🔒 Legal

Privacy Notice?

What you can do
• Use the Contents grid to jump to any of the 18 sections
• Skim the effective date and version stamp at the top
• Email the privacy address to ask questions or opt out

Why it helps
You can locate any specific topic — collection, rights, processors — in seconds instead of scrolling the full Notice.

Effective date: 17 August 2026 · Version 2.4

This Notice describes how Seedfor collects, uses, shares, and protects personal information, and the rights of individuals in the European Economic Area, the United Kingdom, Switzerland, the United States (including California, Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws), and other jurisdictions. It applies to the website at seedfor.io during its pre-launch phase. The companion Terms of Use governs your use of the Website itself; this Notice governs the processing of personal data.

What changed in v2.2 (19 May 2026): §12 cookies / local-storage table updated to list new per-chart persistence keys introduced by the Dataroom version selector (sf_*_version, sf_what_framework), per-chart legend / active-set / pinned-cluster memory keys, and the demonstration-data drafts authored on the Settings, Marketplace, DAO, Lending and AI-Marketplace pages. §01 now cross-references the companion Terms of Use. No change to data categories collected, processors, retention, or your rights.

Contents
  1. About this Notice
  2. Who We Are
  3. Personal Data We Collect
  4. How & Why We Use Data
  5. Legal Bases (GDPR)
  6. Recipients & Processors
  7. International Data Transfers
  8. Data Retention
  9. Your Rights (EU/UK/CH)
  10. California Privacy Rights
  11. Other US State Rights
  12. Cookies, Local Storage & Tracking
  13. Security
  14. Children
  15. Automated Decision-Making
  16. Future Web3 Features
  17. Changes to this Notice
  18. Contact & Complaints

01 —About this Notice

Scope, applicability, and key definitions

This Privacy Notice ("Notice") explains how we, the operators of the Seedfor project ("Seedfor", "we", "us", "our"), process personal data and personal information (collectively, "personal data") when you visit seedfor.io ("Website"), interact with the embedded waitlist form, contact us by email, or access the authenticated management portal.

This Notice does not apply to: (a) third-party websites linked from the Website; (b) future smart-contract or on-chain interactions, which will be governed by a separate, additional notice published prior to launch.

For the purposes of this Notice and applicable law:

02 —Who We Are

Data controller / business operator

The data controller (under the GDPR and UK GDPR) and the "business" (under the CCPA/CPRA and analogous US state laws) is an Italy-based natural person operating the Seedfor project on a pre-launch and pre-incorporation basis. A legal entity will be established prior to the public launch of the platform, at which point full identification details (registered name and address) will be published in this Notice.

Until that date, all data-protection enquiries should be directed to the contact below.

The European supervisory authority of competent jurisdiction is the Italian Garante per la Protezione dei Dati Personali (https://www.gpdp.it). The lead supervisory authority for cross-border processing may change once a legal entity is incorporated.

Seedfor is below the thresholds at which appointment of a Data Protection Officer is mandatory under GDPR Art. 37 or the thresholds at which a Privacy Officer is required under specific US state laws; nevertheless, a dedicated contact point is maintained at the email address above.

03 —Personal Data We Collect?

What you can do
• Review the waitlist data we collect via Beehiiv
• Check what server logs capture during portal access
• Read the CCPA category mapping table below

Why it helps
Knowing exactly what we hold lets you make informed choices about subscribing, contacting us, or requesting deletion.

Categories, sources, and CCPA mapping

a) Waitlist subscription (via Beehiiv)

The waitlist form embedded on the Website is provided by Beehiiv Inc. and posts directly to Beehiiv's servers. All waitlist submissions on the Website (including those triggered from the "in-progress" cards on individual feature pages) open the same Beehiiv-hosted embedded form, so the email address you submit is sent directly to Beehiiv and is not retained on Seedfor-controlled infrastructure (other than ephemeral server logs limited to the events listed in §03(c)).

b) Direct email communications

c) Authenticated portal access (authorised users only)

When an authorised user (a small allow-list of management email addresses, kept private) requests a one-time access code or verifies one, we process:

Sign-in flow in plain language. An authorised user types their allow-listed email into the access form and receives a 6-digit code by email. The code is valid for 15 minutes from issue, single-use, and tied to the specific browser that requested it (it cannot be forwarded to a different device or browser). After successful verification, an authenticated session lasts 24 hours in the same browser; during that window no further codes are needed. Sessions end automatically when the 24-hour timer elapses or when the user explicitly signs out (which deletes the session cookies immediately). The composition of the allow-list is not published.

d) Use Case research lookups

When you type a business name into the "Use Case" tab on the homepage (the optional text field next to the User-type slider), your browser sends the name to our /api/biz-research endpoint, which forwards it to Anthropic PBC (the Claude API, with the web-search tool enabled) for the sole purpose of returning three strategic use-case bullets. The request payload is the business name and your IP & User-Agent; no name is persisted in our database, and our backend logs include only the rate-limit IP counter, not the name itself. Identical lookups within 24 hours are served from Vercel's edge cache so the same name is not re-sent to Anthropic for the cache window. You can refrain from typing in this field at any time — the rest of the tab works without it.

e) Browser error reporting

If a JavaScript error occurs in your browser on a Seedfor page, the message, page URL, line/column number, and stack trace are submitted to our /api/log-error endpoint. Each payload is capped at 2 KB; per-IP submissions are rate-limited; entries are retained only in Vercel's standard log retention window (see §08).

f) Information we do NOT collect

f) CCPA / CPRA category mapping

For California residents, the personal information described above maps to the CCPA/CPRA statutory categories as follows:

CCPA CategoryCollected?Source
Identifiers (email, IP)YesYou (form), automatically (web server)
Personal records (Cal. Civ. Code §1798.80(e))No
Protected classificationsNo
Commercial informationNo
Biometric informationNo
Internet activity (browser-error events)Yes, minimallyAutomatically, on JS error
GeolocationCoarse (city/country from IP only)Automatically by infrastructure providers
Sensory dataNo
Professional/employmentOnly if you provide it via emailYou
EducationNo
InferencesNo
Sensitive personal information (CPRA)No

04 —How & Why We Use Your Data?

What you can do
• Read the seven specific purposes we use your data for
• Check the explicit list of things we do not do
• Cross-reference each purpose with Section 05 legal bases

Why it helps
Spells out every reason your data is touched, so you can spot anything that does not match what you signed up for.

Purposes of processing

We use personal data for the following purposes only:

We do not:

05 —Legal Bases (GDPR / UK GDPR)

Article 6 grounds

06 —Recipients & Processors?

What you can do
• Inspect the table of processors: Vercel, Beehiiv, Resend...
• Follow the DPA link next to each provider's name
• Read the conditions for authority disclosures

Why it helps
You get a complete map of every third party that ever touches your data, plus the contracts that govern their access.

Who we share data with

We do not sell personal data and do not share it with third parties for advertising or marketing. We disclose personal data only to the service providers ("processors") listed below, each engaged under a written agreement that complies with GDPR Art. 28 and includes EU Standard Contractual Clauses where applicable:

ProcessorRoleLocationReference
Vercel Inc. Web hosting, serverless functions, edge middleware, infrastructure logs USA (with EU PoPs) vercel.com/legal/dpa
Beehiiv Inc. Email-marketing platform; waitlist management; transactional welcome / launch emails USA beehiiv.com/dpa · subprocessors at subprocessors.beehiiv.com
Resend Inc. Transactional email delivery (one-time access codes only) USA resend.com/legal/dpa
Upstash, Inc. (if enabled) Serverless Redis for rate-limit and brute-force counters keyed on IP (no email content) USA / EU regions available upstash.com/trust/dpa.pdf
Intuition Machines, Inc. (hCaptcha) (if enabled) Bot-mitigation CAPTCHA challenge on the access form USA hcaptcha.com/privacy · hcaptcha.com/terms
Google LLC (Google Fonts, Google Workspace) Web-font delivery (fonts.googleapis.com / fonts.gstatic.com); business-email hosting for management@seedfor.io USA / EU workspace.google.com/terms/dpa_terms.html
Anthropic, PBC (Claude API + web-search tool) Returns three strategic use-case bullets when you type a business name into the "Use Case" tab (see §03(d)). Receives the business name plus our server-issued API key — never your email, IP, or any other identifier. USA anthropic.com/legal/dpa · anthropic.com/legal/privacy

We may also disclose personal data:

User-triggered third-party endpoints (no Art. 28 controller / processor relationship)

Certain features on the Website cause your browser to query public third-party APIs directly. These calls are not routed through our servers and we receive no copy of the request or response — but each provider receives your IP address, User-Agent, and the query string you generated. We list them here for transparency. Disclosing your data to them is necessary to deliver the feature you triggered; the lawful basis under GDPR Art. 6(1)(f) is our and your legitimate interest in providing that feature.

ServiceTriggered byWhat is sentReference
Wikimedia Foundation, Inc. (Wikipedia API) Typing in or selecting a business in the BMC composer on the On-Chain MSME page The business name you typed or selected (sent in the URL query string); your IP & User-Agent foundation.wikimedia.org/wiki/Policy:Privacy_policy
OpenStreetMap Foundation (Nominatim geocoding + tile servers) Opening the map pointer on the On-Chain MSME or About page Map viewport coordinates and any free-text search you submit; your IP & User-Agent wiki.osmfoundation.org/wiki/Privacy_Policy
GitHub, Inc. (api.github.com — public commits endpoint) Loading any page on the site (footer reads the last-commit timestamp for transparency) An unauthenticated GET request to the public SeedForMgmt/SeedforW repository; your IP & User-Agent docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
jsDelivr (Prospect One) · unpkg Loading any chart page (Chart.js, chartjs-plugin-annotation, Leaflet are served from these CDNs) The asset URL you requested; your IP & User-Agent. No cookies are set. jsdelivr.com/privacy-policy · unpkg.com

These providers act as independent controllers of any data they collect from your browser. We have no contractual access to that data. You can block the calls at the browser level (privacy extensions, content-blockers, or a custom Content-Security-Policy override in your browser) without affecting the rest of the Website — the affected features will simply degrade gracefully (the BMC composer will fall back to its keyword-only classification path; the map pointer will not load; the footer will display "Last commit: unavailable").

07 —International Data Transfers

Transfers outside the EEA / UK / Switzerland

Several of our processors are located in the United States. When personal data is transferred from the EEA, the UK, or Switzerland to the United States or other third countries, we rely on the following legal transfer mechanisms under GDPR Chapter V:

We have conducted a transfer-impact assessment that considered the legal regime of the destination country, the categories of data transferred, the technical and organisational safeguards in place, and the likelihood of public-authority access requests. Where a transfer-impact assessment identifies risk that cannot be mitigated by contractual measures alone, we apply supplementary measures (such as end-to-end transport encryption, hashed identifiers, minimised payloads, and short retention windows).

You may request a copy of the safeguards applicable to a specific transfer by contacting us at the address in §18.

08 —Data Retention

How long we keep your data

Data categoryRetention period
Waitlist email and consent record (at Beehiiv)Until you unsubscribe, until you request deletion, or up to 24 months after the official public launch of the Seedfor platform — whichever is earliest.
Email correspondence with usUp to 24 months from the date of the last meaningful exchange, unless a longer period is required to defend a legal claim.
Server-side audit and access logs (IP, hashed email, event, timestamp)Maximum 30 days within Vercel's infrastructure logging system, after which they are automatically purged. Not exported, archived, or used for any purpose other than security monitoring.
Browser-error logsSame as above — maximum 30 days.
Rate-limit and brute-force counters (Upstash Redis or memory)Auto-expire 15 minutes after the last increment.
One-time-code session (sf_otp)15 minutes (cookie auto-expires; single-use)
Authenticated session (sf_auth, sf_status)24 hours from issue (or until logout)

09 —Your Rights (EU / UK / Switzerland)?

What you can do
• Request access, rectification, erasure, or restriction
• Ask for portability or object to processing
• Lodge a complaint with your supervisory authority

Why it helps
Lists every GDPR / UK GDPR / FADP right you can exercise, with the contact path to submit each request directly.

Rights under the GDPR, UK GDPR, and Swiss FADP

Subject to applicable conditions and exceptions, you have the right to:

To exercise any of these rights, email management@seedfor.io. We will respond within one month (extendable by two further months in complex cases, per Art. 12(3)). We may need to verify your identity before fulfilling certain requests.

Lead supervisory authority: Garante per la Protezione dei Dati Personali (Italy) — https://www.gpdp.it
You may alternatively lodge a complaint with the authority in your country of habitual residence, place of work, or the place of the alleged infringement.

10 —California Privacy Rights (CCPA / CPRA)

For California residents only

California consumers have the rights described below under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"). The categories of personal information we collect and the sources are set out in §03(f); the business purposes for which we use them are listed in §04; the categories of recipients are in §06.

Your CCPA/CPRA rights

How to exercise your CCPA rights

Email management@seedfor.io with the subject "California Privacy Request". We will verify your identity using information we already hold (typically the email address used to interact with us). We will respond within 45 days (extendable by 45 days on notice). You may use an authorised agent to submit a request; we will require written proof of authorisation.

"Do Not Sell or Share My Personal Information"

We do not sell or share personal information. No "Do Not Sell or Share" mechanism is therefore required; however, if you wish to confirm this preference for the record, email us at the address above.

Global Privacy Control (GPC)

Because we do not engage in sale or sharing of personal information, GPC signals received from your browser produce no operational change. We honour user preferences as a matter of policy.

"Shine the Light" disclosure

Under California Civil Code §1798.83 ("Shine the Light"), California residents may request a list of the personal information disclosed to third parties for those third parties' direct-marketing purposes during the prior calendar year. We do not disclose personal information to third parties for their direct-marketing purposes.

Notice of financial-incentive programmes

We do not offer financial incentives or price/service differences based on the collection or sharing of personal information.

11 —Other US State Privacy Rights

VCDPA (VA), CPA (CO), CTDPA (CT), UCPA (UT), and similar state laws

If you are a resident of Virginia, Colorado, Connecticut, Utah, or another US state that has enacted a comprehensive consumer-privacy law (including, where applicable, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Minnesota, Tennessee, Indiana, and Kentucky), you may have the following rights, subject to that state's specific definitions, thresholds, and exceptions:

To exercise these rights, email management@seedfor.io with the subject "US State Privacy Request" and identify your state of residence. We will respond within the timeframe required by that state's law (typically 45 days). If we deny a request, you may appeal by replying within a reasonable time, and we will reconsider and respond within the period required by your state's law. Where your state offers a right to complain to the state Attorney General, instructions will be provided in our response.

12 —Cookies, Local Storage & Tracking

Strictly necessary technologies; no advertising trackers

The Website does not use advertising, analytics, or cross-context behavioural-tracking cookies, and does not load Google Analytics, Meta Pixel, TikTok Pixel, or similar trackers. We therefore do not display a cookie-consent banner: under Article 5(3) of the ePrivacy Directive, cookies and similar technologies that are strictly necessary to provide a service requested by the user are exempt from prior-consent requirements.

a) First-party HTTP cookies

NamePurposeDurationHttpOnly?
sf_otpSigned token holding the one-time access code, used to verify the code you type. Single-use and cleared the moment a valid code is verified.15 minutesYes
sf_authSigned JWT confirming a valid authenticated session; verified by edge middleware on every gated page24 hoursYes
sf_statusUI signal (value 1) so the client knows a valid session exists; carries no personal data24 hoursNo (intentionally readable to JS for UI)

All three cookies are Secure and SameSite=Strict. They are strictly necessary to provide the authenticated management portal.

b) Browser localStorage (strictly necessary, on-device)

Local-storage values remain on your device, are not transmitted to any server, and are cleared when you clear site data in your browser.

KeyPurpose
sf_logoutTimestamp written on logout; signals other tabs of the same browser to terminate the session.
sf_wip_unlockFlag indicating the in-progress / coming-soon overlay has been dismissed.
sf_demoFlag indicating demo mode is active (staging environments only).
sf_guest_sessionFlag indicating an unauthenticated "guest" view on the DAO page; contains no personal data.
sf_biz, sf_geo, sf_sector, sf_sizeFilter and search preferences (business name typed into the search, geography/sector/size filter selections).
sf_biz_facet, sf_facet_user, sf_facet_credit, sf_facet_chain"Use Case" tab state on the homepage hero — the business name typed into the optional field plus the three slider positions (user-type, credit-type, blockchain-integration). Used to restore your tab state across reloads. Session-scoped sibling keys with the prefix sf_biz_research: cache the bullet output from /api/biz-research for 1 hour so retyping the same name is instant and does not re-hit the endpoint.
sf_biz_live, sf_biz_name, sf_biz_bmc_html, sf_biz_bmc_legend, sf_biz_sdg_html, sf_biz_sdg_legend, sf_biz_kpi, sf_biz_tokens_html, sf_biz_groupsDrafts of the business-model canvas, SDG canvas, KPIs, tokens, and grouping you have authored on the business page; kept locally so your work is not lost on reload.
sfd_biz_clusterSelected business-cluster configuration (geography/sector/size) on settings and business pages.
sfd_kyc_status, sfd_kyb_statusLocal indicator of where you are in the (placeholder) KYC/KYB workflow. No identity documents are processed at this stage; values only reflect "unverified" or "pending".
sfd_investor_classLocal indicator of your professional / qualified-investor status. Used to gate access to Seedfor's own tokens (SfC / SdT / SfT), which are offered solely to qualified investors. Placeholder pre-launch — no documents are processed at this stage; values only reflect "unverified", "pending" or "qualified".
sfd_ai_keyAn AI API key you may optionally paste into the settings page to enable optional AI-assisted features locally. This key is stored only on your device and never transmitted to our servers. You may delete it at any time by clearing site data or by emptying the field in settings.
sfd_bg_projects, bmcFormSavedDrafts of saved business-page projects and form state.
sfToken, sfMQRCodesToken-related identifiers and QR codes generated locally for demo/preview purposes.
sf_sft_addrLast-connected MetaMask wallet address (shortened & full). Stored only after the user explicitly clicks Launch App → Connect Wallet → MetaMask; used to optimistically paint the in-nav SfT badge on cross-page navigation. Cleared on disconnect.
sf_pg_rd_what, sf_pg_rd_why, sf_pg_sells, sf_pg_buys, sf_pg_mkt_lend, sf_pg_mkt_borr, sf_pg_mkt_back, sf_pg_mkt_acrb, sf_pg_val, sf_pg_fcstPer-table pagination state ({expanded, page}) so the 5/20-per-page view you chose on each entity table persists across reloads and navigation.
sf_bizrow_visible_land1Whether the under-header business-search row on the homepage is expanded. Toggled by double-clicking the logo.
sf_demo_exitPer-tab flag that records the user has explicitly exited demo mode.
sf_msel_geo, sf_msel_sec, sf_msel_size, sf_msel_wGeo, sf_msel_wSec, sf_msel_wSz, sf_msel_whyGeo, sf_msel_whySector, sf_msel_whySize, sf_msel_globalGeo, sf_msel_globalSector, sf_msel_globalSzPer-chart multi-select filter selections so the chosen Geography / Sector / Size clusters persist across reloads.
sf_why_version, sf_what_version, sf_where_version, sf_who_versionThe model-data version (e.g. v3.99.7, SeedforV2a) the user picked in the Dataroom for each chart page. The chart pages read these so they render the calibrated dataset the user selected.
sf_what_frameworkThe active modelling framework on the Risk Transfer chart (e.g. BaselP1, SeedforV1, SeedforV2a, SeedforV2b, SeedforV3). Drives the formula used to compute the Excess Credit Premium and tail-risk numbers shown.
sf_why_series_state, sf_what_series_state, sf_where_series_statePer-chart legend memory recording which series (and which states — line only, line+band, or hidden) you toggled, so the chart restores your view on reload.
sf_why_active_set, sf_what_active_set, sf_where_active_set, sf_who_active_setPer-chart memory of the active multi-cluster set you assembled, so the chart restores the same combination across reloads.
sf_why_pinned, sf_ww_pinnedThe single cluster you "pinned" on the Credit Access or Risk Transfer chart so a focused detail card persists across reloads.
sf_user_email, sf_logged_in, sf_wallet, sf_bizrow_visibleUI-only signals for the access portal — they record (locally) the email you typed into the access form, whether a valid authenticated session exists, an optional placeholder wallet identifier you supplied, and whether the "business search" row is unhidden. No identity verification occurs at this stage.
sfd_bmc_corpus, sfd_cashflow, sfd_defi_flows, sfd_esg_scores, sfd_fundraise, sfd_nft_traits, sfd_sbt_meta, sfd_sdg_mapping, sfd_sector_bench, sfd_strategy, sfd_txn_sme, sfd_wallet_profiles, sfd_settings_panel, sfd_sycr_alerts2, sfd_wall_load_projectDraft / placeholder content for the pre-launch demonstration pages (Settings, Marketplace, DAO, Lending Market, AI Marketplace, On-Chain MSME). These keys hold mock data you author or load while exploring the demo — they never leave your browser.
sf_dr_uid_v1, sf_dr_uid_v1_nameA pseudonymous identifier (e.g. r3a7b2) and a derived "Researcher #" handle assigned to your browser so your Flag-a-bug votes and comments are not double-counted. Not linked to any account.
sf_dr_flags_v1Local Flag-a-bug "Discussion" thread for the four chart datasets — your draft + posted flag content, comments, and like/dislike votes. Stored only on your device; no server roundtrip. See §19 below for how this changes when an intake pipeline goes live.
sf_gh_commit_v1Cached GitHub last-commit timestamp shown in the footer (10-minute TTL). Holds only a date string; no identifiers.
sf_wip_unlock, sf_statusUI signals for one-time "Continue past warning" actions and authenticated-session presence.
sf_srt_feedbackFree-text feedback you optionally type into the homepage "SRT journey" explainer (the Risk-transfer decision-tree pop-up), with the choice you selected and a timestamp. Stored only on your device; no server roundtrip. Same treatment as Flag-a-bug (§19) — there is no backend, so it is never sent to Seedfor.

If a future feature requires non-essential storage or tracking, we will implement a granular consent mechanism (GDPR Art. 7 / ePrivacy Art. 5(3)) before any such storage is performed, and update this Notice.

How to clear stored preferences. You can delete every key listed above at any time by clearing site data in your browser (in Chrome / Edge: Settings → Privacy and security → Site settings → View permissions and data stored across sites → seedfor.io → Clear data; equivalent paths exist in Firefox and Safari). The Dataroom (tools/chart-csv.html) also exposes a Reset stored preferences button that wipes only the sf_* keys belonging to this Website and reloads the page.

c) Third-party scripts and iframes

d) Content Security Policy

The Website serves a strict Content-Security-Policy that restricts script, style, image, font, and frame sources to those listed above, prevents framing of the site, and forbids embedded objects.

13 —Security

Technical and organisational measures (GDPR Art. 32)

We implement, and require our processors to implement, technical and organisational measures appropriate to the risk, including:

In the event of a personal-data breach affecting EU/UK residents likely to result in a risk to their rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware (GDPR Art. 33). Where the breach is likely to result in a high risk, affected users will be notified without undue delay (Art. 34). US state-law breach-notification timelines will be followed where applicable.

14 —Children

Minors and age restrictions

The Website is not directed at, and we do not knowingly collect personal data from, individuals under 18 years of age. In the United States, the Website is also not directed at children under 13 within the meaning of the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§6501–6506). If you believe we have inadvertently processed personal data of a minor, contact management@seedfor.io and we will delete it promptly.

15 —Automated Decision-Making & Profiling

We do not engage in automated decision-making — including profiling — that produces legal or similarly significant effects on you within the meaning of GDPR Art. 22 or analogous US state-law provisions. CAPTCHA bot-detection, where enabled, applies a heuristic only to the immediate access request; no profile is built or stored.

AI-assisted classification and generation

Several pre-launch features apply automated classification or text generation. None of these features makes a decision with legal or similarly significant effect on you, and you can override or ignore the output at any time:

None of these features produces legal effects, financial obligations, or credit-eligibility determinations. They support exploration and discussion — they are not regulated assessments and should not be relied on as such. See §20 (Risk Disclosures) below.

16 —Future Web3 Features

Wallet addresses, on-chain data, and tokenisation

Seedfor is developing a Web3 platform that, at launch, may involve interactions with public blockchains, wallet addresses, and tokenised credit instruments. Under European Data Protection Board guidance, wallet addresses are considered personal data when combined with other information. Smart-contract interactions are recorded on public, immutable ledgers.

A dedicated and additional privacy notice will be published before any such processing begins. It will describe: (a) how blockchain data is processed; (b) the legal basis; (c) limitations arising from blockchain immutability and the practical limits of the GDPR rights to erasure and rectification in that context; and (d) how risks are mitigated (off-chain storage of personal data, pseudonymisation, hashed identifiers).

No blockchain-related personal data processing occurs at the current pre-launch stage.

17 —Changes to this Notice

We may update this Notice to reflect changes in our practices, our processors, or applicable law. The "Effective date" at the top of this Notice indicates the most recent revision. Material changes will be communicated to waitlist subscribers by email and, where required by applicable law, with prior notice and a renewed consent mechanism. Continued use of the Website after the effective date constitutes acceptance of the revised Notice to the extent permitted by law.

18 —Contact & Complaints?

What you can do
• Email the privacy address with rights or consent requests
• Withdraw consent or unsubscribe from launch updates
• Escalate to a national data-protection authority if needed

Why it helps
Provides a single, monitored contact channel so any privacy concern reaches the right person and gets a timely response.

For any privacy enquiry, to exercise your rights, or to raise a concern:

Email: management@seedfor.io
Postal address: will be published once Seedfor is incorporated; until then, contact by email.

If you are not satisfied with our response, you may lodge a complaint with the supervisory authority or attorney general of your jurisdiction (see §09, §10, §11).

19 —User-Submitted Content (Forward-Looking)

Dataroom uploads, Flag-a-bug discussions, and similar contributions

The Website contains a few channels through which you may submit material to Seedfor. At the current pre-launch stage, none of them is wired to a backend — your submissions stay in your browser's localStorage (Flag-a-bug discussions, and the homepage "SRT journey" feedback) or in the file picker dialog (Dataroom upload) until you explicitly forward them to us by email. This section describes both the current behaviour and the forward-looking framework that will apply once the intake pipelines go live.

a) Dataroom dataset uploads

Each chart card in tools/chart-csv.html exposes an Upload dataset (JSON / CSV) button. Today the button stages the file in the browser, shows a confirmation listing the filename and size, and asks you to email the file to management@seedfor.io with a chart-specific subject. The file is not transmitted anywhere by the Website itself.

By emailing a file to us — or, in the future, by submitting it through an in-app intake pipeline — you confirm that (i) you have the right to share the data (it is yours, public, or licensed for redistribution); (ii) the file does not contain personal data of identifiable third parties; (iii) the file does not contain copyrighted extracts from paywalled commercial sources (S&P, Bloomberg, Cerved, Messari, MSCI subscription products, etc.) that you are not authorised to redistribute; (iv) the file does not contain material non-public information about identifiable companies; and (v) you grant Seedfor a non-exclusive, royalty-free, worldwide licence to use the data for calibration of the chart-data files described in §15 of this Notice. We do not republish raw uploads — only derived multiplier values aligned to the published methodology — and we identify the source publicly only in the chart's references file (so attribution is preserved). You may request deletion of an upload at any time by emailing the same address.

b) Flag-a-bug discussions

Each chart card in the Dataroom carries a Flag a bug button that opens a per-section discussion thread. Today every flag, comment, like and dislike is written only to localStorage on your device (key sf_dr_flags_v1, see §12). No data is sent to Seedfor's servers. The discussion thread is therefore visible only to your own browser. The "Researcher #" handle and the underlying pseudonymous identifier in sf_dr_uid_v1 are generated locally and not linked to any account.

Before any Flag-a-bug intake goes live with a backend — which would mean your submissions are sent to Seedfor and could be displayed to other users — we will publish (and link from the Dataroom) a short Contributor Notice covering: the licence grant you provide to Seedfor for the submitted content; our right to remove content that violates law, third-party rights, or community standards; the takedown / notice-and-action procedure (including a contact channel for IP-rights claims and a request-for-removal channel for content concerning you personally); and the moderation criteria we apply.

c) Right of removal

For any content you have already shared with us by email under (a) above, you may request its removal at any time at management@seedfor.io. We will action the request within a reasonable period and, where the content has been incorporated into the calibration data, we will note the removal in the chart's audit log without disclosing your identity.

20 —Risk Disclosures — Use of the Charts & Data

What the published values are, and what they are not

The four charts on the Website (Credit Access, Risk Transfer, Risk Forecast, On-Chain MSME) and the underlying datasets in /data/ are published for transparency, educational and discussion purposes. To avoid any misunderstanding about the legal status of these outputs:

By using the Website you acknowledge the limitations described in this section.

← Back to Seedfor