Privacy Policy
Effective date: September 22, 2026
1. Who we are and what this covers
Seros, LLC ("Seros", "we", "us") is a solution development company: we scope, build and maintain custom software for businesses. Our website is at https://seros.dev. This policy explains what personal information we collect when you visit our website, enquire about an engagement, or work with us; why we collect it; who we share it with; how long we keep it; and what rights you have.
This policy covers personal information for which we are the controller — for example, the contact and billing details of the people we do business with, and enquiries sent to us. It does not cover the content a client provides for an engagement, or the data inside a system we build or host for them, about their own staff and clients. For that content we act as a processor on the client's instructions. Our Data Processing Addendum governs that relationship. If you are an employee of a client and you want your data changed or deleted from a system we built or host for them, contact that client first; we will help them respond.
Contact: team@seros.dev. Postal: Georgia, United States. EU/UK representative or data protection officer, if appointed: Not appointed.
Current business scope
Seros is a solution development company. We scope, build and maintain custom software for businesses. Our public presence is a static marketing website with no analytics, no forms and no tracking; project enquiries arrive by ordinary email.
We do not currently operate a hosted customer-facing application. Systems we build are normally deployed to infrastructure the client owns and controls, in which case the client is the controller of the data inside them and we are not a processor of it once the engagement ends. Where a client asks us to host or operate a system under a care plan, we act as their processor and the DPA governs that relationship.
An earlier in-house Slack-to-tracker application is paused and is not deployed, so it is not processing anyone's data. See Subprocessors for the vendors it used and their current status.
Marketing email, product analytics, error-tracking, and third-party identity services are not in use. If any is added, this policy and the related vendor disclosures must be updated before it processes personal data.
Our clients are businesses. This website and our services are not directed to children, and business contact details may still be personal data under GDPR, UK GDPR and US state privacy laws.
2. What we collect, why, and on what legal basis
"Legal basis" is a GDPR and UK GDPR concept (Article 6). If you are outside the EU, EEA, UK or Switzerland, the "why" column is still the honest answer to what we do.
| Category | Examples | Why we process it | Legal basis (GDPR Art. 6) | Typical retention |
|---|---|---|---|---|
| Client and contact data | Name, work email, company name, job title, and the contact details of the people we deal with at a client or prospect | Discuss and perform an engagement, and keep a record of who agreed what | Art. 6(1)(b) performance of a contract; Art. 6(1)(f) legitimate interests in business correspondence | Life of the relationship, then for the life of the account, then 30 days |
| Billing data | Billing contact, billing address, tax identifiers, purchase order references, invoices and payment status | Administer a commercial relationship and meet tax and accounting duties | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation for tax and accounting records | 7 years |
| Website and security logs | Request timestamps, request volumes, and security events for our website; device or IP data where the host supplies it. Where we host a system for a client, its equivalent operational logs | Serve and secure the website, diagnose faults, prevent abuse, investigate security incidents | Art. 6(1)(f) legitimate interests in running and securing our systems | 12 months |
| Client materials | Documents, system access, data and other content a client provides so we can perform an engagement, and the contents of a system we build or host for them | Perform the Services stated in the statement of work | Processed on the client's instructions under the DPA. The client determines its own legal basis | For the duration of the engagement; deleted on the schedule in Section 5 and in Section 15.5 of the Terms |
| Enquiries and correspondence | Emails you send us, including project enquiries sent to our published addresses | Answer your question, scope an engagement, keep a record of what was agreed | Art. 6(1)(b) contract and pre-contract steps; Art. 6(1)(f) legitimate interests in business correspondence | 24 months |
| Marketing and prospect data | Work contact details you give us and any marketing preferences, if marketing is provided | Reply to enquiries and send email you asked for | Art. 6(1)(a) consent where consent is required; otherwise Art. 6(1)(f) legitimate interests in business-to-business marketing | Until you opt out, then a suppression record kept only as needed to honour the opt-out |
| Cookies and similar technologies | See the Cookie Policy. Our marketing website sets no analytics or advertising cookies | Serve the website | Strictly necessary cookies: legitimate interests | See the Cookie Policy |
| Security and audit logs | Where we host or operate a system for a client: sign-in attempts, admin actions, permission changes, security alerts and audit events | Detect and investigate unauthorised access, meet our security commitments | Art. 6(1)(f) legitimate interests in security; Art. 6(1)(c) where a law requires it | 12 months |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can ask us for a summary of that assessment at team@seros.dev.
What we do not do
- We do not sell personal information.
- We do not share personal information for cross-context behavioural advertising.
- We do not use client materials to train our own general-purpose models, and we do not provide them to a third-party model provider whose training terms have not been verified and disclosed to the client. See How Seros uses AI.
- We do not make decisions with legal or similarly significant effects about you using automated processing alone. The Service produces drafts and suggestions; a person at the customer decides.
3. Where the information comes from
Most of it comes from you directly — an email you send us, or the details agreed when we set up an engagement. Some comes from a client who gives us access to their systems or materials so we can do the work. Some is generated automatically when you visit our website or use a system we host, such as request logs and security events. If we buy or receive business contact data from a third-party source for sales outreach, we will say so here and name the source: none unless we later identify one.
4. How we use AI
We use AI models as a tool when we build software, and we may build AI features into a system for a client. Where an engagement involves sending client material to an AI provider, the provider and the data it receives are agreed in the statement of work and recorded in Subprocessors before any client data reaches it. AI output is advisory: a person reviews it before it becomes a deliverable, and systems we build require a human confirmation before a consequential action. See How Seros uses AI.
The current default transport is local Ollama/Qwen. A hosted HTTP transport is supported by configuration but no hosted AI vendor has been confirmed in the current vendor list. When a hosted provider is enabled, the provider, location, training terms and retention must be added to Subprocessors before production use. The AI-specific detail is in How Seros uses AI.
We do not use customer content to train a general-purpose model, and the local default does not send content to a third-party model provider. Do not submit sensitive or regulated data unless your agreement and the Acceptable Use Policy expressly permit it.
AI output can be wrong. Do not rely on it without review. That is a legal point as well as a practical one and it is repeated in the Terms of Service.
5. Retention and deletion
We keep personal information only as long as we need it for the purpose it was collected for, plus any period a law requires.
- Client materials are retained for the duration of the engagement. Afterwards the client may export them during a window of 30 days. After that window we delete or irreversibly anonymise them within 30 days, except for the archival copy of deliverables and engagement records permitted by Section 15.5 of the Terms, and except where law requires us to keep something.
- Backups roll off on their own cycle. Deleted data can persist in encrypted backups for up to 35 days before being overwritten.
- Financial records are kept for 7 years because tax and accounting rules require it.
- Aggregate statistics that cannot identify anyone may be kept indefinitely.
6. Who we share it with
We share personal information with:
- Subprocessors and service providers — hosting, email delivery, payments, analytics, error tracking, AI model providers and support tooling. The current list, with each vendor's purpose and location, is in Subprocessors. Each is bound by a written contract that limits use to providing the service to us.
- Your organisation. If you use a system we built or host for your employer, your employer's administrator can see your activity in it and the content you create there.
- Professional advisers — lawyers, accountants, auditors and insurers, under duties of confidence.
- Authorities, where we are legally required to disclose. Where we are permitted to, we will tell the affected customer before we disclose so they can object.
- A buyer or successor, if the business or the relevant assets are sold, merged or reorganised. We will give notice before your information becomes subject to a different privacy policy.
We do not disclose customer content to anyone else without the customer's instruction.
7. International transfers
We are based in the United States, and our website and any system we host are hosted in the United States. If you are in the EEA, the UK or Switzerland, your personal information will be transferred to a country that those laws do not treat as providing an equivalent level of protection by default.
For those transfers we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, together with the UK International Data Transfer Addendum for UK transfers, and the Swiss addendum for Swiss transfers. We carry out a transfer impact assessment and apply supplementary measures such as encryption in transit and at rest.
We do not currently claim certification under the EU-US Data Privacy Framework, the UK Extension, or the Swiss-US Data Privacy Framework. If Seros, LLC certifies in future, this section will be updated and the certification will be verifiable on the official DPF list. Do not state or imply DPF participation until that is true.
Copies of the transfer mechanisms we use are available on request at team@seros.dev.
8. Security
We apply administrative, technical and physical safeguards proportionate to the risk, including encryption in transit and at rest, role-based access control, least-privilege access for staff, logging and monitoring, and a documented incident response process. The current control set is described in Security and in Annex II of the DPA.
We do not hold SOC 2, ISO 27001 or any other security certification, and we do not claim one. No system is perfectly secure. If you find a vulnerability, the disclosure process is in Security.
9. Your rights
If you are in the EEA, the UK or Switzerland
You have the right to: access your personal information; correct it; delete it; restrict or object to processing, including profiling; receive it in a portable format; and withdraw consent at any time where processing is based on consent, without affecting processing done before the withdrawal. You can lodge a complaint with your supervisory authority. In the UK that is the Information Commissioner's Office; in the EU it is the authority of your member state.
If you are in California
Under the CCPA as amended by the CPRA you have the right to know what personal information we collect, use, disclose and retain; to access it and receive a copy; to correct it; to delete it; to limit the use of sensitive personal information; and not to receive discriminatory treatment for exercising a right. We do not sell personal information and we do not share personal information for cross-context behavioural advertising, so there is nothing to opt out of; if that ever changes we will publish a "Do Not Sell or Share My Personal Information" link before making the change. We do not knowingly collect or use sensitive personal information for purposes that would trigger the right to limit.
The categories of personal information we collect, the sources, the business purposes and the categories of recipients are set out in the table in Section 2 and in Section 6. We disclose the categories listed there to service providers for business purposes only.
If you are in another US state with a privacy law
Residents of states including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana have broadly similar rights of access, correction, deletion, portability and opt-out of targeted advertising and profiling with legal effects. We honour those requests through the same process. Some states allow you to appeal a refusal; if we refuse your request you can appeal by replying to our decision email, and we will respond within the period your state's law allows.
How to exercise a right
Email team@seros.dev with the request and the engagement or system it relates to. We will verify your identity, usually by confirming control of the email address we hold, or by asking for additional detail if the request is broad. We respond within 30 days, or within 45 days where a US state law allows, and we will tell you if we need an extension. You may use an authorised agent; we will ask for proof of authority.
If your request concerns content inside a system we built or host for a client, we will forward it to that client and assist them, because they decide.
10. Children
The Service is for businesses. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. Our services are sold to businesses and are not directed to children. If you believe a minor has given us personal information, email team@seros.dev and we will delete it.
11. Changes to this policy
We will update this policy when our business or the law changes. If a change is material we will give notice by email to our clients, or by a notice on our website, at least 30 days before it takes effect, unless a shorter period is required by law. The effective date at the top always reflects the current version. Prior versions are available on request.
12. Contact
- Privacy questions and rights requests: team@seros.dev
- Legal notices: team@seros.dev
- Support: team@seros.dev
- Postal: Georgia, United States
- Security reports: see Security