time from the device settings (Art. 6.1.a of the GDPR).
- Sending the newsletter: managing the subscription and sending informative communications about Bitcoin and corporate treasuries. Legal basis: consent of the data subject (Art. 6.1.a of the GDPR).
- Security and error diagnostics: detection of technical failures to keep the service operational. Legal basis: legitimate interest of the controller (Art. 6.1.f of the GDPR).
- Service improvement: statistical analysis of usage through aggregated data. Legal basis: legitimate interest of the controller (Art. 6.1.f of the GDPR).
We do not carry out profiling and we do not take automated decisions with legal effects on the user, and we do not sell or transfer personal data for advertising purposes.
5. Data retention
- Account data and associated content: retained for as long as the account remains active. When it is deleted, the data is erased permanently and immediately. See Delete your account.
- Newsletter subscribers: retained for as long as the user does not request to unsubscribe. Once the unsubscription is processed, the data is deleted within a maximum of 30 days.
- Technical error logs: retained for the time necessary to diagnose the incident and deleted automatically in accordance with the retention periods configured in the monitoring tool.
6. Where the data is stored
The SatsIntel database and authentication system are hosted on Supabase infrastructure located in the European Union (Ireland). The account, portfolio, alerts and notification token data resides there.
7. Processors and third parties
Standard 21, S.A. does not transfer personal data to third parties for commercial purposes. The providers that process data on our behalf are bound by contract in accordance with Article 28 of the GDPR:
- Supabase — database and authentication. Data hosted in the European Union (Ireland).
- Vercel — hosting of the Website and aggregated traffic measurement.
- Beehiiv Inc. (United States) — sending of the newsletter. It receives only the subscriber's email address. The international transfer is covered by the standard contractual clauses (SCCs) approved by the European Commission, in accordance with Article 46 of the GDPR.
- Sentry — technical error logging. The SatsIntel configuration disables the sending of personal data by default and redacts any email address that might appear in a URL or in an error message before it leaves the browser.
- Google — sign-in with Google: if the user chooses this method, Google communicates their email address and an identifier to us, and processes the operation in accordance with its own privacy policy. Additionally, on the Website and subject to prior consent, Google Analytics 4 (see section 9).
- Expo (650 Industries, Inc., United States) — mobile app infrastructure. It provides the push notification service (Expo Push), which receives the device's push notification token and the content of the alert in order to route it to Apple or Google, and the app updates service, which receives technical device data (platform and version). International transfer covered by standard contractual clauses (Art. 46 GDPR).
- Apple and Google — distribution of the app through the App Store and Google Play, and final delivery of push notifications through their respective services (APNs and FCM), which receive the device identifier in order to route the alert.
The user may exercise their rights over the data held by these providers by contacting us at legal@standard21.com.
8. Data subject rights
The user may exercise the following rights at any time:
- Access to their personal data.
- Rectification of inaccurate data.
- Erasure (“right to be forgotten”).
- Objection to and restriction of the processing.
- Portability of the data.
- Withdrawal of consent at any time, without retroactive effect.
To exercise your rights you may contact us at legal@standard21.com. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
The right of erasure in relation to the account may be exercised directly, without the need for a prior request: see Delete your account for the procedure and the details of which data is deleted.
9. Cookies and storage on the device
On the Website, this site uses two categories of cookies, clearly separated: strictly necessary technical cookies (session and UI preferences stored locally, exempt from consent in accordance with the Spanish Law 34/2002 on information society services (LSSI-CE)) and, subject to express acceptance, analytics cookies (Google Analytics 4) that help us understand in aggregated form how SatsIntel is used in order to improve the service.
The analytics cookies are implemented through Google Consent Mode v2: until the user explicitly accepts, no Google Analytics identifier is persisted in the browser. If the user rejects, no measurement script is loaded. Configuration: anonymised IP, no advertising, no remarketing.
Full details, the list of specific cookies, retention periods and how to manage your consent are in the Cookie Policy. Your decision is stored locally with a validity of 12 months, in accordance with the guidance of the Spanish Data Protection Agency (AEPD) (July 2023). You can change it at any time from the “Cookie preferences” button in the footer.
The mobile app does not use cookies. The app stores in the device's local storage the session token that keeps the user signed in and their interface preferences. That information is deleted when signing out or uninstalling the app.
The official YouTube subscription widget (present on some pages of the Show Me The Bitcoin podcast) loads Google resources that may set YouTube/Google cookies when you interact with it. The activation of these cookies remains under the control of the user when clicking the “Subscribe” button.
10. Minors
SatsIntel is a financial markets information service aimed at an adult audience. Neither the Website nor the App is intended for persons under 18 years of age, and we do not knowingly collect personal data from minors. If we detect that an account has been created in breach of this condition, we will proceed to delete it. If a parent or guardian becomes aware that a minor in their care has provided us with data, they may inform us at legal@standard21.com and we will proceed to erase it.
11. Security
Standard 21, S.A. applies the appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR.
Among those measures, access to each user's data is isolated at database level through row-level security policies: no account can read or modify the portfolio, the alerts or the profile of another. Communications between the client — Website or App — and our servers always travel encrypted.
12. Amendments
This Privacy Policy may be updated to adapt to legislative or service changes. The version in force will always be available on this page with the date of last update.
13. Applicable legislation
This policy is governed by Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 on the Protection of Personal Data and guarantee of digital rights (LOPDGDD) and Spanish Law 34/2002 on information society services and electronic commerce (LSSI-CE).