STELA Privacy Policy

Last updated: June 25, 2026

STELA is a product developed and commercialized by BILESTAR S.A. (hereinafter “STELA”, “we”, “us”, or the “Controller”). BILESTAR S.A. is part of the Software Testing Bureau (STB) business group, composed of its subsidiaries and associated companies in the region. To learn more about our associated entities, you may consult Software Testing Bureau’s Legal Information.

This Policy explains how we process personal data when you visit our website, register for our activities, use the STELA platform, its RPA, Test Automation and AI modules, and when you use STELA SCOUT, including its browser extension.

1. Key Information and Controller

Data Controller: BILESTAR S.A., Av. Gral. José María Paz 1481, Montevideo, Uruguay.

Privacy Contact: contacto@stela.ai.

Website data residency: Microsoft Azure East US, United States.

Platform data residency: Microsoft Azure East US 2, Virginia, United States.

Ethical AI: We do not train models with your content without your express authorization.

2. Processing on the Website and Events

A) Data we collect

  • Event registration data: name, corporate email, company, job title and country.
  • Contact data: information provided through inquiry forms, demo requests or material download forms.
  • Browsing data: IP address, device identifiers, visited pages and analytics or marketing cookies, when applicable.

B) Purposes

  • Training and event management: managing access to webinars, sending educational material, practical challenges, related communications and issuing certificates or badges.
  • Commercial support: responding to inquiries and offering personalized guidance on the use of STELA according to role, company and region.
  • Security: preserving the integrity of the website, preventing abuse and mitigating fraud.

C) Legal basis

  • Consent: by checking the acceptance box in our forms, you authorize the processing of your data for the purposes described.
  • Legitimate interest: for content improvement, website security and continuity of our operations.

3. Processing within the STELA Platform

A) Roles and scope

STELA as Processor: regarding business data that the client organization uploads or processes through robots, test cases, RPA flows, automation processes or AI functionalities. Control over operational content remains with the client.

STELA as Controller: regarding account data, users, roles, licenses, support, billing and platform administration.

B) Use of Artificial Intelligence

Content sent to AI services is used exclusively to generate the response, analysis, recommendation or automation requested by the user.

STELA does not use client content to train global models without express authorization.

When infrastructure providers or AI services are used, STELA seeks to apply contractual and technical configurations aimed at no-training and protection of the processed information.

4. Data Processing in STELA SCOUT

STELA SCOUT is a STELA functionality designed to capture, analyze and interpret user journeys on web applications. SCOUT may use a browser extension to record user navigation and send information to the STELA backend configured by the user or the client organization.

A) When STELA SCOUT processes data

STELA SCOUT processes information only when the user configures a STELA base URL, enters a Personal Access Token, selects a project and starts a capture session.

The user may pause, resume or finish the capture session at any time.

B) Data STELA SCOUT may process

During an active session, STELA SCOUT may process the following categories of information:

  • Authentication and configuration information: STELA backend base URL, Personal Access Token, token validation status, validated user and available projects returned by STELA.
  • Website activity: visited URL, page title, path, timestamps, navigation events and user events such as clicks, focus, inputs, changes, relevant keystrokes, form submissions, interaction coordinates and metadata of the interacted element.
  • Website content: screenshots of the browsed tab, serialized HTML, simplified DOM, visible texts, element attributes, selectors, visual metadata, viewport, form control values and selected file metadata such as name, size and type.
  • Network requests: HTTP method, URL, resource type, status code, frame, initiator and similar technical data. STELA SCOUT does not record request bodies or response bodies.
  • Technical and diagnostic data: browser, extension version, session status, counters, backend errors and local debugging records required to review failed or submitted captures.

C) Data STELA SCOUT does not intentionally process

  • STELA SCOUT does not read cookies, localStorage or sessionStorage.
  • STELA SCOUT does not insert advertising, does not run advertising analytics and does not sell personal data.

D) Purposes of processing in STELA SCOUT

Data processed by STELA SCOUT is used to:

  • Validate the user’s connection with STELA.
  • List available projects for the configured Personal Access Token.
  • Create, document and finish capture or cataloging sessions in STELA SCOUT.
  • Process HTML and screens for element recognition.
  • Analyze screens through computer vision.
  • Help automatically define application elements with user supervision.
  • Generate useful information for documentation, functional analysis, test automation, RPA automation and future Robot Maker or STELA intelligent agent capabilities.
  • Maintain a limited local diagnostic copy so that the user can review or export the session result.
  • Diagnose sending, capture or processing errors.

E) Sensitive information

Because STELA SCOUT may capture screens, HTML, journey events and values associated with form controls, the user should pause or finish the capture before interacting with sensitive information that should not be recorded.

Password fields may be represented within events or serialized HTML when they are part of the captured journey. Base64 encoding, when applicable, does not constitute encryption.

F) Data transmission

During an active session, STELA SCOUT transmits data to the STELA backend configured by the user or the client organization. This may include screenshots, HTML, DOM, events, navigation metadata, project data and the Personal Access Token required to authenticate requests.

STELA SCOUT does not transmit captured data to advertising networks or third-party analytics services.

Google, Mozilla or other extension stores may process data related to the installation or distribution of the extension according to their own policies, but STELA SCOUT does not send them the content captured during user journeys.

G) Local storage

The STELA SCOUT extension may use the browser’s local storage to keep configuration and operational status, including base URL, Personal Access Token, selected project, session status and limited local records of captures, events, network requests and debugging.

This local data remains in the browser until the user changes the configuration, finishes or restarts sessions, deletes the extension data, uninstalls the extension or the browser deletes its storage.

H) Backend retention

Data sent to the STELA backend is retained according to the policies, configurations and contracts applicable to the STELA environment corresponding to the selected project.

To request access, correction or deletion of data stored in STELA, the user or client organization must use the official STELA support or administration channels.

5. Data Transfer and Sharing

Group Companies: You authorize your data to be shared between BILESTAR S.A. and its associated companies or subsidiaries under the Software Testing Bureau brand, including entities in Uruguay, Colombia, Chile or other countries where the group operates. This transfer is exclusively intended to provide regional support, localized commercial management, professional services and platform operation.

Service Providers: We share data with essential subprocessors, such as cloud infrastructure providers, CRM, emailing, support, security and technology service providers necessary for STELA’s operation.

We do not sell personal data to third parties.

6. Retention and Security

Retention periods: Event registration data will be retained for up to 12 months after the last interaction or until the user requests deletion, unless there is a legal or contractual obligation to retain it. Platform data is retained according to the contractual periods agreed with each client.

Security: We apply technical and organizational measures aimed at protecting information, including encryption in transit through TLS, access controls, identity management, reinforced authentication when applicable and audit logs.

For production or non-local environments, we recommend configuring STELA SCOUT using an HTTPS URL to protect data transmission to the STELA backend.

7. Data Subject Rights

In accordance with applicable regulations, including GDPR, LGPD, Colombia Law 1581, Chile Law 19.628 and Uruguay Law 18.331, you may exercise your rights of access, rectification, deletion, objection, restriction and portability, as applicable.

To exercise these rights, you must send a communication to contacto@stela.ai with the subject “Privacy Rights”. We will respond to your request within the legally established timeframes.

When STELA acts as Processor of data belonging to a client organization, some requests may require the intervention or authorization of the client acting as Data Controller.

8. Changes to this Policy

We may update this Policy to reflect legal, technical or functional changes to the service. We will always indicate the last update date at the beginning of the document.

BILESTAR S.A. | Software Testing Bureau
Av. Gral. José María Paz 1481, Montevideo, Uruguay.