Privacy Policy

Last updated: 2026-07-13

1. Who we are

Seentrix Ltd (company number 17169165, registered in England and Wales at 167-169 Great Portland Street, London, England, W1W 5PF) is the data controller for personal data processed through Seentrix, except where we act as a processor on a customer's behalf (see §3). You can reach our privacy team at support@seentrix.com.

2. Data we collect

  • Account data: name, email, role, avatar, password (hashed by Supabase Auth, never stored in plain text), and multi-factor authentication data (TOTP enrolment; recovery codes are stored only as one-way hashes).
  • Organisation data: company legal name, registration number, address, signatory, product information — provided by you during onboarding and product creation.
  • Compliance artefacts: SBOMs, vulnerability reports, incident records, Declarations of Conformity, Academy completions.
  • Seentrix AI conversations: your questions to the AI assistant and its answers, stored per user (see §6 for retention and §4 for the model provider).
  • Support, contact, and feedback data: messages you send through the support chat (including as a visitor without an account: name, email, and your message), the contact form, and the in-app feedback module.
  • Newsletter: your email address, if you subscribe on our website — with double opt-in: we only add you to the list after you confirm via the link in the confirmation email.
  • Usage data: activity-log entries (who did what, when) and a database-level audit trail of changes to your organisation's records — the fields that changed with their old and new values, the acting member (or system process), and the time — kept as tamper-evident compliance evidence for your organisation and readable only by its administrators and compliance officers.
  • Technical data: IP address, user agent, device type — used for security (rate-limiting, abuse prevention, error diagnostics).
  • Aggregated page analytics: cookieless page-view telemetry processed for us by Vercel, our hosting provider: the time of the visit, the page's URL path and route pattern — query strings are stripped in your browser before anything is sent — the referrer, browser, operating system and device type, and a coarse geographic region derived from the request's IP address at the moment the event is received (the IP address itself is not stored in analytics data and is never available to us). No cookies are set and nothing is stored in your browser; repeat page views are de-duplicated with a server-side hash that Vercel discards within 24 hours, after which only aggregated, non-identifying statistics remain.
  • Anonymous funnel counters: we count key product milestones (for example "a signup was completed", "an SBOM was ingested") in our own database. Each count records only the event name, an optional campaign identifier, the interface language, and the time — no user ID, no organisation ID, no IP address, and no other identifier, so these counts cannot be linked to any person.
  • Campaign attribution: if you create your account via a campaign link (a ?src= parameter in the URL), we store that campaign identifier with your account (as signup_source) so we know which campaign or partner introduced you. It is kept for the life of your account and erased with it (see §6).

3. Data we process on behalf of customers

Some features let customer organisations bring third-party personal data into Seentrix. For this data the customer is the controller and Seentrix acts as a processor under our Data Processing Agreement:

  • Security-notice recipients: when a manufacturer uses Seentrix to notify its own product users of an incident or corrective action (a Cyber Resilience Act Art. 14(8) obligation), it supplies the recipients' email addresses. We use those addresses solely to deliver the notice (via our email sub-processor Resend) and keep a delivery record — recipient address, delivery status, and a fingerprint of the message — as evidence that the notification duty was met. This record is kept with the incident it belongs to and is deleted with it (at the latest when the organisation is deleted). We never use these addresses for anything else.
  • Vulnerability reports: researchers who submit a report through a customer's public PSIRT page may include contact details; these are stored for the customer's coordinated vulnerability disclosure process.

If you received a security notice or submitted a vulnerability report, the manufacturer named in it is the controller of your data; contact them first, and us at support@seentrix.com if you need help reaching them.

4. Legal bases for processing

  • Contract (GDPR Art. 6(1)(b)): to provide the Service you subscribed to, including support.
  • Legal obligation (Art. 6(1)(c)): tax and accounting records relating to billing.
  • Legitimate interest (Art. 6(1)(f)): securing the Service (rate-limiting, bot protection, error monitoring, fraud and abuse prevention), understanding how it is used through the cookieless aggregated page analytics and anonymous funnel counters described in §2, and measuring which campaigns bring us customers (campaign attribution, §2). We run no advertising and no cross-site tracking; our page analytics sets no cookies and yields only aggregated, non-identifying statistics.
  • Consent (Art. 6(1)(a)): the marketing newsletter — double opt-in only, revocable at any time with one click via the unsubscribe link included in every newsletter email (or by emailing support@seentrix.com).

5. Where your data lives

Your data is hosted in Europe. The application database, file storage and authentication run in the United Kingdom (covered by the European Commission's adequacy decision), and the web application itself is served from an EU datacentre. A small number of sub-processors (payments, email) operate outside the EEA under Standard Contractual Clauses — see the list below and §7.

  • Supabase (database, auth, file storage): region eu-west-2, London, United Kingdom. Stores all application data — organisations, products, SBOMs, vulnerabilities, incidents, generated PDFs, support threads, AI transcripts.
  • Vercel (web hosting): region fra1, Frankfurt, Germany. Serves the Seentrix web application. Keeps request + IP logs for 30 days for anti-abuse and diagnostics. Also processes our cookieless page analytics (§2): events arrive at Seentrix-origin endpoints, the request IP is used only to derive a coarse geographic region at ingest and is not stored in analytics data, and only aggregated, non-identifying statistics are retained.
  • Sentry (error tracking): region de.sentry.io (Germany). Receives error traces with IP addresses and cookies stripped and known-sensitive fields scrubbed before events leave our runtime; diagnostic replays are captured only when an error occurs, with all text masked and all media blocked.
  • Stripe (billing): global infrastructure under PCI-DSS compliance. Card numbers are tokenised by Stripe — we never see them.
  • Resend (transactional email, US): delivers account and billing notifications, digests, support replies, and customer-composed security notices. (Password-reset and email confirmations are sent through our authentication provider.)
  • Mistral AI (Seentrix AI): region Paris, France. Processes your Seentrix AI prompts and returns the assistant's replies. Mistral AI is a French-incorporated company and does not train on your data (zero-retention agreement) — your prompts stay on European infrastructure throughout.
  • Upstash (Seentrix AI rate-limit store): EU region. Stores only per-user message counters and rate-limit metadata used to enforce plan quotas. No message content is written here.
  • Cloudflare (Turnstile bot protection): global network. Processes technical browser signals (and sets its own cookies, see the Cookie Policy) on our public forms — contact, newsletter, and public vulnerability-report pages — solely to distinguish humans from bots.

Each processor has signed a data-processing agreement. Details and transfer mechanisms are listed in our Data Processing Agreement.

6. Retention

  • Account and organisation data: for the life of your account. You can request deletion of your organisation at any time (see §8); after a 30-day grace period everything is permanently erased — including compliance artefacts, activity logs, files, and member accounts. Residual copies in encrypted backups expire within at most 30 days after that.
  • Compliance artefacts (DoCs, SBOMs, incident records): kept for the life of your account so you can meet the CRA's 10-year documentation obligations. Note: that retention duty is yours as manufacturer — if you delete your organisation, these records are erased with it, so export them first.
  • Activity log: kept for the life of your organisation as compliance evidence, and deleted with it.
  • Organisation audit trail (§2): the database-level record of changes to your organisation's records is likewise kept for the life of your organisation as compliance evidence and deleted with it. When a member's account is deleted, the identifying details about that member inside the trail (name, email, avatar reference) are automatically redacted and their entries are no longer attributed to them; what remains records only that a change happened, and when.
  • Seentrix AI transcripts: plan-tiered — Free 7 days, Professional 90 days, Business 180 days, Enterprise 365 days. A daily job deletes older conversations, and you can delete any of your own conversations at any time. Mistral AI retains none of your prompt content under our zero-retention agreement.
  • Support conversations: if you contact us without a paid account (visitor or Free plan), the thread is deleted after 6 months; threads of paying customers are kept for the life of the account.
  • Security-notice delivery records (§3): kept with the incident they evidence, deleted with the incident or organisation.
  • Newsletter: until you unsubscribe — the one-click unsubscribe link in every email deletes your address from the subscriber list immediately.
  • Page analytics (§2): the server-side de-duplication hash is discarded by Vercel within 24 hours; only aggregated, non-identifying statistics are retained.
  • Funnel counters (§2): kept indefinitely as anonymous aggregate statistics. They contain no identifier and cannot be attributed to any person, so they are not personal data and are unaffected by account deletion.
  • Campaign attribution (§2): the signup_source identifier is kept for the life of your account and permanently erased when your account is deleted.
  • Billing records: as long as tax law requires (typically 6 years in the UK).
  • Sentry error traces: 90 days.

7. International transfers

Application data is stored in Europe: the primary datastore in the United Kingdom (UK adequacy decision) and the application tier in the EU. Where a sub-processor transfers data outside the EEA (e.g. billing or email delivery), we rely on the European Commission's Standard Contractual Clauses and conduct transfer-impact assessments.

8. Your rights (GDPR)

  • Access: request a copy of your data.
  • Rectification: correct inaccurate data.
  • Erasure: organisation administrators can request deletion of the entire organisation directly in the settings (30-day grace period, second-administrator approval where the organisation has more than one admin); individual users can delete their own account from the account settings (or request it by email). Deleting a member's account also redacts their identifying details from the organisation's audit trail (§6).
  • Portability: organisation administrators can export all organisation data as machine-readable JSON from the settings at any time; individuals can request their data by email.
  • Restriction / objection: pause or stop specific processing.
  • Withdraw consent: any time, with no impact on past processing.
  • Complain: to the UK Information Commissioner's Office (ico.org.uk) or to the data-protection authority in your EU country of residence (e.g. the BfDI in Germany, the CNIL in France).

Exercise any right by emailing support@seentrix.com. We respond within one month (GDPR Art. 12(3)).

9. Security

Data is encrypted in transit (TLS) and at rest; integration credentials and webhook secrets are additionally encrypted at the application layer (AES-256-GCM). Every account — including our own staff — must use multi-factor authentication, and sensitive actions require recent re-authentication. Tenant data is isolated with database row-level security, access is role-based, and staff actions on customer accounts are recorded in an append-only audit log. We maintain an incident-response process: where a personal-data breach occurs we will notify the competent supervisory authority within 72 hours where required (GDPR Art. 33) and inform affected users without undue delay when the breach is likely to result in a high risk to them (Art. 34).

10. Cookies

See our Cookie Policy for the list of cookies we set and how to manage them.

11. Children

Seentrix is a B2B platform and is not intended for children under 16. We do not knowingly collect data from children.

12. Changes to this policy

We may update this Privacy Policy to reflect changes in the law, new features, or new sub-processors. Material changes will be notified to the email address on file at least 30 days before they take effect. The "Last updated" date at the top of this page always reflects the most recent revision; minor edits (typos, clarifications) are made silently.

Seentrix Ltd · Company number 17169165 · Registered in England and Wales · 167-169 Great Portland Street, London W1W 5PF, United Kingdom