Seraphina Intelligence // Data Privacy Governance
Effective Date: 5 September 2026

Section 1: Data Controller Information

Seraphina Intelligence (“Seraphina”, “We”, “Us”, or “Our”) is committed to protecting the privacy and security of your personal data[cite: 1]. This Privacy Policy explains how we collect, process, store, and safeguard your information when you visit https://getseraphina.com/, access our web terminals, or utilize our API and Model Context Protocol (MCP) data feeds[cite: 1].

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Seraphina Intelligence operates as the Data Controller[cite: 1].

Section 2: Legal Basis For Data Processing

We collect and process personal data strictly under lawful bases specified by Article 6 of the UK GDPR:

  • Contractual Performance: Processing necessary to fulfill subscription obligations, manage user entitlements, provision API keys, and deliver member terminal feeds[cite: 1].
  • Legitimate Interests: Processing necessary for maintaining infrastructure security, rate limiting, abuse prevention, platform telemetry, and optimization of conversion funnels[cite: 1].
  • Legal Obligation: Processing necessary to comply with financial reporting, statutory tax requirements, and legal compliance obligations in the United Kingdom[cite: 1].
  • Consent: Processing based on explicit user consent for specific communication opt-ins or administrative requests[cite: 1].

Section 3: Information We Collect

We collect only the technical and operational data necessary to deliver our intelligence platform[cite: 1].

Account And Contact Data

When you create an account, purchase a subscription, or request a product demonstration, we collect your email address, primary name, corporate affiliation, and tier entitlement choices[cite: 1].

Payment And Transaction Information

All subscription transactions and catalog pricing are processed directly through our payment partner, Stripe[cite: 1]. Seraphina never receives or stores raw payment card numbers or card verification values on our servers[cite: 1]. Stripe processes transaction data under their independent privacy standards[cite: 1].

Telemetry, Analytics, And System Logs

To maintain platform health and funnel efficiency, our systems log specific interactions[cite: 1]:

  • Funnel Event Data: Pseudonymised tracking of user actions including page views, plan selections, one-time password verifications, checkout initiations, and subscription switches[cite: 1].
  • Technical Identity Data: Internet Protocol (IP) addresses, browser user-agent strings, HTTP referrer headers, and system access timestamps[cite: 1].
  • API and MCP Log Data: Developer request volumes, authentication header validations, and endpoint traffic counts for Quant Desk members[cite: 1].

Spam Protection Data

Our demonstration request forms utilize Google reCAPTCHA v3 to analyze interaction metrics and prevent automated spam submissions[cite: 1]. This evaluation operates under Google Privacy Policy and Terms of Service[cite: 1].

Section 4: How We Use Your Information

We process collected information exclusively for operational purposes[cite: 1]:

  • To provision account entitlements across Signal ($199/mo), Terminal ($399/mo), and Quant Desk ($999/mo) service levels[cite: 1].
  • To enforce latency boundaries ($T+24$ retail versus $T+0$ institutional access)[cite: 1].
  • To execute subscription upgrades with accurate proration and prevent duplicate billing[cite: 1].
  • To monitor telemetry telemetry health without logging unreadable data sources as silent zeros[cite: 1].
  • To secure API proxy routes using router level HMAC signature validation[cite: 1].

Section 5: Data Sharing And Third-Party Processors

Seraphina does not sell, rent, trade, or broker personal data to third parties for commercial advertising or marketing purposes[cite: 1]. We share information solely with trusted infrastructure processors acting under strict contractual boundaries[cite: 1]:

  • Payment Processing: Stripe, Inc. for payment execution and subscription lifecycle management[cite: 1].
  • Infrastructure Hosting: DigitalOcean LLC for secure droplet server execution and database storage in protected data centres[cite: 1].
  • Security Services: Google LLC for reCAPTCHA v3 risk evaluation on public submission routes[cite: 1].

Section 6: Cookies And Analytics Beacons

We utilize functional cookies and rate-capped analytics beacons to manage user sessions and verify platform interactions[cite: 1].

  • Essential Session Cookies: Required to maintain secure member authentication state and honor entitlement passes across terminal views[cite: 1].
  • Funnel Analytics Beacons: Read-only, rate-capped proxies that record funnel progression without collecting unauthorized personal background data[cite: 1].

You may disable cookies within your browser settings; however, disabling essential session cookies will prevent access to paid web terminals[cite: 1].

Section 7: Retention And Technical Security Measures

Account and entitlement records are retained for the active lifespan of your subscription plus seven years to satisfy United Kingdom legal and accounting regulations[cite: 1]. System access logs and telemetry event queues are periodically purged or anonymised[cite: 1].

We maintain rigorous technical safeguards, including HMAC router validation, database schema migrations, dynamic access controls, and immediate verification testing following code deployments[cite: 1].

Section 8: Your Rights Under UK GDPR

Under United Kingdom data protection laws, you hold statutory rights regarding your personal information[cite: 1]:

  • Right of Access: You may request copies of the personal information held by Seraphina[cite: 1].
  • Right to Rectification: You may request correction of inaccurate or incomplete personal records[cite: 1].
  • Right to Erasure: You may request deletion of your personal data where processing is no longer legally necessary[cite: 1].
  • Right to Restrict Processing: You may request that we limit processing activities under specific legal circumstances[cite: 1].
  • Right to Data Portability: You may request transfer of your structured data to another provider[cite: 1].
  • Right to Object: You may object to processing based on legitimate interests[cite: 1].

To exercise any of these rights, please contact our privacy desk at help@getseraphina.com[cite: 1].

Section 9: International Data Transfers

Data is stored primarily within United Kingdom and European Economic Area infrastructure[cite: 1]. Where third-party service providers process data outside the UK, transfers occur under standard contractual clauses or official UK adequacy determinations[cite: 1].

Section 10: Contact Information And Supervisory Complaints

For privacy inquiries, formal notifications, or data protection requests, please contact Seraphina Intelligence using the verified details below[cite: 1]:

Seraphina Intelligence
310 Kingsland Road
London E8 4DB
United Kingdom

Domain: https://getseraphina.com/
Privacy Desk: help@getseraphina.com

If you believe your data has been handled improperly, you have the right to lodge a complaint with the UK supervisory authority[cite: 1]:

Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: https://ico.org.uk/